< ciso
brief />
Tag Banner

All news with #incident response tag

281 articles

CISO View: Security Fundamentals in the AI Era

🔒 Chris Betz argues that as AI amplifies both attacker and defender capabilities, organizations must reinforce core security controls rather than abandon them. He emphasizes layered defenses—MFA, Zero Trust, patching, and detection and response—and describes how AI accelerates vulnerability discovery, threat modeling, and remediation. CISOs should combine technical rigor with strategic leadership to align security with business goals.
read more →

Critical Zimbra RCE Flaw Actively Exploited Now

🛡️ CERT Polska warns that attackers are actively exploiting a critical Zimbra Collaboration Suite vulnerability (CVE-2026-73570). The flaw, patched in Zimbra 10.1.20 on July 20, enables unauthenticated remote code execution via command injection in the SNMP notification processing when SNMP notifications are enabled. Shadowserver reports over 12,100 Zimbra servers exposed online, and administrators are urged to check logs and specific directories for signs of compromise. Zimbra has been a frequent target of APT groups in past campaigns.
read more →

Agentic AI Enhances Operational Resilience in Banking

🤖 Deutsche Bank partnered with Google Cloud to build an agentic AI-driven resilience platform that modernizes regulatory tabletop exercises and incident analysis. The platform ingests architecture, logs, data flows, and telemetry to generate context-aware scenarios, audit-ready evidence, and structured session records. Using Gemini Enterprise Agent Platform, LangGraph, and Google ADK, the bank achieves both deterministic, traceable execution and adaptive investigation. This approach supports continuous, regulator-aligned resilience across complex, distributed systems.
read more →

UT San Antonio IT Systems Taken Offline After Incident

🔒 The University of Texas San Antonio took several IT systems offline after detecting attempted unauthorized activity at the network edge, prompting containment measures by University Technology Solutions and partners. Officials say there is no evidence of data access or exfiltration so far, though the outage disrupted online registration, tuition payments and phone systems ahead of term start. Students were granted extensions and instructed to reset passphrases as remediation steps continue.
read more →

Early breach communications can destroy legal protections

🛡️ During the chaotic first 24 hours after a cyber incident, teams often communicate in ways that later become damaging evidence. Operational notes, Slack messages and emails— even if legal is copied—may not be privileged unless their predominant purpose was legal advice. Courts scrutinize whether communications were created for legal counsel or for ordinary business operations, and widespread channels or AI tools that share data externally can undermine privilege.
read more →

How the CISO Role Will Evolve by 2029

🔐 Security leaders predict that by 2029 the CISO will shift from a primarily technical defender to a strategic business leader. Experts foresee CISOs enabling innovation, advising executives on risk, and coordinating enterprise-wide trust and resilience efforts while adapting to AI-driven speed and complexity. The role will vary by organization but will demand stronger business acumen, orchestration skills, and continuous validation of exposure.
read more →

Reframing cyber backlogs: roles, priorities, and outcomes

🔍 Security teams should oversee risk rather than perform every remediation task. Assign clear roles: security maintains the authoritative risk inventory, prioritizes findings, escalates missed commitments and verifies closure, while infrastructure, cloud, application and business owners execute fixes. Executives resolve resource conflicts and accept residual risk. Backlogs typically reflect organizational failures in ownership, capacity and decision-making rather than purely technical deficiencies.
read more →

Delta investigates in-flight Wi‑Fi deauth and rogue AP

✈️ Delta Air Lines is investigating an unauthorized Wi‑Fi network that briefly appeared aboard Flight 591 from Las Vegas to Atlanta, carrying passengers who attended DEF CON 34. The carrier said the incident did not affect passenger safety or aircraft systems and that cabin crew disabled Wi‑Fi for about 30 minutes while authorities investigate. Federal law enforcement and aviation regulators will be involved in the probe.
read more →

Security leaders confident but unprepared for rogue AI

🔒 A majority of IT and security leaders say they can detect malfunctioning AI agents, but few can trace and mitigate downstream impact quickly. A WanAware survey found 90% confident in detection while only 26% can trace impacts within minutes, and over 45% say it would take hours. Experts warn agents act at machine speed, spread via shared credentials and multiple platforms, and require built-in identities, narrow permissions, audit trails, and hard kill switches to contain incidents.
read more →

Identity-Driven Attacks and SOC Response Trends

🔐 Unit 42 finds identity compromises underpin most modern incidents, with the 2026 Global Incident Response Report showing identity weaknesses in nearly 90% of investigations and 65% of initial access events. Attackers increasingly use phishing, social engineering, MFA manipulation and third-party account misuse to gain entry, then move laterally, escalate privileges and blend into administrative behavior. Unit 42 recommends correlating identity, endpoint, cloud and network telemetry, applying AI-driven correlation and centralized investigations, and investing in continuous threat hunting and SOC engineering to detect and contain identity-driven intrusions earlier.
read more →

Levi Strauss reports corporate data theft after breach

🔒 Levi Strauss & Co. disclosed that attackers used social engineering on three employees to access company-issued machines and exfiltrate corporate data. The company says rapid response contained the intrusion and no consumer data was impacted, with no disruption to business operations. An investigation is ongoing and Levi’s will provide additional notifications as required; some reporting links the incident to voice-phishing campaigns.
read more →

Microsoft Defender: Device Isolation Stops Ransomware Fast

🚨 Microsoft Defender’s attack disruption now includes device isolation, an automated response that isolates compromised endpoints. At QNET, Defender detected a multi-stage attack using mshta.exe and enforced isolation within 128 seconds, blocking a second-stage payload and preventing persistence or lateral movement. This action is AI-driven, time-limited, operator-controlled, and designed to work with user containment to reduce risk and speed SOC response.
read more →

Talos webinar: Q2 incident briefing for security teams

📢 Next Tuesday, August 11, Cisco Talos Incident Responders will host a 30-minute, unrecorded webinar reviewing high-impact incidents from Q2 2026. The session will candidly cover timelines, containment, and remediation efforts rather than repeating the published trends report. Designed for security professionals at all levels, it emphasizes strategic takeaways, business impact, and enough technical detail to inform discussions. Registration is required to attend this exclusive briefing.
read more →

Analog Devices reports system breach but operations steady

🔒 Analog Devices disclosed unauthorized access to some corporate systems discovered on June 23, 2026, and said it activated incident response procedures and engaged external cybersecurity experts. The company reported no evidence so far of leaked or fraudulently used data, informed law enforcement, and will notify affected parties and regulators. Analog Devices stated business operations remain unaffected and it does not expect a material impact on its finances; an unrelated cybersecurity matter and claims by the data extortion group ExfilSquad were also noted and are under assessment.
read more →

Humans of Talos: Black Hat special rewind

🎙️ Amy revisits past guests in a special Black Hat edition of Humans of Talos, exploring the varied career paths that led them to threat intelligence. From forensic labs and newsrooms to kitchen lines, the episode highlights personal stories and lessons that shape the field. Attendees can meet the team at Cisco and Splunk booth 2633 during Black Hat to discuss research and incident response and pick up the latest Snorty.
read more →

Cisco warns of FMC static credential zero-day exploit

🔒 Cisco warns that a high-severity static credential flaw in Secure Firewall Management Center (FMC)—tracked as CVE-2026-20316—has been actively exploited in zero-day attacks to gain unauthorized access. The flaw stems from built-in static credentials for a low-privilege account, enabling unauthenticated remote login and access to account data. Cisco released hot fixes for multiple FMC releases and advises installing them immediately, noting no effective workarounds and recommending credential rotation if compromise is detected.
read more →

Survey Finds Major Gaps in Incident Response Readiness

🔍 New research shows that despite tools and teams, many organizations lack the coordination, visibility, and executive alignment to handle major cyberattacks effectively. The Vanson Bourne survey of 600 security leaders found 73% would not be "fully ready" for a significant incident and 76% experienced at least one attack in the past year. Key issues include stakeholder friction, blind spots across IT/OT/cloud, and delayed legal and communications involvement. The report recommends clearer decision rights, cross-functional exercises, validated visibility, measured AI adoption, and reassessment of external support.
read more →

NCSC issues guidance for disruptive cyber incidents

🛡️ The UK's National Cyber Security Centre (NCSC) has published What To Do When Cyber-Attacks Disrupt Your Organisation, outlining three chronological stages for response: immediate hours and days, recovery to minimum viable operations, and longer-term restoration to business as usual. The guidance emphasizes preparing in advance, practicing realistic simulations, and engaging NCSC-vetted incident response firms to build resilience against escalating threats such as AI-accelerated attacks.
read more →

CubePilot suffers DNS hijack disrupting drone services

🛡️ CubePilot, an Australian drone flight-controller maker, reported a DNS hijacking on July 24 that redirected traffic to attacker-controlled infrastructure and allowed issuance of TLS certificates for all cubepilot.org subdomains. The firm regained domain control the same day, revoked the fraudulent certificates, preserved evidence, and informed authorities. Critical services including OEM portals, the community forum, and documentation remain offline while the company investigates and advises caution around credentials and recent firmware downloads.
read more →

Guidance for isolating critical infrastructure OT

🔒 New joint guidance from U.S. and Australian cybersecurity agencies, including CISA and the ACSC, advises critical infrastructure operators to prepare to isolate vital operational technology systems during cyber incidents. The document defines concepts like vital systems, isolation points, and graduated versus physical isolation, and stresses planning, documentation, and regular testing. It highlights trade-offs, operational impacts, and the need to maintain manual operations and secure offline plans.
read more →