< ciso
brief />
Tag Banner

All news with #incident response tag

305 articles

CISA Endorses Cyber Decoys; FortiDeceptor 6.3

🛡️ CISA published guidance on Using Cyber Decoys to Strengthen Detection and Response, urging an assume-breach posture and use of honeypots, honeytokens, breadcrumbs, and tripwires. FortiDeceptor implements these concepts with decoy VMs, centralized lure management, and integration with the Fortinet Security Fabric. Version 6.3 expands decoy coverage to GitLab, IoT printers, and cloud connectors for S3, GitHub, and SharePoint, and supports automated response workflows.
read more →

Gartner’s ISOC: A New Layer for Security Ops

🔒 Gartner introduced the Integrated Security Operations Center (ISOC) category to address the limits of traditional SIEMs by unifying detection, investigation, case management and response. ISOC emphasizes native detection and response, centralized data ownership, persistent incident case objects and cross-domain correlation to reduce latency and operational friction. The aim is streamlined workflows and lower costs for lean security teams confronting AI-accelerated threats.
read more →

UK schools improving incident recovery but gaps persist

🔒 New government data shows UK schools are recovering faster from cyber incidents, with the proportion experiencing incidents falling from 34% to 27% over three years. Two-thirds (66%) of schools can now recover immediately, up from 55%, and critical damage has dropped to 7%. However, many institutions still treat cybersecurity as an IT-only issue and nearly half of schools have yet to implement essential protections like policies, risk assessments and backups.
read more →

Kiteworks advises temporary shutdown after threat

🔒 Kiteworks has advised customers to shut down their systems for a nine-hour window this weekend after receiving credible threat intelligence of an imminent cyber attack. The company said the advisory is preventative, with no evidence yet of customer compromise, and that customers were notified directly. Kiteworks recommends applying the latest 9.5.1 patches and noted several subsidiaries are not affected.
read more →

Most Organizations Haven’t Rehearsed AI Incident Response

🛡️ New research reveals that most organizations have not rehearsed responses to AI-related security incidents. ISACA's 2026 State of Cyber report found 71% have not run AI incident response exercises and only 3% maintain mature, formal runbooks for AI incidents. Adoption of AI in security is rising, while governance, training and preparedness lag behind.
read more →

CISOs Urged to Update Playbooks for Deepfakes

🔒 The Gartner report reveals nearly half of CISOs experienced at least one deepfake incident in the past year, underscoring the need to update incident response playbooks for multimodal threats. Surveying 297 senior cybersecurity leaders between March and May 2026, the study found AI is increasing volume, personalization and credibility of social engineering while weakening traditional detection cues. Recommendations include shifting verification-focused culture, protecting high-value workflows with phishing-resistant controls, and correlating impersonation reports with account and transaction events.
read more →

Defender’s Window: Turning AI Parity into Security Capability

🔒 The author argues that the Cyber AI Parity Window—when defenders and attackers gain similar AI capabilities simultaneously—has narrowed into a timebound "defender's window." Organizations must rapidly convert access to AI into operational capability by automating safe workflows, measuring performance, and defining authority for machine-speed responses. The piece urges CISOs to redirect human effort toward proactive defense, detection engineering, and continuous improvement.
read more →

Revoking Tokens May Not Evict Cloud‑Backdoor Actors

🔐 The author dissected GraphWorm, a OneDrive‑based backdoor used by the Webworm APT, and found revoking tokens often fails to remove access. The implant authenticates as an OAuth application with embedded credentials and polls a OneDrive folder for tasks, allowing operators to replace credentials remotely. Because the registration itself is durable and the implant identifies hosts by hardware fingerprints, simple token revocation or network changes do not reliably contain the threat. The piece recommends treating application registrations as primary targets for response and hunting in cloud identity telemetry.
read more →

US agencies investigate cyber intrusion on supertanker

🚢 The US Coast Guard and FBI boarded the Liberian-flagged VL Prosperity after indications its network may have been compromised during a voyage from Egypt to Galveston. The alleged intrusion reportedly affected fuel systems, engine speed and communications for about 30 hours before a specialised team spent four days eradicating the threat. Authorities report no injuries or environmental impact while urging stronger cyber hygiene and network segmentation.
read more →

SMBs Must Accelerate Cyber Readiness Amid AI Risks

🔒 AI is accelerating both the scale and speed of cyberthreats, expanding attack surfaces as businesses rush to adopt the technology. SMBs need security that is simple to operate, combines AI-driven automation with human oversight, and aligns with business outcomes. Effective partnerships and prevention-centric, as-a-service models help smaller teams detect, contain and recover from incidents while minimizing operational disruption.
read more →

Cloud reliability incident handling best practices

🔧 This blog summarizes Google Cloud’s recommended “Verify→Investigate→Report→Resolve→Review” workflow for handling reliability incidents and advises preparing in advance by designing for failure, ensuring observability data, maintaining playbooks, and running drills. It distinguishes how to detect incidents via Personalized Service Health, Cloud Service Health, and observability tools, and provides guidance on scoping blast radius, diagnosing causes, and when to open and escalate support cases. It also covers mitigation steps while waiting for resolution and emphasizes blameless post-mortems to improve future response.
read more →

Most Organizations Fail Ransomware Recovery Tests

🔍 Only four of over 800 clients assessed by Fenix24 approached their 24–48 hour ransomware recovery targets and then only for partial operations. None achieved full capacity until weeks later. The firm’s State of Recoverability report, covering 500+ ransomware recoveries published on September 15, highlights routine failures in identity recovery, Active Directory compromise, inadequate backups, and overlooked physical constraints like storage and network. Fenix24 urges organizations to map critical dependencies and run end-to-end restore tests.
read more →

AI Exposes Outdated Security Structures

🔒 Organizations are investing heavily in security but remain stuck in compartmentalized models built for yesterday’s threats. AI-driven impersonation, deepfakes and automated social engineering now traverse digital, physical and operational boundaries, demanding cross-functional verification and unified response pipelines. Without documented processes and integrated tooling across cybersecurity, physical security, HR and legal, response efforts rely on informal relationships and risk critical delays. The next evolution requires threat-driven, integrated programs that pair AI capabilities with human expertise to detect, deter and respond faster.
read more →

Webinar: Malicious OAuth Apps and Google Workspace Risk

🔒 On September 23, 2026, BleepingComputer and Material Security will host a live webinar, "Breach autopsy: How fast-growing companies are breached through Google Workspace," examining two incidents involving malicious OAuth apps and social engineering. Speakers Rajan Kapoor and Rick Fitzgerald will explain how attackers persuade users to grant app permissions and how that access can be abused. The session will cover detection, response, and prioritized security controls for resource-constrained organizations.
read more →

Exchange Online outage triggers email delays

📧 Microsoft is investigating an Exchange Online outage (EX1467029) that began at 02:19 AM EDT and is causing intermittent "Server busy" errors for users sending to and receiving from external domains. The company noted anti-spam protections may be aggravating delays for a subset of accounts and said it is analysing service telemetry to identify the root cause. No timeline for full remediation or affected regions and user counts have been provided.
read more →

Democratization of Cyber Warfare and CISO Implications

🛡️ AI is rapidly lowering the barriers to sophisticated cyber operations, enabling individuals and small groups to perform attacks that once required significant resources and expertise. The article describes real-world examples—from autonomous AI-driven attacks in Taiwan to Claude Code use against private firms—and warns that defenders cannot rely solely on human analysts. Organizations must adopt AI-enabled defense with clear intent and guardrails, allowing systems to act at machine speed while preserving human oversight.
read more →

Incident response guide for AWS CloudTrail

🔍 This guide from the AWS Security Incident Response Team explains how to analyze AWS CloudTrail events to investigate cross-account unauthorized access, cryptocurrency mining deployments, and AI service abuse. It walks through real-world scenarios showing which CloudTrail fields matter, how to interpret session metadata, and investigative techniques for reconstructing activity timelines and assessing blast radius. The guide emphasizes practical steps to prioritize containment, identify misconfigurations such as overbroad cross-account roles or missing MFA, and extract evidentiary details from CloudTrail and related logs.
read more →

Fortinet and FIRST Strengthen Global Cyber Resilience

🔒 Fortinet’s partnership with the Forum of Incident Response and Security Teams (FIRST) advances global cyber resilience by combining FortiGuard Labs’ threat intelligence with FIRST’s incident response network. CORE, a 2025 initiative co-founded by Fortinet, funds capacity building, regional training, and tabletop exercises to close skills gaps and improve cross-border coordination. This collaboration also supports standards like EPSS and CVSS to turn shared practices into operational defenses.
read more →

Thomson Reuters C‑Track Breach Impacts Courts in US and Canada

🔍 Thomson Reuters disclosed a cybersecurity incident affecting its C-Track court management software, detected on June 30, that resulted in unauthorized access to court records in Canada and multiple US jurisdictions. An investigation found files tied to three Ontario courts and appellate courts in 11 US states and the US Virgin Islands may have been exposed, potentially including names, identification numbers and medical information. Thomson Reuters and affected courts say some redacted or sealed content may be impacted; investigations continue and there is no evidence of financial systems being affected or misuse of the data to date.
read more →

First 24 Hours of an AI Agent Security Incident

🛡️ Most published AI agent guidance focuses on taxonomies and governance that are useful for briefings but unhelpful during an active incident. The author outlines an hour-by-hour operational playbook for when an autonomous agent is compromised: recognize abnormal agent behavior, revoke identity credentials, freeze memory and logs, map the blast radius, notify stakeholders early, reconstruct the agent’s decision chain, and avoid restoring the original configuration without hardening. The piece emphasizes containment by identity, rapid evidence preservation, and rehearsed tabletop exercises.
read more →