< ciso
brief />
Tag Banner

All news with #incident response tag

281 articles · page 2 of 15

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

Enterprise resilience and toolchain security insights

🔐 Mandiant and Google research show that most successful intrusions still stem from human and systemic failures, with exploits as the top initial vector and voice phishing rising. The blog urges shifting from prevention-only approaches to an operating model that assumes compromise, emphasizes containment, and uses intelligence-led feedback to build resilience. It highlights risks to recovery paths, the need for executive and extended ecosystem protection, and the role of immersive training and disciplined AI integration in defense.
read more →

The containment paradox in ransomware response

🔒 This article examines a recurring operational gap in ransomware incident response: SOC analysts often have the authority to isolate systems, but business owners hold accountability for service availability. It argues that isolation can itself become the damage when applied to business-critical systems and proposes a governance-based remedy: a no-touch register tied to a RACI model and time‑boxed escalation with pre-agreed safe-state fallbacks. The piece rebuts the objection that operational vetoes slow response by showing how narrow, timed vetoes protect crown-jewel services without paralyzing detection and containment.
read more →

CISOs Rising to Lead Business Resilience

🔒 CISOs are increasingly acting as de facto chief resilience officers, expanding from prevention to incident response and recovery. Experts recommend framing resilience in business terms — uptime, data protection, and financial impact — to secure board-level buy-in and funding. Practical steps include defining minimum viable operations, rehearsing recovery through a "ResOps" approach, and partnering with GRC, finance, and operations to share responsibility.
read more →

Microsoft 365 outage blamed on maintenance bug

🔧 Microsoft attributed the large July 23 outage to a bug in its automated network maintenance request system that removed IP routes from more devices than intended, disrupting Azure and Microsoft 365 services, especially for customers routed through the West US region. The incident began at 10:44 AM ET and was resolved after a rollback completed at 2:26 PM ET, with full recovery of all services by 3:41 PM ET. Microsoft is conducting a full internal review and will publish a final post-incident report.
read more →

Cisco Talos preview at Black Hat USA 2026

🎤 Talos will be present at Black Hat USA 2026 across the Cisco and Splunk booths to discuss threat research, incident response, and how Talos powers the Cisco security portfolio. The team will deliver lightning talks, a Main Stage keynote on securing enterprises in the age of AI agents, and hands-on workshops demonstrating AI-driven SOC workflows and the Foundry Security Spec. Attendees can also learn how Talos is embedded across Cisco products and view the new “Where Protection Starts” video.
read more →

Microsoft and AXA XL Enhance Incident Response

🔒 Microsoft and AXA XL have partnered to provide AXA XL policyholders direct access to Microsoft Defender Experts Cybersecurity Incident Response, aligning technical, legal, and insurance workflows during incidents. The collaboration emphasizes pre-established coordination, proactive planning, and first‑party threat intelligence to accelerate containment and recovery. Together they aim to reduce friction and delays in high‑stakes cyber events.
read more →

AI-Driven Breaches Force Rethink of Incident Response

🛡️ Enterprises face a new class of attacks as threat actors leverage AI agents to automate entire intrusion chains, dramatically compressing the time from initial access to deep compromise. Reports from Sygnia and Sysdig document AI-enabled campaigns that harvest credentials, map services, and persist across cloud environments, often exploiting known vulnerabilities rather than zero-days. Experts warn that traditional, human-speed incident response and hunting are often too slow, and emphasize the need for integrated, AI-assisted defenses and rigorous hygiene: fast patching, secrets rotation, least privilege, segmentation, and automated response playbooks.
read more →

Japan’s largest taxi operator halts systems after attack

🚨 Nihon Kotsu, Japan's largest taxi and chauffeur operator, has shut down parts of its IT infrastructure after detecting unauthorized external access and a malware infection early Saturday. The outage has affected the taxi dispatch system, web booking, reservation management, phone dispatch services, and some internal systems, leaving key services offline while the company investigates. Nihon Kotsu has engaged external cybersecurity experts, warned customers to avoid suspicious attachments and links, and has not yet confirmed any data leakage or any claim of responsibility by ransomware groups.
read more →

Key findings from the 2026 public sector M‑Trends report

🛡️ The 2026 Public Sector Threat Landscape report summarizes Mandiant’s 2025 incident investigations and highlights how adversaries now move at machine speed, notably the 22-second hand-off from initial access to ransomware. It argues public agencies must adopt continuous verification and machine-speed defenses. Google outlines three core capabilities—identity as the perimeter, agentic defense, and hardened infrastructure—and describes new AI agents in Google Security Operations and customer success stories.
read more →

AI Risk Registers Are Not Incident Response Plans

🛡️ Organizations are documenting AI risks but often lack an operational response when those risks materialize. A risk register can list potential failures—like inaccurate outputs or data exposures—but it does not define who can pause systems, preserve evidence, or lead an investigation. Security teams must translate governance artifacts into executable playbooks that include ownership, evidence requirements, triage, escalation and pause authority proportional to risk.
read more →

Progress orders ShareFile Storage Zones offline

🔒 Progress Software has told ShareFile customers to shut down Windows servers running their Storage Zone Controllers in response to a "credible external security threat." The company has temporarily disabled access to affected accounts and says it has no indication of unauthorized access to ShareFile accounts or data while it investigates with internal and external experts. The disruption was made public via a customer post on Reddit and confirmed on Progress's status page; only self-hosted Storage Zone Controllers are affected, not cloud-only ShareFile accounts.
read more →

Progress warns ShareFile customers to shut servers

🛑 Progress Software has alerted ShareFile customers using on-premise Storage Zone Controllers to immediately shut down the Windows servers hosting those controllers after identifying a "credible external security threat." The company temporarily disabled access to Storage Zone Controller–backed accounts and says manual shutdown is required in addition to cloud-side restrictions. Progress is investigating with cybersecurity partners and will update customers within 24 hours while the ShareFile status page shows affected controllers are nonoperational.
read more →

CISA Details Response to Exposed AWS GovCloud Keys

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) detailed its response after a contractor’s personal GitHub repository exposed AWS GovCloud credentials and internal build code. CISA’s OCIO began incident response on May 15, quickly mitigating exposure and confirming no customer data was leaked or credentials used outside CISA environments. The agency emphasized lessons learned, including stronger repo controls, improved logging, adoption of zero trust principles, and clearer reporting channels for researchers.
read more →

Three real-world incident case studies from GERT

🔍 Over the past year, Kaspersky’s Global Emergency Response Team and MDR service investigated diverse security incidents that informed the Anatomy of a Cyber World Global Report 2026. The post presents three real case studies illustrating how adversaries use credential theft, known vulnerabilities, and lateral movement to achieve persistence, escalate privileges, and deploy ransomware or wipers. It highlights recurring misconfigurations, delayed patching, and blind spots in monitoring as root causes of successful attacks.
read more →

CMC analysis of Canvas incident impacts education

🔍 The UK Cyber Monitoring Centre (CMC) has published its review of the Canvas incident affecting Instructure’s Learning Management System, finding ~160 UK higher education institutions impacted and around 9,000 worldwide. The analysis highlights that financial losses arose mainly from response, recovery and risk management rather than prolonged outage. The CMC reinforced best-practice recommendations for the sector, including MFA enforcement, separation of application and data layers, careful third‑party control and clearer vendor communication.
read more →

Scattered Spider members plead guilty in TfL hack

🛡️ Two members of the Scattered Spider group, Thalha Jubair (20) and Owen Flowers (18), pleaded guilty to breaching Transport for London systems between August 31 and September 3, 2024. The intrusion disrupted Oyster refund services and forced 28,000 staff to reset passwords, contributing to an estimated £29 million in losses. Both suspects were arrested in 2025 after investigators recovered incriminating evidence and devices linking them to the attack and other intrusions.
read more →

Cybersecurity’s Shift From Protection to Survival

🔒 The piece argues that cybersecurity must move beyond a prevention-first mindset to a survival-focused discipline. It stresses that while traditional controls (MFA, patching, hardening) remain necessary, organizations need breach readiness: continuity, recoverability, tested incident response, and clear governance. Regulatory and market pressures (EU resilience laws, US disclosure and accountability) plus AI-driven acceleration make resilience an operational imperative.
read more →

Five Eyes urge CSOs to update cyber risk strategies now

🔒 The Five Eyes cybersecurity agencies warn that rapidly advancing AI capabilities are already reshaping offensive and defensive cyber operations and urge CSOs to treat cyber risk as core business risk. They recommend prioritizing secure-by-design practices, defense in depth, rapid patching, reduced attack surface, stronger identity controls, and testing breach responses. Some experts call the guidance too general or overdue but agree it reinforces the need for executive alignment and urgent action.
read more →

Breaking the Cycle of CISO Burnout and Resilience

🔒 When a major cyber incident occurs the CISO becomes the invisible CEO of crisis, making high‑pressure decisions while managing stakeholders and operational recovery. This intense role, combined with limited strategic influence and short tenures, drives burnout and turnover across EMEA. Preparation through exercises, clear measures of risk and a permanent strategic seat at the table are essential to build sustainable resilience.
read more →