< ciso
brief />
Tag Banner

All news with #threat hunting tag

94 articles

CISA Endorses Cyber Decoys; FortiDeceptor 6.3

🛡️ CISA published guidance on Using Cyber Decoys to Strengthen Detection and Response, urging an assume-breach posture and use of honeypots, honeytokens, breadcrumbs, and tripwires. FortiDeceptor implements these concepts with decoy VMs, centralized lure management, and integration with the Fortinet Security Fabric. Version 6.3 expands decoy coverage to GitLab, IoT printers, and cloud connectors for S3, GitHub, and SharePoint, and supports automated response workflows.
read more →

Frustrating Adversaries Through Defensive Tradecraft

🛡️ Cisco Talos outlines practical ways defenders can increase friction for attackers across the attack chain. The piece highlights techniques such as unique configurations, deception (honeypots and tarpits), behavior-based detections, RMM inventorying and allowlisting, social-engineering preparedness, and controls for AI agents. Each recommendation aims to force adversaries into slower, noisier, or less reliable methods while providing defenders more chances to detect and stop activity.
read more →

Route 53 DNS Analytics and Insights via CloudWatch

🔍 Amazon Route 53 Global Resolver and DNS Firewall now integrate with Amazon CloudWatch to provide DNS analytics and insights. These features let network and security teams observe DNS query patterns, evaluate DNS Firewall rule effectiveness, detect anomalies, and optimize DNS performance. An Analytics tab in the Global Resolver and DNS Firewall consoles centralizes access, and CloudWatch Metrics and Contributor Insights enable metric filters, searches, and alarms. Standard CloudWatch pricing applies to opted-in metrics.
read more →

Data Quality Now Top Barrier for Threat Hunters

📊 The SANS 2026 Threat Hunting Survey found that data quality and quantity have overtaken skills as the primary barrier for threat hunting programs, cited by 50% of 500 respondents worldwide. Skilled staff remain a close second at 45%, while formally defined methodologies fell to 37%, raising concerns about repeatability and defensibility. Other common constraints include budget, data standards, tool limits, and processes, and ransomware remains the most encountered threat.
read more →

CISA Guidance Urges Honeytokens for Intrusion Detection

🛡️ CISA has published guidance recommending that critical infrastructure operators deploy decoys such as fake files, accounts and credentials inside their networks to detect intruders who bypass perimeter defenses. The guidance emphasizes honeytokens—low-complexity data tripwires with no legitimate use—over internet-facing honeypots, and frames decoys as complementary to Zero Trust. It outlines three actions: deploy high-fidelity tripwires in high-value areas, map coverage using MITRE ATT&CK and MITRE Engage, and continuously refine through threat emulation.
read more →

When Threat Intelligence Requires Active Validation

🔎 Intelligence alerts are valuable early signals, but the true problem is the queue of unvalidated items that allows risk to accumulate. Organizations often lack the time and offensive expertise to test each indicator, turning volume into backlog. Threat-led penetration testing (TLPT) reframes testing to validate current intelligence—confirming whether a leaked credential or disclosed vulnerability is exploitable in a specific environment. Practical integrations, such as Pentera with Recorded Future, automate validation runs to prioritize proof over probability.
read more →

How AI Is Reshaping Cybersecurity Operations

🛡️ The rise of AI agents is already transforming security operations, shifting first-level triage and repetitive tasks to automated systems while leaving humans for escalation, oversight, and complex judgment. Experts warn of a surge in discovered vulnerabilities that defenders will struggle to absorb and remediate. Organizations should prepare for machine-speed attacks and containment, flattening team structures, new governance needs, and the use of AI as an interface across fragmented tools.
read more →

FBI Releases Strategic Cyber Disruption Plan

🔒 The FBI has published its first Cyber Strategy, outlining how the agency will investigate and disrupt cyber threat actors and impose costs on adversaries. The document, published on September 9, emphasizes proactive disruption of financially motivated criminals and state-sponsored actors, rapid victim support, expanded partnerships, and investment in AI-enabled tools and workforce training. It sets out four pillars: investigate and disrupt, support victims, increase partnerships, and enhance cyber capabilities.
read more →

Amazon GuardDuty adds opt‑in detection rules

🛡️ Amazon GuardDuty now provides Custom Detection Rules, a library of 35 prebuilt, opt‑in rules for CloudTrail management events that produce 26 unique finding types mapped to 10 MITRE ATT&CK® tactics. These rules extend threat coverage without requiring additional log ingestion, normalization, or storage. Administrators can enable rules selectively where activity is unexpected and test in dry‑run mode via the GuardDuty console or API. The feature is available in all AWS commercial Regions and AWS GovCloud (US).
read more →

Hunting MacSync Stealer via behavioral pivots

🔍 Microsoft Defender Experts expanded earlier reporting on MacSync Stealer, a macOS information stealer that rotates infrastructure rapidly. The investigation correlated recurring command-line, request, and upload traits to link over 30 domains and show active staged collection and chunked HTTP PUT exfiltration. The write-up maps payload retrieval, C2 check-in, collection, staging, and cleanup to durable hunting pivots.
read more →

Perimeter Recovery Masks Weak Interior Defenses

🔍 Picus Labs' Blue Report 2026 shows perimeter defenses improved in H1 2026, with prevention rising to 69% and logging at a four-year high of 58%. However, post-compromise prevention inside networks remains weak at 37%, and quiet techniques like reconnaissance and credential theft largely evade controls. The findings highlight signature-dependent gaps and declining IOC-based prevention, urging validation of exposures and stronger detection engineering.
read more →

Identity-Driven Attacks and SOC Response Trends

🔐 Unit 42 finds identity compromises underpin most modern incidents, with the 2026 Global Incident Response Report showing identity weaknesses in nearly 90% of investigations and 65% of initial access events. Attackers increasingly use phishing, social engineering, MFA manipulation and third-party account misuse to gain entry, then move laterally, escalate privileges and blend into administrative behavior. Unit 42 recommends correlating identity, endpoint, cloud and network telemetry, applying AI-driven correlation and centralized investigations, and investing in continuous threat hunting and SOC engineering to detect and contain identity-driven intrusions earlier.
read more →

Five priorities for your Black Hat agenda

🔒 Black Hat remains a vital forum for practitioners despite commercialization; attendees should avoid flashy distractions and focus on substantive technical content. Key topics to prioritize this year include agentic AI exploitation, modern APT infrastructure, AI-powered vulnerability discovery, threat hunting in the AI era, and real-world adversary AI use. Seek sessions and case studies that emphasize operational controls, behavioral detection, and collaboration across security, IT, and development teams.
read more →

Microsoft unveils multi-model agentic cyber stack

🔐 Microsoft announced Project Perception, an AI-driven service entering public preview on Aug. 3 that uses multiple AI agents to continuously evaluate and update enterprise security posture. The multi-model harness selects the best model for each task to balance quality and cost, and Microsoft also introduced MAI-Cyber-1-Flash, a specialist model trained to find vulnerabilities. Integrated agents perform red-, blue- and green-team playbooks to detect, triage, and remediate threats automatically.
read more →

Rethinking Security for the Age of AI

🛡️ Microsoft introduces Project Perception, an agentic security system designed for AI-era threats. It combines signals, context, models and specialized agents to continuously perceive, reason and act at machine speed while keeping humans in control. The system uses a multi-model architecture to optimize for quality and cost, beginning with software vulnerability management using MAI-Cyber-1-Flash in MDASH. Project Perception enters public preview on August 3.
read more →

Shadow Token via Remote Debug: OAuth mailbox hijack

🔒 Kaspersky researchers describe a covert technique named Shadow Token via Remote Debug (STRD) used by the ToddyCat APT to gain persistent access to Google Workspace mailboxes without user interaction. The attackers deploy malware (Umbrij) that duplicates a browser profile, launches a headless debugging browser, and programmatically authorizes a third-party OAuth app to obtain an access token. This approach can survive password resets and evades endpoint detection when properly executed.
read more →

Cloud CISO Perspectives: AI and deep context defense

🛡️ Francis deSouza outlines how deep context gives defenders an AI-driven advantage by unifying enterprise telemetry, vulnerability management, and agentic automation. The post introduces Google AI Threat Defense, combining Gemini, Wiz, CodeMender, and Mandiant into a prepare–scan–remediate–monitor lifecycle. It emphasizes human oversight, Zero Trust for AI, and real-world impact such as Morgan Stanley’s rapid detection improvements.
read more →

AI Helps Find Bugs but Humans Must Prove Them

🛡️ AI is accelerating offensive security by producing many potential findings quickly, but generated reports are not the same as validated evidence. AI tools can read code, generate payloads, and suggest attack paths, yet validation still requires human knowledge of systems, reachability, and exploitability. Low-quality AI submissions are already increasing triage burden, so teams must separate leads from proven findings and apply rigorous validation before driving engineering action.
read more →

The Hunter’s Paradox: Rethinking AI in Threat Hunting

🔍 This post examines whether AI should lead threat hunting, arguing the choice is not binary. The author reframes hunting as a reasoning-driven process rather than a human-only activity and explains why scale, velocity, and capacity force us toward automation. Practical guidance includes scoped hunts, strict access controls, and graduated autonomy while keeping humans responsible for strategy and novel analysis.
read more →

UK unveils AI-driven national Cyber Shield

🔒 The UK’s NCSC and DSIT unveiled a blueprint called Cyber Shield to deploy autonomous AI agents that detect and neutralize cyberattacks at machine speed. The plan uses cooperating “red” and “blue” agents to identify weaknesses, detect threats and progressively automate remediation while operating under organizational control. The initiative emphasizes explainable and federated AI, industry partnerships, and a staged rollout beginning with government and critical sectors.
read more →