< ciso
brief />
Tag Banner

All news with #threat intelligence tag

135 articles

Rogue ransomware affiliate posing as recovery firm

🛡️ GuidePoint Security's GRIT warns that a suspected ransomware affiliate calling itself "Ransom Busters" has been contacting victims before attacks are publicly disclosed, offering decryption keys and data deletion for fees. The group claims to exploit vulnerabilities in RaaS admin panels and demanded $20,000–$60,000 to remove stolen data. Evidence from two incidents suggests the entity is likely the affiliate behind the intrusions, using consistent tools, account patterns, and attacker-controlled hostnames across multiple attacks.
read more →

How Metaphor Shapes AI Security Strategy

🧭 Metaphor frames how we interpret emerging cybersecurity events, especially reports of autonomous AI agents escaping sandbox environments. The article argues that initial narratives — whether innovation or containment failure — shape long-term priorities like speed versus safety. Cisco Talos presents data showing adversaries weaponizing AI in diverse ways, urging defenders to adopt AI-enabled tools to triage alerts and shorten response windows.
read more →

Industry launches SAFE for agentic AI threats

🛡️ A coalition of 120+ tech organizations, led by members of NVIDIA’s Open Secure AI Alliance and coordinated via the Linux Foundation, unveiled the Shared AI Findings Exchange (SAFE) on August 4 to enable confidential information sharing on AI security incidents. The initiative emphasizes shared learning over blame and proposes confidential reporting, timely notification, collaborative analysis across the full AI stack, and independent governance to produce actionable, evidence-based defensive guidance. A public RFP invites broader community input, and proponents say SAFE can surface near misses and behavioral failures that traditional vulnerability disclosure processes miss.
read more →

Unit 42 Threat Intelligence: Contextualized Defense

🔍 Security teams need intelligence that identifies what matters, when it matters, and what to do next. Unit 42 Threat Intelligence integrates proprietary research into the Cortex platform and offers analyst-driven services to deliver contextual, actionable insights. By correlating global visibility with each customer’s environment, it converts signals into prioritized detections, hunts and response actions. This approach addresses accelerated adversary behavior amplified by AI and shortens defenders’ reaction window.
read more →

Humans of Talos: Black Hat special rewind

🎙️ Amy revisits past guests in a special Black Hat edition of Humans of Talos, exploring the varied career paths that led them to threat intelligence. From forensic labs and newsrooms to kitchen lines, the episode highlights personal stories and lessons that shape the field. Attendees can meet the team at Cisco and Splunk booth 2633 during Black Hat to discuss research and incident response and pick up the latest Snorty.
read more →

The branding and attribution behind cybercrime

🔍 Threat actor names like LockBit or Fancy Bear often suggest a single, clear identity, but naming is more complex. Some names are chosen by attackers as public brands; others are labels assigned by researchers, vendors, or databases to track activity clusters. Confusing branding with attribution risks overstating certainty, missing links between aliases, or focusing on names rather than observed behavior. Exposure management helps translate those insights into prioritized action.
read more →

Google GTIG launches unified threat actor names

🔐 Google’s Threat Intelligence Group (GTIG) is introducing a unified cryptonym-based naming schema to standardize threat actor tracking across platforms and reports. The system uses two-word names: a unique memorable term and a second word denoting motivation, origin, or activity type to aid defenders. Several dozen active groups will be renamed initially, with prior aliases and MITRE ATT&CK mappings preserved for continuity. The approach aims to simplify mapping across vendor taxonomies while acknowledging visibility differences.
read more →

Fortinet and Crime Stoppers Launch Cybercrime Bounty

🛡️ The interview outlines a partnership between Crime Stoppers International and Fortinet to create the Cybercrime Bounty program, a secure and anonymous channel for private-sector contributors to report suspected cybercriminals. It emphasizes anonymity, Fortinet’s threat-intelligence validation, and the program’s focus on identifying human actors and networks rather than software vulnerabilities. The initiative aims to turn tips into actionable intelligence for law enforcement and strengthen public–private cooperation to disrupt cybercrime at scale.
read more →

CISOs Must Rethink Vulnerability Management Now

🔍 Security experts urge enterprises to shift from scheduled patch cycles to risk-based, continuous approaches such as just-in-time patching, citing AI-driven vulnerability discovery and exploitation that outpace traditional models. Vendors warn that AI tools can rapidly surface and validate flaws, widening the gap between discovery and remediation and overwhelming teams. Compensating controls like virtual patching can help, but they are stopgaps; organizations need continuous asset visibility, real-time exploitation intelligence, and prioritization based on exposure and exploitability.
read more →

Defender Experts Close the Intelligence‑to‑Action Gap

🛡️ Microsoft announces Defender Experts Threat Intelligence and expands Defender Experts MDR to include third-party and multi-cloud coverage. The expert-led services translate global signals into prioritized, environment-specific guidance and integrate Microsoft Defender Threat Intelligence into the Defender portal for real-time use across detection, investigation, response, and hunting. Defender Experts MDR Plan 2 extends managed detection and response beyond Microsoft products using Microsoft Sentinel, enabling experts to follow threats across heterogeneous estates. These offerings aim to shorten the time from signal to decisive action and will be showcased at Black Hat.
read more →

Fortinet and INTERPOL Strengthen Cybercrime Response

🔍 Fortinet reinforced its decade-long partnership with INTERPOL at the INTERPOL Partners’ Conference in Lyon, stressing the need for faster, trust-based intelligence sharing to counter AI-accelerated cybercrime. Panel discussions highlighted how AI and agentic systems amplify threats across phishing, fraud, and cybercrime-as-a-service while underscoring the role of FortiGuard Labs in supporting coordinated disruption. The piece calls for sustained public-private collaboration, shared detection methods, and resource support for global law enforcement.
read more →

Cisco Talos intelligence integrations overview

🎯 Cisco Talos Intelligence Integrations apply continuous, up-to-date threat intelligence across Cisco security and enterprise products to help identify and block malicious activity. The integrations aim to reduce uncertainty for defenders facing advanced, adaptive threats such as AI-assisted attacks and polymorphic malware. A short video introduces Talos team members and demonstrates how reputation and detection feeds inform security decisions. A more detailed technical overview is available on the Cisco Security site.
read more →

Forg365 PhaaS Targets Microsoft 365 with AI

🛡️ Forg365 is a phishing-as-a-service platform that targets Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device-code phishing with integrated AI-assisted lure generation. The service offers an admin dashboard for campaign management, OAuth and SMTP configuration, token handling, and a browser extension called ForgCookie for persistent cookie harvesting. Researchers at ZeroBEC found the operation uses legitimate delivery services like Amazon SES and SendGrid-hosted resources to blend malicious emails into normal traffic.
read more →

Verify threat indicators before acting on feeds

🔍 The author recounts multiple cases where threat intelligence feeds and advisories mischaracterized malware or buried stronger indicators in machine-readable files. They describe a commercial feed mislabeling a Windows DonutLoader variant as the Linux Chalubo RAT, an official advisory whose PDF lacked stronger hashes present in the STIX bundle, and a CERT report with binary-level discrepancies. The piece stresses that labels and pipeline metadata are guesses until validated and urges analysts to open structured files and detonate samples when stakes are high.
read more →

Google Disrupts NetNut Residential Proxy Network

🛡️ Google says its Threat Intelligence Group, working with FBI and industry partners, has degraded NetNut (aka Popa), a large residential proxy network that turns home devices into rented relays. GTIG estimates NetNut controlled at least 2 million devices, including smart TVs and streaming boxes, which can be used to route criminals' traffic through private home connections. NetNut is linked to publicly traded Alarum Technologies, which denies wrongdoing and says its software provides consented bandwidth sharing. Researchers found many apps did not show consent prompts, and Google warns the network is resilient through reseller arrangements and may reappear under different brands.
read more →

Detection engineering rises as a core SOC capability

🔍 Detection engineering has moved from a niche role to a strategic imperative for many organizations, focused on building tailored, behavior-driven alerts that reduce false positives and improve response. It emphasizes threat modeling, SDLC/CI-CD practices, and integration of threat intelligence to craft detections specific to an organization’s environment. A SANS-Anvilogic survey found broad investment and leadership support, while AI and automation are increasingly used to tune rules and scale workflows.
read more →

Cloudflare launches Attribution Business Insights dashboard

📊 Cloudflare introduces the Attribution Business Insights dashboard to help publishers and business leaders distinguish valuable human referrals from extractive AI crawler traffic. The dashboard provides site-wide and per-operator crawl-to-referral ratios, top bot breakdowns, and updated crawler classifications like Training, Search, and Agent. Available to Cloudflare Bot Management customers, it centralizes visibility so decision-makers can evaluate impact before acting via existing security rules.
read more →

Lessons from underground: combating BEC threats

📣 Flare researchers examined underground forum discussions and tools used to orchestrate Business Email Compromise (BEC) campaigns, finding that attacks extend beyond email to include remote access, cash-out networks, and call centers. Actors target finance and leadership SaaS accounts, increasingly using AI to craft realistic messages and scale operations. Defenders should monitor exposed credentials, enforce MFA, train high-risk staff, and treat multi-channel contacts cautiously.
read more →

Pre-positioned cyber threats around FIFA 2026 event

⚠️ Check Point Research found that cybercriminals pre-built and partially deployed fraud infrastructure targeting FIFA World Cup 2026 before the June 11 kickoff, focusing on financial services, transportation, hospitality, and gambling. Pre-tournament research highlighted weak DMARC enforcement among partners, a 60x surge in fake sportsbook apps concentrated on Google Play, and large volumes of lookalike travel and hotel domains created two months prior. Check Point's exposure, brand protection, and dark web monitoring capabilities flagged the activity and report rapid remediation metrics.
read more →

US offers $10M for info on hackers targeting Signal and WhatsApp

🔔 The U.S. Department of State is offering up to $10 million through its Rewards for Justice program for information identifying members of UNC5792 and UNC4221, two groups tied to Russian intelligence and military services. The bounty follows FBI and CISA updates that these groups conducted phishing campaigns targeting Signal and WhatsApp users, including attempts to steal Signal Backup Recovery Keys by impersonating support agents. Targets included U.S. and NATO officials, journalists, NGOs, and researchers.
read more →