< ciso
brief />
Tag Banner

All news with #threat intelligence tag

150 articles

AI-driven surge in n-day exploits outpaces zero-day

🔍 Google’s Threat Intelligence Group reports attackers are increasingly weaponizing disclosed flaws, with AI accelerating exploit development. GTIG recorded 141 exploited CVEs between January and August 2026 versus 127 in all of 2025, while monthly disclosures doubled. High-risk exploits and time-to-exploit have risen, and perimeter appliances remain prime targets. Organizations must adopt threat-driven triage and automated remediation to manage the growing volume.
read more →

MI5 warns UK academics aided Chinese MSS research

🛡️ MI5 has warned that over 100 academics linked to U.K. institutions have contributed to research projects funded by the China General Technology Research Institute (CGTRI), which the agency assesses as a front for the Chinese Ministry of State Security (MSS). The alert cautions that CGTRI-backed research in AI, cybersecurity, covert communications, and steganography directly enhances MSS espionage capabilities. U.K. universities are urged to review collaborations and funding sources immediately, with potential prosecution under the National Security Act 2023 for continuing material assistance.
read more →

Cloudflare launches scalable Threat Signals

🛡️ Threat Signals converts open-source reporting into actionable intelligence by using agentic AI skills to summarize research, extract and normalize indicators, and apply tags into a private, account-scoped dataset. Feeds (RSS/Atom/RDF) are ingested into Workflows that fetch content, clean it, run IOC extraction and Cloudforce One skills, and store results as Threat Events tied to the original report. Outputs are searchable, tagged, and can be used to create WAF rules; Threat Events Platform access is expanded to all Cloudflare accounts with tiered enhancements for enterprise customers.
read more →

Kiteworks advises temporary shutdown after threat

🔒 Kiteworks has advised customers to shut down their systems for a nine-hour window this weekend after receiving credible threat intelligence of an imminent cyber attack. The company said the advisory is preventative, with no evidence yet of customer compromise, and that customers were notified directly. Kiteworks recommends applying the latest 9.5.1 patches and noted several subsidiaries are not affected.
read more →

Kiteworks urges six-hour global server shutdown

🔒 Kiteworks has urged customers worldwide to shut down their servers for a six-hour window after receiving credible threat intelligence from federal authorities suggesting a possible imminent attack. The advisory, sent by CISO Frank Balonis, recommends taking systems offline even if not internet-exposed and applies across time zones from AEST to PDT. Kiteworks says the notice is precautionary, that no compromise is known, and that known vulnerabilities are fixed in version 9.5.1.
read more →

Microsoft adds integrated SOC features to Defender

🔒 Microsoft now offers Integrated Security Operations Center (ISOC) capabilities inside Microsoft Defender for Microsoft 365 E5 and E7 customers at no extra license cost during public preview. ISOC combines SIEM-like functions with Defender XDR, threat intelligence, automation and AI in a single portal, and ingests Microsoft product logs without charges. From Oct. 1, third-party data ingestion will be metered at $2.40 per GB, and more advanced features require an ISOC workspace and Azure subscription.
read more →

Google named a leader in external threat intelligence

🛡️ Google has been named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026, receiving top scores across multiple criteria. The announcement highlights Google Threat Intelligence’s integration of Mandiant, VirusTotal, and Google-scale telemetry, plus AI-enabled agents powered by Gemini for rapid, autonomous investigations and malware analysis. The recognition emphasizes deep and dark web monitoring, authoritative attribution, and an open partner-centric strategy.
read more →

When Threat Intelligence Requires Active Validation

🔎 Intelligence alerts are valuable early signals, but the true problem is the queue of unvalidated items that allows risk to accumulate. Organizations often lack the time and offensive expertise to test each indicator, turning volume into backlog. Threat-led penetration testing (TLPT) reframes testing to validate current intelligence—confirming whether a leaked credential or disclosed vulnerability is exploitable in a specific environment. Practical integrations, such as Pentera with Recorded Future, automate validation runs to prioritize proof over probability.
read more →

From Intelligence to Disruption in Latin America

🛡️ The 11th Americas Working Group convened INTERPOL, the World Economic Forum, Paraguayan authorities, and public-private experts to explore how intelligence can enable operations against cybercrime in Latin America. Fortinet and FortiGuard Labs emphasized turning telemetry into actionable intelligence that supports investigations and coordinated disruption. The meeting highlighted the need for structured collaboration, real-time sharing, and sustained capability building to raise the cost for cybercriminals.
read more →

Behind the Intelligence: Investigative Tradecraft

🛡️ This edition of the Threat Source newsletter explains the hidden work behind producing usable threat intelligence, highlighting the investigative detours, persona-based adversary engagement, and the human behaviours that shape both attackers and defenders. It spotlights a Beers with Talos episode featuring Azim Khodjibaev, who maintained multiple personas to infiltrate dark-web communities, and raises concerns about AI guardrails that hinder defensive workflows during incidents.
read more →

Fortinet and FIRST Strengthen Global Cyber Resilience

🔒 Fortinet’s partnership with the Forum of Incident Response and Security Teams (FIRST) advances global cyber resilience by combining FortiGuard Labs’ threat intelligence with FIRST’s incident response network. CORE, a 2025 initiative co-founded by Fortinet, funds capacity building, regional training, and tabletop exercises to close skills gaps and improve cross-border coordination. This collaboration also supports standards like EPSS and CVSS to turn shared practices into operational defenses.
read more →

AI-enabled intrusions target Latin American organizations

🔎 We analyzed two multi-stage intrusion and data-exfiltration campaigns targeting Latin America that leverage AI to streamline operations. One cluster (CL-CRI-1131) targeted Mexican transportation and government entities using LotL techniques and self-hosted NextChat, while a second (CL-CRI-1163) targeted Brazil’s financial sector with custom RATs and a Go-based SOCKS5 proxy. Both clusters share proxy infrastructure and evidence of commercial LLMs aiding attackers.
read more →

International Operation Disrupts Long‑Running Sality Botnet

🛡️ A coordinated law enforcement action on August 31 disrupted the Sality P2P botnet, active for over 20 years. Authorities from the US, Bulgaria, Hungary and Romania, supported by Europol and private partners CrowdStrike and the Shadowserver Foundation, used sinkholing and protocol manipulation to redirect infected machines and enable remediation. The operation targeted Sality’s decentralized peer lists to remove malicious super peers and insert sinkhole entries, while ISPs and CSIRTs helped identify and notify victims.
read more →

DoJ Revises Statement on China-Linked Hacking Targets

🛡️ The U.S. Department of Justice corrected a prior press release to state several federal agencies were "among the targets" of QTFY, a China-linked threat actor, rather than confirmed victims. The update clarifies the government affidavit and follows disruptions by the FBI of domains tied to QTFY's tools. The actor, tied to Nanjing Xinjiuwei and allegedly funded by the MSS, provided reconnaissance and proxy services to enable espionage.
read more →

Nucleus expands AI to detect exposures earlier

🛡️ Nucleus Security is rolling out Nucleus Helix, an AI Agent for natural-language interaction with security data and workflows, plus Nucleus Discover and expanded Nucleus Insights to accelerate early exposure detection and vulnerability intelligence. The company says these capabilities aim to shorten the gap between disclosure and scanner coverage by using environment context, prior scan data and real-time threat intelligence to identify likely affected systems before scanner plugins are available. Nucleus positions Helix as a reasoning assistant while deterministic automation executes approved workflows, and plans to release Helix and Discover in September with Insights available now.
read more →

Rogue ransomware affiliate posing as recovery firm

🛡️ GuidePoint Security's GRIT warns that a suspected ransomware affiliate calling itself "Ransom Busters" has been contacting victims before attacks are publicly disclosed, offering decryption keys and data deletion for fees. The group claims to exploit vulnerabilities in RaaS admin panels and demanded $20,000–$60,000 to remove stolen data. Evidence from two incidents suggests the entity is likely the affiliate behind the intrusions, using consistent tools, account patterns, and attacker-controlled hostnames across multiple attacks.
read more →

How Metaphor Shapes AI Security Strategy

🧭 Metaphor frames how we interpret emerging cybersecurity events, especially reports of autonomous AI agents escaping sandbox environments. The article argues that initial narratives — whether innovation or containment failure — shape long-term priorities like speed versus safety. Cisco Talos presents data showing adversaries weaponizing AI in diverse ways, urging defenders to adopt AI-enabled tools to triage alerts and shorten response windows.
read more →

Industry launches SAFE for agentic AI threats

🛡️ A coalition of 120+ tech organizations, led by members of NVIDIA’s Open Secure AI Alliance and coordinated via the Linux Foundation, unveiled the Shared AI Findings Exchange (SAFE) on August 4 to enable confidential information sharing on AI security incidents. The initiative emphasizes shared learning over blame and proposes confidential reporting, timely notification, collaborative analysis across the full AI stack, and independent governance to produce actionable, evidence-based defensive guidance. A public RFP invites broader community input, and proponents say SAFE can surface near misses and behavioral failures that traditional vulnerability disclosure processes miss.
read more →

Unit 42 Threat Intelligence: Contextualized Defense

🔍 Security teams need intelligence that identifies what matters, when it matters, and what to do next. Unit 42 Threat Intelligence integrates proprietary research into the Cortex platform and offers analyst-driven services to deliver contextual, actionable insights. By correlating global visibility with each customer’s environment, it converts signals into prioritized detections, hunts and response actions. This approach addresses accelerated adversary behavior amplified by AI and shortens defenders’ reaction window.
read more →

Humans of Talos: Black Hat special rewind

🎙️ Amy revisits past guests in a special Black Hat edition of Humans of Talos, exploring the varied career paths that led them to threat intelligence. From forensic labs and newsrooms to kitchen lines, the episode highlights personal stories and lessons that shape the field. Attendees can meet the team at Cisco and Splunk booth 2633 during Black Hat to discuss research and incident response and pick up the latest Snorty.
read more →