< ciso
brief />
Tag Banner

All news with #threat intelligence tag

135 articles · page 2 of 7

Fortinet Supports INTERPOL Operation CyberProtect III

🔎 Fortinet contributed to INTERPOL’s Operation CyberProtect III by providing intelligence and analysis through its role in the World Economic Forum’s Cybercrime Atlas. The four-day initiative helped identify dozens of suspicious cases, suspect profiles, and potential victims on content subscription platforms. The operation highlighted trends such as encrypted messaging, coded language, cryptocurrency payments, and AI-generated profiles used to facilitate exploitation.
read more →

VisionHeight managed rules added for AWS Network Firewall

🛡️ AWS Network Firewall now offers two new managed rule groups from VisionHeight in AWS Marketplace: Zero-Day Threat Protection and Noisy Scanners and Tor Protection. These rule groups use VisionHeight's Pulse telemetry to provide proactive blocking of malicious IP infrastructure and suppression of noisy Tor and scanner traffic. Daily refresh cycles reduce SOC alert volume and SIEM ingestion costs while improving protection for targeted workloads.
read more →

AI-Augmented Threat Intelligence: Beyond IOCs

🛡️ The article examines how AI, particularly large language models, can bridge the gap between atomic indicators of compromise (IOCs) and richer strategic threat intelligence by indexing and relating unstructured reports. It highlights opportunities to retrieve relevant intelligence and generate tailored defensive advice while warning about data veracity and confidentiality. The piece also emphasizes practical Windows threats abusing COM and recommends tooling and hunting practices to detect such misuse.
read more →

Microsoft named Leader in Forrester XDR Wave 2026

🛡️ Microsoft has been named a Leader in The Forrester Wave™: Extended Detection and Response Platforms, Q2 2026, earning the top Strategy and Vision scores. The report highlights Microsoft Defender and Microsoft Threat Intelligence for high marks across identity detection, cloud detection, SIEM replacement, threat hunting, and more. Microsoft emphasizes an XDR foundation that unifies signals across identities, endpoints, email, SaaS, and cloud workloads to enable coordinated, AI-assisted attack disruption and faster SOC operations.
read more →

Survey Finds AI Attacks Top Concern for Security Leaders

🔍 A Filigran survey of 168 security leaders at Infosecurity Europe 2026 found AI-powered attacks are the leading worry, cited by 41% of respondents, outpacing supply chain and unknown threats. Teams report alert fatigue as a major time sink, with chasing false positives (26%) and validating risks (25%) common. Trust in threat intelligence and AI decision-making remains low, and only 28% have a continuous exposure management program.
read more →

Staffing and AI Shape Modern SOC Challenges

🛡️ The SANS 2026 SOC Survey of 513 security professionals highlights staffing as the top operational challenge for SOCs, with a marked perception gap between practitioners and cyber leaders about hiring and retention. The report shows widespread AI/ML adoption (79%) but limited operational integration (36%), with most teams using vendor tools without customization. It also flags maturity issues in CTI use, OT/IoT coverage, and SOC measurement practices.
read more →

Survey Finds Anonymized IPs Drive Modern Incidents

🔍 A recent study of over 200 security practitioners by Spur Intelligence shows anonymizing infrastructure—VPNs and residential proxies—appears in nearly every incident, yet many teams lack the context and workflows to act on IP data. Analysts increasingly face noisy enrichment feeds without attribution, behavioral signals, or automation to inform real-time decisions. Organizations remain reactive, applying IP intelligence mainly during investigations, while internal risks from employee VPNs and proxy usage add blind spots that zero-trust must address.
read more →

Fortinet and MITRE CTID Strengthen Threat-Informed Defense

🔍 Fortinet highlights its role as a research partner with the MITRE Center for Threat-Informed Defense (CTID), contributing threat intelligence, operational expertise, and research to practical R&D projects. The CTID impact report (2019–2025) demonstrates collaborative efforts to map adversary behavior to detection, controls, and cloud security. Fortinet’s contributions focus on operationalizing ATT&CK-based frameworks, improving detection quality, and advancing program maturity across cloud, identity, and AI-driven workflows.
read more →

Cloudflare adds realtime threat intel to WAF

🛡️ Cloudflare now exposes live Threat Events signals directly to its WAF engine, enabling security teams to create proactive rules using attacker names, target industries, countries, attack types, and dataset sources. The integration enriches HTTP request metadata in real time without adding noticeable latency, supporting both UI and Infrastructure-as-Code workflows via API and Terraform. Matches are logged in Security Analytics for auditing, and Saved Views can be exported directly into WAF rules for streamlined operations.
read more →

Gap Between Threat Intelligence and Business Risk

🔍 A new paper from Silobreaker and the SANS Institute warns that business leaders often misunderstand threat intelligence and its value, creating an "intelligence–stakeholder gap." The report, launched at Infosecurity Europe 2026, finds that intelligence outputs can be overlooked or misinterpreted, limiting funding and visibility for intelligence teams. To close the gap, teams must tailor briefings to senior leaders, provide forward-looking exposure analysis, prioritise speed and seek regular stakeholder feedback to ensure intelligence changes decisions and drives risk-informed actions.
read more →

Six critical security gaps every CISO must address

🔒 CISOs admit many organizations remain underprotected, with surveys showing gaps in data protection, incident preparedness, and resourcing. As adversaries adopt automation and AI, security programs must close six core gaps: perception, speed versus attackers, business‑security alignment, skills, AI security, and legacy systems. Experts urge CISOs to shift toward resilience, accelerate operations with automation and CTEM, and invest in workforce and governance.
read more →

Less Panic Patching, More Precision in Remediation

🔍 This edition of Threat Source argues for smarter patch prioritization, pairing CVSS severity with EPSS likelihood to focus scarce operations on vulnerabilities being actively exploited. It contrasts centralized KEV visibility with emerging decentralized GCVE enrichment and highlights Cisco Talos' new open-source EvidenceForge for generating realistic synthetic logs to train defenders. The newsletter also summarizes recent incidents, vulnerability research, and tooling updates.
read more →

Google launches AI Threat Defense for enterprises

🔒 Google announces AI Threat Defense, an integrated, automated security system that uses Gemini, Mandiant, Wiz, and CodeMender to detect, prioritize, and remediate AI-powered threats. The platform combines multi-model scanning, live exposure mapping, and AI agents to validate exploitability, generate fixes, and accelerate remediation. It emphasizes machine-speed monitoring, autonomous response, and consolidated visibility across development and runtime environments to reduce attack surface and speed patching.
read more →

The Art of Being Ungovernable: Career and Threats

📝 This edition of the Threat Source newsletter blends career reflection with active threat intelligence. The author argues that being ungovernable — intellectually curious and challenging — can accelerate growth when paired with the right peers. Cisco Talos also documents a Chinese-language BadIIS MaaS campaign, highlighting indicators like embedded demo.pdb strings and recommending IIS monitoring and updated endpoint detections.
read more →

Interpol leads major MENA cybercrime crackdown operation

🔎 Interpol coordinated a first-of-its-kind campaign, Operation Ramz, across 13 MENA countries from October 2025 to February 2026 to disrupt phishing, malware and scam networks. The campaign resulted in 201 arrests, identification of 382 additional suspects and 3,867 victims, and led to the seizure of 53 servers. Authorities also disseminated almost 8,000 pieces of data and intelligence to support follow-up investigations. Private-sector partners including Group-IB, Kaspersky, Team Cymru, Shadowserver and TrendAI supported operational visibility and takedown efforts.
read more →

From WarGames to Cyberwar: Nation-State Cyber Threats

🔍 In a RSA 2025 conversation, Allie Mellen, author of Code War, frames modern cyber conflict through historical doctrine, showing how nations' distinct strategies shape attacks and espionage. She cautions that attribution based solely on technical signals is insufficient because actors can forge signatures and deploy false flags, so motive and context matter. Mellen warns that AI will make attacks faster and more adaptive, and urges defenders to strengthen fundamentals and adopt automation and AI on the defensive side.
read more →

Unplug to Improve Focus: Physical Hobbies Aid Devs

🌳 The Threat Source newsletter urges cybersecurity professionals to step away from screens and engage in tactile hobbies to reset mental focus and foster creative problem solving. The author describes a miniature‑painting session at the office and recommends simple anchors — walking, knitting, building a keyboard — to refresh cognition. Separately, Cisco Talos flags a rise in phone‑number‑based scam infrastructure and urges clustering of telephony IOCs.
read more →

Google Named a Leader in 2026 Gartner Cyberthreat IQ MQ

🔒 Google has been named a Leader in the 2026 Gartner Magic Quadrant for Cyberthreat Intelligence Technologies. The company highlights a unified ecosystem combining Mandiant, VirusTotal, Google infrastructure visibility and Gemini-powered agentic intelligence to detect and preempt threats. Google reports high signal accuracy, turnkey integrations with Security Operations, and combined human expertise to reduce false positives and accelerate response.
read more →

CrowdStrike Named Leader in Gartner Cyberthreat Intelligence

🔒 CrowdStrike was named a Leader in the inaugural 2026 Gartner Magic Quadrant for Cyberthreat Intelligence Technologies and ranked furthest to the right for Completeness of Vision. The company emphasizes its AI-native Falcon platform and Threat AI agents — including Malware Analysis and Hunt agents — to deliver tailored, actionable intelligence at decision points. It highlights telemetry from trillions of daily events and multiple integration paths to operationalize intelligence.
read more →

OpenAI Broadens TAC Program to Government Cyber Defenders

🔐 OpenAI has published a roadmap titled 'Cybersecurity in the Intelligence Age' pledging to democratize AI-powered cyber defense and to extend its Trusted Access for Cyber (TAC) program. The April 30 paper, released shortly after the debut of GPT5.4-Cyber, outlines new TAC tiers for authenticated cyber defenders and wider inclusion of governments, major platforms, cloud hyperscalers and critical infrastructure operators. OpenAI also commits to strengthen internal red-teaming, misuse detection and safety mechanisms while collaborating with governments on threat models and intelligence sharing.
read more →