< ciso
brief />
Tag Banner

All news with #threat intelligence tag

150 articles · page 2 of 8

The branding and attribution behind cybercrime

🔍 Threat actor names like LockBit or Fancy Bear often suggest a single, clear identity, but naming is more complex. Some names are chosen by attackers as public brands; others are labels assigned by researchers, vendors, or databases to track activity clusters. Confusing branding with attribution risks overstating certainty, missing links between aliases, or focusing on names rather than observed behavior. Exposure management helps translate those insights into prioritized action.
read more →

Google GTIG launches unified threat actor names

🔐 Google’s Threat Intelligence Group (GTIG) is introducing a unified cryptonym-based naming schema to standardize threat actor tracking across platforms and reports. The system uses two-word names: a unique memorable term and a second word denoting motivation, origin, or activity type to aid defenders. Several dozen active groups will be renamed initially, with prior aliases and MITRE ATT&CK mappings preserved for continuity. The approach aims to simplify mapping across vendor taxonomies while acknowledging visibility differences.
read more →

Fortinet and Crime Stoppers Launch Cybercrime Bounty

🛡️ The interview outlines a partnership between Crime Stoppers International and Fortinet to create the Cybercrime Bounty program, a secure and anonymous channel for private-sector contributors to report suspected cybercriminals. It emphasizes anonymity, Fortinet’s threat-intelligence validation, and the program’s focus on identifying human actors and networks rather than software vulnerabilities. The initiative aims to turn tips into actionable intelligence for law enforcement and strengthen public–private cooperation to disrupt cybercrime at scale.
read more →

CISOs Must Rethink Vulnerability Management Now

🔍 Security experts urge enterprises to shift from scheduled patch cycles to risk-based, continuous approaches such as just-in-time patching, citing AI-driven vulnerability discovery and exploitation that outpace traditional models. Vendors warn that AI tools can rapidly surface and validate flaws, widening the gap between discovery and remediation and overwhelming teams. Compensating controls like virtual patching can help, but they are stopgaps; organizations need continuous asset visibility, real-time exploitation intelligence, and prioritization based on exposure and exploitability.
read more →

Defender Experts Close the Intelligence‑to‑Action Gap

🛡️ Microsoft announces Defender Experts Threat Intelligence and expands Defender Experts MDR to include third-party and multi-cloud coverage. The expert-led services translate global signals into prioritized, environment-specific guidance and integrate Microsoft Defender Threat Intelligence into the Defender portal for real-time use across detection, investigation, response, and hunting. Defender Experts MDR Plan 2 extends managed detection and response beyond Microsoft products using Microsoft Sentinel, enabling experts to follow threats across heterogeneous estates. These offerings aim to shorten the time from signal to decisive action and will be showcased at Black Hat.
read more →

Fortinet and INTERPOL Strengthen Cybercrime Response

🔍 Fortinet reinforced its decade-long partnership with INTERPOL at the INTERPOL Partners’ Conference in Lyon, stressing the need for faster, trust-based intelligence sharing to counter AI-accelerated cybercrime. Panel discussions highlighted how AI and agentic systems amplify threats across phishing, fraud, and cybercrime-as-a-service while underscoring the role of FortiGuard Labs in supporting coordinated disruption. The piece calls for sustained public-private collaboration, shared detection methods, and resource support for global law enforcement.
read more →

Cisco Talos intelligence integrations overview

🎯 Cisco Talos Intelligence Integrations apply continuous, up-to-date threat intelligence across Cisco security and enterprise products to help identify and block malicious activity. The integrations aim to reduce uncertainty for defenders facing advanced, adaptive threats such as AI-assisted attacks and polymorphic malware. A short video introduces Talos team members and demonstrates how reputation and detection feeds inform security decisions. A more detailed technical overview is available on the Cisco Security site.
read more →

Forg365 PhaaS Targets Microsoft 365 with AI

🛡️ Forg365 is a phishing-as-a-service platform that targets Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device-code phishing with integrated AI-assisted lure generation. The service offers an admin dashboard for campaign management, OAuth and SMTP configuration, token handling, and a browser extension called ForgCookie for persistent cookie harvesting. Researchers at ZeroBEC found the operation uses legitimate delivery services like Amazon SES and SendGrid-hosted resources to blend malicious emails into normal traffic.
read more →

Verify threat indicators before acting on feeds

🔍 The author recounts multiple cases where threat intelligence feeds and advisories mischaracterized malware or buried stronger indicators in machine-readable files. They describe a commercial feed mislabeling a Windows DonutLoader variant as the Linux Chalubo RAT, an official advisory whose PDF lacked stronger hashes present in the STIX bundle, and a CERT report with binary-level discrepancies. The piece stresses that labels and pipeline metadata are guesses until validated and urges analysts to open structured files and detonate samples when stakes are high.
read more →

Google Disrupts NetNut Residential Proxy Network

🛡️ Google says its Threat Intelligence Group, working with FBI and industry partners, has degraded NetNut (aka Popa), a large residential proxy network that turns home devices into rented relays. GTIG estimates NetNut controlled at least 2 million devices, including smart TVs and streaming boxes, which can be used to route criminals' traffic through private home connections. NetNut is linked to publicly traded Alarum Technologies, which denies wrongdoing and says its software provides consented bandwidth sharing. Researchers found many apps did not show consent prompts, and Google warns the network is resilient through reseller arrangements and may reappear under different brands.
read more →

Detection engineering rises as a core SOC capability

🔍 Detection engineering has moved from a niche role to a strategic imperative for many organizations, focused on building tailored, behavior-driven alerts that reduce false positives and improve response. It emphasizes threat modeling, SDLC/CI-CD practices, and integration of threat intelligence to craft detections specific to an organization’s environment. A SANS-Anvilogic survey found broad investment and leadership support, while AI and automation are increasingly used to tune rules and scale workflows.
read more →

Cloudflare launches Attribution Business Insights dashboard

📊 Cloudflare introduces the Attribution Business Insights dashboard to help publishers and business leaders distinguish valuable human referrals from extractive AI crawler traffic. The dashboard provides site-wide and per-operator crawl-to-referral ratios, top bot breakdowns, and updated crawler classifications like Training, Search, and Agent. Available to Cloudflare Bot Management customers, it centralizes visibility so decision-makers can evaluate impact before acting via existing security rules.
read more →

Lessons from underground: combating BEC threats

📣 Flare researchers examined underground forum discussions and tools used to orchestrate Business Email Compromise (BEC) campaigns, finding that attacks extend beyond email to include remote access, cash-out networks, and call centers. Actors target finance and leadership SaaS accounts, increasingly using AI to craft realistic messages and scale operations. Defenders should monitor exposed credentials, enforce MFA, train high-risk staff, and treat multi-channel contacts cautiously.
read more →

Pre-positioned cyber threats around FIFA 2026 event

⚠️ Check Point Research found that cybercriminals pre-built and partially deployed fraud infrastructure targeting FIFA World Cup 2026 before the June 11 kickoff, focusing on financial services, transportation, hospitality, and gambling. Pre-tournament research highlighted weak DMARC enforcement among partners, a 60x surge in fake sportsbook apps concentrated on Google Play, and large volumes of lookalike travel and hotel domains created two months prior. Check Point's exposure, brand protection, and dark web monitoring capabilities flagged the activity and report rapid remediation metrics.
read more →

US offers $10M for info on hackers targeting Signal and WhatsApp

🔔 The U.S. Department of State is offering up to $10 million through its Rewards for Justice program for information identifying members of UNC5792 and UNC4221, two groups tied to Russian intelligence and military services. The bounty follows FBI and CISA updates that these groups conducted phishing campaigns targeting Signal and WhatsApp users, including attempts to steal Signal Backup Recovery Keys by impersonating support agents. Targets included U.S. and NATO officials, journalists, NGOs, and researchers.
read more →

Fortinet Supports INTERPOL Operation CyberProtect III

🔎 Fortinet contributed to INTERPOL’s Operation CyberProtect III by providing intelligence and analysis through its role in the World Economic Forum’s Cybercrime Atlas. The four-day initiative helped identify dozens of suspicious cases, suspect profiles, and potential victims on content subscription platforms. The operation highlighted trends such as encrypted messaging, coded language, cryptocurrency payments, and AI-generated profiles used to facilitate exploitation.
read more →

VisionHeight managed rules added for AWS Network Firewall

🛡️ AWS Network Firewall now offers two new managed rule groups from VisionHeight in AWS Marketplace: Zero-Day Threat Protection and Noisy Scanners and Tor Protection. These rule groups use VisionHeight's Pulse telemetry to provide proactive blocking of malicious IP infrastructure and suppression of noisy Tor and scanner traffic. Daily refresh cycles reduce SOC alert volume and SIEM ingestion costs while improving protection for targeted workloads.
read more →

AI-Augmented Threat Intelligence: Beyond IOCs

🛡️ The article examines how AI, particularly large language models, can bridge the gap between atomic indicators of compromise (IOCs) and richer strategic threat intelligence by indexing and relating unstructured reports. It highlights opportunities to retrieve relevant intelligence and generate tailored defensive advice while warning about data veracity and confidentiality. The piece also emphasizes practical Windows threats abusing COM and recommends tooling and hunting practices to detect such misuse.
read more →

Microsoft named Leader in Forrester XDR Wave 2026

🛡️ Microsoft has been named a Leader in The Forrester Wave™: Extended Detection and Response Platforms, Q2 2026, earning the top Strategy and Vision scores. The report highlights Microsoft Defender and Microsoft Threat Intelligence for high marks across identity detection, cloud detection, SIEM replacement, threat hunting, and more. Microsoft emphasizes an XDR foundation that unifies signals across identities, endpoints, email, SaaS, and cloud workloads to enable coordinated, AI-assisted attack disruption and faster SOC operations.
read more →

Survey Finds AI Attacks Top Concern for Security Leaders

🔍 A Filigran survey of 168 security leaders at Infosecurity Europe 2026 found AI-powered attacks are the leading worry, cited by 41% of respondents, outpacing supply chain and unknown threats. Teams report alert fatigue as a major time sink, with chasing false positives (26%) and validating risks (25%) common. Trust in threat intelligence and AI decision-making remains low, and only 28% have a continuous exposure management program.
read more →