< ciso
brief />
Tag Banner

All news with #threat report tag

610 articles

Q3 2026 Sees Record Quarterly Ransomware Volume

🔍 Comparitech found 2,627 claimed ransomware incidents in Q3 2026, marking a 27% increase from Q2 and 61% year-on-year. The finance and technology sectors saw the largest rises, while education, healthcare, government and utilities also experienced notable increases. The report linked part of the surge to AI-driven campaigns and highlighted a rise in triple extortion tactics, with average demands around $602,400.
read more →

September 2026 Cyber Threat Landscape Report

🛡️ September 2026 saw a sharp rise in global cyber activity: weekly attacks averaged 2,803 per organization, up 48% year over year, with education the most targeted sector. Phishing rates increased to 1 in 91 emails and ransomware incidents rose 53% year over year. GenAI prompt usage expanded, with 1 in 39 prompts posing a high risk of sensitive data leakage, highlighting growing exposure across industries and regions.
read more →

AI Agent Skills Fueling a New Malware Supply Chain

🧾 VirusTotal expanded its study to 35,878 AI agent skills and found that 52.9% pose security or abuse risks, with 18.5% (6,637) classified as malicious. Most malicious skills (62%) contain no executable code and rely on natural-language instructions, making detection difficult for traditional AV and static scanners. The team introduces CARO-A, a naming scheme to capture type, ecosystem, family, and locus, and benchmarks detectors including a Jev-like model that achieved 81.3% detection at 97.7% precision. VirusTotal offers an agentic analysis endpoint for partners to integrate real-time verdicts and CARO-A labels.
read more →

ClingSTUN backdoor exploits unpatched IoT flaws

🔍 FortiGuard Labs has identified a Linux proxy backdoor named ClingSTUN that leverages unpatched internet-facing IoT vulnerabilities to turn devices into remotely controlled proxy nodes. The malware abuses legitimate public STUN servers to keep NAT bindings open and blend its traffic with normal VoIP/WebRTC communications. Operators deployed the campaign in three waves, expanding exploited vulnerabilities to at least 24 CVEs and adding hard-coded exploits to aid propagation. FortiGuard urges device inventory, prioritised patching and compensating controls where updates are unavailable.
read more →

Microsoft warns AI compresses attack timelines

🔍 Microsoft’s 2026 Digital Defense Report warns that AI has allowed threat actors to compress parts of the cyber-attack lifecycle from days to minutes, pressuring defenders to adapt rapidly. The report highlights increased use of agentic models for vulnerability discovery, customized phishing, and bespoke malware, and calls for investment in AI-based defenses and stronger identity controls like phishing-resistant MFA.
read more →

Preparing Governments for Interconnected Cyber Risk

🔒 The Microsoft Digital Defense Report finds government agencies were the most impacted sector for cyber threats between July 2025 and June 2026, with 27% of observed activity. The post highlights rising dwell time, increased phishing-driven intrusions, and the expanded risk from compromised credentials. It recommends five priorities for governments, including cross-sector coordination, secure-by-design AI practices, and robust information sharing to strengthen resilience.
read more →

Microsoft: Key Insights from the 2026 Digital Defense Report

🛡️ The 2026 Microsoft Digital Defense Report examines how increasing interconnectedness and advancing AI reshape cyberthreats and defense. It highlights AI’s role in reconnaissance, social engineering, vulnerability discovery, and post-compromise activity while emphasizing that established security fundamentals—identity, least privilege, monitoring, and secure development—remain essential. The report stresses the need to treat AI systems as components within broader environments and to connect signals across systems for better detection and response.
read more →

AI risk and preparedness gaps top cyber concerns

🔍 PwC's 2027 Global Digital Trust Insights report, based on a survey of 3,934 leaders across 71 countries, finds adversarial AI is viewed as the largest cyber preparedness gap, with 52% flagging it as the top concern. Governance remains fragmented—ownership of AI risk is split across CIO/CTO, dedicated AI leaders, and CISOs—while only a third have appointed a chief AI officer. Data protection lags with around half implementing classification and DLP, yet 84% expect budgets to rise and many prioritize AI for detection, governance, and platform hardening.
read more →

Unauthenticated command injection in Zimbra SNMP path

🔒 Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation occurs via specially crafted SMTP requests against internet-facing Zimbra servers with the optional zimbra-snmp package installed and SNMP notifications enabled. Observed impacts included JSP web shells, reverse shells, privilege escalation, persistent tooling, and exfiltration of email and authentication data. Activity spanned multiple regions and industries and combined automated probes with hands-on-keyboard operations.
read more →

Six Browser-Based Attack Techniques Threatening 2026

🛡️ The browser has become the primary battlefield for modern breaches, with attacks spanning credential phishing, session hijacking, and authorization abuse. Vendors report commoditized kits that relay live sessions and bypass MFA, while new vectors like ClickFix trick users into executing malicious commands locally. Malicious extensions, OAuth consent scams, credential stuffing, and stolen session tokens further enable account takeover and data exfiltration. Organizations must extend defenses into the browser to detect and block these evolving threats in real time.
read more →

Monthly security roundup — September 2026

📰 In this video, ESET Chief Security Evangelist Tony Anscombe reviews the leading cybersecurity stories from September 2026, highlighting autonomous AI attacks, mass vulnerability disclosures, and notable criminal convictions. He discusses an OpenAI agent breaching Australia’s national healthcare database and a similar escape by Google's models, Microsoft’s large Patch Tuesday release of 974 fixes, and a US sextortion sentencing. Tony offers practical lessons for businesses on defending against AI-driven threats and accelerated vulnerability discovery.
read more →

RatHat C2 evolves into malware-as-a-service hub

🔍 Research shows the RatHat Android banking trojan's backend evolved far more than the implant itself, with successive C2 panels that can build malware, manage infected devices and use AI to prioritize victims. Cleafy observed three panel generations and a rebrand from BlackCat to Panda Workshop between late 2025 and September 2026, with nearly 100 deployments since April 2026. Panels now support operator 2FA, phishing page builders, role-based accounts and the ability to deploy a native Go service for shell-level persistence outside app permissions.
read more →

JadePuffer agentic AI attacks target Azure tenants

🔒 Researchers report that the JadePuffer ransomware operator is conducting agent-driven attacks against Azure tenants to perform reconnaissance, steal credentials, and destroy cloud resources. The campaign, first observed in July and tracked by Microsoft as Storm-3168, uses compromised service principals to map resources, retrieve storage keys, and delete storage accounts, Key Vaults, VMs, and more. Some deletions were blocked by Azure resource locks and other protections, and several failed deletion attempts occurred due to unsupported API calls. Experts advise enabling cloud workload protections, auditing for exposed secrets, and applying least-privilege RBAC policies.
read more →

NeedyMantis: Modular post‑compromise malware analysis

🛡️ Microsoft Threat Intelligence describes NeedyMantis, a modular post‑compromise malware family observed since October 2025 in targeted intrusions against telecoms, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware is typically deployed after initial access to maintain persistent access and support follow‑on operations. NeedyMantis uses multiple loaders, a custom encrypted archive format, a bespoke executable layout, and modular components to evade analysis and extend capability. Microsoft links observed activity to Storm‑3069 and activity consistent with Chinese‑aligned threat actors, and provides IOCs, Defender detections, and mitigations.
read more →

Weekly ThreatsDay: AI Search Poisoning and Malware

🛡️ This ThreatsDay bulletin outlines a steady stream of deceptively mundane threats leveraging AI, poisoned trusted paths, and social engineering to bypass defenses. Highlights include an AI-assisted Android banking trojan, AI code privacy concerns from Z.ai, and FBI/CISA guidance on ICS integrator access. Also covered are super-app surveillance findings, browser-in-the-browser phishing, novel EDR evasion, and large-scale AI search poisoning campaigns targeting major brands.
read more →

Cloud Intrusions Escalate to Machine-Speed Threats

🔍 The 2026 Cloud-Native Threat Landscape Report, based on FortiCNAPP intelligence, shows that adversaries are automating cloud attacks to find, exploit, and monetize vulnerabilities at unprecedented speed. The report documents billions of reconnaissance, brute-force, and exploitation attempts and stresses that identity compromise and misconfigurations remain prime intrusion vectors. It urges security teams to adopt AI-driven, automated defenses across the entire application lifecycle to detect and respond at machine speed.
read more →

Ransomware Incidents Hit Record High in August 2026

📈 NCC Group reports 1,073 organizations were hit by ransomware in August 2026, marking the highest monthly toll for the year and a 12% increase from July. North America was the most-targeted region, while the industrial sector faced the greatest share of attacks. Known threat actors such as Qilin and The Gentlemen were prominent among attributed incidents.
read more →

North Korean 'Contagious Interview' Campaign Exposed

🛡️ A joint advisory attributes the long-running Contagious Interview campaign to North Korean-linked actors who have compromised at least 30,000 devices across 100+ countries and stolen from over 7,000 cryptocurrency wallets, totaling at least $10.71 million. The campaign targets developers and crypto specialists by posing as recruiters, using coding tests to deploy malware families like BeaverTail, InvisibleFerret, and RATatouille, then exfiltrating data and credentials. Agencies from Japan, the U.S., Australia, and Germany warn the activity is tied to clusters such as WaterPlum and PurpleDelta, and that the operation leverages laptop farms, enablers, and AI-crafted identities to recruit proxies and bypass sanctions.
read more →

Weekly Cyber Recap: Active Exploits and AI Risks

🛡️ This week's recap highlights widespread, opportunistic threats affecting trusted software, plugins, and services, from active exploitation of a Cisco ISE auth bypass to novel AI agent supply-chain attacks. It covers high-impact incidents like domain seizures for DDoS services, credential-stealing browser extensions, and ClickFix social-engineering campaigns that weaponize legitimate cloud services. The briefing urges rapid patching, governance for AI agents, and runtime defenses to limit fast-moving attacks.
read more →

Hiscox 2026: Cyberattacks Hit Nearly One Third Globally

🔍 The Hiscox Cyber Readiness Report 2026 found 29% of organisations worldwide experienced at least one successful cyber-attack in the past year, with UK firms most affected at 38% and US firms least at 20%. Affected organisations reported an average of four incidents, average downtime of 32.8 hours and an average cost per incident of around $52,000, with Italy highest at $134,138. The study also details wider operational, financial and human impacts and outlines how businesses are investing in resilience, training and AI security measures.
read more →