< ciso
brief />
Tag Banner

All news with #threat report tag

573 articles

White House Memo Expands Private Cyber Operations Role

📝 This week's Threat Source newsletter by Mick Baccio examines a recent presidential memorandum directing DOJ and DHS to create a program that allows private companies to conduct government-authorized cyber surveillance and effects operations against transnational criminal organizations. The piece highlights operational questions about attribution, intelligence handling, and geopolitical risk, and notes Talos reporting on AI-driven Chinese cybercrime group UAT-10147 and critical active exploits.
read more →

ThreatsDay: Signed Drivers, AI Risks, and RCEs

🛡️ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more →

Back-to-School Cyber Risks Hit Education Hard

📚 Check Point Research reports that the education sector was the most targeted industry between January and July 2026, averaging 4,696 weekly attacks per organization—more than double the global cross-industry average. Attack volumes rose further in July, while APAC saw the highest regional pressure and Europe and Latin America recorded the fastest growth. Researchers also observed surges in newly registered education-themed domains and coordinated phishing campaigns targeting students and staff, often leveraging counterfeit sites and compromised legitimate pages.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

Weekly ThreatsDay: GhostJacking and New Attacks

📰 This ThreatsDay Bulletin aggregates a week of security updates across cloud services, AI agents, malware, data breaches, scams, and novel attack techniques. It summarizes campaigns like City-Forum targeting guest access in Salesforce and ServiceNow, the ShipMonk customer data exposure, and Cursor's pre-trust code execution flaw. The bulletin also highlights vishing platforms, AI agent hijacking (GhostJacking), defensive prompt-injection use, and other noteworthy incidents.
read more →

Ransomware Q2 2026: Spread and Shifting Threats

🔍 Data leak sites recorded 2,139 ransomware victims in Q2 2026, effectively flat versus Q1 and up 33% year over year. The top 10 groups still accounted for most victims, but active groups rose to a record 93. Leaked chats from The Gentlemen showed a nine-person core using AI coding tools to rapidly build a top-tier operation, highlighting the need to prioritize initial access, exfiltration detection, and exposure reduction.
read more →

July 2026 Cyber Threats: Ransomware and GenAI Risks

🔒 July 2026 saw a marked uptick in cyber incidents, with weekly attacks averaging 2,336 per organization and ransomware victims rising sharply. Education, Latin America, and Business Services were among the most affected, while GenAI use exposed sensitive data through risky prompts. Email remained a primary entry point as organizations confront multi-vector threats and growing operational exposure.
read more →

Cloudflare DDoS Threat Report H1 2026 Summary

📊 Cloudflare's H1 2026 DDoS Threat Report from Cloudforce One summarizes DDoS activity across January–June 2026. The report details mitigation of 23.2 million network-layer attacks and 29.64 trillion HTTP requests, highlights April as a peak month, and describes growth in hyper-volumetric and reflection-based vectors like CLDAP. It emphasizes the necessity of automated, always-on protection.
read more →

ThreatsDay bulletin: weekly cyber risk roundup

📌 This ThreatsDay bulletin summarizes a week of active cyber risks, including supply-chain npm packages, ClickOnce phishing chains, AI-driven attacks and new macOS and Samsung device exploits. It highlights research on coding-agent trust, AI-powered proxyjacking, and large-scale malicious npm campaigns, and notes policy and platform responses from Apple, Signal, and Microsoft. The report emphasizes common causes: exposed services, trusted defaults, recycled bugs, and poisoned agent instructions.
read more →

UNC6671 Targets Financial and Cloud Environments

🔎 GTIG reports UNC6671 continues active compromises and data-theft extortion despite the alleged BlackFile retirement, diversifying into Redact, Pink, Helix, and Falcon. The actor uses targeted voice phishing (vishing) to lure employees—often on personal phones—to spoofed login portals with AiTM infrastructure to harvest credentials and MFA tokens, then deploys scripts to exfiltrate data from enterprise cloud apps like Microsoft 365 and Okta. The update details infrastructure linkages, evolving targeting focused on financial services and private equity, and offers hardening guidance to mitigate these identity-centric threats.
read more →

Talos webinar: Q2 incident briefing for security teams

📢 Next Tuesday, August 11, Cisco Talos Incident Responders will host a 30-minute, unrecorded webinar reviewing high-impact incidents from Q2 2026. The session will candidly cover timelines, containment, and remediation efforts rather than repeating the published trends report. Designed for security professionals at all levels, it emphasizes strategic takeaways, business impact, and enough technical detail to inform discussions. Registration is required to attend this exclusive briefing.
read more →

New OctLurk and SilkLurk Campaign Targets Central Asia

🛡️ Kaspersky attributes a sustained campaign since January 2025 to a suspected Chinese-speaking threat actor targeting government and public-sector organizations across Central Asia and Syria. The attacker toolkit includes two memory-resident backdoors, OctLurk and SilkLurk, plus a proxy utility dubbed LurkProxy, enabling credential theft, keylogging, remote access, network scanning and plugin-based expansion. Initial access remains unknown, and infrastructure links were observed to a previous campaign using a C++ implant called SilentRaid. Victim-specific payload encoding and in-memory operation complicate detection and analysis.
read more →

Amazon Links npm Supply-Chain Attacks to DPRK Actor

🔍 Amazon tied several high-profile npm supply-chain compromises to the Sapphire Sleet group, attributing trojanized packages like typo-crypto, debug, chalk, and axios to North Korea–linked hackers. The campaign began in March 2025 and escalated into 2026, leveraging social engineering of maintainers to push malicious updates that propagated automatically. Amazon reported medium confidence attribution based on shared TTPs, C2 infrastructure, and operational similarities while noting a likely financial motive and AI-enabled enhancements to attack techniques.
read more →

Talos Threat Source: Q2 IR Trends and Insights

🧭 This edition of the Threat Source newsletter ties a challenging Old Rag hike to cybersecurity resilience and introduces the Talos Q2 2026 Incident Response Trends report. The report highlights spikes in authentication abuse and advanced phishing techniques, including QR-based lures and ARToken platforms, while noting ransomware groups abusing legitimate remote management tools. It recommends phishing-resistant MFA, behavior-based monitoring, centralized logging, and prioritized patching.
read more →

Ad fraud and proxy risk in generic TV streaming sticks

🛡️ Security researchers uncovered that inexpensive, off‑brand TV streaming sticks not only run residential proxy software but also impersonate mobile phones to click ads on AI‑generated sites. Bitsight TRACE researcher Pedro Falé analyzed telemetry from an expired domain tied to H96 devices and found apps linked to Zhejiang Fengwo IoT Technology that coordinate ad‑fraud campaigns. These devices switch roles between proxying traffic when in use and executing ad‑clicking jobs when idle, enabling large‑scale monetization and deceptive marketing claims.
read more →

ThreatsDay: AI-Driven Attacks and Widespread Malware

🛡️ This week’s ThreatsDay Bulletin surveys a wide set of active campaigns and vulnerabilities, from phishing that delivers XWorm and LunaSpy to custom ransomware (GenieLocker) and crypto-focused stealers. Reports detail fileless WebDAV execution, supply-chain hardening by GitHub, a My Eicher fleet takeover flaw, and AI-agent-driven autonomous exploitation across multiple CVEs. Enterprise and consumer impacts include large data exposures and targeted SaaS account takeovers.
read more →

AI Agents Gain Access to Financial Workflows

🤖 Pathlock’s 2026 AI Governance Gap Report reveals many enterprises now give AI agents the ability to create records, execute workflows, and approve transactions across finance, procurement, HR, and supply chain systems. The survey found 79% of organizations lack a dedicated AI governance team and over half cannot fully verify AI-driven actions. Only 19% report complete, real-time visibility into agent activity, leaving tracing and investigation capabilities largely immature.
read more →

IBM: Average Data Breach Cost Nears $5M

🔍 The 2026 IBM Cost of a Data Breach Report, published on July 29 and based on incidents at 602 organizations between March 2025 and February 2026, found the global average breach cost rose 12% to $4.99 million. Lost business and long-term reputational damage are key drivers of cost, while healthcare remains the most affected sector. The report also highlights a surge in AI-driven attacks, which added about $1 million to breach costs, and recommends zero trust and stronger data governance.
read more →

Ransomware Q2 2026: EDR-Kill Becomes Standard

🔍 Halcyon’s Q2 2026 Ransomware Evolution Report warns that shutting down endpoint detection and response (EDR) tools—known as EDR-kill—has become routine among leading ransomware groups, reducing defenders’ time to react. The Gentlemen, a prolific emerging group, incorporates reversed techniques from other gangs and explicitly includes EDR/antivirus shutdowns in attack chains. The report also notes a decline in claimed attacks but a marked rise in sophistication, faster operations, AI-assisted tactics, and the use of ransomware for state-aligned objectives.
read more →

DevMan RaaS Portal Centralizes Payloads and Management

🛡️ Swiss firm PRODAFT reports that the DevMan ransomware-as-a-service operation runs a centralized affiliate portal enabling payload builds, victim management, finance tracking, and team coordination. The platform evolved to v3 in January 2026 with structured victim records, deadlines, and shared access, while affiliates follow strict rules and an 80-20 revenue split. The locker targets Windows, ESXi, and Linux and uses ChaCha20-Poly1305 encryption.
read more →