< ciso
brief />
Tag Banner

All news with #threat report tag

573 articles · page 2 of 29

Ransomware Attacks Rise Against Universities in H1 2026

🔍 Analysis shows ransomware attacks against higher education rose in H1 2026, driven largely by The Gentlemen operation. Comparitech’s report records 104 attacks on the education sector, 36 confirmed as ransomware, with US institutions the most affected. The median ransom demand jumped to $420,620 and the largest demand reached $1.9m after the Mount Royal University incident.
read more →

Threat Source newsletter: Q2 2026 vulnerability trends

📈 This edition of the Threat Source newsletter reviews Q2 2026 vulnerability trends, noting a 49% YoY increase in tracked CVEs and roughly 200 CVEs per day by June. The author contrasts a shifting AI model landscape with slower real-world impact, highlights concerns about keyword-sensitive AI-CVE counts, and advocates prioritizing patches using EPSS rather than raw CVSS scores. Additional coverage includes Cisco Talos' discovery of the Rust-based msaRAT, new Antares SLMs for vulnerability localization, major incidents impacting land registries and WordPress sites, and tactical detection recommendations.
read more →

Weekly ThreatsDay Bulletin: Multifaceted Cyber Risks

🛡️ This week's ThreatsDay Bulletin catalogs varied, evolving threats that masquerade as useful software or ordinary files. Highlights include npm and PyPI supply-chain risks, a rogue VS Code extension, a fake Claude app delivering SectopRAT, and Android apps posing as civil-defense tools that instead enable surveillance. The report also details PLC-targeting activity linked to Iranian-affiliated actors and new AI-related exploitation techniques.
read more →

Ransomware Landscape Expands with New Groups Weekly

🛡️ The Black Kite Ransomware Report 2026 finds 146 active ransomware groups as of June 2026, up from 105 a year earlier, with 61 new groups emerging in 2026 alone. The study highlights a fragmented ecosystem where groups often have short lifespans—averaging 4.9 months—and a small number of operators still account for a large share of disclosed victims. Black Kite urges organizations to prioritize rapid patching of critical vulnerabilities and strengthen identity and vendor controls to mitigate attacks.
read more →

Ransomware Now Disrupts a Government Every Day

🔒 Analysis from Comparitech finds ransomware attacks on government agencies rose in early 2026, averaging one incident per day. The study recorded 187 attacks from January to June 2026, a 13% increase from late 2025, with just over half publicly confirmed. The US was the most targeted country (31%), mean demands were around $100,000, and groups like The Gentlemen, Qilin and LockBit were prominent. Experts stress timely patching, backups and staff training to reduce risk.
read more →

The Gentlemen Tops Ransomware Incidents in Q2

🛡️ ReliaQuest's July analysis shows The Gentlemen ransomware gang conducted 300 attacks in the three-month period, surpassing Qilin's 289 incidents. Researchers tracked 1,368 victim claims across 99 countries from 11 ransomware groups, with DragonForce, Akira and LockBit also active. ReliaQuest attributes The Gentlemen's rise to aggressive affiliate recruitment, pre-packaged intrusion kits and AI-accelerated tooling.
read more →

AI as a Force Multiplier in Incident Response

🔍 Unit 42’s 2026 Global Incident Response Report examines how threat actors integrate AI to accelerate attacks. Drawing on hundreds of engagements, the report finds AI shortens development cycles, automates content generation and streamlines reconnaissance, compressing attack lifecycles. Despite this speed, adversaries continue to rely on established TTPs like credential theft, phishing and ransomware, meaning defenders can apply existing controls while adapting to AI-driven efficiencies.
read more →

AI Appreciation Day: Honest View on Risks and Rewards

🤖 Today is AI Appreciation Day, and while AI has transformed coding, threat analysis, and productivity, Check Point’s AI Security Report 2026 warns that those same strengths empower attackers. Researchers observed AI running exploitation workflows autonomously, producing vast volumes of malware code and executing thousands of commands in real intrusions. Organizations are adopting many AI apps rapidly, often without governance, increasing high-risk prompts and exposure.
read more →

OAuth client ID spoofing exposes cloud sign‑in blind spot

🔒 Proofpoint has identified at least two threat clusters weaponizing a technique called OAuth client ID spoofing to enumerate accounts and validate stolen credentials in Microsoft Entra ID environments while avoiding successful sign‑in telemetry. By supplying spoofed or manipulated client_id values in OAuth token requests—often using the ROPC flow—attackers can cause different AADSTS error responses that reveal whether an account exists and whether a password is correct without recording a successful login. Campaigns such as UNK_pyreq2323 and UNK_OutFlareAZ have used millions of randomized or modified client IDs across thousands of tenants to probe and lock out users, undermining per‑application detections and Conditional Access policies.
read more →

Check Point Research: AI Security Threats 2026

🛡️ The Check Point AI Security Report 2026 documents how AI has shifted from an assistant to an operator in cyberattacks, running multi-step intrusions with minimal human direction. It highlights collapsed vulnerability response windows, widespread probing of exposed AI infrastructure, and a doubling of sensitive data leakage through approved AI use. The report recommends visibility, machine-speed defenses, and governance to protect AI systems and manage workforce AI.
read more →

Key findings from the 2026 public sector M‑Trends report

🛡️ The 2026 Public Sector Threat Landscape report summarizes Mandiant’s 2025 incident investigations and highlights how adversaries now move at machine speed, notably the 22-second hand-off from initial access to ransomware. It argues public agencies must adopt continuous verification and machine-speed defenses. Google outlines three core capabilities—identity as the perimeter, agentic defense, and hardened infrastructure—and describes new AI agents in Google Security Operations and customer success stories.
read more →

Dormant GitHub Accounts Exploited to Scrape Orgs

🔎 Datadog Security Labs warns of coordinated campaigns using dormant or compromised GitHub accounts and exposed personal access tokens to enumerate organizations via the GitHub API. Operators use automated scraping tools, aged "ghost" accounts, and legitimate-sounding user agents to blend into normal API traffic, primarily collecting public data but occasionally cloning private repositories. The activity leverages unauthenticated API surfaces and GraphQL queries to map repos, memberships, followers, and other artifacts for reconnaissance.
read more →

GigaWiper: Multipurpose Windows backdoor and wiper

🛡️ Microsoft dissected a destructive Windows backdoor dubbed GigaWiper, which bundles three older wipers into a single Go-based platform offering selectable destructive commands. The implant can wipe entire disks, overwrite the Windows drive, or run fake ransomware that encrypts files without saving keys, and also provides remote control capabilities like screenshots, VNC access, and process management. Microsoft and Binary Defense observed the same file hashes and command servers, with Binary Defense linking the samples to an Iran-linked actor while Microsoft refrains from attributing a country. Defenders should monitor for a OneDrive Update scheduled task, RabbitMQ/Redis traffic from desktops, and suspicious use of takeown/icacls, and apply tamper protection, endpoint blocking, and blocklisted server addresses.
read more →

Weekly ThreatsDay: Emerging cyber risks and trends

🔒 This ThreatsDay roundup highlights a series of recent, pragmatic security incidents and research findings that stem from routine administrative mistakes and small configuration errors. It covers a multinational fraud takedown, malicious typosquatting of payment SDKs, novel code-injection techniques, and a critical unauthenticated ArcGIS Server flaw. The report also outlines ransomware tool overlaps, data-exfiltration concerns in Claude Code, social engineering campaigns abusing Teams and Meta, and multiple kernel and driver vulnerabilities.
read more →

June 2026: Global Cyber Attacks and Ransomware Shift

📈 June 2026 saw a notable rebound in global cyber attacks, with weekly incidents per organization averaging 2,270, up 10% from May and 17% year over year. Education, Government, and Telecommunications were the most targeted industries, while Latin America recorded the largest regional increase. Ransomware incidents surged 33% year over year, and The Gentlemen overtook Qilin as the most active ransomware group.
read more →

AI-Accelerated Cloud Attack Exploits Management Gaps

🔎 A Sygnia report details how a lone threat actor leveraged AI to complete in 72 hours what would normally take weeks, using established cloud attack techniques rather than novel exploits. The attacker obtained an AWS access key via an internet-facing app and used agentic AI workflows to search for secrets, establish persistence, exfiltrate RDS data, and perform impact actions. The report highlights gaps in secrets management, identity governance, deployment workflows and visibility, and provides containment recommendations for defenders.
read more →

ESET H1 2026: Threats, AI, and Ransomware Trends

🔍 The first half of 2026 sees attackers adapting established techniques to new platforms and behaviours, with AI increasingly shaping operations. ESET analyzed nearly 900,000 AI skills and found tens of thousands suspicious and thousands malicious, while AI features began appearing inside malware such as the Android PromptSpy. Other trends include expanded click-based social engineering, surging QR-code phishing, and persistent ransomware activity using EDR killers.
read more →

New Java-based QuimaRAT MaaS Targets All Platforms

🛡️ Cybersecurity researchers have identified QuimaRAT, a modular Java-based remote access trojan offered as malware-as-a-service that targets Windows, Linux, and macOS. The kit includes a builder, loader, dropper, and the RAT itself, with subscription tiers from $150 to $1,200. QuimaRAT uses encrypted plugins, native libraries via JNA, and multiple persistence and delivery techniques to evade protections and maintain robust C2 connectivity.
read more →

Qilin Emerges as Dominant Ransomware Operation

🛡️ Check Point and Sophos research shows Qilin has consolidated a large share of the ransomware market after disruption of rival groups. Active since 2022, Qilin lists the most victims and attracts affiliates with high payouts, mature infrastructure and AI-enabled tools. Rival groups like The Gentlemen have resurged, while increased prominence raises the likelihood of law enforcement action.
read more →

Industrialized ransomware through criminal collaboration

🔐 Sophos reports a new collaboration between the Vect ransomware group and TeamPCP, a supply-chain credential theft gang linked to The Com collective. The partnership combines TeamPCP’s large-scale credential harvesting from developer toolchains with Vect’s ransomware-as-a-service operations, raising the risk that compromised accounts could be escalated into ransomware incidents. Sophos and the FBI have both issued warnings and detailed associated malware and tactics, urging organizations to harden developer and supply-chain security.
read more →