< ciso
brief />
Tag Banner

All news with #threat report tag

610 articles · page 2 of 31

Most Organizations Fail Ransomware Recovery Tests

🔍 Only four of over 800 clients assessed by Fenix24 approached their 24–48 hour ransomware recovery targets and then only for partial operations. None achieved full capacity until weeks later. The firm’s State of Recoverability report, covering 500+ ransomware recoveries published on September 15, highlights routine failures in identity recovery, Active Directory compromise, inadequate backups, and overlooked physical constraints like storage and network. Fenix24 urges organizations to map critical dependencies and run end-to-end restore tests.
read more →

The Modern Bank Heist Is Already Under Way

🔒 Research from Trend AI shows attackers now embed themselves inside financial networks to study responses and access payment systems, market intelligence and customer identities. Forty-eight CISOs surveyed reported increases in AI-enabled attacks and API targeting, while many noted attempts to steal non-public market information. The report warns adversaries are operating like cartels, using AI, deepfakes and island-hopping to escalate threats.
read more →

August 2026 Cyber Threat Landscape Overview

🔍 August 2026 saw rising cyber threats across multiple vectors, with weekly attacks per organization averaging 2,422 and ransomware incidents nearly doubling year over year. GenAI usage surged to 106 prompts per user, yet high-risk prompts persisted affecting 86% of GenAI-using organizations. Email phishing and regionally varied attack volumes further illustrate a broadening and intensifying risk environment that demands expanded governance and prevention.
read more →

Compromised Non‑Human Identities Outpace Phishing Risks

🔍 A new SpyCloud report finds compromised non-human identities (NHIs) — including AI agents, service accounts, API keys and tokens — accounted for 31% of intrusions versus 17% for social engineering. Based on a survey of 750 cybersecurity leaders across North America and Europe, the study highlights a gap between perceived and actual NHI visibility and monitoring. The report also notes weak AI governance, inconsistent third‑party identity checks, and elevated supply chain identity risk.
read more →

From Prompting to Autonomy: Adversarial AI Trends

🛡️ Since the May 2026 report, Google Threat Intelligence Group (GTIG) observed adversaries shift from simple prompting to agentic AI workflows and AI-enabled automation, compressing defender response windows. In Q2 2026, threat actors executed an agent-enabled mass credential harvesting campaign within six hours and UNC6780 exploited AI coding assistants and LLM security scanners to compromise open source supply chains. GTIG also noted increasing targeting of proprietary AI models, exfiltration of API credentials, and misuse of cloud compute for unauthorized AI workloads.
read more →

Attackers Use Agentic AI to Scale Credential Theft

🛡️ Google Threat Intelligence Group (GTIG) reports financially motivated and state-aligned actors are leveraging agentic AI and autonomous multi-agent frameworks to conduct rapid, large-scale credential harvesting and supply chain compromises. Teams like TeamPCP (aka Altered Spider) deploy credential stealers such as SANDCLOCK and DUSTMAKER to target developer tools, cloud environments, and AI assets. Adversaries also repurpose open-weight models and misappropriate proprietary AI research, increasing risks to enterprise AI deployments and prompting calls for industry safety baselines.
read more →

Threat actors increasingly exploit AI coding tools

🔍 A Google Threat Intelligence Group (GTIG) report warns that AI-assisted coding tools have become a primary target for threat actors, contributing to large-scale software supply chain compromises in 2025–2026. GTIG highlights a financially motivated group, UNC6780, using Dustmaker malware to compromise PyPI, npm and Docker Hub packages, extract tokens from GitHub Actions runners, and hide malicious files in AI assistant workspaces. The report also describes espionage and extortion targeting proprietary AI research and models, and growing adversary experimentation with agentic AI to accelerate attacks.
read more →

Democratization of Cyber Warfare and CISO Implications

🛡️ AI is rapidly lowering the barriers to sophisticated cyber operations, enabling individuals and small groups to perform attacks that once required significant resources and expertise. The article describes real-world examples—from autonomous AI-driven attacks in Taiwan to Claude Code use against private firms—and warns that defenders cannot rely solely on human analysts. Organizations must adopt AI-enabled defense with clear intent and guardrails, allowing systems to act at machine speed while preserving human oversight.
read more →

AI-enabled intrusions target Latin American organizations

🔎 We analyzed two multi-stage intrusion and data-exfiltration campaigns targeting Latin America that leverage AI to streamline operations. One cluster (CL-CRI-1131) targeted Mexican transportation and government entities using LotL techniques and self-hosted NextChat, while a second (CL-CRI-1163) targeted Brazil’s financial sector with custom RATs and a Go-based SOCKS5 proxy. Both clusters share proxy infrastructure and evidence of commercial LLMs aiding attackers.
read more →

INTERPOL: Cybercrime Industrialization Threatens Africa

🔎 INTERPOL’s African Cyberthreat Assessment Report 2026, with contributions from FortiGuard Labs, finds cybercrime in Africa has shifted into an industrialized, borderless ecosystem driven by specialized service providers, shared infrastructure, automation, and AI. The report links rapid digital adoption to rising exploitation, noting reported losses doubled from 2024 to 2025 and credentials are often the initial foothold. It calls for integrated identity-centric defenses, faster intelligence-to-protection workflows, and stronger public-private collaboration to enable disruption.
read more →

Gambling Goblin hijacks government sites for SEO fraud

🔍 Check Point Research details a campaign by a Chinese-speaking actor dubbed Gambling Goblin that compromises Brazilian government web servers and repurposes them as invisible reverse proxies for phishing pages. The operation installs malicious Apache modules and toolkits to proxy trusted domains to attacker-controlled pages impersonating major app stores, using borrowed reputation to boost SEO and push online gambling. The campaign is linked to the Earth Berberoka cluster and demonstrates an industrialized, scalable fraud model.
read more →

Weekly cybersecurity recap: espionage, AI, and breaches

⚠️ This week’s recap highlights major disruptions and ongoing campaigns, from an FBI takedown of a Chinese proxy network to AI agents and supply-chain failures. Coverage includes router backdoors, chained PaperCut flaws, malware delivered via fake CAPTCHAs, and the evolving tactics of China-linked actors like Fire Ant. Patch and verify trusted infrastructure controls to reduce risk.
read more →

APT28-linked HOOKEDGE backdoor targets diplomats

🛡️ Recorded Future's Insikt Group has identified campaigns from late September 2025 to April 2026 that delivered a newly observed Windows batch backdoor named HOOKEDGE via macro-enabled Word documents targeting government and diplomatic entities in Romania, Spain, and Türkiye. The activity is attributed with moderate confidence to APT28 (aka Fancy Bear), with HOOKEDGE exhibiting significant overlap with the group's earlier HEADLACE tooling and abusing webhook[.]site for C2, staging, and exfiltration.
read more →

Weekly ThreatsDay: Botnets, Stealers, and RATs

🔍 This week’s ThreatsDay roundup highlights diverse active campaigns and new tooling, from a 296,000‑device IoT botnet to live operator phishing frameworks and AI‑assisted botnet orchestration. Researchers observed trojanized Electron apps, new stealers and RATs, a Rust backdoor tied to ransomware, and a loader using blockchain for C2. Also covered: a social‑engineering incident at ReliaQuest, an Android fraud bot for rent, and an unpatched disk‑encryption bypass in HP ThinPro.
read more →

Tortoiseshell expands toolkit with backdoor, SSH tunnel

🛡️ Group-IB identified new Tortoiseshell activity, uncovering a reverse SSH tunneling utility and a C++ backdoor disguised as wtsapi32.dll. The SSH tool leverages Windows OpenSSH to create reverse tunnels into compromised networks, while the backdoor supports HTTPS C2 communications, file and shell execution, and in-memory DLL loading. Researchers also linked domains resolving to servers with regional subdomains, suggesting possible targeting across Europe and the Middle East and urging enhanced threat hunting and monitoring.
read more →

CISA red team reveals starkly different SOC outcomes

🛡️ CISA released dual red team reports showing two critical infrastructure organizations were fully domain-compromised using similar tradecraft. Organization A suffered extensive undetected access due to default machine account quotas, misconfigured AD CS templates, cleartext credentials, static cloud keys, and fragmented SOC visibility. Organization B detected and isolated initial footholds quickly, limiting spread despite similar underlying weaknesses, illustrating the decisive role of people and processes.
read more →

Phishing-as-a-Service Exploits AI Calls to Strip Activation Lock

📣 SOCRadar researchers uncovered a PhaaS platform called AnonyMousKIT that uses rented AI voice agents and multi-channel lures to trick owners of recently lost or stolen Apple devices into revealing passcodes, Apple ID credentials, and live 2FA codes. The service is credit-metered across email, SMS, WhatsApp, recorded calls, and AI calls, and its capture pages show device model and Find My status to increase believability. Calls—mostly to Brazil—ran between August 2025 and May 2026, and the kit is offered through multiple storefronts with shared infrastructure and operational features resembling a small criminal SaaS business.
read more →

White House Memo Expands Private Cyber Operations Role

📝 This week's Threat Source newsletter by Mick Baccio examines a recent presidential memorandum directing DOJ and DHS to create a program that allows private companies to conduct government-authorized cyber surveillance and effects operations against transnational criminal organizations. The piece highlights operational questions about attribution, intelligence handling, and geopolitical risk, and notes Talos reporting on AI-driven Chinese cybercrime group UAT-10147 and critical active exploits.
read more →

ThreatsDay: Signed Drivers, AI Risks, and RCEs

🛡️ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more →

Back-to-School Cyber Risks Hit Education Hard

📚 Check Point Research reports that the education sector was the most targeted industry between January and July 2026, averaging 4,696 weekly attacks per organization—more than double the global cross-industry average. Attack volumes rose further in July, while APAC saw the highest regional pressure and Europe and Latin America recorded the fastest growth. Researchers also observed surges in newly registered education-themed domains and coordinated phishing campaigns targeting students and staff, often leveraging counterfeit sites and compromised legitimate pages.
read more →