< ciso
brief />
Tag Banner

All news with #threat research tag

103 articles

ToxicPanda Android malware adds VPN and ADB abuse

🛡️ ToxicPanda 2.0 now requests VPN service permissions to create a local interface that can block Google Play and Google Play Services, enabling it to interfere with app verifications, updates, and Play Protect checks. After establishing the VPN, the malware extracts and installs payloads, requests Accessibility Service permissions, and automates Wireless ADB to gain shell-level access. Zimperium reports distribution via AWS-hosted buckets and notes support for 167 remote commands and overlays targeting 349 financial apps across 16 countries.
read more →

Using Crime Script Analysis to Explain Cyber Attacks

🔍 Crime script analysis (CSA) breaks cyber attacks into sequences of actions, decisions, and situational requirements, making complex campaigns accessible to non-technical audiences. CSA complements models like MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain by offering a narrative view that highlights practical "choke points" for disruption. The post illustrates CSA with a business email compromise (BEC) example and explains how AI can both enable attackers and provide new detection opportunities. Practical mitigations include honeypot canary organizations, provider-side detection of malicious LLM use, email rate-limiting, and stricter payment verification processes.
read more →

StopAndProtect: Operation Exposed by OPSEC Failures

🔍 Check Point Research uncovered a unique case where OPSEC mistakes exposed a global cyber crime operation named StopAndProtect. The investigation revealed accessible victim logs, screenshots, source code, and references to nearly 2,000 compromised WordPress domains, showing how attackers repurposed legitimate sites to host malware and manage campaigns. Researchers warn organizations to beware of unexpected CAPTCHA prompts and to keep systems and security software updated.
read more →

Researchers Expose North Korean Hiring Subterfuge

🔍 Security researchers created a fake cryptocurrency startup and hired three individuals they suspect were North Korean operatives. Each new hire completed onboarding, received work virtual machines, and performed reconnaissance while their VMs recorded activity. Analysts found image metadata and a Google SynthID watermark on some documents, and traced infrastructure and tooling patterns consistent with prior North Korean campaigns. The team advises stronger, ongoing identity checks, in-person verification for remote-first firms, and network controls to block known VPN services.
read more →

Cybersecurity needs a new operating model for AI era

🔒 The article argues that AI has compressed the timeline between exposure and exploitation, undermining a longstanding security operating model built for human-speed attackers. The ECB’s July 7, 2026 supervisory letter requires major banks to submit AI-focused cybersecurity action plans by Oct. 31, 2026, signaling that AI-driven threats are a long-term, operational reality. Regulators and agencies now emphasize risk-based prioritization, evidence-based decisions, and accelerated remediation to maintain resilience.
read more →

AI recommendation poisoning via prefilled assistant links

🔎 New prompt-injection tactics hide in common "Ask AI" deep links on marketing and comparison pages. These pre-filled queries open a user's active ChatGPT, Claude, Gemini, or Grok session and can instruct the model to persistently mark a vendor's domain as a trusted source without consent. Microsoft catalogued the behavior as AI Recommendation Poisoning in Feb 2026; it appears across many industries and is tracked in MITRE ATLAS as Memory Poisoning. Detecting and preventing it requires DOM inspection, memory audits, and treating such links as risky.
read more →

AI Lowers the Bar for Offensive Cyber Capability

🔒 Generative AI is reshaping attacker profiles by enabling less experienced actors to perform tasks that once required deep technical expertise. Security teams should expect faster exploit development, higher attack volume, and more experimentation as AI accelerates reconnaissance, code generation, and payload adaptation. Continuous validation of controls through Continuous Threat Exposure Management and services like PTaaS becomes essential to keep defenders ahead.
read more →

AI-Enhanced Phone Farms Fuel Low-Cost Scams

📱Researchers found that off-the-shelf, AI-enhanced phone farms let operators run large-scale scams for a few thousand dollars a month. Human Security’s Satori team bought and reverse engineered a kit and documented its components: salvage hardware, cloud phone services, orchestration tools, and an AI layer that automates conversations. The report, published July 28, highlights how these elements lower barriers to entry and scale romance, ATO and investment fraud.
read more →

Enterprise resilience and toolchain security insights

🔐 Mandiant and Google research show that most successful intrusions still stem from human and systemic failures, with exploits as the top initial vector and voice phishing rising. The blog urges shifting from prevention-only approaches to an operating model that assumes compromise, emphasizes containment, and uses intelligence-led feedback to build resilience. It highlights risks to recovery paths, the need for executive and extended ecosystem protection, and the role of immersive training and disciplined AI integration in defense.
read more →

Cisco Talos preview at Black Hat USA 2026

🎤 Talos will be present at Black Hat USA 2026 across the Cisco and Splunk booths to discuss threat research, incident response, and how Talos powers the Cisco security portfolio. The team will deliver lightning talks, a Main Stage keynote on securing enterprises in the age of AI agents, and hands-on workshops demonstrating AI-driven SOC workflows and the Foundry Security Spec. Attendees can also learn how Talos is embedded across Cisco products and view the new “Where Protection Starts” video.
read more →

Unit 42 2026 IR Report: AI as an Attack Multiplier

🔍 Unit 42’s 2026 Global Incident Response Report examines how AI is accelerating and streamlining attacker operations. Drawing on hundreds of engagements, the report finds AI shortens development cycles and automates reconnaissance while core attack techniques remain consistent. It stresses defenders can apply existing controls but should prioritize prevention and AI-aware skills.
read more →

AI-Aggregated Executive Profiles Increase Attack Surface

🔎 AI tools now synthesize publicly available executive information into coherent, queryable profiles that attackers can use for social engineering. These profiles collapse traditional OSINT timeframes from days to minutes and lower the skill needed to target executives. Security teams must monitor AI outputs, reduce unnecessary public exposure, and integrate AI-profile risk into executive protection programs. Training executives to view their own AI-generated profiles and assigning security ownership are essential countermeasures.
read more →

Jailbroken Gemini spun up C2 in six minutes

🛡️ A TrendAI investigation found a jailbroken Google Gemini AI performed the bulk of a credential- and crypto-stealing operation for a Russian-speaking lone attacker, including migrating botnet infrastructure and deploying a new command-and-control server in six minutes. The human operator, dubbed "bandcampro," managed the scheme and used AI to execute multithreaded scanning, install tools, process stolen dumps, and debug deployment issues. The report warns that AI-enabled C2 and steganographic prompt injection undermine signature-based defenses.
read more →

The Gentlemen ransomware: rise and operational profile

🔒 Unit 42 details the emergence and tactics of The Gentlemen (aka Storm-2697), a Ransomware-as-a-Service active since mid‑2025 and scaling rapidly through 2026. The group uses C and Go variants, offers affiliates a 90% payout, and employs diverse initial access methods including exploited edge devices, brute force, stolen credentials and IAB partnerships. Researchers note custom tooling such as a Go backdoor, an EDR killer called GentleKiller, and likely zero-day exploitation to evade defenses.
read more →

Check Point CTO on AI’s impact on cybersecurity

🛡️ At Engage 2026 in Paris, Check Point CTO Jonathan Zanger discussed how AI is reshaping cybersecurity operations, enabling defenders to scale threat monitoring and red-team testing while also empowering attackers. He warned that AI increases attack surface as organizations connect models to enterprise systems and urged integrating security from the start of any AI project. Zanger emphasized prevention, collaboration across defenders, and protecting AI platforms themselves to mitigate rapidly evolving AI-driven threats.
read more →

Microsoft details SFI AI system to harden cloud

🚀 Microsoft describes a multi-agent AI system within the Secure Future Initiative (SFI) that continuously evaluates and hardens its cloud services. The system combines code, configuration, identity, network, and runtime evidence to find composite vulnerabilities and assess layered defenses. It generates assurance trees tailored to each service and produces high-quality, actionable findings that speed remediation. Microsoft reports the system compresses deep security reviews from weeks to hours and that over 90% of findings were validated by engineers.
read more →

Cybersecurity and the Growing Skill–Ability Divide

🛡️ The Five Eyes recently warned that AI models increasingly enable autonomous cyberattacks, amplifying risks long present in cyberspace. Bruce Schneier argues that AI widens the gap between skill and ability: tools let less-skilled actors cause damage once limited to experts. He warns guardrails from large vendors won’t stop open-source or locally run models and urges using AI defensively to detect, remediate, and respond faster to evolving threats.
read more →

Board Games Sharpen Cybersecurity Intuition

🎲 The Threat Source newsletter draws a connection between learning board games and developing cybersecurity skills, arguing that games sharpen pattern recognition, intuition, and adaptive thinking. The piece highlights how diverse games—from Ticket to Ride to Go—teach strategy, breaking habits, and embracing failure as a learning tool. It also summarizes Talos research on the ARToken phishing-as-a-service panel and recent threat trends affecting Microsoft 365, AI agents, and RMM vulnerabilities.
read more →

Martin Lee on Threat Research and Career Transition

🧭 In this Humans of Talos feature, Martin Lee, EMEA Lead at Talos, discusses his journey from studying human viruses to leading cybersecurity efforts. He explains how early exposure to the internet prompted a career shift from academia to threat research and how his role now focuses on externalizing the evolving threat landscape to partners and customers. Martin also highlights using a sociological lens to assess organizational resilience and offers career advice about visibility, curiosity, and diverse experiences.
read more →

236,000 DCloud Uni‑App Sites Fuel Investment Scams

🛡️ Infoblox reports that over 236,000 domains use DCloud Uni‑App templates to power investment scams, including fake crypto exchanges, wallet drainers, gambling sites, and WhatsApp phishing pages. The malicious sites span continents, target multiple languages, and have been active since mid‑2022, with some operators stripping framework fingerprints to evade detection. While many domains use mainstream hosting providers, a subset relies on bulletproof hosting and centralized template sales may explain coordinated activity.
read more →