Skip to main content

Tag: threat intelligence

438 articles

Office desk with papers and a nearby workstation showing a blurred email inbox, hinting at disruption.

SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling

A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.

Analyst 207
Senior executive looks concerned standing in front of a window with a blurred laptop screen behind.

AI Reshapes Cyber Threat Landscape, Favoring Attackers

The balance of power in cybersecurity has been dramatically upset, with AI capabilities now favoring attackers and rendering traditional defenses obsolete in the face of machine-speed attacks. This marks a generational shift, where attackers have the upper hand and organizations must adapt to keep up.

Analyst 207
A calm office lobby with a blurred digital screen on a reception desk.

CRPx0 Ransomware Service Rapidly Expands, Targets 48 Organizations

CRPx0's ransomware service has exploded onto the scene, rapidly expanding its reach to target a staggering 48 organizations - a number that's skyrocketed from fewer than 10 just a few months ago. This alarming growth follows the group's shift from a basic hacking service to a full-fledged, white-label ransomware operation.

Analyst 207
Security analysts collaborate around a large screen and conference table in a brightly lit operations center.

AI Adoption Surges in Security Operations

With cyber threats escalating and bad actors already leveraging AI, a surge in AI adoption is underway in security operations, driven by the urgent need to stay ahead. The stark reality: teams are drowning in alerts, with an average of 100+ daily, and struggling to keep pace with the sheer volume.

Analyst 207
Cybersecurity professional examining screens and devices in a brightly-lit room.

AI Models Accelerate Vulnerability Discovery

New AI models are revolutionizing vulnerability discovery, condensing a process that once took months into just hours and leaving defenders scrambling to keep up. This acceleration is outpacing traditional patch cycles, with attackers now able to develop working exploit code in as little as a week.

Analyst 207
Empty workstation area in a cybersecurity operations center with laptops and network equipment.

AI-Enabled Malware Detected but Not Dominant

The surprising truth about AI-enabled malware: despite collecting 405 samples, only 12 actually appeared on customer endpoints, revealing a significant gap in detection. This finding highlights the limited presence of AI-powered threats in the wild.

Analyst 207
Person using laptop outdoors in front of government or academic building.

Google Tracks Russian Cyber Spies Abusing OAuth in Targeted Phishing Campaigns

Google is sounding the alarm on Russian cyber spies who are using OAuth to carry out highly targeted phishing campaigns against top industries, and is sharing details of the attacks to help people recognize malicious outreach. The tech giant has identified three distinct groups behind the ongoing operations, which have been targeting individuals in Europe and the US since last year.

Analyst 207
Employees work at desks in a modern office, one looking concerned and isolated.

Attackers Exploit Trusted Collaboration Platforms for Identity Abuse

Collaboration platforms like Microsoft Teams and Slack have become a prime target for attackers, who are exploiting their trusted status to launch identity abuse attacks through chat phishing operations. These attacks are thriving, with 99% of alerts generated by one study related to chat phishing, signaling a major shift away from traditional email-based attacks.

Analyst 207
Concerned office worker scrutinizes a paper at their cluttered desk.

MSPs Face Evolving Phishing Threats from AI-Driven Attacks

AI-powered phishing attacks have transformed from a filtering issue to a detection challenge, with Kaseya warning that the numbers are stark. AI now turbocharges every stage of a phishing campaign, from lightning-fast reconnaissance to convincing content generation and evasive post-compromise activity.

Analyst 207
A cluttered computer workstation with a blank laptop screen sits unoccupied in a dimly lit server room with rows of…

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware

Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Analyst 207
Empty office cubicle with laptop and smartphone on desk, surrounded by papers and office supplies.

Shadow AI Runs Rampant in 74% of Organizations

Most organizations are flying blind to the sprawling presence of AI tools, with 74% discovering more AI tools than they expected, and 30% of those finding 16 or more running in their environments. This unexpected AI use poses a governance problem, as these tools can access sensitive data, run code, and connect to other services.

Analyst 207
Blurred laptop on reception desk in brightly-lit office lobby with large window.

Ransomware Attacks Pivot to Identity-Based Exploits

Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Analyst 207
Public sector office interior with subtle digital infrastructure and blurred people in the background.

City-Forum Attacks Exploit Salesforce, ServiceNow Portals for Data Theft

A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

Analyst 207
Newsroom setup with desk, papers, and blank broadcast monitor.

DDoS Attacks Surge Amid Global Conflicts, Sports Events

DDoS attacks skyrocketed in Q2, with a 519 percent surge in network-layer attacks over 1 Tbps, and the media and publishing sector bore the brunt, accounting for 14.2 percent of all attacks launched in 2026. This sector was hit with nearly four times as many attacks as the second most-targeted sector, and a whopping six times more in Q2 alone.

Analyst 207
Laboratory workstation with blurred coding interface on laptop screen.

Malicious Servers Exploit AI Coding Agents via MCP

Malicious servers are cleverly exploiting AI coding agents using a sneaky technique called GhostSplice, which breaks down secret-stealing instructions into harmless-sounding messages that the agents unwittingly combine. This allows hackers to leak sensitive information, like secret keys and proprietary data, in a way that's hard to detect.

Analyst 207
Security professional working in modern lab with laptop displaying abstract cybersecurity interface.

OpenAI Unveils ChatGPT 5.6 Cyber for Select Security Partners

OpenAI is supercharging cybersecurity with the launch of GPT 5.6 Cyber, a cutting-edge model designed to help defenders detect and fix vulnerabilities faster than ever before. This game-changing tool is being rolled out to select security partners, empowering them to identify and tackle serious threats with unprecedented speed and accuracy.

Analyst 207
Modern office workstation with laptop and smartphone on a desk near a large window overlooking a cityscape.

AI Agents Exposed to Ghostjacking Attacks Bypassing Firewall Defenses

Imagine a stealthy attack that turns your own AI agents against you, routing sensitive email and web traffic around your firewall defenses - and it starts with just a single, seemingly harmless fake bug report. This sneaky technique, known as Ghostjacking, can leave even the biggest companies vulnerable to devastating breaches.

Analyst 207
Mid-level manager looks concerned while gazing at laptop screen in office setting.

Ransomware Gangs Target Mid-Level Managers to Accelerate Payments

Ransomware gangs are now taking a sniper approach, targeting mid-level managers with precision to get payments faster. This new tactic is a far cry from the scattergun methods of the past, with one recent campaign hitting 351 victims across 334 organizations in just a month.

Analyst 207
Person looks concerned at mobile phone with blurred figure in help-desk uniform in background.

UNC6671 Targets SaaS Data with Vishing Attacks

Beware of voice phishing scams where attackers pose as IT help desk staff, contacting employees on their personal mobile devices with urgent security migration requests that lead to fake login portals. These clever scams capture sensitive credentials and multi-factor authentication tokens in real-time, putting your SaaS data at risk.

Analyst 207
Person sitting at desk with laptop, surrounded by empty notes and papers, looking concerned at screen.

Humans Miss Third of Malicious AI Coding Requests

Can you really trust your instincts to spot malicious AI coding requests? A recent browser game experiment revealed that humans miss a whopping one in three malicious requests, making them the weakest link in the approval process.

Analyst 207
Rows of server racks in a modern office background with a laptop screen in the foreground.

AI-Powered Phishing Outpaces Blocklist Defenses

Phishing campaigns are now a moving target, with 89% of domains disappearing within two days - and by the time they're blocked, the attackers have already packed up and moved on. AI-powered phishing has outsmarted traditional blocklist defenses, using disposable infrastructure and trusted platforms to stay one step ahead.

Analyst 207
Security practitioner examines notes and laptop at office desk.

Prompt Injection Tops List of LLM Threats

Despite having relatively few recorded incidents, prompt injection tops the list of LLM threats due to the significant efforts and resources security teams invest in preventing it. This threat's prominence highlights the substantial risk it poses, even if it doesn't always make the public headlines.

Analyst 207
Person holding smartphone with blurred screen, surrounded by cityscape.

Generative AI Disrupts Hacker Landscape

The technical barriers that once limited credible cyberattacks are rapidly eroding, making it essential to rethink security strategies and prioritize exploitable risk over theoretical exposure. With generative AI, the traditional ranking of attacker sophistication is collapsing, empowering less-skilled hackers to launch more potent threats.

Analyst 207
Rows of computer equipment and cloud-connected devices in a brightly-lit server room or office space.

Cyber-Attackers Target Cloud and SaaS Environments With Identity-Based Threats

Cyber attackers have found a clever way to infiltrate cloud and SaaS environments: they exploit trusted identities and legitimate tools, eliminating the need to bypass security controls. By compromising identities and using delegated access, threat actors can wreak havoc without triggering traditional alarms.

Analyst 207