Tag: threat intelligence
438 articles

SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling
A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.

AI Reshapes Cyber Threat Landscape, Favoring Attackers
The balance of power in cybersecurity has been dramatically upset, with AI capabilities now favoring attackers and rendering traditional defenses obsolete in the face of machine-speed attacks. This marks a generational shift, where attackers have the upper hand and organizations must adapt to keep up.

CRPx0 Ransomware Service Rapidly Expands, Targets 48 Organizations
CRPx0's ransomware service has exploded onto the scene, rapidly expanding its reach to target a staggering 48 organizations - a number that's skyrocketed from fewer than 10 just a few months ago. This alarming growth follows the group's shift from a basic hacking service to a full-fledged, white-label ransomware operation.

AI Adoption Surges in Security Operations
With cyber threats escalating and bad actors already leveraging AI, a surge in AI adoption is underway in security operations, driven by the urgent need to stay ahead. The stark reality: teams are drowning in alerts, with an average of 100+ daily, and struggling to keep pace with the sheer volume.

AI Models Accelerate Vulnerability Discovery
New AI models are revolutionizing vulnerability discovery, condensing a process that once took months into just hours and leaving defenders scrambling to keep up. This acceleration is outpacing traditional patch cycles, with attackers now able to develop working exploit code in as little as a week.

AI-Enabled Malware Detected but Not Dominant
The surprising truth about AI-enabled malware: despite collecting 405 samples, only 12 actually appeared on customer endpoints, revealing a significant gap in detection. This finding highlights the limited presence of AI-powered threats in the wild.

Google Tracks Russian Cyber Spies Abusing OAuth in Targeted Phishing Campaigns
Google is sounding the alarm on Russian cyber spies who are using OAuth to carry out highly targeted phishing campaigns against top industries, and is sharing details of the attacks to help people recognize malicious outreach. The tech giant has identified three distinct groups behind the ongoing operations, which have been targeting individuals in Europe and the US since last year.

Attackers Exploit Trusted Collaboration Platforms for Identity Abuse
Collaboration platforms like Microsoft Teams and Slack have become a prime target for attackers, who are exploiting their trusted status to launch identity abuse attacks through chat phishing operations. These attacks are thriving, with 99% of alerts generated by one study related to chat phishing, signaling a major shift away from traditional email-based attacks.

MSPs Face Evolving Phishing Threats from AI-Driven Attacks
AI-powered phishing attacks have transformed from a filtering issue to a detection challenge, with Kaseya warning that the numbers are stark. AI now turbocharges every stage of a phishing campaign, from lightning-fast reconnaissance to convincing content generation and evasive post-compromise activity.

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware
Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Shadow AI Runs Rampant in 74% of Organizations
Most organizations are flying blind to the sprawling presence of AI tools, with 74% discovering more AI tools than they expected, and 30% of those finding 16 or more running in their environments. This unexpected AI use poses a governance problem, as these tools can access sensitive data, run code, and connect to other services.

Ransomware Attacks Pivot to Identity-Based Exploits
Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

City-Forum Attacks Exploit Salesforce, ServiceNow Portals for Data Theft
A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

DDoS Attacks Surge Amid Global Conflicts, Sports Events
DDoS attacks skyrocketed in Q2, with a 519 percent surge in network-layer attacks over 1 Tbps, and the media and publishing sector bore the brunt, accounting for 14.2 percent of all attacks launched in 2026. This sector was hit with nearly four times as many attacks as the second most-targeted sector, and a whopping six times more in Q2 alone.

Malicious Servers Exploit AI Coding Agents via MCP
Malicious servers are cleverly exploiting AI coding agents using a sneaky technique called GhostSplice, which breaks down secret-stealing instructions into harmless-sounding messages that the agents unwittingly combine. This allows hackers to leak sensitive information, like secret keys and proprietary data, in a way that's hard to detect.

OpenAI Unveils ChatGPT 5.6 Cyber for Select Security Partners
OpenAI is supercharging cybersecurity with the launch of GPT 5.6 Cyber, a cutting-edge model designed to help defenders detect and fix vulnerabilities faster than ever before. This game-changing tool is being rolled out to select security partners, empowering them to identify and tackle serious threats with unprecedented speed and accuracy.

AI Agents Exposed to Ghostjacking Attacks Bypassing Firewall Defenses
Imagine a stealthy attack that turns your own AI agents against you, routing sensitive email and web traffic around your firewall defenses - and it starts with just a single, seemingly harmless fake bug report. This sneaky technique, known as Ghostjacking, can leave even the biggest companies vulnerable to devastating breaches.

Ransomware Gangs Target Mid-Level Managers to Accelerate Payments
Ransomware gangs are now taking a sniper approach, targeting mid-level managers with precision to get payments faster. This new tactic is a far cry from the scattergun methods of the past, with one recent campaign hitting 351 victims across 334 organizations in just a month.

UNC6671 Targets SaaS Data with Vishing Attacks
Beware of voice phishing scams where attackers pose as IT help desk staff, contacting employees on their personal mobile devices with urgent security migration requests that lead to fake login portals. These clever scams capture sensitive credentials and multi-factor authentication tokens in real-time, putting your SaaS data at risk.

Humans Miss Third of Malicious AI Coding Requests
Can you really trust your instincts to spot malicious AI coding requests? A recent browser game experiment revealed that humans miss a whopping one in three malicious requests, making them the weakest link in the approval process.

AI-Powered Phishing Outpaces Blocklist Defenses
Phishing campaigns are now a moving target, with 89% of domains disappearing within two days - and by the time they're blocked, the attackers have already packed up and moved on. AI-powered phishing has outsmarted traditional blocklist defenses, using disposable infrastructure and trusted platforms to stay one step ahead.

Prompt Injection Tops List of LLM Threats
Despite having relatively few recorded incidents, prompt injection tops the list of LLM threats due to the significant efforts and resources security teams invest in preventing it. This threat's prominence highlights the substantial risk it poses, even if it doesn't always make the public headlines.

Generative AI Disrupts Hacker Landscape
The technical barriers that once limited credible cyberattacks are rapidly eroding, making it essential to rethink security strategies and prioritize exploitable risk over theoretical exposure. With generative AI, the traditional ranking of attacker sophistication is collapsing, empowering less-skilled hackers to launch more potent threats.

Cyber-Attackers Target Cloud and SaaS Environments With Identity-Based Threats
Cyber attackers have found a clever way to infiltrate cloud and SaaS environments: they exploit trusted identities and legitimate tools, eliminating the need to bypass security controls. By compromising identities and using delegated access, threat actors can wreak havoc without triggering traditional alarms.