Skip to main content

Tag: threat intelligence

438 articles

Server equipment in a neutral setting with ambient daylight and empty screens.

AI Emerges as Dual Threat in Cyberattacks

Artificial intelligence has taken a dark turn, now serving as both a powerful tool and prime target for cyber attackers, with AI-driven malicious activity skyrocketing 89% in just one year. This emerging threat landscape demands attention, as adversaries harness AI to supercharge their attacks.

Analyst 207
Modern tech facility with sleek conference table and laptop, hinting at tension.

Cyberattacks Surge 89% as AI Becomes Dual Threat

The threat landscape is evolving at an alarming rate: AI is now being wielded as a powerful tool by cyberattackers, with a staggering 89% surge in AI-enabled attacks. This dual threat - where AI is both the weapon and the target - has adversaries leveraging AI agents at 2.5 times the rate of human-triggered threats.

Analyst 207
Modern lab with workstations and instruments, featuring a projected neural network diagram.

Malware Evolves with AI-Driven Tactics

Malware is getting a scary upgrade: attackers are harnessing AI-driven tactics to create a surge in suspicious and malicious activity, with tens of thousands of dubious AI "skills" already detected. This emerging threat landscape is multiplying opportunities for hackers to exploit, making it a critical concern for anyone online.

Analyst 207
Laptop screen displays npm package management interface amidst office workspace.

AWS Tracks North Korean Group in npm Supply Chain Attacks

AWS has uncovered a string of sneaky supply-chain attacks on popular npm libraries, and their threat intel team is pointing to a notorious North Korean group, known as Saphire Sleet, as the likely culprit. The attacks hit big-name libraries like axios, debug, and chalk, raising concerns about the security of the software supply chain.

Analyst 207
Modern law firm reception area with laptop and smartphone on desk.

AiTM Phishing Overtakes Credential Theft as Top Law Firm Threat

Law firms are under siege from a new type of phishing attack, with AiTM phishing now accounting for 28.57% of initial access events in the sector, overtaking conventional credential theft as the top threat. This sophisticated attack method has become the go-to tactic for hackers, bypassing even multifactor authentication defenses.

Analyst 207
Concerned IT staff stand behind rows of computer terminals in a brightly-lit corporate IT environment with a blurred ERP…

AI Attacks Expose Enterprise Security Gaps

Nearly a quarter of organizations have been hit with AI-powered attacks, exposing significant security gaps in their defenses. Are your company's critical business platforms protected from the growing threat of artificial intelligence-driven exploitation?

Analyst 207
Technicians work on networking equipment in a well-lit network operations center with rows of servers and IT infrastructure.

NCSC Urges Vendors to Embed Forensic Observability in Network Devices

When cyber incidents strike, organizations need a reliable way to piece together what happened and determine if a device is still trustworthy - that's where forensic observability comes in. The NCSC is urging vendors to build this capability into network devices, like firewalls and VPN gateways, to help defenders quickly investigate and respond to threats.

Analyst 207
Laptop screen displays a business webpage in a neutral office setting.

LogoKit Phishing Kit Dynamically Recreates Victim Sites

This phishing-as-a-service platform takes impersonation to the next level by dynamically recreating victim sites, using live screenshots of the target organization's own website as the page background to create a convincing and highly personalized attack. It's a clever twist on traditional phishing that's making it harder for victims to spot the scam.

Analyst 207
Security architect analyzes network data on tablet and laptop in network operations center.

AI Compresses Exploit Timelines, Exposes Prioritization Flaws

The arrival of AI models like Anthropic's Mythos is compressing exploit timelines, shrinking the window to patch vulnerabilities from weeks to just days or even hours. This acceleration exposes flaws in traditional prioritization methods, where only a handful of findings truly matter - out of 50,000, only a dozen make the cut.

Analyst 207
Cluttered electronics workbench with a partially disassembled phone farm device and glowing smartphone screens.

AI-Enhanced Phone Farms Enable Low-Cost Fraud at Scale

Meet the phone farm kit, a game-changing tool that lets scammers run hundreds of conversations at once, making it ridiculously easy to commit low-cost fraud at scale. With just a subscription and a prompt, romance scams can now be executed on a massive scale, no longer limited by human labor.

Analyst 207
Researcher working at a lab bench with technology and security tools, surrounded by notes and diagrams.

AI-Assisted Tools Discover More Vulnerabilities, But Exploitation Rate Remains Steady

AI-assisted tools are supercharging vulnerability discovery, uncovering over 1,000 new defects in just six months, yet the rate of exploitation remains surprisingly steady, with only 1.3% of AI-discovered vulnerabilities being exploited in the wild. This finding challenges the notion that AI-discovered vulnerabilities are inherently more attractive to attackers.

Analyst 207
Control room of a municipal water treatment plant with industrial and administrative equipment.

Minnesota Water Utilities Targeted in Coordinated Cyberattack

A coordinated cyberattack has left over 30 Minnesota communities without access to water services, with officials working swiftly to contain and investigate the damage. Minnesota Information Technology Services is leading the response, sharing vital threat intelligence and guiding affected utilities through the recovery process.

Analyst 207
Person working on laptop surrounded by threat intelligence screens and maps.

Google Unveils Unified Naming System for Hacker Groups

Say goodbye to memorization overload - Google's Threat Intelligence Group is shaking up threat tracking with a sleek, unified naming system for hacker groups, using simple two-word code names to make it easier to stay on top of cyber threats. This game-changing approach kicks off with dozens of high-priority groups and will keep expanding to make threat tracking a whole lot more intuitive.

Analyst 207
Dimly lit server room with rows of network equipment and industrial shelving.

Dysphoria IoT Botnet Evolves With Blockchain Command Centers

The Dysphoria IoT Botnet has reached a staggering 200,000 bots worldwide, with a single-day peak of 239,000 bots abroad, according to recent telemetry data from CNCERT and XLab. This massive network of compromised devices is now being controlled through sophisticated blockchain command centers.

Analyst 207
People work at desks in a neutral room, with a taxonomy chart displayed on a large screen in the foreground.

Google Unveils Cybercrime Taxonomy, Shakes Up Threat Naming Norms

Google is shaking up the world of cybercrime threat naming with a fresh approach, introducing a simple and streamlined taxonomy that's easy to map across different systems. The tech giant has teamed up with Mandiant to launch the Google Threat Intelligence Group, using a catchy two-word naming schema to identify cybercrime crews.

Analyst 207
City transit platform with people in background, foreground computer screen blurred, hinting at malware threat.

Malvertising Campaign SourTrade Exploits Browsers to Deliver Malware

Meet SourTrade, a sneaky malvertising campaign that's exploiting browsers to deliver malware - without leaving a single piece of malware on the network. This clever attack uses a complex web of code to assemble Windows executables right inside your browser.

Analyst 207
Cluttered computer workstation with code on laptop screen in dimly lit room.

Unfettered AI Fuels New Wave of Cybercrime

The alarming reality is that unregulated AI has become a cybercrime game-changer, with 6,644 openly available models labeled as "uncensored" and "unfiltered" racking up over 22 million downloads in just 30 days. This staggering statistic proves that guardrail-free AI is no longer a hypothetical threat, but a readily accessible tool for malicious use.

Analyst 207
Laptop open on a plain surface with a blank screen showing soft glow.

Dolphin X Malware Exploits AI to Prioritize High-Value Targets

Meet Dolphin X Malware, a sneaky threat that uses AI to help attackers zero in on their most prized targets - and it's equipped with an impressive 329 features to do so. Its AI Profiler tool can sort and rank infected computers, giving hackers a daily summary of the most valuable victims.

Analyst 207
Developer workstation with laptop, monitor, and notes, surrounded by empty coffee cups in a brightly lit room.

Malware Exploits Trust In Ordinary Systems

This week's ThreatsDay bulletin revealed a disturbing trend: hackers are disguising malware as ordinary tools and features, using familiar names and routine functions to infiltrate code repositories, desktop systems, mobile apps, and more. Even trusted platforms like GitHub and PyPI are being exploited, with GitHub announcing a security update to block vulnerable support bundle uploads.

Analyst 207
Cybersecurity team working at desks with laptops and papers in a brightly-lit IT operations room.

Patch Management Struggles to Keep Pace with AI-Accelerated Threats

Nearly a third of breaches occur because hackers exploit known vulnerabilities that could have been easily fixed with a patch, highlighting the urgent need for more efficient patch management. By speeding up patching, organizations could prevent around one in three incidents, making it a crucial defense against cyber threats.

Analyst 207
Rows of computer equipment in a dimly lit server room lie in disarray, cables scattered and screens flickering with error…

AI Emerges as Force Multiplier in Cyberattacks

As AI continues to evolve, it's crucial to treat AI-driven threats as a top priority, as they can significantly accelerate and scale attacks. By leveraging AI, cyber attackers can speed up their operations, but their tactics remain familiar, including credential theft, phishing, and ransomware.

Analyst 207
Researcher stands beside computer screen displaying code review interface in laboratory setting.

Google Unveils Gemini 3.5 Flash Cyber to Accelerate Vulnerability Detection

Meet Gemini 3.5 Flash Cyber, a game-changing AI model that supercharges vulnerability detection with lightning-fast speed and pinpoint accuracy. This lightweight powerhouse helps you discover, validate, and patch vulnerabilities quickly and efficiently, without breaking the bank.

Analyst 207
City street with busy storefronts and office buildings, hinting at disruption.

Ransomware Landscape Fractures as New Groups Proliferate

The ransomware landscape is shattering into more factions than ever, with over one new group emerging every week in 2026, according to the Black Kite Ransomware Report. This explosion of new players has led to a surge in attacks, with 61 new groups appearing in just one year alone.

Analyst 207
Security analysts work together in a brightly-lit operations center surrounded by computer screens, with a cityscape…

Exposure Window Leaves Security Teams Vulnerable

The exposure window - the time between a vulnerability appearing and your team fixing it - is the critical gap that attackers exploit to cause real damage. With 48,185 CVEs disclosed in 2025 alone, and an average eCrime breakout time of just 29 minutes, the urgency to shrink this window has never been greater.

Analyst 207