Tag: threat intelligence
438 articles

AI Emerges as Dual Threat in Cyberattacks
Artificial intelligence has taken a dark turn, now serving as both a powerful tool and prime target for cyber attackers, with AI-driven malicious activity skyrocketing 89% in just one year. This emerging threat landscape demands attention, as adversaries harness AI to supercharge their attacks.

Cyberattacks Surge 89% as AI Becomes Dual Threat
The threat landscape is evolving at an alarming rate: AI is now being wielded as a powerful tool by cyberattackers, with a staggering 89% surge in AI-enabled attacks. This dual threat - where AI is both the weapon and the target - has adversaries leveraging AI agents at 2.5 times the rate of human-triggered threats.

Malware Evolves with AI-Driven Tactics
Malware is getting a scary upgrade: attackers are harnessing AI-driven tactics to create a surge in suspicious and malicious activity, with tens of thousands of dubious AI "skills" already detected. This emerging threat landscape is multiplying opportunities for hackers to exploit, making it a critical concern for anyone online.

AWS Tracks North Korean Group in npm Supply Chain Attacks
AWS has uncovered a string of sneaky supply-chain attacks on popular npm libraries, and their threat intel team is pointing to a notorious North Korean group, known as Saphire Sleet, as the likely culprit. The attacks hit big-name libraries like axios, debug, and chalk, raising concerns about the security of the software supply chain.

AiTM Phishing Overtakes Credential Theft as Top Law Firm Threat
Law firms are under siege from a new type of phishing attack, with AiTM phishing now accounting for 28.57% of initial access events in the sector, overtaking conventional credential theft as the top threat. This sophisticated attack method has become the go-to tactic for hackers, bypassing even multifactor authentication defenses.

AI Attacks Expose Enterprise Security Gaps
Nearly a quarter of organizations have been hit with AI-powered attacks, exposing significant security gaps in their defenses. Are your company's critical business platforms protected from the growing threat of artificial intelligence-driven exploitation?

NCSC Urges Vendors to Embed Forensic Observability in Network Devices
When cyber incidents strike, organizations need a reliable way to piece together what happened and determine if a device is still trustworthy - that's where forensic observability comes in. The NCSC is urging vendors to build this capability into network devices, like firewalls and VPN gateways, to help defenders quickly investigate and respond to threats.

LogoKit Phishing Kit Dynamically Recreates Victim Sites
This phishing-as-a-service platform takes impersonation to the next level by dynamically recreating victim sites, using live screenshots of the target organization's own website as the page background to create a convincing and highly personalized attack. It's a clever twist on traditional phishing that's making it harder for victims to spot the scam.

AI Compresses Exploit Timelines, Exposes Prioritization Flaws
The arrival of AI models like Anthropic's Mythos is compressing exploit timelines, shrinking the window to patch vulnerabilities from weeks to just days or even hours. This acceleration exposes flaws in traditional prioritization methods, where only a handful of findings truly matter - out of 50,000, only a dozen make the cut.

AI-Enhanced Phone Farms Enable Low-Cost Fraud at Scale
Meet the phone farm kit, a game-changing tool that lets scammers run hundreds of conversations at once, making it ridiculously easy to commit low-cost fraud at scale. With just a subscription and a prompt, romance scams can now be executed on a massive scale, no longer limited by human labor.

AI-Assisted Tools Discover More Vulnerabilities, But Exploitation Rate Remains Steady
AI-assisted tools are supercharging vulnerability discovery, uncovering over 1,000 new defects in just six months, yet the rate of exploitation remains surprisingly steady, with only 1.3% of AI-discovered vulnerabilities being exploited in the wild. This finding challenges the notion that AI-discovered vulnerabilities are inherently more attractive to attackers.

Minnesota Water Utilities Targeted in Coordinated Cyberattack
A coordinated cyberattack has left over 30 Minnesota communities without access to water services, with officials working swiftly to contain and investigate the damage. Minnesota Information Technology Services is leading the response, sharing vital threat intelligence and guiding affected utilities through the recovery process.

Google Unveils Unified Naming System for Hacker Groups
Say goodbye to memorization overload - Google's Threat Intelligence Group is shaking up threat tracking with a sleek, unified naming system for hacker groups, using simple two-word code names to make it easier to stay on top of cyber threats. This game-changing approach kicks off with dozens of high-priority groups and will keep expanding to make threat tracking a whole lot more intuitive.

Dysphoria IoT Botnet Evolves With Blockchain Command Centers
The Dysphoria IoT Botnet has reached a staggering 200,000 bots worldwide, with a single-day peak of 239,000 bots abroad, according to recent telemetry data from CNCERT and XLab. This massive network of compromised devices is now being controlled through sophisticated blockchain command centers.

Google Unveils Cybercrime Taxonomy, Shakes Up Threat Naming Norms
Google is shaking up the world of cybercrime threat naming with a fresh approach, introducing a simple and streamlined taxonomy that's easy to map across different systems. The tech giant has teamed up with Mandiant to launch the Google Threat Intelligence Group, using a catchy two-word naming schema to identify cybercrime crews.

Malvertising Campaign SourTrade Exploits Browsers to Deliver Malware
Meet SourTrade, a sneaky malvertising campaign that's exploiting browsers to deliver malware - without leaving a single piece of malware on the network. This clever attack uses a complex web of code to assemble Windows executables right inside your browser.

Unfettered AI Fuels New Wave of Cybercrime
The alarming reality is that unregulated AI has become a cybercrime game-changer, with 6,644 openly available models labeled as "uncensored" and "unfiltered" racking up over 22 million downloads in just 30 days. This staggering statistic proves that guardrail-free AI is no longer a hypothetical threat, but a readily accessible tool for malicious use.

Dolphin X Malware Exploits AI to Prioritize High-Value Targets
Meet Dolphin X Malware, a sneaky threat that uses AI to help attackers zero in on their most prized targets - and it's equipped with an impressive 329 features to do so. Its AI Profiler tool can sort and rank infected computers, giving hackers a daily summary of the most valuable victims.

Malware Exploits Trust In Ordinary Systems
This week's ThreatsDay bulletin revealed a disturbing trend: hackers are disguising malware as ordinary tools and features, using familiar names and routine functions to infiltrate code repositories, desktop systems, mobile apps, and more. Even trusted platforms like GitHub and PyPI are being exploited, with GitHub announcing a security update to block vulnerable support bundle uploads.

Patch Management Struggles to Keep Pace with AI-Accelerated Threats
Nearly a third of breaches occur because hackers exploit known vulnerabilities that could have been easily fixed with a patch, highlighting the urgent need for more efficient patch management. By speeding up patching, organizations could prevent around one in three incidents, making it a crucial defense against cyber threats.

AI Emerges as Force Multiplier in Cyberattacks
As AI continues to evolve, it's crucial to treat AI-driven threats as a top priority, as they can significantly accelerate and scale attacks. By leveraging AI, cyber attackers can speed up their operations, but their tactics remain familiar, including credential theft, phishing, and ransomware.

Google Unveils Gemini 3.5 Flash Cyber to Accelerate Vulnerability Detection
Meet Gemini 3.5 Flash Cyber, a game-changing AI model that supercharges vulnerability detection with lightning-fast speed and pinpoint accuracy. This lightweight powerhouse helps you discover, validate, and patch vulnerabilities quickly and efficiently, without breaking the bank.

Ransomware Landscape Fractures as New Groups Proliferate
The ransomware landscape is shattering into more factions than ever, with over one new group emerging every week in 2026, according to the Black Kite Ransomware Report. This explosion of new players has led to a surge in attacks, with 61 new groups appearing in just one year alone.

Exposure Window Leaves Security Teams Vulnerable
The exposure window - the time between a vulnerability appearing and your team fixing it - is the critical gap that attackers exploit to cause real damage. With 48,185 CVEs disclosed in 2025 alone, and an average eCrime breakout time of just 29 minutes, the urgency to shrink this window has never been greater.