Advertisement
Securing Enterprise AI: Managing Risks & Incident Readiness
Organizations face expanding attack surfaces and new risks from rapid AI adoption, including shadow AI and AI agents with excessive permissions.
Faronics Deploy Abused by Phishing Actors to Install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint management tool to gain remote access and install ScreenConnect via malicious installers.
The Agentic SOC: From AI Theater to Real Defense
Explore the Agentic SOC transition, focusing on measurable AI ROI, new risks like indirect prompt injection, and redefining analyst roles for autonomous defense.
Leaked Russian Cyber-Ops Training Exposes Institutional Pathways
Leaked materials reveal Russia's institutional system for generating cyber capabilities, linking university recruitment to GRU and Sandworm units for diverse operations.
AI-Generated Email Praise: A New Pre-Scam Tactic Emerges
Analysts observe AI-generated "thank you" emails from suspicious accounts, potentially an early stage of sophisticated social engineering scams.
ClickFix Campaign Exploits Polygon Blockchain for C2 Evasion
The ClickFix campaign compromises 31 organizations, dynamically updating its C2 server via EtherHiding and the Polygon blockchain.
Advertisement
Sevii's AI Module: Autonomous Defense Against AI-Speed Attacks
Sevii extends its Autonomous Defense & Remediation (ADR) platform with a new AI security module, enabling real-time, autonomous response to AI-driven cyber attacks.
BREEZE COMET Exploits Brazilian Financial Systems
BREEZE COMET, a financially motivated threat actor, targets Brazilian financial services for fraudulent transfers, leveraging custom malware and AI for development.
AI Baby Monitors & Privacy Risks: The Nanit Surveillance Trend
AI-powered baby monitors like Nanit collect vast child data, raising significant long-term privacy and surveillance concerns for families.
TerminalFix: PowerShell Weaponization in Enterprise Attacks
Analysis of 'TerminalFix' campaign, detailing PowerShell weaponization, multistage attack chain, and reverse tunnels into enterprise networks.
AI-Assisted PLC Exploit Porting: WAGO RCE via Claude
Forescout researchers used Anthropic's Claude to port a WAGO PLC RCE exploit, demonstrating AI's potential in offensive security but highlighting current challenges.
Threat Actors Prefer Repeatable Playbooks Over Novel Exploits
Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.
Cloudflare Adaptive Intelligence: Reversing Bot Attack Economics
Cloudflare introduces Adaptive Intelligence, a new bot detection engine designed to increase the economic cost for attackers and continuously adapt defenses.
AI's Impact on Threat Intelligence & Business Risk Management
Discover how AI is intensifying vulnerability volumes and enabling faster threat actor operations, necessitating a strategic shift to risk-based threat intelligence.
Recorded Future Launches AI Alert Filtering for Analysts
Recorded Future introduces AI Alert Filtering, an agent designed to automatically reduce security alert volume by 63% for threat analysts.
APT28's HOOKEDGE Backdoor Targets European Diplomacy
Russian state-sponsored BlueDelta (APT28) leverages HOOKEDGE backdoor via macro-enabled documents to target European government and diplomatic entities.
Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws
Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.
Malicious PE Stats: Compiler Analysis of Malware Samples
Analysis of 1.3TB of malware samples examines PE headers, compiler trends, and tools used by attackers over a multi-year dataset.
Rogue LLM Endpoints: Data Exposure & RCE Risk for AI Agents
Unverified LLM endpoints pose significant risks, enabling data leakage and potential remote code execution via compromised AI agent sessions.
Diagnosing LLM Safety Fragility with Perturbation Probing
New research introduces Perturbation Probing to diagnose LLM safety fragility, revealing guardrails are often concentrated in few neurons.
Spring Ring Voice Phishing Targets Microsoft Teams Users
Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.
Evaluating LLMs for SOC Operations and Log Analysis
Discover how Cisco Talos evaluated 66 model and reasoning combinations for SOC workflows, focusing on cost, speed, and consistency.
Deobfuscating Malicious JavaScript for Threat Analysis
Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.
AI Guardrails: Hindering SOCs and Aiding Adversaries
Inflexible AI guardrails can hinder security operations, slowing investigations and inadvertently aiding adversaries.