Tag: detection
-
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and…
-
Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access
Threat actors are increasingly bypassing conventional malware detection by abusing legitimate remote monitoring and management software instead of deploying custom implants. In a recent phishing operation, attackers delivered a genuine, digitally signed ConnectWise ScreenConnect client configured to establish remote access to infrastructure controlled by the operator. The message claimed that a payment of $5,745.65 had…
-
Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands
Microsoft Threat Intelligence has identified a ClickFix campaign in which compromised websites use fake CAPTCHA-style verification prompts to trick Windows users into executing malicious commands. The operation stages its payload inside the browser cache before the victim runs the command, helping attackers evade conventional download-based detection and work around Windows Run dialog character limits. The…
-
The Fine Art of Frustrating the Adversary
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
-
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-careers/ai-reshapes-soc-career-ladder
-
Why AI won’t fix your cybersecurity problem
James Gillies, Head of Cyber Security at Logicalis UKI There is no escaping the fact that AI is creating significant opportunities for cybersecurity teams, from analysing security data and identifying suspicious activity to accelerating detection, response and remediation. However, the same capabilities are also changing the threat landscape. This comes at a time when security…
-
OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection
Threat actors behind the OpenSUpdater malware family are concealing a reflective loader inside recompiled 7-Zip self-extracting archive components, allowing malicious code to blend into otherwise legitimate-looking installers and evade conventional triage. Rather than relying solely on a malicious embedded executable, the operators modify the decompression stub itself the code responsible for unpacking an embedded archive,…
-
Securing the keys to the kingdom: Announcing Executive Threat Detection
This new proactive service joins the suite of retainer offerings to provide dedicated, intelligence-led hunting specifically for your organization’s most high-value IT assets. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/securing-the-keys-to-the-kingdom-announcing-executive-threat-detection/
-
Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded endpoint detection and response products during laboratory testing. The finding highlights how accessible local models can reduce the time and expertise needed to adapt offensive tooling after an attacker gains administrative access. Eddie…
-
Threat detection dashboards are masking security coverage gaps
A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/25/threat-detections-coverage-gaps-report/
-
Apple’s new iOS 27 feature looks for signs you’re being scammed
Apple introduced a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature allows supported apps to request a risk assessment when a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/24/apple-ios-27-impersonation-risk-detection/
-
Dubai Unveils Open-Source Deepfake Detection AI
Cybersecurity Regulator Says Saraab AI Model Can Spot Deepfakes With 91% Accuracy. The Dubai Electronic Security Center, the Middle Eastern emirate’s cybersecurity regulator, has built an AI model called Saraab that detects deepfake videos, and plans to open source it by the end of the year so it can be improved by researchers, AI companies…
-
Salt Security adds native AI detection and response to agentic security platform
Salt Security has expanded its Agentic Security Platform with native AI Detection and Response (AI-DR) capabilities designed to connect attacks targeting large language models with subsequent activity across MCP servers, tools and APIs. The new capabilities provide real-time protection against direct and indirect prompt injection, jailbreak attempts, unsafe model behaviour and other threats that emerge…
-
Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation
Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising the cost of static detection and automated reverse engineering. First observed in 2018, Vidar remains a widely tracked credential-stealing malware family. Its operators continually alter internal protections without necessarily changing the malware’s broader operational purpose:…
-
Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation
Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising the cost of static detection and automated reverse engineering. First observed in 2018, Vidar remains a widely tracked credential-stealing malware family. Its operators continually alter internal protections without necessarily changing the malware’s broader operational purpose:…
-
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.Microsoft’s own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
US cyber agency endorses ‘decoy’ tactics
Official US guidance suggests organisations consider using cyber decoys to strengthen their detection and response capabilities. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650815/US-cyber-agency-endorses-decoy-tactics
-
PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
China-aligned threat actors are using low-quality Chinese-language casino and adult websites to conceal PeckBirdy command-and-control infrastructure, creating a detection challenge for enterprises that routinely deprioritize gambling-related domains. Infoblox telemetry found that just over 3% of enterprise customers resolved at least one PeckBirdy-related C2 domain, indicating that the infrastructure is appearing well beyond the campaign’s apparent…
-
12 Best CDR Solutions Compared (2026): Features Pricing
Quick Answer: Cloud detection has a real free floor Falco (OSS, on this list in its own right) plus usage-priced native services (GuardDuty-class) so paid CDR must justify itself on correlation and response speed. CrowdStrike, Wiz, and Palo Alto bill CDR inside platform units; Sysdig monetizes the Falco lineage; specialists Permiso (identity), Stream.Security (real-time model),…
-
AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrite scripts, generate commands, and alter obfuscation on demand producing variants that can evade static hashes and traditional…
-
98% of fraudulent hires have company credentials by the time they’re caught
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hypr-hiring-fraud-detection-report/
-
“Zero-Code Cloaking”: Attackers Weaponize Google Search and Hacked .ac.th Domain to Bypass Ad Moderation
Security researchers at ADEX have documented a cloaking technique that requires no cloaking code at all. Instead of running user-agent detection on attacker-controlled servers, the operators chained together three fully legitimate components a Google search results page, a hacked educational website, and a standard redirect in an evasion strategy designed to bypass Google Ads screening…
-
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled >>Using Cyber Decoys to Strengthen Detection and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/cisa-guidance-for-implementing-cyber-decoys/
-
SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
A wider cluster of SpiceRAT command-and-control infrastructure has been linked to the SilkParasite cyber-espionage activity targeting government, telecommunications, and energy-related entities across Central Asia. The infrastructure findings extend the operational footprint around servers previously associated with the suspected China-nexus cluster, but do not establish that any impersonated organization was compromised. Detection logic derived from Cisco…
-
Aurora-MDR-Connect von Arctic Wolf speziell für ManagedProvider
Arctic Wolf gibt die Einführung von Aurora-MDR-Connect bekannt, einer neuen Stufe von Aurora-Managed-Detection and Response (MDR), die exklusiv für Managed-Service-Provider (MSPs) entwickelt wurde. Aurora-MDR-Connect basiert auf der Aurora-Superintelligence-Platform und dem Aurora-Agentic-SOC, welches auch dem bewährten MDR-Angebot von Arctic Wolf zugrunde liegt. Damit können MSPs moderne Security-Operations, einschließlich 24/7-Erkennung, Untersuchung von Vorfällen und vorab autorisierter Reaktion,…
-
Google’s new agent security system detects tool misuse, loops and rogue behavior
Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/google-agent-anomaly-detection-audit-layer/
-
CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks
Tags: cisa, credentials, cyber, cybersecurity, data, detection, hacker, infrastructure, network, strategyThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to deploy cyber decoys, which include fake credentials, systems, data, and services. This strategy aims to expose attackers sooner and enhance post-compromise detection. In new guidance titled >>Using Cyber Decoys to Strengthen Detection and Response,<< published on September 16, 2026, CISA outlined how defenders…
-
Detection engineering fundamentals for SOC teams
Detection engineering is the discipline of turning attacker behaviour, business context, and available telemetry into reliable detections that a SOC can operate at scale. For many UK SMEs, the challenge is not buying another tool. It is building a repeatable… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detection-engineering-fundamentals-for-soc-teams/

