Tag: detection
-
PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
-
Cribl buys CardinalOps for detection engineering, edges into SecOps
Tags: detectionErstwhile Splunk nemesis adds a “SIEM-like” experience, with IP and engineering from CardinalOps folded into its “Bring Your Own Agent” pitch to IT buyers. First seen on techtarget.com Jump to article: www.techtarget.com/searchitoperations/news/366645843/Cribl-buys-CardinalOps-for-detection-engineering-edges-into-SecOps
-
Flock Safety kills acoustic system designed to detect ‘human distress’
Tags: detection“Community consultation” is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection system. First seen on therecord.media Jump to article: therecord.media/flock-safety-kills-audio-detection-system-human-distress
-
Attackers Combo Up Evasion Tactics for BEC Phishing
The TFF Trap uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/attackers-combo-evasion-tactics-bec-phishing
-
The 12 Best Identity Threat Detection Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs and MSPs, Microsoft Defender for Identity is effectively the bundled default inside E5 estates, Sophos…
-
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Tags: detectionCruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/
-
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026. The report, Gen’s first half-yearly threat publication after previously reporting…
-
Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools organized into modules that cover asynchronous I/O operations, BPF inspection and manipulation, EDR evasion techniques,…
-
Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
Hackers are increasingly abusing trusted file formats and lightweight scripting environments to evade detection, with a newly observed campaign leveraging Lua-based loaders. Disguised as TrueType (.ttf) font files to deploy commodity malware, including Remcos RAT, Agent Tesla, XWorm, and Snake Keylogger variants. The campaign impersonates legitimate businesses and brands in email lures, often using payment-themed…
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers
-
CISA urges immediate action on actively exploited Fortinet flaws
CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-fortinet-fortisandbox-flaws-by-sunday/
-
Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed…
-
Hacker können BindFunktion in Windows zum Erstellen virtueller Pfade in Datensystemen missbrauchen
Legitime Tools und Dienste bieten Hackern eine effektive Möglichkeit, ihre Living-off-the-Land (LOTL)- oder Living-off the-Services (LOTS)-Angriffe zu verbergen. Mit der Tarnkappe einer legitimen Funktion wie auch eines Dienstes oder Tools unterlaufen solche Angriffe die Erkennung von Endpoint-Detection and Response (EDR) oder anderer Analysetools. Weitere Beispiele für ein solches Mimikri haben die Experten der […] First…
-
Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root
Hackers are actively exploiting two zero-day vulnerabilities in the SonicWall SMA 1000 Series remote access appliances. They are chaining a critical server-side request forgery flaw with a local code injection bug to execute commands with root privileges. Rapid7’s Managed Detection and Response team detected targeted attacks before SonicWall publicly disclosed these vulnerabilities on July 14,…
-
Cribl Acquires CardinalOps In Move To Expand Into Security Operations
Cribl acquires CardinalOps in move to strengthen its presence in the cybersecurity space for threat detection, providing an alternative to legacy SIEM products. First seen on crn.com Jump to article: www.crn.com/news/security/2026/cribl-acquires-cardinalops-in-move-to-expand-into-security-operations
-
ClickFix’s Mushrooming Ecosystem Demands New Defense Tactics
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/clickfixs-ecosystem-demands-new-defense
-
ANY.RUN Integrates Threat Intelligence and Interactive Sandbox to Streamline SOC Workflows
Security Operations Centers (SOCs) often encounter challenges that go beyond just managing alert volume. Each alert necessitates that analysts validate indicators, investigate behaviors, assess scope, decide on escalation paths, and create detections to prevent future occurrences. When these tasks rely on separate tools, crucial evidence can be lost during transitions, leading analysts to enrich the…
-
Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
Proofpoint details how attackers spoof OAuth client IDs to probe Microsoft Entra accounts, test credentials and bypass common sign-in detections at cloud scale. First seen on hackread.com Jump to article: hackread.com/microsoft-entra-accounts-oauth-client-id-spoofing/
-
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
New macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild detections confirmed the malware had moved from development into active deployment. The malware is…
-
Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities
Adaptive, AI-driven malware could challenge a foundational assumption in enterprise defense: that a malicious program’s exploitation logic remains fixed after deployment. New research on adaptive computer worms argues that a self-replicating agent paired with an onboard reasoning loop could assess different environments, select target-specific attack paths, and regenerate capabilities as older methods become less effective.…
-
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped…
-
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
Armored Likho, a previously undocumented threat group also tracked as Eagle Werewolf based on circumstantial evidence, is targeting government institutions and electric-power organizations across Russia, Brazil, and Kazakhstan with a new Python-based infostealer named BusySnake. The group’s activity reflects an unusual overlap between cyber-espionage and financially motivated operations. Armored Likho targets organizations for intelligence collection…
-
Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656)
Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the Malware Protection Engine used by Defender. The Microsoft Malware Protection Engine (mpengine.dll) powers Defender’s malware scanning, detection, and removal…
-
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabilities for its antivirus and First seen on…
-
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders.The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack.Decrypting…
-
Claude Code, Cursor, and OpenAI Codex Trigger Cyberattack-Like Telemetry Alerts
AI-powered coding assistants such as Claude Code, Cursor, and OpenAI Codex are increasingly triggering endpoint detection and response (EDR) alerts that resemble active cyberattacks, according to new research from Sophos X-Ops. This analysis, based on real-world telemetry collected in June 2026, highlights how autonomous AI behavior, while often benign, closely mirrors adversarial tactics, creating new…
-
Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts
The phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/big-brand-jobs-scam-marketing-pros-google-accounts
-
Britain plans to build autonomous AI ‘Cyber Shield’ to defend nation
The capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.” First seen on therecord.media Jump to article: therecord.media/britain-plans-autonomous-ai-cyber-shield
-
Britain plans to build autonomous AI ‘Cyber Shield’ to defend nation
The capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.” First seen on therecord.media Jump to article: therecord.media/britain-plans-autonomous-ai-cyber-shield
-
Huntress Signs Giacom to Widen UK MSP Access to Managed Detection and Response
Huntress has struck a new distribution partnership with UK channel marketplace Giacom, giving the managed service providers (MSPs) on Giacom’s Cloud Market platform direct access to Huntress’ Agentic Security Platform and its 24/7 AI-centric Security Operations Centre (SOC). The deal is one of two announced this week, alongside a parallel agreement with MSP Nordics covering Denmark, Finland, Iceland, Norway and Sweden, as Huntress looks…

