Tag: intelligence
-
Sophisticated Cyberattackers Boost Productivity Using AI
But Less-Skilled Attackers Have Trouble Turning Ideas to Reality, Researchers Find Everybody seems hellbent on applying artificial intelligence tools to boost productivity, and criminal hackers appear to be no exception. But as with non-illicit use of large language models, the most sophisticated results appear to trace to the most highly skilled users wielding LLMs. First…
-
Open Secure AI Alliance Proposes AI Agent Security Rules
SAFE framework seeks incident sharing after AI agent security breaches. The Open Secure AI Alliance has proposed a cybersecurity information-sharing framework for AI agents following recent security incidents involving OpenAI and Anthropic models. The SAFE guidelines would require members to report AI security incidents, share threat intelligence and preserve evidence to help reduce systemic risks…
-
DEF CON 2026: Flare Launches Free Dark Web Intelligence Training Platform
Flare’s free Darkroom platform provides hands-on, AI-powered dark web intelligence training. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/def-con-2026-flare-launches-free-dark-web-intelligence-training-platform/
-
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take. First seen on therecord.media Jump to article: therecord.media/interview-jim-hockenhull-uk-defence-intelligence-russia-ukraine
-
Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams
Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the tools security teams already run Mallory, the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams. The architecture has three…
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams
Las Vegas, United States, 4th August 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/
-
Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams
Las Vegas, United States, 4th August 2026, CyberNewswire First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/
-
Russian businesses erase Durov-linked products after ‘terrorist’ designation
The designation, announced last week, came a day after Russia’s Federal Security Service (FSB) charged Durov with aiding terrorist activity and said it would seek to place him on an international wanted list. The agency accused Telegram of failing to remove channels and bots allegedly used by Ukrainian intelligence, as well as terrorist and extremist…
-
DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
Tags: apple, credentials, cyber, data-breach, exploit, google, group, intelligence, iphone, login, risk, threatDarkSword’s leaked iOS exploit chain is now powering a fast”‘moving server cluster that marries one”‘click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credential theft. Originally disclosed by Google Threat Intelligence Group, iVerify, and Lookout, the kit was later leaked to…
-
Nvidia-backed Open Secure AI Alliance puts AI security and sovereignty in focus for Middle East
Tags: ai, control, cyber, data, government, infrastructure, intelligence, middle-east, nvidia, risk, toolIndustry coalition aims to develop open tools for securing artificial intelligence systems, a model that could resonate strongly in the UAE and Saudi Arabia as governments and enterprises seek greater control over AI infrastructure, data and cyber risk First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646515/Nvidia-backed-open-secure-AI-alliance-puts-AI-security-and-sovereignty-in-focus-for-Middle-East
-
OpenAI Shuts Down ChatGPT Accounts Powering a Cambodia-Based Scam Factory
OpenAI has shut down a coordinated network of ChatGPT accounts that powered a Cambodia-based scam factory running multi-vector fraud and trafficking-linked operations, and has shared indicators with industry peers and authorities to make the network’s reconstitution significantly harder. Earlier in 2026, OpenAI’s threat intelligence team disrupted a scam syndicate that weaponized ChatGPT to drive investment,…
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
China Is Training Military AI With Knowledge Extracted From American Models
China’s artificial intelligence ecosystem is rapidly advancing through a controversial technique known as model distillation, with mounting evidence suggesting that military-linked entities are extracting high-value capabilities from leading American AI systems. Distillation, or “knowledge distillation,” refers to training a smaller AI model using outputs generated by a more advanced “teacher” model. While widely used across…
-
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/midnight-blizzard-hotel-wi-fi-networks-hacking/
-
PortSwigger Adds AI Agent to Penetration Testing Portfolio
PortSwigger has made available a beta release of an artificial intelligence (AI) agent for its Burp Suite penetration testing tools. Katie Warren, product leader for Burp AI at PortSwigger, said Burp AT will make it simpler for cybersecurity teams to simulate attacks without necessarily requiring a lot of expertise. At the core of that capability..…
-
Travelers Beware: Russian Intel Hacking Hotel Wi-Fi
Russian Intelligence Hackers Capture Captive Portals. Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest. Microsoft’s threat intelligence arm began tracking the threat in early May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/travelers-beware-russian-intel-hacking-hotel-wi-fi-a-32405
-
Google’s Cyber Threat Actor Naming System Ditches Jargon, Makes Intelligence More Actionable
A cyber threat actor by any other name”¦can probably be found in Google Threat Intelligence Group’s new taxonomy for tracking threat actors. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/googles-cyber-threat-actor-naming-system-ditches-jargon-makes-intelligence-more-actionable/
-
3rd August Threat Intelligence Report
Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/3rd-august-threat-intelligence-report/
-
How the World’s Most Active Ransomware Operation Expanded in H1 2026
The first half of 2026 reinforced a familiar reality in ransomware: a small number of highly capable operators continue to drive a disproportionate share of global attacks. Among them, Qilin ransomware emerged as the most active threat group tracked by Cyble Research and Intelligence Labs (CRIL), demonstrating the scale and reach of today’s ransomware-as-a-service (RaaS) ecosystem. First seen on thecyberexpress.com Jump to article:…
-
Kaspersky to scan AI agents for backdoors as shadow AI spreads
The security supplier will release a tool this month that vets agent skills, models and artificial intelligence development components before they reach corporate networks to defend against threats from shadow AI First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646680/Kaspersky-to-scan-AI-agents-for-backdoors-as-shadow-AI-spreads
-
Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia’s Foreign Intelligence Service (SVR). First seen on thecyberexpress.com Jump to article: thecyberexpress.com/captivecrunch-midnight-blizzard/
-
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.”These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the First seen…
-
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…
-
AI in Healthcare: New HIPAA Compliance Challenges for Organizations
The healthcare industry is rapidly embracing artificial intelligence to improve patient outcomes, streamline operations, and support clinical decision-making. From AI-powered diagnostic tools and virtual health assistants to predictive analytics and automated administrative workflows, AI in Healthcare is transforming how organizations collect, process, and use sensitive health information. However, the rapid adoption of AI is also……
-
South Korea Warns of State-Backed Watering Hole Attacks
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean…
-
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign. First seen on cyberscoop.com Jump to article: cyberscoop.com/trump-blames-minnesota-water-cyberattacks-iran/
-
ISMG Editors: A New Front in the Naming War
Also: The AI Spending Reality Check, Nvidia Takes on Closed AI. In this week’s panel, four ISMG editors discussed Google’s controversial new threat actor naming system and the need for standardization, whether the artificial intelligence boom is built on solid economic foundations, and the growing battle between open and closed AI models. First seen on…
-
The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats
Tags: ai, cyber, cyberattack, data, exploit, finance, fraud, government, infrastructure, intelligence, leak, malicious, malware, software, threatThis weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses. First seen…
-
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge.The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries…

