Tag: threat
-
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we’ve seen bad actors leveraging cloud-based AI. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/
-
OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments
The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities in the Middle East by an East Asia-linked threat actor tracked as OctLurk. The disclosure follows Part 1, which detailed the TELESHIM backdoor and the MIXEDKEY loader used earlier in the same multi-stage intrusion chain.…
-
KI macht Smartphones zur neuen Hochrisiko-Zone der Unternehmens-IT
Mobile Endgeräte rücken durch KI-gestützte Angriffe ins Zentrum der Cyberabwehr. Der »Global Mobile Threat Report 2026« von Zimperium zeigt, wie stark Phishing, Spyware, Schatten-KI und unsichere KI-generierte Apps die mobile Sicherheitslage in Unternehmen verschärfen und warum klassische Endpoint-Strategien nicht mehr ausreichen. Management Summary Mobile Security wird zur KI-Frage: KI-gesteuerte Phishing-Angriffe auf Mobilgeräte sind laut… First…
-
CrowdStrike 2026 Threat Hunting Report: KI ist heute fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. CrowdStrike hat am 3. August den 2026 Threat Hunting Report veröffentlicht, der verdeutlicht, wie sehr künstliche Intelligenz mittlerweile Bestandteil von… First…
-
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
-
Travelers Beware: Russian Intel Hacking Hotel Wi-Fi
Russian Intelligence Hackers Capture Captive Portals. Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest. Microsoft’s threat intelligence arm began tracking the threat in early May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/travelers-beware-russian-intel-hacking-hotel-wi-fi-a-32405
-
Google Warns Open-Source Attacks Will Reach New Heights
Google Says Open-Source Compromises Are Easier to Scale and Replicate. Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, making it a lucrative tactic that will continue to expand, warned Google. One of the largest open-source supply-chain attacks involved a North Korean threat actor. First seen on…
-
N-able N-central Vulnerability Under Active Exploitation
Threat actors are actively exploiting an N-able N-central vulnerability that can grant unauthenticated administrative access. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/n-able-n-central-vulnerability-under-active-exploitation/
-
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data…
-
China-based hacker employs DeepSeek in autonomous threat campaign
Researchers said the hacker also attempted to test Western AI tools, but ultimately was forced to revert to manual operations to succeed.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/china-based-hacker-deepseek-autonomous/826784/
-
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chinalinked-threat-actors/
-
Google’s Cyber Threat Actor Naming System Ditches Jargon, Makes Intelligence More Actionable
A cyber threat actor by any other name”¦can probably be found in Google Threat Intelligence Group’s new taxonomy for tracking threat actors. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/googles-cyber-threat-actor-naming-system-ditches-jargon-makes-intelligence-more-actionable/
-
3rd August Threat Intelligence Report
Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/3rd-august-threat-intelligence-report/
-
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
A Chinese threat actor operating under the aliases >>knaithe<>KnYuan<< used multiple LLMs to automate cyberattacks against internet-facing systems … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/deepseek-ai-autonomous-cyberattacks-hermes-agent/
-
Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate
Cybersecurity startup Horizon3 raised $250 million at a $2 billion valuation as companies want continuous, AI-powered security validation instead of annual pentesting. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/03/horizon3-hits-2-billion-valuation-with-250m-series-e-as-ai-threats-escalate/
-
Künstliche Intelligenz ist fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. Dies verdeutlicht der aktuelle <> von Crowdstrike. So nutzten China-nahe Angreifer innerhalb von 24 Stunden nach der Veröffentlichung eines […] First seen…
-
How the World’s Most Active Ransomware Operation Expanded in H1 2026
The first half of 2026 reinforced a familiar reality in ransomware: a small number of highly capable operators continue to drive a disproportionate share of global attacks. Among them, Qilin ransomware emerged as the most active threat group tracked by Cyble Research and Intelligence Labs (CRIL), demonstrating the scale and reach of today’s ransomware-as-a-service (RaaS) ecosystem. First seen on thecyberexpress.com Jump to article:…
-
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
Tags: ai, api, attack, business, control, cybersecurity, data, data-breach, endpoint, exploit, flaw, injection, LLM, remote-code-execution, risk, service, threat, tool, update, vulnerabilityTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs, it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team’s…
-
Kaspersky to scan AI agents for backdoors as shadow AI spreads
The security supplier will release a tool this month that vets agent skills, models and artificial intelligence development components before they reach corporate networks to defend against threats from shadow AI First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646680/Kaspersky-to-scan-AI-agents-for-backdoors-as-shadow-AI-spreads
-
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain…
-
Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia’s Foreign Intelligence Service (SVR). First seen on thecyberexpress.com Jump to article: thecyberexpress.com/captivecrunch-midnight-blizzard/
-
SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted WebSocket request into root-level control on internet-facing VPN gateways. The campaign, dissected by Volexity and other researchers, shows how a previously undocumented threat actor, tracked as UTA0533, abused SonicWall’s wsproxy…
-
Unspecified threat actors targeting US water systems, CISA warns
First seen on scworld.com Jump to article: www.scworld.com/news/unspecified-threat-actors-targeting-us-water-systems-cisa-warns
-
AiTM phishing overtakes credential theft as top threat to law firms
First seen on scworld.com Jump to article: www.scworld.com/brief/aitm-phishing-overtakes-credential-theft-as-top-threat-to-law-firms
-
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…
-
Okta übernimmt Permiso Security und erweitert seine Identity Threat Detection
Okta übernimmt Permiso Security und erweitert seine Plattform um Funktionen zur Erkennung und Abwehr von Identitätsbedrohungen in Cloud- und KI-Umgebungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/okta-uebernimmt-permiso-security-und-erweitert-seine-identity-threat-detection/a45972/
-
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chinese-hacker-deepseek-ai/
-
Okta Buys Permiso to Extend ITDR Beyond Native Identity Logs
Customers Gain Broader Identity Telemetry Across Cloud and Directory Services. Okta said its planned acquisition of Permiso will expand identity threat detection beyond native Okta telemetry by adding thousands of risk signals, AI agent security capabilities and graph-based correlation that combines identity exposures with active threats to improve detection and response. First seen on govinfosecurity.com…

