Tag: threat
-
Forescout Threat Review 2026H1 zeigt: KI-Boom treibt Cyberrisiken drastisch nach oben
Im ersten Halbjahr 2026 wurden weltweit 37.137 Schwachstellen veröffentlicht. Gegenüber dem Vorjahreszeitraum entspricht das einem Anstieg von 51 Prozent. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/forescout-threat-review-2026h1-zeigt-ki-boom-treibt-cyberrisiken-drastisch-nach-oben/a45831/
-
Middle East faces new cyber reality: attackers logging in, not breaking in
Geopolitical tensions, stolen credentials and increasingly rapid attacker movement are reshaping the Middle East’s cyber threat landscape, putting pressure on organisations to look beyond traditional, alert-driven security models First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646049/Middle-East-faces-new-cyber-reality-attackers-logging-in-not-breaking-in
-
Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on First seen on thehackernews.com…
-
Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns
Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the…
-
Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns
A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims. The >>Cyber Threat Landscape: UK & Ireland<< report, published by threat intelligence…
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user sessions directly. Detailed by Infoblox Threat Intel researchers Darby Wise and Nick Sundvall, the widespread campaign has targeted universities,…
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar…
-
Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform
A Russian-speaking threat actor known as “Trim” has reportedly transformed Anthropic’s Claude Opus into the central component of an automated, AI-powered penetration testing platform. This development highlights the rapid repurposing of advanced AI models for offensive security operations. According to research by Cato CTRL, Trim progressed from sharing jailbreak instructions on a Russian cybercrime forum…
-
Kritische Rechteausweitung in Standardinstallationen von Ubuntu-Desktop
Ubuntu-Desktop ist in Unternehmen, öffentlichen Einrichtungen und bei Entwicklern im deutschsprachigen Raum weit verbreitet. Da die betroffenen Versionen in Standardkonfiguration verwundbar sind, sollten IT- und Sicherheitsverantwortliche zeitnah handeln. Die Qualys Threat Research Unit (TRU) hat eine Local-Privilege-Escalation-Schwachstelle (LPE) in snap-confine identifiziert (CVE-2026-8933). Diese Schwachstelle erlaubt es einem nicht privilegierten lokalen Benutzer, auf Standardinstallationen von Ubuntu-Desktop…
-
AI Cybercrime Report Warns of Emerging AI-Powered Threats
A ThreatDown report warns that AI is making cyberattacks faster, smarter, and more accessible to threat actors. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ai-cybercrime-report-warns-of-emerging-ai-powered-threats/
-
House intel bill includes provisions on state and local threat intelligence, election security, AI
The House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday. First seen on cyberscoop.com Jump to article: cyberscoop.com/house-intel-bill-includes-provisions-on-state-and-local-threat-intelligence-election-security-ai/
-
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and…
-
JadePuffer returns with ransomware built to target AI models and infrastructure
JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/jadepuffer-encforge-ransomware/
-
Forescout Report Reveals Surge in AI-Driven Cyber Threats
The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day. The…
-
A New Ransomware Threat Actor Emerges Every Week, Warns Report
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-ransomware-weekly/
-
2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year”‘over”‘year surge in Qilin activity that reshapes the threat landscape. The data points to a structurally higher operating tempo, a middle”‘market pivot, and attacker visibility that often outpaces defenders’ own understanding of their…
-
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Tags: advisory, ai, authentication, cve, cyber, exploit, flaw, hacker, remote-code-execution, threat, vulnerabilityThreat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed exploitation activity targeting this flaw. Initially, ServiceNow’s advisory stated it was not aware of any…
-
SonicWall SMA zero-days were exploited weeks before disclosure
Two recently disclosed SonicWall SMA 1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited in zero-day attacks for weeks, allowing threat … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/
-
Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel
At a glance Threat actor Project CAV3RN cluster; linked to OilRig (APT34) with low confidence Activity type Cyberespionage; First seen on securityonline.info Jump to article: securityonline.info/project-cav3rn-outlook-calendar-c2/
-
AWS wants GuardDuty to automate the first steps of threat investigations
Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/amazon-guardduty-investigation-agent-on-demand/
-
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances. The affected SonicWall SMA models include the 1000 series, specifically models 6210, 7210, and 8200.…
-
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.Patches for the flaw…
-
PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
-
Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids
Bit2Watt is a newly disclosed cyber”‘physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid”‘scale threat surface. Measurements on NVIDIA accelerators show sub”‘millisecond power ramps where a single Volta V100 or RTX”‘series GPU swings from low-load phases to near”‘TDP draw,…
-
Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments
Hackers are increasingly blending malicious traffic with legitimate services, and a newly uncovered campaign shows how far this tactic has evolved. The activity has been attributed to a threat actor with links to East Asia, with researchers uncovering a previously undocumented malware suite comprising TELESHIM, MIXEDKEY, and a final-stage implant dubbed BINDCLOAK. The campaign demonstrates…
-
Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments
Hackers are increasingly blending malicious traffic with legitimate services, and a newly uncovered campaign shows how far this tactic has evolved. The activity has been attributed to a threat actor with links to East Asia, with researchers uncovering a previously undocumented malware suite comprising TELESHIM, MIXEDKEY, and a final-stage implant dubbed BINDCLOAK. The campaign demonstrates…
-
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/
-
Director of Commerce AI standards office out after three months
The Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems pose. First seen on cyberscoop.com Jump to article: cyberscoop.com/director-of-commerce-ai-standards-office-out-after-three-months/
-
The 12 Best Identity Threat Detection Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs and MSPs, Microsoft Defender for Identity is effectively the bundled default inside E5 estates, Sophos…

