Threat intelligence stories
Organisations face a growing risk of silent data theft as criminals exploit cloud identities and credentials for extortion instead of encryption.
Defensive teams are racing to match attackers using AI to find flaws and weaponise exploits within hours of disclosure.
Malicious packages are now spreading faster across code repositories, with Google saying open source ecosystems face the sharpest rise in risk.
Employees now face more realistic phone-based fraud tests as security teams can simulate vishing using local caller IDs and AI voices.
Cloud, AI and hybrid work are pushing system administrators into frontline risk management as phishing threats become harder to spot.
Defenders in Australia and New Zealand face faster, more adaptive intrusions as state-backed hackers use generative AI to scout and spread.
Proofpoint says underground forums are advertising tools that use indirect prompt injection across emails, PDFs, calendar invites and web pages.
Ukrainian and US organisations were exposed for months after a Zimbra bug let attackers steal emails and credentials without a click.
Victims can be tricked more easily as Logokit now tailors fake login pages in real time, sending stolen credentials to Telegram bots.
Windows users face session theft risk as MedusaHVNC lets attackers operate in hidden browser desktops using existing cookies and log-ins.
Security teams could cut incident response from hours to minutes as Team Cymru folds telemetry, investigation and AI access into one platform.
Despite widespread concern over stolen logins, only 19% of organisations continuously monitor and automatically remediate exposed credentials.
The new model is designed to halve operating costs for Microsoft's MDASH security system as automated attacks grow cheaper and more frequent.
Demand is rising for outside-in cyber monitoring as firms seek earlier warning of impersonation, leaks and fraud before systems are breached.
Routine hunting can now be run in hours rather than days, helping security teams uncover intrusions and gaps they might otherwise miss.
The deal gives regulated businesses extra protection against phishing, data leaks and rogue apps as work shifts deeper into browsers and AI tools.
Security teams could cut storage and response delays as ReliaQuest's new platform detects threats before telemetry is indexed or centralised.
Security teams can now pull threat intelligence into existing AI workflows, reducing manual analysis across fragmented data and incident investigations.
Security teams could be missing thousands of related files, as Stairwell says published malware hashes often expose only part of an attack.
The rollout targets post-login attacks, rogue AI use and fake job candidates as customers seek stronger control over identities and access.