Threat intelligence stories - Page 2
Small alert, big defense: Inside a SOC's early-morning response
Last week
#
vpns
#
ransomware
#
mfa
UK SOC spots Monday-morning conditional access failure from Germany, helps reset compromised Microsoft 365 account before attackers can strike.
iProov report warns of soaring iOS injection attacks
Last week
#
uc
#
data protection
#
devops
iProov warns iOS injection attacks surged 1,151% in late 2025 as generative AI fuels deepfake impersonation and identity fraud.
Microsoft 365 EvilToken campaign hits hundreds daily
Last week
#
mfa
#
cloud security
#
phishing
Microsoft warns that 10 to 15 EvilToken phishing runs are launched daily, compromising hundreds of organisations through OAuth token abuse.
Qualys warns attackers exploit flaws before disclosure
Last week
#
firewalls
#
vpns
#
network security
Qualys says attackers are exploiting flaws before disclosure as remediation backlogs swell, with edge devices facing the highest risk.
TrendAI: Evolving the cybersecurity value proposition
Last week
#
hybrid cloud
#
digital transformation
#
cloud security
TrendAI urges stronger AI governance as it shifts cybersecurity from fear-based selling to platformised risk reduction for Australian firms.
Microsoft warns of Storm-1175's rapid Medusa attacks
Last week
#
ransomware
#
cybersecurity
#
microsoft
Microsoft says Storm-1175 is exploiting newly disclosed flaws within hours, hitting organisations in the UK and elsewhere with fast-moving Medusa ransomware.
Qualys warns exploitation is outpacing manual patching
Last week
#
firewalls
#
vpns
#
network infrastructure
Qualys study says attackers are exploiting flaws before patches exist, as manual remediation lags and edge systems emerge as the highest risk.
Permiso launches sandbox for AI agent skill security
Last week
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
China-aligned TA416 resumes spying on EU & Mideast
Last week
#
phishing
#
email security
#
cybersecurity
China-linked TA416 returns to spying on European diplomats and later expands attacks to Middle Eastern government targets after Iran conflict.
Attackers turn trusted tools into cyber weapon
This month
#
malware
#
ransomware
#
advanced persistent threat protection
Attackers abuse trusted tools, remote support software and stolen SSO sessions to breach systems, ReliaQuest says.
Zscaler flags Xloader malware's tougher obfuscation
This month
#
malware
#
firewalls
#
encryption
Zscaler says Xloader malware has added layered encryption, decoy servers and new obfuscation tricks to hinder analysts.
DeepLoad malware steals credentials via ClickFix campaign
This month
#
malware
#
firewalls
#
network infrastructure
ReliaQuest flags DeepLoad malware stealing live credentials in enterprise networks, with AI-style obfuscation, USB spread and hidden WMI persistence.
Firms warned on ransomware amid backup & AI sprawl
This month
#
saas
#
firewalls
#
data protection
Experts warn firms must improve visibility and backup resilience as automated ransomware campaigns and hidden SaaS and AI assets widen exposure.
Bitdefender launches free attack surface assessment
This month
#
firewalls
#
network security
#
pam
Bitdefender offers free 45-day internal security check to spot over-entitled staff access as attackers increasingly abuse trusted tools.
Eventus Security wins four Global InfoSec awards
This month
#
advanced persistent threat protection
#
socs
#
risk & compliance
Eventus Security's AI-led platform earns four Global InfoSec honours at RSAC as the firm's managed detection and response offering gains fresh momentum.
CrowdStrike & HCLTech launch continuous threat service
This month
#
data protection
#
hybrid cloud
#
digital transformation
CrowdStrike and HCLTech deepen cybersecurity tie-up with a service to spot, prioritise and fix threats across cloud, identity and endpoints.
SonicWall flags SMB cyber gaps as attacks rise 20.8%
This month
#
firewalls
#
vpns
#
ransomware
SonicWall says small firms are being hit hardest by basic security lapses as ransomware, bot traffic and identity theft keep climbing.
Commvault adds threat-hunting tools to backup scans
Last month
#
data protection
#
dr
#
ransomware
Commvault adds Hyper Threat Hunting and Deep Inspection to Cloud Threat Scan, linking backup scanning with verified clean recovery after cyber attacks.
Why AI-powered security needs network telemetry across the hybrid cloud
Last month
#
firewalls
#
private cloud
#
hybrid cloud
AI security tools are only as smart as the data they see, and network telemetry is emerging as the missing piece in hybrid cloud oversight.
Resemble AI launches deepfake detector & threat report
Last month
#
data protection
#
physical security
#
risk & compliance
Resemble AI unveils free Chrome extension and X bot as chief executive officer Zohaib Ahmed warns synthetic media risks are widening across businesses.