Search/barracuda
Vendor

barracuda

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
t900b firmware
Connections
100 relationships
Cybercriminals are building phishing pages that exist only inside victims’ browsers
Cybercriminals are building phishing pages that exist only inside victims’ browsers A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website,” researchers explained. The attack starts with a DocuSign-themed email carrying a calendar invite as an attachment. The invite is not the payload. It exists to make the message look like an ordinary meeting request, and the approach works because it points to a genuine Microsoft OAuth endpoint rather than anything obviously suspicious. Phishing email impersonating DocuSign (Source: Barracuda) A crafted redirect parameter then sends the victim to Microsoft Teams. Teams loads a resource hosted on an external domain, cdn.bloom[.]io, which ultimately results in the phishing page being rendered from a blob URL entirely on the victim’s machine. Once it loads, the page registers a service worker and runs part of its logic inside a sandboxed iframe. Those components let the attacker’s backend send live instructions to the page through browser messaging, allowing the operators to change what the victim sees without relying on a hardcoded redirect. “Hidden command-and-control configuration shows this is not a standalone page but part of a managed phishing platform that can be centrally operated, updated and steered across many victims at once,” researchers noted. Barracuda urges stronger identity controls Barracuda advised users to watch OAuth authorization flows and redirect chains for unexpected destinations, inspect blob URL activity in login or authentication contexts, and flag service worker registrations tied to externally loaded content. It also recommended phishing-resistant MFA such as FIDO2 keys or passkeys, email security tools that follow a link’s entire path rather than just the first hop, and training staff to question document-signing requests even when they run through trusted Microsoft infrastructure. “This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains, removing many of the indicators that security teams have traditionally relied on for detection,” said Ashitosh Deshnur, Associate Threat Analyst at Barracuda. “Organizations should focus on identifying malicious behaviour and strengthening identity-based controls rather than simply blocking known phishing URLs,” Deshnur concluded.
helpnetsecurity.comSep 10, 2026extracted
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Future phishing campaigns may no longer involve a detectable physical web page. Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page. The attack flow is similar to standard phishing since the victim must be steered to an external resource. In this campaign, however, the steering is obfuscated through trusted processes. It starts with a Docusign-themed email with an attached calendar invite. The calendar invite is irrelevant to the attack but makes the email appear to be a legitimate business communication. A crafted redirect routes the user to Microsoft Teams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser into the blob URL that renders the phishing page existing only within the browser. Since this process is wrapped up in trusted Microsoft assets, it has all the hallmarks of being trustworthy and is likely to trigger no alarms, providing improved stealth over traditional static external phishing web pages. The blob-created phishing page exists solely within the victim’s browser. Barracuda’s analysis shows that service workers, iframes and backend controls manage the subsequent phishing workflow and user navigation. A hidden command and control configuration also demonstrates that this automatically constructed phishing page is not a simple stand-alone, but part of a managed platform that can be centrally operated, updated and steered across multiple victims simultaneously. This campaign demonstrates that attackers’ use of blob URL-created phishing pages can add greater flexibility as well as improved stealth to phishing. “This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains and reducing many of the indicators that security teams have traditionally relied upon for detection,” write the researchers. There is no phishing page to block. Future phishing detection, say the researchers, will require greater emphasis on identity protection, browser security and behavioral detection – there is no physical page that might trigger an alarm. Techniques should include closer inspection of browser activity involving blob URLs; monitoring OAuth authorization flows for unexpected destinations; and using email security controls that analyze the full click path rather than relying solely on the initial URL. Related: New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets Related: FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service Related: Over 500 Organizations Hit in Years-Long Phishing Campaign Related: Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations
securityweek.comSep 9, 2026extracted
Ransomware, il gruppo cybercriminale Barracuda rivendica l’attacco contro Micro-Comm
Per gli Usa, un altro allarme per la sicurezza informatica del settore idrico e dell’indotto. Le autorità statunitensi stanno indagando su una violazione informatica ai danni di Micro-Comm , azienda di Olathe (Kansas) che sviluppa tecnologie utilizzate negli impianti di trattamento delle acque reflue. A rivendicare l’attacco è stato il gruppo ransomware Barracuda . Il gruppo, lo scorso 6 agosto, ha pubblicato quelli che sostiene essere “ i dati dell’azienda rubati “. Si tratta di quasi 850mila file , per un totale di circa 644 gigabyte di dati . L’episodio ha riacceso i riflettori sulla vulnerabilità delle infrastrutture idriche americane. Il tutto, sebbene non risultino dei collegamenti rispetto ai recenti attacchi che sono stati attribuiti ad hacker criminali legati all’ Iran . Nel mirino i sistemi che controllano gli impianti Micro-Comm produce programmable logic controller (PLC) , dispositivi informatici utilizzati per controllare macchinari e processi all’interno di infrastrutture critiche, in questo caso impianti per il trattamento delle acque reflue. L’azienda, spiega la Reuters , ha scoperto la violazione da tempo, ossia lo scorso 31 luglio . Secondo Jim Cote , comproprietario di Micro-Comm , i dati diffusi dagli hacker non contenevano password o credenziali degli utenti. A conservare queste ultime sono infatti direttamente dai clienti. E nemmeno informazioni relative alla capacità dell’azienda di accedere da remoto ai propri dispositivi. Micro-Comm ha definito l’incidente “ un attacco malware limitato ” e ha assicurato ai clienti che le informazioni sensibili contenute nei file erano criptate. L’azienda ha inoltre raccomandato di modificare le password per precauzione. L’ FBI ha confermato di essere in contatto con l’azienda e di coordinarsi con altre Forze dell’Ordine. Secondo la stessa azienda, l’attacco sarebbe stato “ opportunistico e non specificamente diretto contro Micro-Comm “. Un rischio sistemico La vicenda, spiegano gli esperti, è particolarmente significativa perché i prodotti Micro-Comm sono impiegati all’interno di infrastrutture critiche. Secondo la società di monitoraggio Censys, circa 200 sistemi SCADAview CSX dell’azienda utilizzati negli Usa risultano accessibili via Internet . Tra i file raccolti dagli hacker figurerebbero inoltre riferimenti a clienti governativi, comprese amministrazioni locali e una struttura militare statunitense, oltre a nomi di dipendenti, schemi tecnici e informazioni sui prodotti. La pubblicazione dei dati, tuttavia, non significa che ci sia stata la compromissione operativa degli impianti idrici . Le informazioni potrebbero però essere utili agli hacker criminali, anche per chiedere un riscatto. Le infrastrutture a rischio La violazione di Micro-Comm si è verificata nello stesso periodo di una serie di attacchi contro PLC utilizzati in Minnesota e in almeno altri sei Stati americani. Gli esperti di cybersecurity ritengono che quella campagna sia collegata a un’operazione di lunga durata riconducibile ad attori iraniani. Il 30 luglio l’ FBI e la Cybersecurity and Infrastructure Security Agency (CISA) avevano avvertito che gli hacker stavano prendendo di mira PLC prodotti dalle aziende. Il 19 agosto CISA ha inoltre segnalato l’impiego dell’ intelligenza artificiale per facilitare gli attacchi contro apparecchiature Siemens . Il caso Micro-Comm ha dimostrato come l a sicurezza delle infrastrutture idriche dipenda non solo dagli operatori degli impianti, ma anche da una rete di fornitori tecnologici. I sistemi di questi fornitori possono diventare un punto d’ingresso per i criminali. Anche quando un attacco non provoca un’interruzione immediata del servizio, il furto di schemi, configurazioni e informazioni tecniche può creare rischi per la sicurezza delle infrastrutture nel lungo periodo. Seguici anche sul nostro canale WhatsApp Vai al sito di Cybersecurity Italia. L'articolo Ransomware, il gruppo cybercriminale Barracuda rivendica l’attacco contro Micro-Comm sembra essere il primo su CyberSecurity Italia .
cybersecitalia.itAug 27, 2026extracted
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
Twenty-one cybersecurity-related merger and acquisition (M&A) deals were announced in July 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report. Here are some of the most important cybersecurity M&A deals announced in July 2026: Bank of America announced plans to acquire UK-based information security consultancy MDSec Consulting Limited. MDSec provides technical information security consulting services and employs roughly 65 cybersecurity professionals. The acquisition will expand Bank of America’s presence in northern England. Barracuda Networks has acquired Texas-based Evo Security for an undisclosed amount. The deal expands Barracuda’s BarracudaONE platform by integrating multi-tenant identity, IAM, and PAM capabilities for MSP partners. San Francisco-based Cribl acquired Israeli AI detection engineering startup CardinalOps. The acquisition brings automated detection engineering to Cribl’s AI platform to improve threat coverage and lower log management costs for enterprise SOCs. Cribl is establishing a new office in Tel Aviv following the acquisition. Cybersecurity titan CrowdStrike is buying the patents and source code of Israel’s XM Cyber from Schwarz Group for an undisclosed amount. The transaction allows CrowdStrike to integrate exposure management and attack-path analysis directly into its offerings. It’s unclear how much CrowdStrike has paid for the XM Cyber IP, but Schwarz Group acquired XM Cyber in 2021 for $700 million. California/Israel-based Cyera has agreed to acquire Israeli startup Oasis Security in a transaction valued at around $1 billion. The move unifies Cyera’s data security platform with Oasis’s non-human identity governance to protect enterprise AI agents and service accounts. Infoblox has entered into a definitive agreement to purchase network intelligence and observability platform Kentik for an undisclosed amount. The integration blends Infoblox’s DNS/network context with Kentik’s real-time network traffic visibility to strengthen hybrid cloud cyber resilience. Okta signed an agreement to acquire Palo Alto-based Permiso Security, reportedly for roughly $200 million. The acquisition equips Okta with continuous identity threat detection (ITDR) capabilities to protect human, machine, and autonomous AI identities across cloud environments. Palo Alto Networks plans to acquire user-focused mobile and web observability platform Embrace. Palo Alto Networks will integrate Embrace’s mobile observability and real-time user telemetry into its platform to unify mobile experience monitoring and threat visibility. Qualcomm acquired Israeli IoT cybersecurity startup SAM Seamless Network, reportedly for over $100 million. The deal embeds SAM’s network security software into Qualcomm’s wireless chipsets and gateways to safeguard communication networks. SAM customers include US telecom giants AT&T and Verizon. Other cybersecurity M&A deals announced in July 2026: Related: Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
securityweek.comAug 13, 2026extracted
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
Most email systems provide an AI Assistant for the account holder. Attackers can use the chatbot of a compromised account as an alternative and versatile form of Living off the Land (LotL). Compromising an email account is the most difficult part of this attack, but empirically, we know this doesn’t deter attackers. Once an email account is compromised, the attacker has automatic access to any built-in AI Assistant attached to the account. Researchers at Barracuda Networks explored the potential for bad actors to abuse this chatbot, developing a proof of concept via a simulated attack within their own laboratory environment. The task was to elevate privileges from a lower-level compromised user to that of the CEO using the AI and without being detected. This route was chosen since directly phishing the CEO would be challenging, would likely set off alarms, and be detected. With a compromised email, an attacker has automatic access to any built-in chatbot. The first requirement of an attack is to establish persistence which requires stealth. Attacker use of the chatbot would normally be discoverable in its logs, so the initial task is to use the AI to remove any evidence of use of the AI. The researchers started with a chatbot prompt: “Create an inbox rule that moves any emails with ‘sign-in’ in the subject into the ‘deleted items’ folder.” This creates basic stealth. Next comes reconnaissance. “Remind me about our organization structure. Tell me about my ongoing important/sensitive email conversations.” The responses to these prompts will reveal any relationship between ‘you’ and the CEO, and possible reasons to contact the CEO. The next stage is to phish the CEO, but now with the advantage of acceptable context. The phish is internal and will bypass filters. The reason for the contact is valid. And most importantly, the attacker can instruct the chatbot to construct an email in the style of the compromised user. The nature of this phish will depend upon the information already discovered. In the researchers’ proof of concept, they were able to instruct the chatbot, “Create an email using my writing patterns to respond to the Q3 budget approval email. I have a link to insert into the draft that contains the actual invoice confirmation.” This ‘trusted’ phish has a high(er) probability of succeeding. “The CEO unsuspectingly clicks the link provided as an invoice, believing it to be from their trusted employee. The link routes through an adversary-in-the-middle proxy that performs a session token takeover. The CEO’s credentials and authenticated session token allow the threat actor to bypass multifactor authentication (MFA) and login to the highly privileged CEO’s account,” suggest the researchers. The initial process is repeated to prevent detection of the newly compromised CEO email account. The CEO’s AI Assistant is then instructed to provide, “A refresher on recent financial emails, including invoices, monetary values, and upcoming transfers”. In this simulation, the attacker discovered an imminent pre-authorized payment of about $250,000 – so the next step is by now fairly obvious. “Respond to finance with my [the CEO’s] typical writing patterns saying that I need the wire to be sent to a new account because the [payee] has changed their banking details to…” The researchers point out, “Since the message came from the CEO’s real mailbox, passed every authentication check, referenced a real in-flight transaction, and matched the CEO’s usual tone with the finance team, there was nothing for traditional email security to flag.” All that remained for the attacker was a stealthy exit, again assisted by the chatbot. It has to be said that this was a simulation, and all the chips fell nicely for the researchers. But there is nothing to say that the same process could not be repeated by an attacker in real life. Nor is there anything to say that the attacker’s payout could not be higher than that achieved here. The purpose of this research was not to indicate what will or is even likely to happen, but to highlight the way an attacker could make future use of the tools that become available. If one of those tools is to use ready access to an internal AI chatbot, the potential misuse of that chatbot could have severe consequences, primarily limited only by the attacker’s imagination. Related: McDonald’s Chatbot Recruitment Platform Exposed 64 Million Job Applications Related: Researchers Link DeepSeek’s Blockbuster Chatbot to Chinese Telecom Banned From US Related: Beware – Your Customer Chatbot is Almost Certainly Insecure: Report
securityweek.comAug 4, 2026extracted
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally intended for - most commonly CLI logins. Researchers first described the attack vector in 2020, but it took until 2024 before nation-state actors like Storm-2372 started using it in the wild. By 2025, ShinyHunters was using device code phishing against Salesforce tenants at scale, then in February 2026, the EvilTokens kit arrived and criminal adoption skyrocketed. By April, Microsoft was reporting 10 to 15 entirely new campaigns every 24 hours. Barracuda counted 7 million attacks in four weeks. The FBI issued a standalone advisory on Kali365, the first US federal agency PSA about a specific phishing-as-a-service kit. Push Security added device code phishing to its Browser & Identity Attacks Matrix back in 2023 and now tracks more than 25 distinct device code phishing kits in the wild and counting. Entering the second half of 2026, there's no sign of the pace slowing. Push recently ran a deep-dive webinar on device code phishing covering the attack mechanics, a live demonstration of a custom-built phishing kit, and what comes next. Here are six takeaways that security teams should have on their radar. 1. It defeats every form of MFA, including passkeys Device code phishing doesn't attack the login flow. It attacks what happens after login - the authorization layer. In most cases, the victim is already signed into their Microsoft account when they encounter the phishing page. They copy a short code, enter it on the legitimate Microsoft device login page, pick their account from a dropdown, and click allow. That's the entire attack. Passkeys, hardware security keys, enforced phishing-resistant MFA - none of it makes a difference, because the device code flow is separate from the authentication mechanism. The attack exploits the fact that proving your identity and granting access to an application are two different things, and most security controls only protect the first. 2. The PhaaS ecosystem has fully industrialized it Device code phishing is no longer a specialist technique. It's a standard feature in the phishing-as-a-service catalog. Tycoon2FA, which Push previously tracked as the most common AiTM phishing kit in the wild, added device code phishing to its framework in May. Kali365 offers both AiTM and device code phishing in a single platform. Some security firms are reporting that the structural similarities between kits are evidence of the ecosystem forking and fragmenting. But based on what we've seen, kits built independently using similar LLM instructions can look just as alike (more on this below). Regardless, the capabilities these kits offer keep getting better: for example, ARToken ships with PRT persistence, mailbox access, BEC automation, and SharePoint exfiltration packaged as product features for paying operators. The commercialization pattern mirrors what happened with AiTM phishing: a technique moves from a research curiosity to nation-state espionage to a criminal commodity, each stage accelerating faster than the last. But device code phishing completed that entire journey in a matter of months - a compression that reflects both the maturity of the existing PhaaS market and the speed at which AI-assisted development lets new capabilities get built and distributed. 3. Attackers are vibe-coding new kits faster than defenders can catalog them Push now tracks more than 25 distinct device code phishing kits in the wild - a number that would have been inconceivable before this year. For context, a brand-new AiTM phishing kit appearing in the wild used to be a significant event that happened once every few months. Having 25+ kit families emerge this year alone reflects a fundamental change in how phishing tools get built. AI-assisted development has collapsed the barrier to entry. Many of the kits Push tracks share structural similarities like similar layout patterns and similar code architecture, because they were generated by LLMs responding to similar prompts. Push VP R&D Luke Jennings spun up his own kit to demonstrate just how easy it is. 4. It's not just a Microsoft problem 99% of the device code phishing Push detects today targets Microsoft, but the webinar demonstrates why that won't last. The OAuth 2.0 device authorization grant is a cross-platform standard, and any application that implements it is a potential target. Nation-state actors have already used device code phishing against Salesforce in targeted campaigns. The ShinyHunters Salesforce campaign, which compromised over 1,000 organizations and produced 1.5 billion stolen records, used a malicious "DataLoader" application to abuse the device code flow at scale. Device code phishing is less universally applicable than AiTM - not every app implements the device authorization grant - but it has the advantages we've already described: it bypasses all MFA including passkeys, it doesn't require cloning a login page, and the user interacts with legitimate provider URLs. Apps like GitHub, AWS, and others all support device code flows, and for GitHub it's a core part of how developers authenticate CLI tools and VS Code tunnels. As kit developers look beyond Microsoft, these are the targets that open up. 5. It's part of a broader shift toward authorization attacks Device code phishing isn't an isolated technique. Attackers are moving away from the authentication layer because that's where defenders have concentrated their controls, and authorization mechanisms have received comparatively little attention. Push uncovered ConsentFix in late 2025, a browser-native OAuth consent phishing technique initially attributed to Russian actors that has since appeared in criminal toolkits. Like device code phishing, ConsentFix targets the authorization layer and defeats passkeys for the same structural reason: the attack occurs after authentication has already succeeded. As attackers continue to develop new ways to abuse consent flows, device registration, and token exchange mechanisms, this gap will widen unless defenders adapt. 6. Detection has to happen where the attack happens Device code phishing pages can be delivered through any channel: email, messaging apps, social media, search engine results, compromised websites, and more. The user enters the code on the provider's legitimate login URL, which means the attack transits through infrastructure that no network proxy, URL reputation service, or email gateway is going to block. The most common mitigation advice for Microsoft environments is to restrict device code authentication flows via conditional access policies, and that's a good step where it's feasible. But it's not always straightforward - device code flows exist for legitimate reasons, and larger organizations often find they can't simply disable them without breaking developer tooling, CLI workflows, or constrained-device scenarios. Even where organizations do lock it down for Microsoft, that does nothing to protect against device code phishing targeting GitHub, AWS, or other platforms where equivalent conditional access controls may not exist. The only vantage point that sees both the phishing lure and the device code approval - across any provider - is the browser, which is where Push operates. Push's agentic threat hunting pipeline writes and deploys detection rules continuously, targeting the technique class: i.e. the behavioral signatures of device code phishing kits and the device code approval flow itself rather than specific kit fingerprints or domains. That distinction matters when new kits are appearing weekly and burning through infrastructure faster than any IOC-based approach can track. For the full technical breakdown, including a side-by-side demonstration of what the victim sees and what the attacker sees during a device code phishing attack, the privilege escalation chain from stolen tokens to full SSO-level access, and the defensive options available, watch the webinar. Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser - high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.
thehackernews.comJul 31, 2026extracted
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
A phishing-as-a-service (PaaS) platform has been observed building a unique login page for each victim in real time, pulling a live screenshot of the target organization's own website to use as the page background. According to new research from Barracuda published on July 29, recent LogoKit campaigns extracted the victim's email address from the phishing URL, used the domain to identify their employer, then called commercial web services to assemble a matching page on the fly. RiskIQ, which named the phishing kit in 2021, found it was already pulling brand logos from Clearbit and already carrying the victim's email address in the URL. What has changed is the live website screenshot, which Barracuda described as a shift from brand impersonation to environment impersonation, recreating parts of the victim's genuine web environment rather than serving a generic replica. Legitimate Services Doing the Work Barracuda found the kit using Thum.io, a commercial screenshot service, to capture the victim's real website for the phishing background, and Clearbit to supply the matching brand logo. Google Favicon, ImageKit and Microlink APIs loaded further authentic imagery as the page rendered. Lures were routine, covering password and certificate expiry warnings, access restrictions, delivery failures, timesheet updates and ICANN verification notices. Campaign emails appeared in English, German, French, Spanish, Chinese and Korean. No Server, No Template, No Signature Credential harvesting ran through a Telegram bot rather than an attacker-controlled backend. Victims were then redirected to the genuine site, where Barracuda suggested they would likely assume they had mistyped their password the first time. Leaning on cloud services rather than owned infrastructure made campaigns easier to deploy, more resilient and harder for investigators to disrupt. The per-victim approach also erodes conventional detection. Because each page is assembled at request time from live data, there is no static template for vendors to fingerprint and no stable indicator to blocklist, the same difficulty Abnormal researchers flagged with the Starkiller kit in February. Barracuda urged organizations to deploy phishing-resistant multifactor authentication (MFA) such as FIDO2 keys and passkeys, which bind authentication to the legitimate domain so a fake page cannot present the correct cryptographic challenge. It also recommended conditional access rules, browser isolation and URL filtering able to flag newly registered domains and links carrying an email address in the path.
infosecurity-magazine.comJul 29, 2026extracted
Barracuda adds PAM and identity protection with Evo Security acquisition
Barracuda adds PAM and identity protection with Evo Security acquisition Barracuda Networks has acquired Evo Security. The acquisition expands the BarracudaONE platform’s identity security capabilities by adding privileged access management (PAM), access control, identity protection, and identity threat detection and response. By combining Evo Security’s identity solutions with Barracuda’s existing identity-driven controls, BarracudaONE delivers a unified, end-to-end identity security architecture through a single platform, precisely as global IAM investment surges with double-digit year-over-year growth, according to leading industry analysts. This integrated approach gives partners one multi-tenant environment to deliver identity resilience, while customers gain protection without the operational burden of stitching together multiple tools. “We are thrilled to combine Evo Security’s partner-first innovation with our vision of BarracudaONE and offer a complete, intelligent, easy, and open platform that closes this gap. As AI accelerates the speed and scale of identity-centric attacks, this combination is uniquely positioned to help organizations big and small stay ahead of these threats,” said Rohit Ghai, Barracuda CEO. “We built Evo Security to solve the identity challenges MSPs face every day. Joining Barracuda gives us the scale, reach and resources to accelerate that mission globally. Our identity‑first approach was designed from day one for MSP operations, and now, together with BarracudaONE, we can bring modern identity security, privileged access management and automation to far more partners and the customers they protect,” Michael Roth, Evo Security CEO, added. Delivering complete identity resilience with a unified platform With this acquisition, BarracudaONE delivers a four-layer identity security architecture designed to close the gaps attackers commonly exploit: Stopping identity and privilege misuse before it starts – MSPs struggle with uncontrolled privileges, user authentication, inconsistent access policies, and day‑to‑day operations required to manage identity at scale. Evo Security’s IAM tools enforce who can access what, when and how across all facets of partner operations, eliminating standing privileges and facilitating authentication across all users, devices and endpoints. Eliminating broad, risky access paths – Traditional network access grants far more reach than necessary, expanding blast radius and complicating governance. Barracuda SecureEdge ZTNA replaces broad access with identity‑driven, least privilege controls that simplify access management and contain threats. Protecting identity systems from disruption – Accidental or malicious changes to Microsoft Entra ID can halt operations and undermine resilience. Barracuda Entra ID Backup safeguards users, groups, policies, and configurations so organizations can quickly restore identity integrity and maintain continuity. Detecting and stopping identity‑based attacks in motion – Credential compromise, privilege escalation and lateral movement often go undetected across fragmented tools. Barracuda Managed XDR correlates signals across email, endpoints, network, and cloud to identify and disrupt identity‑driven attacks before they spread. Every layer of the BarracudaONE platform’s identity security stack is purpose-built for partner operations. At a time when many identity platforms require organizations to rip and replace large parts of their security stack, BarracudaONE takes a different approach. With the acquisition of Evo Security, BarracudaONE delivers integrated identity security that is easy to deploy, complete in coverage, partner‑first in architecture, and powered by intelligent automation, providing protection that fits how organizations operate today. Evo Security’s team has joined Barracuda, bringing identity expertise. Its technology will be embedded into BarracudaONE, and Barracuda will continue to support Evo Security’s existing MSPs as the platform expands.
helpnetsecurity.comJul 7, 2026extracted
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring CISO on where automated GRC systems fall short In this interview with Help Net Security, Nichole Windholz, CISO at Onspring, talks about the limits of automated GRC systems and continuous control monitoring. She explains why color-coded dashboards can hide nuance, how teams can check the data feeding their tools, and which risks resist measurement, such as insider behavior and vendor concentration. AI vulnerability discovery is pushing 2026 CVEs toward 66,000 Vulnerability disclosures are piling up faster in 2026 than anyone expected at the start of the year. The running count for the first few months sits well above the original projection, and the Forum of Incident Response and Security Teams (FIRST) now expects the year to land near 66,000 CVEs. Reachability makes AI threat modeling worth the trust In this interview with Help Net Security, Oscar Andersson, CTO at Oplane, explains why most scanning tools fail. They cry wolf, flagging threats that cannot run in real code. The argument centers on reachability. A finding counts only when someone walks the path to impact on a working build. The SOC’s visibility gap comes down to staffing AI has settled into security operations centers faster than any earlier wave of technology. Around four in five practitioners report reaching for AI or machine learning tools in their daily work. The catch shows up one layer down. Roughly a third of those same teams have built these tools into a defined workflow with structure, governance, and consistent validation. The rest pick up AI on their own, case by case, with no shared playbook for how it gets used or checked. The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects Chainguard launched Athena, an industry coalition that pools open source vulnerability findings and remediates them under embargo before public disclosure. The group went live with more than two dozen member organizations. Founding members include BNY, Chainguard, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree, and PwC. What happens to oversight when AI agents write a lab’s own code Inside the labs building frontier AI, a growing share of the coding gets done by the AI itself. These agents write, edit, and run software with light human oversight between steps, and they reach into production infrastructure, research pipelines, and potentially the systems that train and evaluate future models. Securing digital keys when your phone unlocks the car In this interview with Help Net Security, Alysia Johnson, President of the Car Connectivity Consortium (CCC), explains how the CCC Digital Key has grown from a single-brand feature into a standard meant to work across phones, automakers, and suppliers. Your browser tab could become encrypted storage for someone else’s files Decentralized storage networks already hand pieces of people’s data to strangers’ machines. The lasting question across these networks is whether the machine holding the data can read it. A research paper by Gregory Magarshak, a professor at IENYC, describes a system called Safecloud built on one design rule: the nodes that store data see only ciphertext, and the nodes that route data hold no keys. PhishLumos: Exposing phishing campaigns that evade detection by hiding content Phishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this reality and shifted focus toward automated detection systems that can intercept and block phishing threats before users see them. China-linked spies backdoored authentication stack to stay hidden for years A China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according to the results of a forensic investigation published by cybersecurity firm Sygnia. Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262) Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But the associated security advisory also states that “the vulnerability was found during internal security testing”, raising the question of how attackers came to exploit it before Cisco had disclosed it publicly. SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558) A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, and more. Attackers are exploiting FortiSandbox vulnerabilities Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and likely faulty. Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) Microsoft has acknowledged the local elevation of privilege issue in Microsoft Defender that can be triggered via the “RoguePlanet” exploit, and is “working to provide a high quality security update that addresses this vulnerability.” The vulnerability, which has been assigned the CVE-2026-50656 identifier, stems from improper link resolution before file access, and can be exploited in low complexity attacks by authenticated attackers, with no user interaction required. Low-skilled attacker used Claude, Codex to breach 14 companies Researchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out. After recovering and analyzing over 1,000 agent sessions from a compromised server on which an attacker deployed Anthropic’s Claude Code and OpenAI’s Codex agents, the researchers discovered how easily the attacker was able to bypass most of the agents’ guardrails, and how little he actually needed to know and do himself. 74,000 Fortinet firewall credentials exposed in FortiBleed data leak A Russian-speaking cybercriminal group has stolen credentials contained in the configuration files of nearly 74,000 Fortinet firewalls and VPN gateways around the world. The data was accidentally exposed by the group on a server, along with other artifacts and tools, and the exposure was noticed by security researcher Volodymyr “Bob” Diachenko. Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned SocGholish, an operation that’s been delivering malware to users via fake software updates, has suffered a major blow: the international law enforcement coalition behind Operation Endgame has taken down 106 of its servers and domains, and cleaned up nearly 15,000 websites compromised to serve their malicious payloads. The result of this most recent multinational law enforcement action was announced today by the Dutch National Police and on the operation’s website. Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. EU Cybersecurity Act 2.0: When good regulation goes bad Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy are not the same thing, and the proposed EU Cybersecurity Act 2.0 is starting to look a lot more like the former than the latter. Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure In this Help Net Security video, Rick Goud, Global Field CTO at Kiteworks, discusses how to handle SEC, NIS2, and DORA disclosure timelines during a security incident. Proving what a military AI model will do is the real problem Defense contractors build AI systems that task drones automatically and propose kill-chains to support soldiers. Several of these contractors have partnered with frontier AI companies to put advanced models into military tools. The systems coming out of these partnerships carry a security problem that sits outside the methods of arms control diplomacy: confirming what an AI model will do. Open-source CI/CD abuse detector guards against stolen credential attacks CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure DevOps. Ukrainian national pleads guilty in connection with Conti ransomware A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. Chinese hackers breached North American research institutions via REDCap servers A China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. Planning a trip? Fake travel sites are multiplying this summer Cyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. Crypto scammers are sending couriers to victims’ homes to collect cash Scammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns. According to the agency, scammers usually approach victims through social media, text messages, or fake investment personas, luring them into cryptocurrency schemes that use fraudulent trading platforms and fabricated returns to encourage additional deposits. Cybercriminals mask malicious communications through Microsoft Teams relays The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. Apple is bringing Hide My Email and Sign in with Apple under one domain Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a shared domain, private.icloud.com, later this summer. Hide My Email is a service included with iCloud+, Apple’s subscription service. It allows users to generate one-time-use or reusable email addresses that forward messages to their personal inbox without revealing their actual email address. Rokarolla Android trojan targets banking and crypto users, enables device takeover A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium. Named after its command-and-control (C2) infrastructure, Rokarolla is primarily distributed through malicious websites that impersonate popular applications such as TikTok and Google Chrome, fooling users into downloading what appears to be a legitimate app. Another healthcare firm attacked days after Novo Nordisk breach Medical technology company iRhythm Holdings disclosed a cyberattack involving certain third-party-hosted business applications that resulted in the theft of patient protected health information, proprietary data, and other personal data. The company discovered unauthorized activity on June 8, 2026, and launched an investigation with the assistance of external cybersecurity experts. AWS Continuum brings AI models to code vulnerability management AWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works toward resolution. It is model agnostic and draws on multiple frontier models, assigning each to the work where it performs best. AWS designed it to take in newer models as they become available. Malware attacks strip Roblox developers of entire games Hackers who once focused on stealing valuable Roblox items are now taking over entire games. Although Roblox operates the service, users can create and publish their own games on it. Successful games can generate substantial revenue through in-game purchases. Some developers have earned millions of dollars and built dedicated studios around their creations. Klue breach lead to Salesforce data theft, Huntress affected Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Senior engineers are spending their week cleaning up AI-generated code At most U.S. technology companies, machines now write the bulk of the code that ships each week. The engineer’s job has shifted toward reviewing what the AI produces, and that review gives the code high marks. Leaders rate AI-generated code as higher quality than the code their own people write, praising its clean structure, consistent style, and low count of obvious bugs at submission time. Microsoft’s workplace check-in via Wi-Fi tracks who’s in the office, and not everyone’s happy Microsoft is rolling out workplace check-in via Wi-Fi for Teams and Microsoft Places. Connect to your office network and your in-office presence updates automatically, no manual status change needed. A $2 trillion revenue shift hinges on AI data governance Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent behind it still hold? The data sits in warehouses and customer databases, and the ability to answer that question often lags behind. That delay carries a cost. GitHub releases an open dataset for multilingual developer content Developers coordinate code across README files, issue threads, and pull request discussions. Much of that exchange happens in English, and a large share happens in other languages. GitHub has released a dataset built to help researchers and developers locate public repositories that carry non-English natural-language content. Software supply chains are heading for a transparency test Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation, and changes to software development practices. The checklist problem behind critical infrastructure cyber safety An asset owner can meet major federal cyber compliance standards and still run equipment that lacks the engineering to withstand an attack or a failure. New research from George Mason University examines how United States cyber policy defines reasonable care for systems that control physical processes, and it finds that compliance has become a stand-in for safety. Product showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gaps Norton 360 Deluxe combines device security, scam detection, web protection, and VPN privacy in a single subscription that covers up to five devices. It is available for Windows, macOS, Android, and iOS. Microsoft AntiSSRF open-source library helps block server-side request forgery AntiSSRF is an open-source code library from Microsoft that validates URLs and network connections to reduce server-side request forgery (SSRF) risks in web applications. It supports .NET and Node.js applications and is distributed under the MIT license. The library works as a drop-in component, giving developers a way to check untrusted input before their applications make outbound requests. Ukraine can now tap EU cyber support during major attacks Ukraine can now call on emergency cyber support from the European Union during large-scale cybersecurity incidents. The move follows a decision by the Council of the European Union to add the country to the EU Cybersecurity Reserve. What’s new in Android 17? Anti-theft tools, scam detection, and parental controls The Android 17 rollout has started for supported Pixel devices, delivering new security and privacy capabilities before expanding to other devices later this year. Most agentic AI projects in production have stalled over data problems Enterprises are connecting AI agents to live data feeds and putting them to work on tasks that once required human review, from IT operations to software development. The number doing this in production reached 32 percent in 2026, up from 29 percent the year before, according to Confluent’s annual Data Streaming Report, which surveyed 4,625 IT leaders across 14 countries. Homebrew tightens tap security, begins work on its interface Anyone who installs software through a third-party Homebrew tap runs Ruby code written by people outside the project, and that code runs without a sandbox. That risk sits at the center of Homebrew 6.0.0. It now requires a tap, along with any tap-qualified formula or cask, to be trusted before its code is evaluated or run. Google’s open standard for AI agents to discover and verify tools AI agents rely on tools, services, and other agents distributed across different teams, organizations, and platforms. Because these resources are often isolated in separate systems, agents have limited ability to discover and connect to capabilities outside their own environment. Google aims to solve this with Agentic Resource Discovery, an open specification for publishing, discovering, and verifying AI capabilities across the web, regardless of framework, protocol, or provider. GentleKiller targets more than 400 security processes across 48 products Most ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) products, then provide these tools directly to the affiliates who rent the gang’s encryptors. Asia-Pacific scam networks generate nearly $40 billion a year Cybercrime is taking a larger share of criminal activity in Asia and the Pacific. More than half of surveyed jurisdictions reported that cybercrime accounts for over 30% of all crimes recorded nationally, according to INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report. Companies are discarding the logs they need to catch a breach Many large enterprises discard most of the log data their systems generate, and they do it on purpose to keep costs down. A Dynatrace survey of 450 senior IT leaders at large enterprises found that half of organizations drop or never collect an average of 86 percent of their logs, even after filtering and aggregation. Many also limit how long they retain the logs they do keep. The rise of machine identities and agentic AI: Securing trust in the next era of digital autonomy For years, identity security has been centered on humans, ensuring that the right person has the right level of access to the right resources. But now, the same principle applies to non-human entities: machines, APIs, bots, and increasingly, AI agents. These new “digital actors” authenticate, access sensitive information, execute workflows, and even make decisions, often faster and at greater scale than any human ever could. How security teams are getting credential visibility into developer endpoints Attackers increasingly target developer machines to steal credentials. Recent supply chain attacks, including Megalodon, TrapDoor, and Miasma, focused on compromising developer environments where secrets often reside in shell histories, .env files, cloud CLI configs, local caches, and AI agent directories. To address this risk, GitGuardian has introduced Developer Endpoint Protection in ggshield, enabling organizations to discover credentials on developer workstations. Google sets timeline for Android developer verification enforcement Android’s developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadline. Mastodon 4.6 adds profile Collections and two-factor controls People who run accounts on the open source social network Mastodon can now group profiles together and share those groups across the web. The 4.6 release centers on a feature called Collections, along with reworked profiles, email newsletters, server administration controls, and a set of accessibility changes. Forget traffic lights, Google’s reCAPTCHA may ask for hand gestures Google has introduced hand gesture verification for reCAPTCHA, a new method for verifying that a user is human. Google’s reCAPTCHA is part of Google Cloud Fraud Defense, a fraud and abuse prevention platform for bot, account, and transaction protection. It uses risk analysis and challenge-based verification to help organizations identify automated activity and suspicious behavior. Cybersecurity jobs available right now: June 16, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 19, 2026 Here’s a look at the most interesting products from the past week, featuring releases from ArmorCode, Barracuda Networks, Blue Planet, Flip, Fortinet, Legit Security, Tigera, and WitnessAI.
helpnetsecurity.comJun 21, 2026extracted
New infosec products of the week: June 19, 2026
New infosec products of the week: June 19, 2026 Here’s a look at the most interesting products from the past week, featuring releases from ArmorCode, Barracuda Networks, Blue Planet, Flip, Fortinet, Legit Security, Tigera, and WitnessAI. Fortinet FortiSOC unifies SIEM, SOAR, threat intelligence, and AI in one platform Fortinet has announced the availability of FortiSOC, a unified, cloud-delivered security operations center (SOC) platform. FortiSOC brings together six security operations functions into a single Software-as-a-Service (SaaS) experience and embeds agentic AI to autonomously investigate and correlate alerts across assets and identities, then recommend or execute response actions under analyst oversight. Legit Security brings agentic AI to AppSec remediation and risk reduction Legit Security has launched new remediation agents that independently prioritize issues, generate fixes, open pull requests, and confirm results using context learned from each organization’s distinct codebase. ArmorCode helps product manufacturers prepare for EU Cyber Resilience Act requirements ArmorCode has announced new Cyber Resilience Act (CRA) capabilities within the ArmorCode Agentic AI Platform. The capabilities help manufacturers of products with digital elements (PDEs) prepare for the European Union’s cybersecurity regulation that will impact all sellers of these solutions in the region. Flip expands platform with digital identity, no-code apps, and AI automation Flip has announced Frontline Identity and Flip Fusion, two new offerings that help organizations securely connect frontline employees to enterprise systems, applications and AI-powered workflows. Flip’s new products expand the platform beyond employee communications, helping organizations provide secure digital identity, enterprise application access and AI-powered workflow automation through a single mobile experience. Tigera introduces unified control plane for Kubernetes-based AI agent security Tigera has announced the general availability of Tigera Lynx, a unified control plane for Kubernetes-native AI agents. Lynx gives enterprises a single place to find every agent in their Kubernetes estate, tighten security posture, assign sandboxes, provide each agent with a cryptographic identity, enforce policy on every action it takes, audit agent activity, and detect anomalous behavior, all without changing a line of agent code. WitnessAI Agentic Control secures AI agents, tools, and MCP server access WitnessAI has announced extended agentic security capabilities that govern how AI agents interact with enterprise systems, tools, and Model Context Protocol (MCP) servers. With the launch of Agentic Control, enterprises have greater visibility and control over their AI agents with a single control plane to discover, monitor, govern, and restrict agent behaviors at runtime. Blue Planet helps service providers reduce risk with unified network change governance Blue Planet is closing the governance gap in network operations by unveiling Blue Planet Configuration and Change Management (CCM), unifying device configuration, change, and lifecycle management across multi-vendor networks. Backed by Blue Planet’s deep Operations Support System (OSS) expertise, CCM replaces fragmented tools and manual processes with AI-driven workflows to reduce risk, prevent outages, and strengthen the foundation for autonomous networking. Barracuda introduces AI-powered email security with automated threat response Barracuda Networks has unveiled Barracuda Integrated Email Protection, an Integrated Cloud Email Security (ICES) solution delivering protection against evolving AI-driven threats. Powered by AI, the solution continuously and autonomously detects and remediates threats across the attack lifecycle, explains Microsoft 365 and Google Workspace verdicts and enables rapid post-delivery message clawback.
helpnetsecurity.comJun 19, 2026extracted
Barracuda introduces AI-powered email security with automated threat response
Barracuda introduces AI-powered email security with automated threat response Barracuda Networks has unveiled Barracuda Integrated Email Protection, an Integrated Cloud Email Security (ICES) solution delivering protection against evolving AI-driven threats. Powered by AI, the solution continuously and autonomously detects and remediates threats across the attack lifecycle, explains Microsoft 365 and Google Workspace verdicts and enables rapid post-delivery message clawback. Built on BarracudaONE platform telemetry across domains, including email, identity, network, data, and applications, and designed for single and multitenant environments, it also enables MSPs to quickly identify, investigate and eliminate risk, simplifying operations, strengthening resilience and accelerating growth. “Email is no longer a human-centric communication platform; it’s an operational fabric where humans and AI interact, making it a much bigger target and amplifying the speed, scale and impact of attacks when threats go undetected,” said Rohit Ghai, Chief Executive Officer at Barracuda. “In the agentic AI era, effective security requires a platform approach that delivers continuous visibility and response across the full attack lifecycle. Barracuda Integrated Email Protection is fundamentally different because it correlates cross-domain signals in real time and turns them into automated, explainable action partners and customers can trust and control. The result is measurable, high-efficacy protection that stops threats as they evolve and makes cyber resilience dramatically easier.” Barracuda research exposes the speed and scale of email attacks New findings released by Barracuda Research highlight how quickly email attacks escalate. A single phishing email progressed to identity theft, multifactor authentication (MFA) bypass and endpoint compromise in minutes, demonstrating the speed at which attacks move beyond the inbox. These results come from the Barracuda Red Team’s end-to-end recreation of a multistage AI-powered attack. One in seven compromised accounts is now used to launch additional attacks, a figure expected to rise with AI-driven threat automation, fueling lateral movement and expanding risk across identities, systems and data. As threats evolve after delivery and at machine speed, organizations face increasing pressure to understand risk, detect threats and respond in real time. AI-powered security for evolving threats As email evolves into a high-value data and orchestration layer in the agentic AI era, point-in-time security approaches can no longer keep pace. Barracuda Integrated Email Protection meets this shift with continuous, autonomous attack lifecycle protection that leverages cross-domain signals to detect, reevaluate and eliminate threats as they evolve, stopping attacks that emerge or activate long after message delivery. As part of the BarracudaONE platform, the solution also integrates natively with Barracuda Managed XDR and data protection offerings, providing unified visibility, coordinated response and 360-degree resilience across the broader attack surface. Barracuda’s Bailey AI assistant enhances this approach by providing explanations for every decision and enabling teams to review or reverse actions. This gives teams the visibility and control to manage every automated action, differentiating Barracuda from opaque, black-box ICES solutions. Barracuda pairs autonomous remediation agents with rich, cross-domain telemetry, including threat intelligence, URL activity and BarracudaONE signals, giving agents the context needed to detect and respond to sophisticated, multistage attacks. These advanced AI agents deliver breakthrough capabilities that secure evolving email workflows and provide continuous protection against fast-moving, AI-driven threats. New capabilities include: Agentic threat investigation and response: AI agents triage threat activity, correlate signals across environments and execute real-time clawback with tenant-wide remediation as threats evolve, eliminating hours of manual cleanup. Agentic AI explainability: Bailey unifies Microsoft 365, Google Workspace and Barracuda verdicts in one conversational interface and clearly explains how decisions differ across vendors. Unified quarantine: Consolidates Microsoft-quarantined emails into Barracuda for faster, safer decisions with automatic rescanning before release. Integrated value reporting: Quantifies threats stopped before, during and after delivery, demonstrating measurable protection effectiveness. Powered by the Barracuda IQ engine and enriched by one of the largest threat intelligence datasets in the industry, spanning hundreds of threat feeds, Barracuda delivers high-efficacy detection by continuously learning from real-world data across hundreds of thousands of customer environments. As part of this intelligence, Barracuda analyzes approximately 1.5 billion URLs each day, proactively identifying threats before users click and strengthening detection accuracy over time. Barracuda Integrated Email Protection strengthens Microsoft 365 and Google Workspace with attack lifecycle protection. It deploys in minutes via an API-based architecture with no Mail Exchange (MX) record changes, mail-flow disruption or manual configuration, delivering immediate protection with minimal operational overhead.
helpnetsecurity.comJun 18, 2026extracted
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now - meanwhile some researcher casually drops a technique that turns a "minor" foothold into total account compromise because apparently six digits and blind trust were all that stood between your vault and getting absolutely pwned. Cool. Great. Love that for us. Then there's the supply chain mess... signed binaries, poisoned updates, legit tooling getting hijacked like it's still 2017, plus a few reports this week that feel less like advanced tradecraft and more like watching skiddies discover low-hanging fruit with enterprise branding slapped on top. The weird part isn't that it works. The weird part is how damn easy it still is. Anyway. Grab caffeine. Let's get into it. Massive regional C2 footprintHunt.io said it identified more than 1,350 command-and-control (C2) servers across 98 Middle East infrastructure providers over the past three months, between February 1 and May 1, 2026. "C2 infrastructure dominates malicious activity (~96.8%), far exceeding phishing infrastructure (~0.5%) and publicly reported IOCs (~0.5%), while malicious open directories account for the remaining ~2.2% of observed artifacts," it said. "Saudi Arabia's STC (Saudi Telecom Company) hosts 981 C2 servers, representing 72.4% of all detected C2 infrastructure in the region. IoT-focused botnets (Hajime, Mozi, and Mirai) combined with offensive frameworks (Tactical RMM, Cobalt Strike, Sliver) represent the dominant malware families operating across Middle Eastern infrastructure." AKS privilege escalation flawMicrosoft is said to have silently fixed a privilege escalation flaw in Azure Backup for AKS that allowed a user with only the "Backup Contributor" Azure role (zero Kubernetes permissions) to gain cluster-admin on any AKS cluster, per security researcher Justin O'Leary. The vulnerability, which does not have a CVE, carries a CVSS score of 9.9. While Microsoft rejected the vulnerability report as "AI-generated content," it appears to have been patched since, and additional validation checks were enforced that did not exist in March 2026. Cybercrime operator jailedA 46-year-old Romanian national found guilty of breaking into an Oregon state government office in 2021 and other cyber attacks across the U.S. has been sentenced to 56 months in prison. Catalin Dragomir pleaded guilty to one count of aggravated identity theft and one count of obtaining information from a protected computer in February. Dragomir was arrested in Romania in November 2024 and extradited to the U.S. in January 2025 to face charges. Dragomir "sold access to a computer on the network of an Oregon state government office after obtaining unauthorized access to it in June of 2021," the Justice Department said. "During the sale, Dragomir provided the prospective buyer with samples of personal identifying information from the computer. He also sold access to the computer networks of numerous other victims in the United States, causing losses of at least $250,000." DAEMON Tools added to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the supply chain attack targeting DAEMON Tools software to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply necessary fixes by May 30, 2026. The incident is now being tracked under the identifier CVE-2026-8398 (CVSS v4 score: 9.3). "Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe," according to the description of the CVE. "These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection." Apple unveils PQC codeApple has published its post-quantum cryptography (PQC) implementations in corecrypto, including quantum-secure ML-KEM and ML-DSA algorithms, along with mathematical verification tools that it built to assure compliance with FIPS 203 and FIPS 204 specifications for independent evaluation by experts. "Corecrypto is used continuously in our products, providing encryption and decryption, hashing, random number generation, and digital signatures on over 2.5 billion active devices," Apple said. "A critical bug in corecrypto has the potential to compromise the security and reliability of every app and feature that depends on it, so we are conservative when adding new code to the library and make exceptional efforts to be comprehensive in our testing." Law firms targeted by SRGThe U.S. Federal Bureau of Investigation (FBI) has warned that the threat actor known as the Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, has been targeting law firms using social engineering techniques as part of fresh attacks since spring 2026. Law firms are a rich target due to the highly sensitive nature of the data they possess. "Through phone calls and phishing emails, SRG actors pose as IT support to establish access to victim computers and exfiltrate data, usually through legitimate remote access tools or by sending an individual in-person to the victim company's location to gain physical access to computers," the FBI said. "While SRG has victimized companies in many sectors, including those in the insurance, finance, and healthcare industries, the group has consistently targeted U.S.-based law firms since Spring 2023." As part of the scheme involving in-person visits, the threat actor tells the victim they need to image the device or create a backup file to address potential impacts from the phishing email. Upon gaining a foothold, the attackers move swiftly to escalate privileges and pivot to data exfiltration without encryption. "By sending someone in-person to the victim's location to facilitate the intrusion, SRG actors exfiltrate data to an external hard drive or USB drive inserted by the threat actor into the victim's computer," the FBI added. Fake installers spread Deno RATAttackers are hosting counterfeit installers and plugins masquerading as popular software, including ChatGPT, Claude, ZENOLOGY, Ableton Live, AutoTune, and Kontakt, on GitHub and SourceForge to distribute a Deno backdoor known as DinDoor (aka Tsundere). "Attackers are using compromised YouTube channels to distribute links to these platforms," Malwarebytes said. "DinDoor ultimately drops different types of malware, including a stealthy remote access Trojan (RAT), which also uses the Deno JavaScript runtime." PureLogs phishing waveA phishing campaign is using deceptive emails disguised as purchase orders to trick recipients into opening malicious JavaScript files contained within RAR archives that lead to the deployment of a PureLogs variant to steal sensitive data from the victim's device. "Upon analyzing the PureLogs module, the malware's primary capability is to collect sensitive data from the victim's system, including basic hardware and system information, saved credentials, cryptocurrency-related data, and more," Fortinet said. "The malware then compresses and encrypts the collected data before transmitting it to the C2 server." U.K. targets crypto sanctions evasionThe U.K. has announced sanctions against cryptocurrency exchanges and the A7 network used by Russia to evade existing restrictions. Among those hit by sanctions is HTX (aka Huobi Global), which is one of the largest cryptoasset exchanges in the world, with $3.3 trillion in trading volume in 2025. "It is suspected of providing services to A7, the sanctioned Russian payments network, and Garantex, the sanctioned cryptocurrency exchange," Elliptic said. It's worth noting that the A7 corporate-and-token infrastructure emerged in the wake of the March 2025 Garantex takedown. Per data from TRM Labs, Huobi has sent more than $4.9 billion in direct on-chain transactions to U.K.-sanctioned and A7-network entities since 2021. Other entities hit by sanctions include Bitpapa and Rapira Group, the latter of which has transacted $375.6 million with Garantex's named successor Grinex.io. Claude gains built-in code reviewAnthropic has announced two new security features for its Claude AI: a self-hosted sandbox for Claude Managed Agents and a new security-guidance plugin. "The security guidance plugin makes Claude review its own code changes for common vulnerabilities while it works and fixes what it finds in the same session," Anthropic said. "The plugin catches issues such as injection, unsafe deserialization, and unsafe DOM APIs before the code reaches a pull request, reducing how much security review falls to human reviewers downstream. Once installed, the plugin runs automatically. There is nothing to invoke and no separate command to remember." As described by Red Hat, a self-hosted sandbox "outsources the 'thinking' while keeping the 'doing' on your own infrastructure." DACH cyberattacks jump 124%Data from Check Point has revealed that hacktivism and ransomware targeting organizations across Germany, Austria, and Switzerland increased 124% in 2025. More than 60% of the hacktivist incidents have involved defacing websites to amplify political messaging. These efforts originated from NoName057(16), Mr Hamza, chinafans, Dark Storm Team, and Hezi Rash. Ransomware attacks, on the other hand, were mainly led by Akira, Qilin, and Safepay. "Germany accounted for more than 80% of regional incidents, with Switzerland at 12% and Austria at 8%," Check Point said. "Across Europe, the DACH region represented 18% of all recorded attacks, placing Germany above France, Spain, and Italy by individual country share." World Cup scams explode onlineThreat actors are increasingly capitalizing on the public excitement around the FIFA World Cup 2026 for scam campaigns. Bitdefender said it has identified more than 55 football-related malvertising campaigns targeting users through fake online stores, social media ads, IPTV piracy operations, fraudulent football apps, and FIFA-themed giveaway and lottery scams distributed through email. "The most-targeted users were in the United Kingdom, Portugal, Spain, Algeria, the United States, Canada, Mexico, Belgium, Germany, Brazil, and Australia," the Romanian company said. Check Point said bad actors are "flooding the internet" with fake merchandise stores, fraudulent betting platforms, and phishing domains designed to steal personal data and money. Host nations of the sporting event, Canada, Mexico, and the U.S., have also recorded an increase in the weekly average number of cyber-attacks per organization in April 2026, with Mexico registering a weekly average of 3,548 cyber attacks per organization. Group-IB said it uncovered six distinct fraud schemes and over 4,300 fraudulent domains impersonating FIFA's official web presence. This includes a sophisticated phishing campaign conducted by a Chinese-speaking, financially motivated operator called GHOST STADIUM that involves using more than 300 domains using a shared phishing kit that exploits FIFA's PingIdentity SSO login flow to harvest credentials and conduct fake ticket sales and payment fraud at scale. "GHOST STADIUM has built a pixel-perfect clone of the official FIFA website, complete with a replicated single sign-on (SSO) authentication flow, and multi-language support in 11 languages," Group-IB said. "Facebook Ads serves as the primary paid traffic acquisition channel for the GHOST STADIUM campaign." Chrome extensions harvest WhatsApp dataCybersecurity researchers have uncovered a 126-extension Chrome Web Store extension network dubbed WaSteal that masquerades as independent WhatsApp CRM tools while exfiltrating user personal data, advertising cookies, and voice messages to operator-controlled servers, affecting nearly 148,000 users. According to researcher Jean-Marie R., the network is operated by wascript.com.br, which operates a white-label platform. "The largest variant (WaSeller, 100k installs) embeds a live GTM container giving its operator silent, permanent remote code execution with no extension update or Chrome review required," the researcher said. "The operator's own privacy policy directly contradicts every behavior documented." GhostTree breaks endpoint scanningA new technique named GhostTree abuses NTFS junctions to generate infinite file paths, causing endpoint security products to hang and leave files unscanned. "We discovered that by pointing a junction back at its own parent directory, an attacker can create recursive loops that generate effectively infinite file paths," Varonis said. "With just two lines of code, a user can generate endless valid paths, making it impossible to finish scanning parent directories with the dir command recursively. The same applies to EDR products that scan folders for malicious files. An attacker places malware in the parent directory, sets up the GhostTree structure, and the containing folder becomes effectively unscannable. The scan hangs. The malicious files go unexamined." Kali365 targets Microsoft 365An emerging Phishing-as-a-Service (PhaaS) platform called Kali365, first observed in April 2026, has been targeting Microsoft 365 environments. "Kali365 has primarily been distributed via Telegram, enabling cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without intercepting the user's credentials," the FBI said. "Through the Kali365 platform subscription, cyber threat actors can capture 'OAuth' tokens and gain persistent access to targeted individuals/entities' Microsoft 365 environments." Like other PhaaS platforms, Kali365 risks lowering the barrier of entry to cybercrime, offering less-technical attackers access to artificial intelligence (AI)-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities. Kali365 is available to affiliates on a subscription basis, ranging from $250 for 30 days to $2,000 for a year. In a report published last month, Arctic Wolf said it observed a device code phishing campaign using Kali365 to obtain initial access and conduct follow-on activity. "The campaign relied on high-fidelity lures directing victims to Microsoft's legitimate device login flow, where users unknowingly authorized threat actor-initiated sessions," the company said. "Captured OAuth access and refresh tokens enabled immediate mailbox access and post-compromise activity. In select cases, threat actors established malicious inbox rules to suppress security notifications, extending dwell time and reducing user awareness." Barracuda Networks and Proofpoint have also warned of a spike in device code phishing campaigns in recent months. Barracuda said it detected more than 7 million device code attacks between March and April 2026. "The surge of device code phishing is the natural progression of credential phishing, as more people become aware of multi-factor authentication bypass techniques, criminals must get creative," Proofpoint noted. Vaultjacking targets Google passwordsPhishU has detailed a new technique called Vaultjacking, which demonstrates how a victim's 6-digit Google Password Manager (GPM) PIN captured via an adversary-in-the-middle (AitM) phishing page can be used to decrypt the entire synced GPM vault. "That single PIN releases Google's Security Domain Secret, which decrypts every synced password and passkey on the account -- not just the credential being registered, the entire vault," Curtis Brazzell, PhishU Flounder and CEO, said in a statement. Once the AitM page harvests the user's session cookies and GPM PIN, a threat actor can add a passkey to the victim's Google account for persistence and then unlock the victim's entire synced credential vault from their own infrastructure. Signed RVTools trojan spreads RATA trojanized MSI installer for RVTools is being used to deploy a modular Python-based remote access trojan (RAT) using a VBScript loader. The malware includes a reconnaissance module that fingerprints the host and maps out Active Directory and a persistent command-and-control (C2) agent that encrypts stolen data and waits for operator commands. "What made this campaign particularly effective was the use of a legitimately issued Sectigo code-signing certificate, registered under what appears to be a shell entity - Xiamen Lunwei Huage Network Co.(Sectigo), Ltd," K7 Labs said. "At the time of delivery, the certificate was fully valid, meaning Windows SmartScreen and most endpoint controls raised no flags. It has since been revoked, though it offers limited protection to environments not enforcing real-time OCSP or CRL checks at execution time." None of this was especially sophisticated. That's the lesson nobody wants to hear. Most breaches still start with trust abuse, stale configs, lazy access controls, or users getting socially engineered by someone sounding vaguely competent over the phone. Patch faster. Audit harder. Stop assuming signed software, MFA prompts, or "internal-only" tooling means safe. The attackers already figured out the shortcuts. Might be time defenders stop pretending those shortcuts don't exist.
thehackernews.comMay 28, 2026extracted
CypherLoc, la nuova truffa dello schermo bloccato: cos’è e come difendersi
È stata ribattezzata CypherLoc ed è la nuova truffa dello schermo bloccato che combina tecniche di intrusione avanzate e una buona capacità di manipolazione psicologica per indurre le vittime a contattare servizi di assistenza tecnica fraudolenti. Si tratta, a tutti gli effetti, di uno scareware, una tipologia di attacco informatico che inganna gli utenti convincendoli che i loro dispositivi siano infetti, spingendoli a scaricare antivirus fasulli, pagare per proteggere i propri dati personali o, come in questo caso, chiamare servizi che si rivelano tutt’altro che funzionali alla sicurezza. “CypherLoc è un caso esemplare di come lo scareware, una tecnica considerata a questo punto “datata”, continui a essere straordinariamente efficace quando viene supportata da un’ingegneria sofisticata, come in questo caso”, commenta Sofia Scozzari, CEO & Founder Hackmanac. “Quello che colpisce di questo kit”, continua l’esperta, “è il livello di complessità tecnica (loader crittografati, esecuzione condizionale basata su hash, sostituzione dinamica della pagina a runtime, evasione attiva di sandbox e scanner) che denota un framework strutturato, non un attacco artigianale, e un gruppo organizzato, con risorse significative. È evidente che la stessa infrastruttura tecnica potrebbe essere facilmente riadattata per campagne più mirate e con implicazioni ben più pericolose. Quello che mi preoccupa maggiormente, però, sono le ripercussioni in ambito aziendale. Con 2,8 milioni di attacchi in soli cinque mesi la probabilità che tra le vittime ci siano anche dipendenti che hanno interagito con questa minaccia da dispositivi aziendali o connessi a reti corporate è concreta. In quello scenario, le conseguenze cambiano scala favorendo furto di credenziali aziendali, compromissione di ambienti e, soprattutto, esposizione ad attacchi futuri a partire dalle informazioni sottratte”. Indice degli argomenti CypherLoc: come funziona l’attacco Secondo quanto riportato dai ricercatori di Barracuda Research, CypherLoc è una truffa subdola e mirata che segue una pianificazione di attacco ben precisa. Tutto comincia con un’e-mail di phishing che, attraverso un link contenuto nel testo o in un file allegato, spinge le vittime verso una pagina web malevola: apparentemente innocua, questa contiene un codice dannoso che si attiva solo al verificarsi di determinate condizioni, quando la “pagina supera una serie di controlli di integrità crittografica”, bypassa i sistemi di sicurezza o elude gli ambienti di analisi. In questo caso, come segnalano i ricercatori, si avvia una modalità “a schermo intero che blocca il browser, visualizza messaggi di sicurezza allarmanti e invita l’utente a contattare immediatamente l’assistenza”, segnalandogli un chiaro problema di sistema. Una volta avviato l’attacco, infatti, le vittime si ritrovano a non poter interagire in alcun modo con il browser e a essere bombardate da una serie di input che non fanno altro che alimentare la loro preoccupazione. Tra questi, nello specifico, i ricercatori includono suoni di avviso che vengono riprodotti ogni volta che gli utenti tentano di cliccare sulla pagina e moduli di accesso progettati per costringerli a rimanere il più a lungo possibile sulla pagina bloccata, al fine di alimentare il senso di panico. A questo punto, alle vittime non resta altro da fare che aggrapparsi all’unica soluzione offerta dal browser: un servizio di assistenza, il cui numero di telefono viene visualizzato in maniera chiara sullo schermo. Chiamando, gli utenti si mettono in contatto con operatori in carne e ossa, che si fingono personale di supporto Microsoft. In realtà, come sottolineano i ricercatori di Barracuda Research, la chiamata permette ai malintenzionati di prendere il controllo del dispositivo delle vittime, accedendo in maniera indisturbata a dati e informazioni di ogni genere. Una truffa ben orchestrata, che ha permesso ai criminali di mettere a segno oltre 2 milioni di attacchi fino a ora. Una cifra decisamente preoccupante per gli esperti di sicurezza informatica. “CypherLoc dimostra quanto le frodi online stiano diventando sempre più sofisticate e psicologiche”, commenta Pierluigi Paganini, esperto di cyber security. “Non serve installare un malware quando basta bloccare il browser, mostrare falsi avvisi e spingere la vittima a chiamare un finto supporto tecnico. Il dato più allarmante è la diffusione: secondo Barracuda, da inizio 2026 sono già stati osservati circa 2.8 milioni di attacchi, un dato impressionante che ci dà una dimensione del fenomeno. Queste campagne funzionano perché sfruttano paura e urgenza, confermando che le tecniche di ingegneria sociale restano una delle minacce più efficaci e difficili da fermare”. Come difendersi “Il fattore umano resta l’anello debole di qualsiasi architettura di sicurezza e gli attaccanti ne sono consapevoli”, sottolinea ancora Sofia Scozzari. “Per questo motivo, le strategie di difesa non possono limitarsi a soluzioni tecniche, ma è necessario mitigare il fattore umano integrando programmi di formazione continua con simulazioni realistiche di scenari di attacco, incluso lo scareware, troppo spesso sottovalutato nei piani di awareness. Allo stesso tempo, è fondamentale che le policy aziendali siano adeguate e che prevedano procedure chiare su come reagire in caso di situazioni di emergenza tecnica (sia reale che apparente)”. Considerata la minaccia, dunque, cosa possono fare utenti e aziende per difendersi ed evitare di cadere nell’ennesima trappola dei criminali informatici? “I team di sicurezza dovrebbero assicurarsi di disporre di solide protezioni anti-phishing, per i browser e per gli endpoint, in grado di rilevare e bloccare qualsiasi comportamento sospetto degli script. La formazione degli utenti è altrettanto importante, poiché gli avvisi di sicurezza legittimi non mostrano numeri di telefono, non bloccano i browser né richiedono un intervento immediato tramite finestre pop-up”, riferiscono gli esperti di Barracuda Research. E, considerando il livello sempre più avanzato degli attacchi informatici, gli stessi ricercatori invitano le aziende a pensare di mettere in campo “strumenti di controllo che proteggano gli utenti, non solo i dispositivi”.
cybersecurity360.itMay 27, 2026extracted
Microsoft 365 users targeted by new phishing threat that bypasses MFA
Microsoft 365 users targeted by new phishing threat that bypasses MFA Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning. First observed in April 2026, Kali365 has been distributed through Telegram, allowing cybercriminals to obtain Microsoft 365 access tokens and bypass MFA without stealing user credentials. “Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,” the FBI said. This type of attack is known as device code phishing, where attackers trick users into logging into their accounts through a legitimate authentication flow and then steal their access and refresh tokens. How the attack works The attack starts with a phishing email that impersonates trusted cloud or document-sharing services and includes a device code with instructions to visit a legitimate Microsoft verification page. After the victim enters the code, they unknowingly authorize the attacker’s device. The attacker then captures OAuth access and refresh tokens, allowing continued access to Microsoft 365 services such as Outlook, Teams, and OneDrive without requiring a password or additional MFA prompts. In its announcement, the FBI outlined several tips users and organizations can follow to protect themselves from device code phishing attacks. Telegram-based phishing services Researchers recently identified EvilTokens, another PhaaS platform sold through Telegram. The service gives less-experienced attackers ready-made tools for phishing campaigns, including fake login pages, Microsoft API automation, and AI-generated emails. It also comes with templates built around common business notifications, such as SharePoint access requests, password expiration messages, and shared document alerts. According to Barracuda Networks, the most common phishing themes in 2025 pushed users toward clicking links, scanning QR codes, opening attachments, or handing over personal information.
helpnetsecurity.comMay 22, 2026extracted
Researchers Warn CypherLoc Scareware Has Targeted Millions of Users
Security researchers have sounded the alarm over new scareware designed to lock users’ browsers and drive them to fraudulent tech support teams. Since the start of 2026, Barracuda researchers said they have observed around 2.8 million attacks which used the scareware dubbed CypherLoc. According to the cybersecurity firm, the CypherLoc campaign usually begins with a phishing email that directs the victim to a malicious web page through a link embedded in the email or in an attachment. A harmless malicious web page is loaded, only triggering the full scareware environment if several conditions are met. “The code only decrypts when the page is opened under the right conditions: when the required URL fragment hash is present and the page passes a series of cryptographic integrity checks,” Barracuda explained in an article. “If the hidden fragment is missing or the page is being opened in a scanner, sandbox or test environment, the malicious payload refuses to run, and the page redirects to a blank screen. This hides the attack from security tools.” What follows is a series of actions designed to discomfort the user: The browser switches to full-screen mode, disabling context menus, hiding the cursor, and flooding the screen with overlays Any attempt to regain control triggers a “relock” A fake security page plays warning sounds whenever the user clicks This extra activity might slow the browser or cause it to crash CypherLoc retrieves and displays the user’s IP address A login popup is show to the user which escalates the sense of panic when it doesn’t work “A fraudulent support phone number is prominently displayed on the screen throughout the attack and presented as the only way to fix the problem,” Barracuda continued. “When victims call the number, human operators posing as Microsoft support staff take over and continue the scam via a live conversation.” It’s not immediately clear what the end goal is, although credential theft is one option. How to Tackle Scareware “CypherLoc shows how modern scareware is shifting away from obvious malware and towards browser-based, user-driven scams that are difficult to detect and highly effective,” said Saravanan Mohankumar, manager, threat analysis team at Barracuda. “It uses the browser itself to pressure victims into acting. By combining hidden code, delayed activation and aggressive on-screen behaviour, it creates a convincing illusion of a serious system problem while leaving very little technical trace.” Barracuda recommended that corporate security teams put in place anti-phishing, browser and endpoint protections to detect and block suspicious script behavior. And to ensure users are educated about such threats.
infosecurity-magazine.comMay 20, 2026extracted
Perché anche la leadership IT espone le aziende al phishing. E non solo
Nonostante investimenti crescenti in cyber security, il fattore umano resta una delle principali cause di violazioni. Errori di phishing, comportamenti rischiosi e uso improprio dell’intelligenza artificiale continuano a esporre dati e organizzazioni. A confermarlo è il report “Human Risk Behavior 2025” di Arctic Wolf, basato su oltre 1.700 leader IT ed end‑user, che mette in luce una profonda disconnessione tra percezione del rischio e comportamenti reali. Indice degli argomenti Perché il rischio umano è oggi il vero punto debole della cyber security Il report “Human Risk Behavior 2025” di Arctic Wolf evidenzia una marcata disconnessione tra percezione e realtà del rischio: nonostante l’aumento degli incidenti informatici e la crescente esposizione dei dirigenti senior agli attacchi cyber, i leader IT continuano a mostrare una fiducia eccessiva nelle difese di sicurezza delle proprie organizzazioni. Il fattore umano si conferma uno dei principali vettori di compromissione. Gli attori malevoli sfruttano soprattutto: compromissione delle credenziali, ingegneria sociale, minacce interne, scarsa igiene informatica, trasformando comportamenti quotidiani in punti di accesso critici per gli attacchi. Particolarmente esposti risultano dirigenti e leader senior, in virtù dei privilegi elevati e dell’accesso a dati sensibili. I dati percentuali mostrano che: il 39% dei leader è stato colpito da attacchi di phishing, il 35% ha subito infezioni malware, il 31% è stato bersaglio di attacchi di social engineering, nel 69% degli incidenti informatici, la vittima iniziale è stata proprio un membro del team di leadership. Il phishing si conferma così una delle minacce più persistenti e redditizie, favorita dalla propensione – anche tra leader IT e utenti esperti – a cliccare su link malevoli e a sottovalutare i rischi associati ai propri comportamenti digitali. Fonte immagine: Arctic Wolf® Report – “Human Risk Behavior 2025” . Anche gli esperti sbagliano: perché il personale IT cade nelle trappole di phishing Il phishing continua a essere una delle minacce più efficaci, anche tra utenti esperti. Il 65% dei leader IT ammette di aver cliccato su link di phishing e quasi il 17% non ha segnalato l’incidente, spesso per timore di ripercussioni. Eppure, il 76% dei leader IT ritiene che la propria organizzazione non subirà attacchi di phishing, evidenziando una pericolosa distanza tra comportamenti reali e percezione del rischio. Una fiducia eccessiva che indebolisce la cultura della sicurezza e aumenta l’esposizione complessiva. Fonte immagine: Arctic Wolf® Report – “Human Risk Behavior 2025”. Spear phishing e intelligenza artificiale: attacchi sempre più mirati ai dirigenti A rendere il quadro ancora più complesso contribuisce la crescente diffusione del spear phishing, una tecnica mirata che sfrutta informazioni dettagliate sugli obiettivi di alto valore, come i dirigenti e i responsabili IT, per costruire messaggi estremamente credibili. Questo tipo di attacco sta diventando sempre più comune anche grazie alle capacità di ricerca, analisi e personalizzazione offerte dall’intelligenza artificiale, che riducono drasticamente la soglia di errore nella fase di ingegneria sociale. Già nel 2023, il report “Spear Phishing Trends” di Barracuda Networks aveva lanciato un segnale d’allarme significativo: pur rappresentando meno dello 0,1% del totale delle email analizzate, lo spear phishing è stato responsabile del 66% delle violazioni informatiche andate a buon fine, confermandosi come una delle tecniche più efficaci – e pericolose – nel panorama delle minacce cyber. Eccessiva fiducia e rischio phishing: i dati chiave Le simulazioni di phishing sono ampiamente diffuse (91% dei leader IT), ma percepite in modo ambivalente: il 49% degli utenti le considera solo in parte efficaci. I dati mostrano però un miglioramento concreto: oggi solo circa la metà degli utenti cade vittima di attacchi reali. Le simulazioni funzionano soprattutto quando integrate in una strategia più ampia e utilizzate come strumenti educativi, non punitivi. Inoltre, la ripetizione costante rafforza la consapevolezza e promuove una cultura della sicurezza condivisa, basata su formazione continua e su un approccio educativo, non punitivo, che allena nel tempo la cyber resilienza. Il report evidenzia, altresì, tra il 63% degli utenti finali che utilizzano per lavoro tecnologie LLM – come ChatGPT – il 41% ammette di aver condiviso informazioni riservate su questi strumenti. Ancora più impressionante è il dato relativo ai leader IT: l’80% li utilizza e il 60% ha condiviso materiale confidenziale. Policy sull’uso dell’IA: il rischio non è l’assenza di regole, ma la mancata comunicazione L’adozione dell’IA e dei modelli LLM sta accelerando anche i rischi. L’88% dei leader IT ha introdotto policy sull’uso dell’IA (dal 60% nel 2024), ma il 43% degli utenti non sa se tali regole esistano. Le principali preoccupazioni riguardano l’eccessiva dipendenza dall’IA (58%) e la possibile divulgazione di informazioni sensibili (56%), confermando che governance e formazione non procedono allo stesso ritmo dell’innovazione. Fonte immagine: Arctic Wolf® Report – “Human Risk Behavior 2025”. Educare o punire? Perché il secondo approccio peggiora la sicurezza Dal report di Arctic Wolf emerge che il 77% dei leader IT (in aumento rispetto al 66% del 2024) dichiara di aver licenziato o di poter licenziare un dipendente vittima di attacchi di ingegneria sociale, come il phishing. Tuttavia, l’approccio punitivo non riduce il rischio umano: al contrario, formazione e sensibilizzazione si confermano le leve più efficaci per rafforzare la sicurezza. Fonte immagine: Arctic Wolf® Report – “Human Risk Behavior 2025”. In alternativa alle sanzioni, il 62% dei leader IT ha modificato o limitato gli accessi dei dipendenti coinvolti in incidenti; tra chi ha adottato queste misure correttive, l’88% ne riconosce l’efficacia. Tale approccio favorisce una cultura della sicurezza priva di paura, incentivando la segnalazione tempestiva degli incidenti e riducendo il rischio complessivo. Nonostante ciò, solo il 31% delle organizzazioni considera la promozione della consapevolezza della sicurezza un obiettivo prioritario della cybersecurity, un dato critico alla luce della crescente incidenza del rischio umano. Disattivare i controlli di sicurezza: una pratica diffusa e sottovalutata Il report di Arctic Wolf evidenzia come la disattivazione dei controlli di sicurezza rappresenti un rischio critico. Nel 2025 il 51% del personale IT ha dichiarato di aver disabilitato misure di sicurezza, in aumento rispetto al 36% del 2024. Le principali cause sono rallentamenti operativi (25%), gestione di incidenti (23%), limitazioni operative (19%) e policy inefficaci (16%) o troppo restrittive (15%). Il fenomeno è particolarmente allarmante perché i cyber threat actor prendono di mira soprattutto account con privilegi elevati, spesso appartenenti a figure senior. Una cultura del “fai come dico, non come faccio” aumenta l’esposizione ad attacchi di social engineering e BEC. Crescono anche i tentativi di elusione da parte degli utenti finali: dal 12% nel 2024 al 32% nel 2025, con il 16% che riesce effettivamente a bypassare le misure di sicurezza. Per ridurre il rischio umano, il report raccomanda di evitare disattivazioni non necessarie, rafforzare le politiche di Identity & Access Management (IAM) e monitorare continuamente gli endpoint. Fonte immagini: Arctic Wolf® Report – “Human Risk Behavior 2025”. Formazione sulla cyber security: perché quella tradizionale non basta più La formazione continua emerge come una leva decisiva. Il 97% dei leader IT gestisce programmi di sensibilizzazione, ma quasi la metà ne critica l’efficacia, chiedendo contenuti più aggiornati, interessanti e coinvolgenti. Di fatto, un programma efficace deve prevedere formazione regolare e aggiornata, sessioni brevi e mirate (fino a 3 minuti), accesso semplice ai contenuti e materiali progettati per favorire memorizzazione e richiamo. Accanto alla formazione tradizionale, la riduzione del rischio umano si fonda su quattro pilastri culturali: guidare con l’esempio; comunicare policy chiare sull’uso degli LLM; costruire una cultura della sicurezza basata su buone pratiche e MFA; educare anziché punire, utilizzando le simulazioni di phishing come strumenti di apprendimento. La vera sfida della cyber security non è tecnologica, ma culturale L’evoluzione delle minacce e dei modelli di lavoro rende evidente un dato: la tecnologia, da sola, non basta. La vera sfida della cyber security è culturale e passa dalle persone. Costruire consapevolezza, autoefficacia e sicurezza psicologica non è un’opzione accessoria, ma una condizione necessaria. La capacità critica degli individui resta l’ultima e più importante linea di difesa. A tal proposito, Liuva Capezzali, Psicologa-psicoterapeuta, psico-oncologa, criminologa ed esperta in Intelligence e Analisi delle Informazioni afferma che “il senso di autoefficacia è un costrutto introdotto dalla teoria socio-cognitiva di Albert Bandura ad indicare la convinzione che una persona deve essere capace di organizzare ed eseguire le azioni necessarie per raggiungere un determinato obiettivo. Riguarda non le abilità in sé, ma la fiducia che persona possa utilizzarle nel modo corretto”. E ancora: “Tale fiducia, a sua volta, è sostenuta da esperienze pregresse di successo per compiti per i quali non si sono avuti training di apprendimento e le cui criticità sono state superate in virtù della perseveranza ai tentavi di risoluzione e di una buona tolleranza alla frustrazione. Come mostrato dagli studi di Bandura, l’autoefficacia percepita correla positivamente con l’efficacia stessa di una azione, potendo quasi assumere un valore predittivo sugli esiti attesi”. Capezzali evidenzia, altresì che “l’atteggiamento punitivo adottato dai leader nei confronti dei dipendenti vittime di attacchi di ingegneria sociale è, quindi, una barriera nella prevenzione degli errori imputabili al fattore umano, sia perché abbasserebbe la soglia di tolleranza alla frustrazione sia perché ridurrebbe le occasioni di perseverare nell’apprendimento delle soluzioni preventive e di sicurezza. D’altra parte, il coinvolgimento emotivo delle persone, come approccio strategico per una formazione efficiente ed efficace, può essere ottenuto solo quando alle persone sia data la possibilità di acquisire “sicurezza psicologica””. La sicurezza psicologica è un concetto coniato per la prima volta da Amy Edmondson, docente ad Harvard, come “la convinzione condivisa che il team sia sicuro per l’assunzione di rischi interpersonali. Descrive un clima di gruppo caratterizzato da fiducia interpersonale e rispetto reciproco, in cui le persone si sentono a proprio agio nell’essere se stesse” o “la convinzione che non si sarà puniti o umiliati per aver portato idee, posto domande, espresso preoccupazioni o raccontato di errori commessi”. “Anche in questo caso – sottolinea Livia Capezzali – approcci punitivi postumi ad un errore non favorirebbero nei dipendenti la percezione di quella sicurezza psicologica propedeutica all’espressione di sé, alla segnalazione di eventuali propri errori e quindi alla maturazione di competenza. Si delineerebbe un clima di non condivisione, non apprendimento e crescita con competenze che rimarrebbero solo nelle mani di chi già le possiede e una cultura della sicurezza poco collettiva”. Ne consegue che comprendere i meccanismi psicologici e investire in una cultura della sicurezza matura che contempli la sicurezza psicologica non è un’opzione accessoria, ma una condizione necessaria. Di fatto, la capacità critica degli individui resta l’ultima e più importante linea di difesa. Costruire una cyber security efficace significa partire dalle persone, non dimentichiamolo!
cybersecurity360.itMay 20, 2026extracted
Foxconn confirms cyberattack impacting North American factories
Foxconn confirms cyberattack impacting North American factories Taiwanese electronics manufacturer Foxconn said factories in North America are resuming their normal production cycles after a cyberattack affected several facilities. A spokesperson for the company confirmed the incident but declined to provide specifics on how many factories in North America were impacted. Foxconn has factories in Wisconsin, Ohio, Texas, Virginia, Indiana and several across Mexico. “The cybersecurity team immediately activated the response mechanism and implemented multiple operational measures to ensure the continuity of production and delivery. The affected factories are currently resuming normal production,” the spokesperson said. On Monday, the Nitrogen ransomware gang took credit for the attack, claiming to have stolen 8 terabytes of data and millions of files that include technical information from several prominent tech firms. An employee at one of Foxconn’s Wisconsin factories told DysruptionHub that they began dealing with Wi-Fi issues on Friday and were sent home due to the network outages. Computers were not working and employees had to use paper and pen for several different tasks. At the time, Foxconn confirmed to the news outlet that it was dealing with technical issues and had implemented emergency response mechanisms. Foxconn reported $258.3 billion in revenue in 2025 and is considered the world's largest contract manufacturer of electronics — making products for companies like Apple, Google, Microsoft, Cisco and others. The company has been repeatedly targeted by ransomware gangs over the years. Its semiconductor segment was attacked by the LockBit ransomware gang in 2024. The same cybercriminal group targeted Foxconn’s Mexican manufacturing factories in 2022 and another ransomware gang attacked other facilities in Mexico in 2020. Cybersecurity experts believe the Nitrogen ransomware strain was created using a builder based on the now-defunct Conti ransomware. Researchers at Barracuda Networks said Nitrogen “is a sophisticated and financially motivated threat group that was first observed as a malware developer and operator in 2023.” Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaMay 12, 2026extracted
Attacchi BEC, saperli riconoscere per poterli respingere
Le truffe Business Email Compromise (BEC) sono in circolazione da anni, probabilmente da prima che, nel 2013, l’FBI le classificasse come tali. Colpiscono organizzazioni e privati e, stando al censimento fatto dal Federal Bureau of Investigation sulla scorta delle denunce note, gli attacchi BEC hanno causato danni per 55 miliardi di dollari in poco più di un decennio (47 miliardi di euro). Uno studio prodotto da ricercatori del Department of Computer Science, della Shaqra University (Riyadh, Arabia Saudita) e della School of Electronics and Computer Science dell’Università di Southampton (Regno Unito), certifica che le truffe BEC continuano a essere minacce di rilievo sul piano finanziario, riuscendo a causare danni globali che – nel periodo dal 2021 e i primi tre mesi del 2023 – sono stati calcolati in oltre 8 miliardi di dollari (almeno 6,85 miliardi di euro). Non hanno confini e si estendono anche in Italia, come insegna il caso della truffa BEC a scapito della onlus Opera Santa Maria del Fiore, costato 1,7 milioni di euro. Ci sono diversi metodi per riconoscere e mitigare gli attacchi BEC, tutti accomunati dalla necessità di formazione degli utenti. Indice degli argomenti A differenza del phishing e delle sue tante forme, il BEC non fa leva su allegati malevoli e non instrada gli utenti verso risorse web truffaldine ma sfrutta la manipolazione psicologica e si insinua nella fallacità delle procedure e dei processi aziendali. Nella sua formula più matura, un attacco BEC funziona come un’operazione di ingegneria sociale mirata che sfrutta la fiducia interna ai processi aziendali più di quanto sfrutti vulnerabilità tecniche. L’attaccante inizia con una fase di ricognizione approfondita, durante la quale analizza informazioni pubbliche e semi‑pubbliche per ricostruire la struttura gerarchica dell’azienda, le responsabilità finanziarie, le abitudini comunicative dei dirigenti e i rapporti con fornitori strategici. Questa fase, basata su OSINT e su un’osservazione attenta dei flussi comunicativi, serve a costruire un contesto credibile in cui inserire la futura manipolazione. Il termine OSINT, acronimo di Open source intelligence, descrive la raccolta e l’analisi di dati provenienti da fonti pubbliche ovvero, in altri termini, ottenibili senza particolari forzature o violazioni. Tali fonti possono essere registri governativi, notizie pubblicate sui media, contenuti pubblicati sui social network ma anche le informazioni che chiunque può evincere, riguardo un’azienda o una persona, consultando un qualsiasi motore di ricerca. In seguito, dopo avere individuato il bersaglio, l’attaccante procede compromettendo un account email aziendale oppure impersonificandolo. Attività affini ma diverse nel modo di procedere: nel primo caso, il cyber criminale ottiene l’accesso all’account email tramite phishing mirato, credential stuffing o malware e prende possesso delle mailbox, osservando ogni conversazione e scegliere il momento migliore per inserirsi nel filone comunicativo passando inosservato. Nel secondo caso, l’attaccante registra domini quasi identici a quelli dell’entità (azienda o privato) di cui vuole assumere le sembianze digitali, sfruttando debolezze nei controlli SPF, DKIM e DMARC, e scrive email che imitano tono, stile e tempi di risposta del mittente legittimo. Poi è la volta del passaggio cardine: l’attaccante si inserisce in una conversazione o ne crea una che sembra essere la continuazione di uno scambio di email già in essere. Il criminale sfrutta una delle leve tipiche di ogni truffa, ossia urgenza, riservatezza o autorità del ruolo per indurre la vittima a modificare coordinate bancarie, eseguire bonifici oppure condividere dati sensibili che potrebbero essere usati in un secondo momento. Infatti, l’FBI sottolinea che il BEC non è limitato alle frodi finanziarie, ma include anche la sottrazione qualsiasi dato utile ad alimentare attacchi successivi. Riconoscere un attacco BEC significa sapere leggere segnali che, presi singolarmente, possono sembrare innocui e che, nel loro insieme, delineano un comportamento anomalo rispetto al normale flusso comunicativo di un’organizzazione. C’è una difficoltà di fondo che risiede nella natura stessa di un attacco BEC il quale, se ben congegnato, non si manifesta mai attraverso indicatori evidenti ma mediante deviazioni del contesto, manipolazioni dei processi aziendali e mostrando lievi elementi di discontinuità comportamentale. Non si tratta di verificare la presenza di allegati malevoli o di link, ma discovare nelle email segnali che tendono a non balzare agli occhi. Un elemento osservabile è la coerenza del mittente, sulla quale si è concentrata l’azienda americana di cyber security Huntress che ha riscontrato alcune evidenze come, per esempio, l’invio di email in orari inusuali per il mittente impersonato oppure l’uso di stili linguistici non consueti che, spesso, introducono situazioni di urgenza o vertono a esercitare pressioni sul destinatario. Si tratta di piccoli scostamenti dal consueto: sintassi rigide o sbrigative che normalmente non sono nelle corde del mittente, oppure richieste di non coinvolgere terzi nello scambio di email. Un altro elemento ricorrente è la richiesta (o l’imposizione, a seconda del ruolo impersonato dal mittente) di modificare processi aziendali consolidati, soprattutto quando si tratta di flussi finanziari o di procedure amministrative. In questo ambito rientrano le richieste di cambiare coordinate bancarie alle quali fare pervenire bonifici, il fare pressioni affinché un pagamento venga effettuato in fretta, oppure la richiesta di condividere documenti sensibili senza le dovute autorizzazioni. La multinazionale della cyber security Palo Alto Networks sostiene che le discrepanze notate dai destinatari delle email fanno la differenza nello scoprire le truffe BEC, argomento questo sul quale torneremo in chiusura. Un ulteriore tratto distintivo è la progressione dell’interazione. Il BEC raramente si manifesta con una richiesta diretta e immediata. Gli attaccanti tendono a creare un contesto credibile attraverso uno scambio preliminare di messaggi, magari chiedendo informazioni innocue o confermando dettagli già noti. Questo serve a rafforzare la fiducia e a rendere la richiesta finale più naturale. Modelli di Machine learning e di elaborazione del linguaggio naturale (NLP) hanno dimostrato una certa efficacia nell’individuare attacchi BEC. Proofpoint usa modelli derivati da Bert e altri transformer per esaminare testo, tono e pattern nelle email. Ironscales si focalizza sul rilevamento del BEC, del phishing e del social engineering in genere, ricorrendo a modelli di Machine learning che apprendono da email reali per individuare ciò che non lo è. Barracuda Sentinel è una soluzione incentrata su analisi comportamentale, NLP e pattern linguistici per identificare phishing, impersonificazione e BEC. È integrata in Exchange365 di Microsoft, azienda che, dal canto suo, ha un approccio proattivo al pari di Google che, in Workspace (Gmail), integra modelli di Machine learning e NLP proprietari per bloccare spam, phishing e BEC prima che vengano recapitati nelle mailbox. Questi prodotti e servizi sono solo alcuni tra i tanti disponibili sul mercato. A prescindere dalle peculiarità di ognuno e dai modelli AI deputati alla difesa dalle minacce, tutti sono accomunati da addestramenti svolti su milioni di email legittime confrontate con attacchi reali e tutti godono di aggiornamenti continui. Così come il ricorso a modelli AI può non essere sufficiente perché non sempre i dataset sono tanto grandi e realistici da garantire risultati certi, credere che la crittografia possa risolvere un attacco BEC è argomento perfettibile. Infatti, il BEC non è un attacco che si schiera contro un canale di comunicazione, ma al suo interno. Sfrutta la fiducia e il contesto per riuscire a infiltrarsi tra le procedure aziendali per procurare un tornaconto all’attaccante, non sfrutta eventuali debolezze dei protocolli di cifratura. La crittografia protegge il contenuto di un’email durante il trasporto ma, nel BEC, l’attaccante non ha bisogno di intercettare traffico: se compromette le credenziali di un dipendente di un’azienda, queste risultano legittime. Inoltre, la crittografia non interviene su un altro elemento chiave del BEC: la compromissione dell’account. Se l’attaccante ottiene accesso tramite phishing, credential stuffing o malware, opera dall’interno dell’ecosistema email con privilegi reali. A quel punto, ogni messaggio che invia è tecnicamente indistinguibile da un messaggio legittimo. La cifratura end‑to‑end non può distinguere un dipendente reale da uno che reale non è. Al di là delle tecnologie e dei servizi di cui si è scritto sopra, ciò che è utile per intercettare un attacco BEC è una difesa su più livelli. Sono utili i già citati modelli capaci di rilevare pattern di testo, cambiamenti di tono e anomalie nel flusso del discorso ma, a fare la differenza, è l’elemento umano. Formare adeguatamente il personale, spiegare che ogni tentativo di esercitare pressioni sulla scorta di urgenze o dell’autorità di chi fa richieste (un manager di alto livello se non persino il proprietario dell’azienda) è già un potenziale indizio che necessita pochi secondi per essere esaminato da vicino. Infatti, approntando procedure di controllo, le aziende dovrebbero fare ricorso a una doppia approvazione per la trasmissione via email di dati sensibili, la predisposizione di bonifici al di sopra di un certo importo oppure la modifica di coordinate bancarie. Dopo avere ricevuto una richiesta di questi tipi, il dipendente avvia una procedura standard che prevede una telefonata al mittente dell’email, per controllare che sia davvero artefice della richiesta stessa.
cybersecurity360.itMay 6, 2026extracted
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during a simple install. It is definitely a busy time to be online. Security is always a moving target. Millions of servers are currently sitting online without any passwords, and old software bugs are showing up in the most unexpected places. Even with the right fixes available, staying one step ahead is a full-time job for all of us. Data is shifting in strange ways, too. Some browser tools are now legally selling user history for profit, and new kits are making it simpler for almost anyone to launch a campaign. You have to see these latest updates to believe them. Let’s look at the full list... SMS blaster phishing crackdownCanadian authorities have arrested three men for operating an SMS blaster device that masquerades as a cellular tower to send phishing texts to nearby phones. These tools trick devices into connecting to them by emitting signals that mimic a legitimate tower. "An SMS blaster works by mimicking a legitimate cellular tower. When nearby phones connect to it, users receive fraudulent text messages that appear to come from trusted organizations," authorities said. "These messages often prompt recipients to click on links that lead to fake websites designed to capture personal information, including banking credentials and passwords." The three men are facing 44 charges in connection with the crime. About tens of thousands of devices were connected to the blaster over several months, the official said. This is the first time that an SMS blaster has been spotted in the country. npm brandsquat data theftA new supply chain attack has leveraged an npm package impersonating TanStack to ship malicious versions that exfiltrate environment variables from developers’ machines during install. The package, named tanstack, is designed to "silently steal environment variable files, including .env, .env.local, and .env.production, from developers' machines at install time, exfiltrating them to an attacker-controlled endpoint," Socket said. The malicious package is maintained by a user named "sh20raj." Versions 2.0.4 through 2.0.7 are confirmed malicious. Update: In a post shared on X, Shaswat Raj (@SH20RAJ), the developer behind the package, apologized for his actions and claimed he demanded $10,000 from Tanner Linsley, creator of TanStack, as he "thought it was acceptable to ask for a bounty" for returning the name. The developer also stated the malicious code was part of "random testing" for jailbreaking Google Antigravity. Extensions legally sell user dataIn a new analysis, LayerX found that multiple networks of browser extensions collect user data and resell it for profit. Unlike malicious extensions that conceal their behavior by offering some harmless functionality, the identified 80 extensions explicitly inform users in their privacy policy that they collect and sell data of users who install their extensions. "A network of 24 media extensions that are installed on 800,000 users and collect viewing data and demographic information on major streaming platforms such as Netflix, Hulu, Disney+, Amazon Prime Video, HBO, Apple TV, and others," LayerX said. "12 separate ad blockers with a combined install base of over 5.5 million users openly selling user data. Nearly 50 other extensions, with over 100,000 users in aggregate, that collected and resold users’ browsing data." Komari tool weaponized in attacksHuntress has revealed that unknown threat actors used stolen VPN credentials to pivot into a Windows workstation belonging to an unspecified organization via Impacket's smbexec.py, and dropped a SYSTEM-level backdoor using the Komari agent, a Go-based remote-control, monitoring, and management tool. The development marks the first publicly documented case of the tool being abused in a real-world intrusion. It also illustrates how bad actors are increasingly switching to publicly available and legitimate tools to conduct attacks. "Komari is not a telemetry tool that happens to be abusable - it is a bidirectional control channel by design. The agent opens a persistent WebSocket to its server and accepts three server-to-agent event types out of the box: exec (arbitrary command execution via PowerShell / sh), terminal (interactive PTY reverse shell in the operator's browser), and ping (ICMP / TCP / HTTP probing)," Huntress said. "All three are enabled by default." Whereas other tools like Velociraptor and SimpleHelp that have been abused by threat actors typically act as means to an end, Komari gives an operator arbitrary command execution, an interactive PTY reverse shell, and network probing by default, over a TLS-fronted WebSocket. Next-gen phishing kits escalateThreat actors have detailed two new phishing kits named Saiga 2FA and Phoenix System that have been linked to emails and SMS phishing attacks. According to Barracuda, Saiga 2FA goes beyond traditional adversary-in-the-middle (AitM) features by integrating tools like FM Scanner for extracting and analyzing mailbox content. "Saiga 2FA is an example of how phishing kits are evolving into application-level platforms," the company said. "Unlike traditional phishing kits, Saiga integrates infrastructure, automation, and post-compromise capabilities into a unified system, supporting advanced and highly targeted campaigns." Phoenix System, on the other hand, has been tied to over 2,500 phishing domains since January 2025, while relying on IP-based filtering and geofencing for precision targeting. It's assessed to be the successor to the now-defunct Mouse System. "The campaigns are delivered via SMS, potentially leveraging fake Base Transceiver Stations (BTS) to bypass carrier-level filtering and allow threat actors to send messages that appear under the brand names of trusted organizations directly to victims," Group-IB said. "The campaign has so far targeted more than 70 organizations across the financial services, telecommunications, and logistics sectors globally." Mass exposure of remote access serversA new analysis from Forescout has found 1.8 million RDP and 1.6 million VNC servers are exposed on the internet. "China accounts for 22% of exposed RDP and 70% of exposed VNC servers; the U.S. accounts for 20% and 7%; Germany accounts for 8% and 2%," the company said. "Of 91,000 RDP and 29,000 VNC servers mapped to specific industries, retail, services, and education lead RDP exposure; education, services, and healthcare lead VNC." What's more, 18% of exposed RDP servers run end-of-life Windows versions, more than 19,000 RDP servers remain vulnerable to BlueKeep (CVE-2019-0708), and nearly 60,000 VNC servers have authentication disabled. To make matters worse, more than 670 exposed VNC servers have authentication disabled and provide direct access to OT/ICS control panels. China-linked influence op faltersA China-linked online influence campaign attempted to undermine April 26 elections for the Tibetan parliament-in-exile with little impact. The operation, part of Spamouflage, a long-running influence network linked to Beijing, has used a cluster of 90 Facebook profiles and 13 Instagram profiles to push criticism of the Tibetan government-in-exile and its leadership. "The network tries to drive wedges within the community," DFRLab said. "The goal is to erode trust in the exile government, weaken its international voice, and raise doubts about whether it can credibly represent Tibetans without the Dalai Lama. However, virtually none of these posts seem to have attracted any organic engagement, possibly because all the identified assets are regular Facebook profiles with limited reach and not established pages." Unpatched RPC privilege escalationAn unpatched vulnerability can allow for local privilege escalation in Windows systems through the abuse of the Remote Procedure Call (RPC) architecture in the operating system. Called PhantomRPC, the flaw stems from an architectural weakness in how RPC handles connections to unavailable services. To exploit the flaw, an attacker with limited local access needs to first compromise a privileged service that runs under the Network Service identity, deploy a fake RPC server with the same RPC interface UUID and exposed endpoint name (i.e., TermService), listen to specific requests, and then impersonate the targeted service to escalate their privileges to SYSTEM. Kaspersky, which identified the weakness, said it discovered four PhantomRPC exploitation paths that could lead to privilege escalation. Following responsible disclosure in September 2025, Microsoft opted to not address the issue as it requires an attacker to first compromise the machine through some other means. Vidar dominates infostealer marketThe information stealer known as Vidar (now in its second iteration called Vidar Stealer 2.0) has vaulted to the top of the infostealer market since November 2025 in the aftermath of law enforcement takedowns of Lumma and Rhadamanthys. "Vidar profited from the generated chaos to rise to the top of the stealer ecosystem," Intrinsec said. "We assess that this rise was made available due to the release of version 2.0 of the malware, and to the collaboration with 'Cloud' Telegram channels." It's advertised by a user named "Loadbaks" on underground forums. Recent campaigns have been observed distributing malware that has used bogus links shared via YouTube videos promoting fake software to direct users to Mediafire pages, which are used to deliver executables responsible for downloading and running the broad-spectrum credential harvester. The stolen credentials are then quickly monetized on underground marketplaces like Russian Market. Critical flaws hit healthcare platformThirty-eight critical security vulnerabilities have been disclosed in OpenEMR, the world's most widely used open-source electronic medical records platform. The vulnerabilities, now patched, range in severity from medium to critical and include missing or incorrect authorization checks, cross-site scripting (XSS), SQL injection, path traversal, and insufficient session expiration. These issues, which include two designated critical (CVE-2026-24908 and CVE-2026-23627), could have been exploited to access and tamper with patient and provider data, posing a serious health and regulatory risk to individuals and institutions. "In the most severe cases, SQL injection vulnerabilities combined with modest database privileges could have led to full database compromise, PHI exfiltration at scale, and remote code execution on the server," AISLE said. OpenEMR is used by more than 100,000 medical providers, serving more than 200 million patients in 34 languages. Swiss crackdown on Black AxeA coordinated police operation in Switzerland has led to the arrest of 10 suspected members of the Black Axe criminal network, including the Black Axe "Regional Head" for the Southern European region. Most of those arrested are reported to be of Nigerian origin. The suspects are accused of numerous crimes, including romance scams, cyber fraud offences causing millions of Swiss francs in damages, and money laundering. "The criminal network is known for its involvement in a wide range of criminal activities, including cyber-enabled fraud, drug trafficking, human trafficking and prostitution, kidnapping, armed robbery, and fraudulent spiritual practices," Europol said. PyPI package hijacked via CI exploitIn yet another software supply chain attack, unknown threat actors pushed a malicious version of the popular "elementary-data" package on the Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. According to StepSecurity, elementary-data version 0.23.3 was uploaded to PyPI on April 24, 2026, at 10:20 p.m. UTC. The attacker opened a pull request with malicious code and exploited a script-injection vulnerability in one of its GitHub Actions workflows to publish it as release 0.23.3. Specifically, it came embedded with a "elementary.pth" file that enabled the theft of developer credentials and secrets. "The attacker exploited a script injection vulnerability in one of the project's own GitHub Actions workflows, then used the workflow's GITHUB_TOKEN to forge a signed release commit and dispatch the legitimate publishing pipeline against it – without ever touching the master branch or opening a pull request," the company said. The developers urged users who installed 0.23.3, or pulled and ran its Docker image, to assume compromise and rotate any credentials. $230M crypto laundering sentence22-year-old Evan Tangeman of Newport Beach, California, was sentenced to 70 months in prison for laundering funds stolen in a massive $230 million cryptocurrency heist as part of an elaborate social engineering scheme. "This criminal enterprise was built on greed so brazen it borders on the cartoonish. They stole millions, spent it on half-million-dollar nightclub tabs, Lamborghinis, and Rolexes," said U.S. Attorney Jeanine Ferris Pirro. "But Evan Tangeman didn't just launder the money that fueled that lifestyle. When his co-conspirators were arrested, he moved to destroy the evidence. That is consciousness of guilt, and this office and the court have treated that accordingly." Tangeman pleaded guilty in December 2025. The criminal enterprise began no later than October 2023 and continued through at least May 2025. Legacy TLS finally deprecatedMicrosoft has announced plans to start blocking legacy TLS connections for POP and IMAP email clients in Exchange Online starting in July 2026. "We're planning to fully deprecate support for legacy TLS versions (TLS 1.0 and TLS 1.1) for POP3 and IMAP4 connections to Exchange Online. These older TLS versions have been industry-deprecated for some time and are no longer considered secure," the company said. "Several years ago, we started the move to block these older versions, but we did allow you to use them by opting in; we're now removing support for them entirely. Our expectation is that only customers who have explicitly opted into using those legacy endpoints are impacted by the deprecation." Phishing via account flow abuseThreat actors are abusing online trading platform Robinhood's account creation process to send phishing emails that bypass spam filters. The emails, which originate from "noreply@robinhood[.]com," warn of suspicious activity tied to their accounts and urge them to click to complete a security check by clicking on a link that directs to a phishing site. "This phishing attempt was made possible by an abuse of the account creation flow," Robinhood said in an X post. "It was not a breach of our systems or customer accounts, and personal information and funds were not impacted. If you received this email, please delete it and do not click any suspicious links. If you have clicked a suspicious link or have any questions about your account, please contact us directly within the Robinhood app or website." Reports on Reddit indicate that the attackers created new Robinhood accounts using modified versions of existing Gmail addresses via the so-called "dot trick." The technique takes advantage of the fact that Gmail ignores periods inserted into or removed from a username, whereas Robinhood treats each variation as a distinct user, allowing the attackers to create a new account that points to an existing account. Social media scams surgeThe U.S. Federal Trade Commission (FTC) warned of a massive increase in losses from social media scams since 2020, exceeding $2.1 billion in 2025, including $794 million to scams that started on Facebook, more than on any other platform. "In 2025, nearly 30% of people who reported losing money to a scam said that it started on social media, with reported losses reaching a staggering $2.1 billion. Social media scams produced far more in losses – an eightfold increase since 2020 – than any other contact method used by scammers to reach consumers," the FTC said. "Social media creates easy access to billions of people from anywhere in the world, making a scammer's job easier at very little cost. Scammers may hack a user's account, exploit what a user posts to figure out how to target them, or buy ads and use the same tools used by real businesses to target people by age, interests, or shopping habits." Billions of credentials exposedKELA said it tracked 2.86 billion compromised credentials in 2025 globally. These included usernames, passwords, session tokens, cookies found in URL, login and password (ULP) lists, breached email repositories, and cybercrime marketplaces. At least 347 million were originally obtained by infostealers found on around 3.9 million infected machines. arXiv papers leak sensitive dataAn analysis of 2.7 million submissions to the arXiv preprint service -- which also makes available the LaTeX sources and other files used to create them -- has found that they include unnecessary files, expose metadata embedded in files (usernames, email addresses, hardware details, GPS information, software versions), and leak irrelevant content in files such as source code comments. This includes backups, hidden .nfs files, Git repositories (including editing histories), andconfiguration files containing API keys. "Apart from unused template files that put unnecessary storage burden on arXiv, we further discovered scripts, research data, and even entire Git repositories. Additionally, comments in LaTeX sources reveal, e.g., author conversations or todo items – for some of those comments, we are certain that the authors did not intend to disclose them publicly. Alarmingly, our findings also include URLs without any access restrictions to other resources (e.g., Google Docs), security tokens, and private keys," the study said. While arXiv recommends Google's arxiv_latex_cleaner to clean the LaTeX code, the researchers have released a tool called ALC-NG to comprehensively remove files, metadata, and comments that are not needed to compile a LaTeX paper. Roblox account hacking ring bustedThe Ukrainian police have arrested three individuals who hacked more than 610,000 Roblox gaming accounts and sold them for a profit of $225,000 on Russian websites. The suspects face up to 15 years in prison if convicted and have been placed in pretrial detention while the investigation is in progress. The scheme was allegedly masterminded by a 19-year-old resident of Drohobych, Lviv Oblast, who met his accomplices, aged 21 and 22, on gaming forums last year. From October 2025 to January 2026, the suspects are believed to have accessed more than 600,000 Roblox user accounts. Iran-linked group targets troopsThe Iran-linked threat actor Handala Hack has targeted U.S. troops in Bahrain in an influence campaign carried out via WhatsApp, according to Stars and Stripes. The messages, signed Handala and containing a link to the group’s website, claimed the service members were under surveillance and soon to be targeted with drones and missiles. "Your identities are fully known to our missile units, and every move you make is under our surveillance. Very soon, you will be targeted by our Shahed drones and Kheibar and Ghadeer missiles," the message sent on April 28, 2026, read. Record surge in privacy finesU.S. states issued $3.45 billion in privacy-related fines to companies in 2025, a total larger than the last five years combined, per Gartner. "Regulators are also shifting their efforts away from spreading awareness to full-scale enforcement," the company said. "This is increasingly becoming the standard in 2026 and beyond." WordPress plugin backdoor uncoveredAnchor Hosting has revealed that a WordPress plugin named Quick Page/Post Redirect plugin, which has over 70,000 installs, was compromised with a backdoor that enables injecting arbitrary code into users' sites. Plugin versions 5.2.1 and 5.2.2, released between 2020 and 2021, have been found to include a covert self-update mechanism that reaches out to a third-party domain, anadnet[.]com, to facilitate the execution of arbitrary code. It's worth noting that the passive backdoor triggers only for logged-out users to hide its activity from site administrators. As of April 16, the plugin has been closed temporarily pending a full review. Qinglong flaws abused for miningHackers are exploiting two authentication bypass vulnerabilities in Qinglong, an open-source timed task management platform with over 19,500 GitHub stars, to deploy cryptocurrency miners. The two flaws – CVE-2026-3965 and CVE-2026-4047 – enable authentication bypass that results in remote code execution. "While these vulnerabilities were formally reported on February 27, exploitation had already been underway for weeks," Snyk said. "Starting around February 7-8, 2026, Qinglong users began opening issues about a hidden process called .fullgc consuming 85-100% of their CPU. The .fullgc filename may have been chosen to blend in with legitimate processes. In Java/JVM environments, 'Full GC' (Full Garbage Collection) is a known source of CPU spikes, which could delay an administrator's investigation." The issues have since been addressed in #PR 2941. Trivy hack enabled repo breachIn a new update shared this week, Checkmarx said its investigation into the cybersecurity incident has revealed the TeamPCP attack affecting the Trivy scanner is the "likely vector that enabled the attackers to obtain credentials and to gain unauthorized access to our GitHub repositories." This, in turn, allowed the attackers to interact with Checkmarx's GitHub environment and publish malicious code to certain artifacts. The development comes as the company acknowledged that data stolen from the GitHub repository was published on the dark web by a cybercrime group known as LAPSUS$. npm stealer tied to DPRK groupThe North Korean threat actor known as Famous Chollima has been attributed to the npm package named js-logger-pack that comes embedded with a WebSocket stealer that's triggered via a postinstall hook. "The payload is a long-running WebSocket agent that: installs the attacker's RSA key into ~/.ssh/authorized_keys on Linux; exfiltrates Telegram Desktop tdata sessions; drains credentials from 27 crypto wallets and Chromium-family browsers; steals .npmrc, cloud provider tokens, and shell history; and runs a native keylogger on Windows, macOS, and Linux with autostart persistence on all three," SafeDep said. Security is a team sport. We keep seeing the same gaps because we focus on the new shiny toys while the basics, like simple passwords and old software versions, fall through the cracks. It is clear that just having a patch isn't enough if nobody actually installs it. The best lesson here is to stay curious and cautious. Whether it is a weird text from a "trusted" source or a new tool that seems too good to be true, taking a second to verify can save a lot of trouble later. Let's keep learning and stay sharp until the next update!
thehackernews.comApr 30, 2026extracted
I 3 fenomeni che minacciano le aziende: quasi nove attacchi su dieci partono dal Medio Oriente
Il panorama delle minacce informatiche continua a evolversi con ritmi serrati, e i dati raccolti nel primo trimestre del 2026 da Barracuda Managed XDR offrono una fotografia preoccupante di quanto stia accadendo nelle reti aziendali di tutto il mondo. Comprendere la natura di queste minacce, i fattori di rischio che le alimentano e le contromisure disponibili è oggi una priorità per qualsiasi organizzazione che voglia mantenere un adeguato livello di resilienza informatica. Ecco i tre fenomeni che si distinguono in modo particolare. Indice degli argomenti Tre fenomeni si distinguono in modo particolare: l’impennata degli attacchi brute force contro i dispositivi perimetrali, la rapidità fulminante con cui il ransomware Qilin riesce a propagarsi all’interno dei sistemi colpiti, e la crescente diffusione degli attacchi ClickFix, una tecnica di ingegneria sociale che sfrutta la buona fede degli utenti per aggirare le difese automatizzate. attacchi di autenticazione brute force Sul fronte degli attacchi di autenticazione brute force, i dati del Security Operations Center di Barracuda indicano una crescita significativa dei tentativi rivolti contro dispositivi SonicWall e FortiGate nel periodo compreso tra gennaio e marzo 2026. Si tratta di apparati largamente diffusi nelle infrastrutture aziendali con funzione di firewall e gateway VPN, il che li rende bersagli di particolare interesse per i criminali informatici: compromettere un dispositivo perimetrale equivale spesso a ottenere un accesso diretto alla rete interna dell’organizzazione, bypassando buona parte delle difese successive. Medio Oriente Ildato geografico che emerge dall’analisi merita una riflessione approfondita: circal’88% dei tentativi rilevati proviene dal Medio Oriente. Sebbene attribuire con certezza la paternità di un attacco informatico sia un’operazione complessa, una concentrazione così marcata suggerisce l’esistenza di infrastrutture organizzate e di campagne condotte in modo sistematico. Non si tratta, in altri termini, di episodi casuali o isolati, ma di attività di scansione e testing aggressive e continuative, finalizzate a individuare credenziali deboli o configurazioni errate. Nel bimestre febbraio-marzo, questi incidenti hanno rappresentato oltre la metà, precisamente il 56%, di tutti gli eventi confermati registrati dal SOC. Un dato che da solo restituisce la dimensione del fenomeno. La maggior parte degli attacchi è stata neutralizzata, sia dagli strumenti di sicurezza in uso, sia perché i tentativi erano indirizzati verso nomi utente inesistenti. Tuttavia, sarebbe un errore interpretare questa circostanza come una ragione di rassicurazione: ogni tentativo fallito è anche una prova, e la ripetizione sistematica di queste prove aumenta la probabilità statistica che prima o poi una password debole o una configurazione non aggiornata apra una breccia nei sistemi. Nel bimestre febbraio-marzo, questi incidenti hanno rappresentato oltre la metà, precisamente il 56%, di tutti gli eventi confermati registrati dal SOC. Un dato che da solo restituisce la dimensione del fenomeno. La maggior parte degli attacchi è stata neutralizzata, sia dagli strumenti di sicurezza in uso, sia perché i tentativi erano indirizzati verso nomi utente inesistenti. Tuttavia, sarebbe un errore interpretare questa circostanza come una ragione di rassicurazione: ogni tentativo fallito è anche una prova, e la ripetizione sistematica di queste prove aumenta la probabilità statistica che prima o poi una password debole o una configurazione non aggiornata apra una breccia nei sistemi. fattori di rischio I fattori strutturali che espongono le organizzazioni a questo tipo di attacco sono ben identificabili. L’assenza diautenticazione multifattoriale sugli account che gestiscono firewall e VPN è tra le vulnerabilità più gravi: in sua mancanza, una credenziale compromessa è sufficiente a garantire l’accesso. A questo si aggiunge l’utilizzo di password deboli o riciclate, pratica ancora diffusa nonostante anni di campagne di sensibilizzazione. Contribuisce al rischio anche la presenza di dispositivi esposti su Internet privi di un monitoraggio continuo, che non segnalano in modo tempestivo sequenze anomale di tentativi di accesso falliti. Infine, un aspetto spesso sottovalutato è la persistenza di account legacy o cosiddetti profili fantasma: utenze create in passato, mai disattivate, che restano silenziosamente accessibili e rappresentano porte d’ingresso potenzialmente inesplorate per gli attaccanti. Qilin Passando al secondo fronte critico emerso nel periodo analizzato, quello del ransomware Qilin, ciò che colpisce non è soltanto la pericolosità del gruppo, che si conferma tra i più attivi nel panorama del crimine informatico, ma soprattutto la velocità con cui riesce ad operare una volta ottenuto l’accesso ai sistemi. Il SOC di Barracuda ha recentemente gestito un attacco riconducibile a Qilin, partito dalla compromissione di un endpoint vulnerabile. Dopo l’esecuzione del malware, l’offensiva ha prodotto in pochi minuti modifiche di file su larga scala accompagnate da attività di esecuzione sospette, costringendo il team di risposta a isolare la rete per contenere la propagazione. Questa rapidità operativa rappresenta una sfida concreta per i team di sicurezza: la finestra temporale disponibile per individuare la minaccia e reagire è estremamente ridotta, e qualsiasi ritardo nella rilevazione si traduce quasi inevitabilmente in un danno maggiore. Le condizioni che favoriscono il successo di un attacco ransomware come quello di Qilin riguardano anzitutto la mancanza di visibilità completa sulla rete, che impedisce di individuare movimenti laterali o anomalie nei comportamenti dei file. Pesano inoltre l’assenza di autenticazione multifattoriale, l’eccesso di dipendenti con privilegi di accesso elevati, la presenza di endpoint non protetti o monitorati in modo insufficiente, e processi di backup e ripristino inadeguati a garantire il recupero dei dati in tempi accettabili dopo un incidente. Un aspetto che merita attenzione è la relazione tra la formazione del personale e la prevenzione del ransomware: molti attacchi di questo tipo hanno origine da campagne di phishing o di social engineering che vanno a buon fine proprio perché chi le riceve non è in grado di riconoscerle. La sensibilizzazione periodica dei dipendenti sulle tecniche di inganno più recenti è quindi una componente della difesa tanto rilevante quanto gli strumenti tecnologici. tecnica ClickFix Su questo tema si innesta il terzo fronte di preoccupazione emerso dall’analisi di Barracuda: la diffusione degli attacchi ispirati alla tecnica ClickFix. Si tratta di una modalità di attacco basata sull’ingegneria sociale che porta l’utente a eseguire autonomamente codice malevolo, nella convinzione di stare risolvendo un problema tecnico. La vittima viene indotta a cliccare su un elemento o a copiare e incollare un comando in una casella, un’operazione apparentemente innocua, che in realtà attiva l’esecuzione di un file o di uno script dannoso. L’efficacia di questa tecnica risiede nella sua capacità di sfruttare la fiducia e, in certi casi, lo stato di urgenza o preoccupazione dell’utente. I pop-up e le richieste visualizzate imitano comunicazioni tecniche legittime, riproducono loghi familiari, usano un linguaggio plausibile. Questa verosimiglianza rende la minaccia particolarmente insidiosa non solo per l’utente, ma anche per i sistemi di sicurezza automatizzati: poiché è la persona stessa a inserire manualmente il codice, l’azione può non essere immediatamente distinguibile da una normale attività utente, almeno nelle prime fasi dell’attacco. Il quadro complessivo che emerge dall’analisi di Barracuda Managed XDR per il primo trimestre 2026 indica con chiarezza che le minacce informatiche si stanno facendo più rapide, più frequenti e più difficili da intercettare con le sole difese automatizzate. La combinazione di attacchi tecnici, come il brute force contro i dispositivi perimetrali, con tecniche di manipolazione sociale sempre più sofisticate, come ClickFix, e con ransomware capaci di agire in pochi minuti, come Qilin, richiede un approccio alla sicurezza che sia allo stesso tempo tecnologico, procedurale e culturale.
cybersecurity360.itApr 21, 2026extracted
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
Threat actors have migrated to other phishing-as-a-service (PhaaS) platforms after Tycoon 2FA’s disruption and are reusing its tools, cybersecurity firm Barracuda Networks says. Active since at least 2023, Tycoon 2FA allows threat actors to launch phishing attacks, bypass two-factor authentication, and compromise user accounts. It has been used in attacks against half a million organizations. Last year, Tycoon 2FA accounted for 62% of the phishing attempts seen by Microsoft, and was the most used PhaaS platform, with 89% market share, Barracuda says. In early March, a coordinated effort resulted in the seizure of 330 active Tycoon 2FA domains, but the platform’s operations continued seemingly unaffected. According to the fresh Barracuda report, despite the rebound, Tycoon 2FA lost the PhaaS crown, as threat actors have migrated to other platforms, such as Mamba 2FA, EvilProxy, and Sneaky 2FA. The overall number of attacks leveraging these four phishing kits has increased following the disruption, from roughly 20 million to over 23 million, but Tycoon is no longer the leader as it was prior to the law enforcement operation. It’s now well behind Mamba and EvilProxy based on Barracuda detections. Tycoon 2FA, Barracuda says, absorbed the hit, the underlying ecosystem lived on, and other phishing kits have matured their infrastructure and expanded their offerings with tools previously used by the disrupted service. “Tycoon 2FA was widely used by independent affiliates. This means that variants of Tycoon 2FA’s attack code that have been cloned or modified by individual adversaries continue circulating. It also means that independently hosted deployments remain active and that fragmented, low-volume campaigns persist,” Barracuda notes. According to the cybersecurity firm, PhaaS toolsets are increasingly similar to open source software, where threat actors reuse, modify, and redeploy the code. Combined with residual infrastructure, built-in redundancy to survive disruptions, and persistent access to compromised environments, this makes phishing kits sturdier and more difficult to detect and tackle. According to Barracuda, these artifacts reflect an ecosystem diversification, where Tycoon 2FA is redistributed across more platforms rather than restored. “This does not mean the takedown operation failed. Rather, it shows what happens when disruption hits a maturing underground economy, and why security defenses need to look more broadly than individual players,” Barracuda notes. Related: 53 DDoS Domains Taken Down by Law Enforcement Related: US Confirms Handala Link to Iran Government Amid Takedown of Hackers’ Sites Related: SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown Related: 1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium
securityweek.comApr 18, 2026extracted
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
You know that feeling when you open your feed on a Thursday morning and it's just... a lot? Yeah. This week delivered. We've got hackers getting creative in ways that are almost impressive if you ignore the whole "crime" part, ancient vulnerabilities somehow still ruining people's days, and enough supply chain drama to fill a season of television nobody asked for. Not all bad though. Some threat actors got exposed with receipts, a few platforms finally tightened things up, and there's research in here that's genuinely worth your time. Grab your coffee and keep scrolling. Targeted wallet breachCryptocurrency wallet service Zerion has disclosed that one of its team member's devices was compromised, resulting in the theft of approximately $100K in stolen funds from internal company hot wallets. The company noted that user funds, Zerion apps, or infrastructure were not impacted by the breach. The team member is said to have been the target of an artificial intelligence (AI)-enabled social engineering attack carried by a North Korean threat actor tracked as UNC1069. The hacking group was recently attributed to the poisoning of the popular Axios npm package. "This allowed the attacker to gain access to some of the team members' logged-in sessions and credentials as well as private keys to company hot wallets used for testing and internal purposes," Zerion said. "This was not an opportunistic attack. The actor is clearly sophisticated and well-resourced. They planned the attack thoroughly." Anonymous age checksThe European Union has announced that it will soon roll out a new online age verification app to allow users to prove their age when accessing online platforms. Users can set it up by downloading the app on their Android or iOS device using a passport or ID card. The Commission has emphasized that the app will respect users' privacy. "Users will prove their age without revealing any other personal information," President of the European Commission, Ursula von der Leyen, said. "Put simply, it is completely anonymous: users cannot be tracked. Third, the app works on any device – phone, tablet, computer, you name it. And, finally, it is fully open source – everyone can check the code." The development comes as countries around the world are undertaking various stages of regulatory action to keep cyberspace a safer place for children and minors and protect them from serious harm. New Defender zero-dayA researcher using the alias "Chaotic Eclipse" released a zero-day exploit called BlueHammer earlier this month following Microsoft's handling of the vulnerability disclosure process. Although the issue appears to have been fixed as of this month's Patch Tuesday release (CVE-2026-33825), the researcher has since disclosed a new unpatched Microsoft Defender privilege escalation vulnerability. The exploit has been codenamed RedSun. "This works 100% reliably to go from unprivileged user to SYSTEM against Windows 11 and Windows Server with April 2026 updates, as well as Windows 10, as long as you have Windows Defender enabled," security researcher Will Dormann said. A third exploit released by "Chaotic Eclipse," referred to as UnDefend, also targets Defender and triggers a denial-of-service (DoS) condition. "This tool, while stupid, is quite dangerous [be]cause if paired with BlueHammer, your machine is basically a hole, anyone can run anything with administrator privileges andwindows defender can't really do much about it," the researcher said. "Considering that's the whole purpose of an antivirus, you're better off removing it LOL." Legacy Excel RCE activeThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added an old remote code execution vulnerability impacting Microsoft Office to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the shortcoming by April 28, 2026. The vulnerability in question is CVE-2009-0238, which has a CVSS score of 8.8. "Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object," CISA said. sudo now requires passwordRaspberry Pi has released version 6.2 of its Raspberry Pi OS, which introduces one significant change: it disables passwordless sudo by default. As a result, users who run a sudo command for administrator-level access will be prompted to enter the current user's password. The change affects only new installations; existing setups are untouched. "Given the ever-increasing threat of cybercrime, we continually review the security of Raspberry Pi OS to ensure it is sufficiently robust to withstand potential attacks," Raspberry Pi said. "This is always a tricky balance, as anything that makes the operating system more secure will invariably inconvenience legitimate users to some extent, so we try to keep such changes to a minimum. This particular security update is one that many users may not even notice, but it will affect some." Stealth C2 frameworks uncoveredA previously undocumented command-and-control (C2) framework dubbed ObsidianStrike has been deployed on infrastructure belonging to a Brazilian law firm. "Only two instances of ObsidianStrike exist on the entire internet," Breakglass Intelligence said. "The framework has zero presence on GitHub, zero samples on VirusTotal or MalwareBazaar, and near-zero vendor detection. This is a fully private, Portuguese-language C2 built for targeted Windows operations, hidden behind a victim organization's domain." Also discovered by the security vendor is ArchangelC2, a C2 panel behind an industrial-scale ScreenConnect remote-access fraud campaign that has been operational since November 2024. Fake app drains $9.5MA fake Ledger app managed to slip onto the Apple App Store, draining $9.5 million in cryptocurrency from more than 50 victims between April 7 and April 13, 2026. The app, named Ledger Live, was released by a developer, "SAS Software Company," and published under "Leva Heal Limited." Users who downloaded the fraudulent app were tricked into entering their seed phrases, giving attackers full access to their wallets and allowing them to send digital assets to external addresses under their control. While Apple has since removed the macOS app from the store, questions remain as to how it managed to pass the company's review process. In more Apple-related news, the company has also removed a data harvesting app called Freecash from its App Store after it was deceptively advertised as a way to "make money just by scrolling TikTok," while collecting sensitive information from users. This included details about a user's race, religion, sex life, sexual orientation, health, and other biometrics. Once installed, however, instead of the promised functionality, users were routed to a roster of mobile games where they are offered cash rewards for completing time-limited in-game challenges. The app continues to be available on the Google Play Store. Localized ransomware campaignCybercriminals are using a new ransomware strain called JanaWare to target people in Turkey, according to Acronis. The attack leverages phishing emails containing a Google Drive link that paves the way for the download and subsequent execution of a malicious JAR file via javaw.exe. The payload is a customized Adwind (aka AlienSpy, jRAT, or Sockrat) variant with polymorphic characteristics that's used to deliver the ransomware module. The malware implements geofencing and environment filtering to ensure that the compromised systems match the Turkish language and region. While none of these tricks are particularly novel or advanced, they continue to work against unprotected small targets. It's unclear how many people or businesses might have fallen prey to the scheme. The low-stakes, localized approach has allowed the campaign to persist since at least 2020 without any major disruption. "Victimology appears to primarily include home users and small to medium-sized businesses. Initial access is assessed to occur via phishing emails delivering malicious Java archives," the company said. "Ransom demands observed in analyzed samples range from $200–$400, consistent with a low-value, high-volume monetization approach." Crackdown on navigation abuseGoogle said it's introducing a new spam policy for "back button hijacking," which occurs when a site interferes with a user's browser navigation and prevents them from using their back button to immediately get back to the page they came from. Instead, the hijack could redirect users to sketchy sites or other pages they have never visited before. "Back button hijacking interferes with the browser's functionality, breaks the expected user journey, and results in user frustration," Google said. "Pages that are engaging in back button hijacking may be subject to manual spam actions or automated demotions, which can impact the site's performance in Google Search results. To give site owners time to make any needed changes, we're publishing this policy two months in advance of enforcement on June 15, 2026." Stealth cloud credential theftThe China-linked hacking group known as APT41 has been attributed to an undetectable, purpose-built ELF backdoor targeting Linux cloud workloads across Amazon Web Services (AWS), Google Cloud, Microsoft Azure, and Alibaba Cloud environments. "The implant uses SMTP port 25 as a covert command-and-control channel, harvests cloud provider credentials and metadata, and phones home to three Alibaba-themed typosquat domains hosted on Alibaba Cloud infrastructure in Singapore," Breakglass Intelligence said. "A selective C2 handshake validation mechanism renders the server invisible to conventional scanning tools like Shodan and Censys." RDP phishing hardeningStarting with the April 2026 security update (CVE-2026-26151), Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (RDP) files, adding security warnings and turning off redirections by default. "Malicious actors misuse this capability by sending RDP files through phishing emails," Microsoft said. "When a victim opens the file, their device silently connects to a server controlled by the attacker and shares local resources, giving the attacker access to files, credentials, and more." Russian hacking groups like APT29 have weaponized RDP configuration files to target Ukrainian government agencies, enterprises, and military entities in the past. Plugin supply chain breachUnknown threat actors have staged a supply chain attack on a WordPress plug-in maker called Essential Plugin (formerly WP Online Support) after acquiring it in early 2025 from the original developers in a six-figure deal to plant a backdoor in August and subsequently weaponize it early this month to distribute malicious payloads to any website with the plug-ins installed. WordPress has since permanently closed all the plugins. "The plugin's wpos-analytics module had phoned home to analytics.essentialplugin.com, downloaded a backdoor file called wp-comments-posts.php (designed to look like the core file wp-comments-post.php), and used it to inject a massive block of PHP into wp-config.php," Anchor Hosting said. "The injected code was sophisticated. It fetched spam links, redirects, and fake pages from a command-and-control server. It only showed the spam to Googlebot, making it invisible to site owners." In addition, it resolved the command-and-control (C2) domain through an Ethereum smart contract to make it resilient to takedown efforts. Prior to their removal, the plugins collectively had more than 180,000 installs. "This is a classical case of supply chain compromise that happened because the original vendor sold their plugins to a third-party, which turned out to be a malicious threat actor," Patchstack said. Sanctioned crypto market persistsTelegram has continued to host Xinbi Guarantee, an illicit marketplace that has processed over $21 billion in total transaction volume, despite sanctions issued by the U.K. last month. The development has raised questions about the platform's willingness to police its own ecosystem and suspend bad actors. The Chinese-language bazaar is known to offer money laundering solutions to cryptocurrency scammers, harassment services, and products like electrified batons and tasers that cater to investment scams operating out of Southeast Asia. "Xinbi is still going strong," Elliptic's cofounder and chief scientist, Tom Robinson, told WIRED. "They're on track to become the largest market of this kind that has ever existed." Malvertising leads to ransomwareOrange Cyberdefense has revealed that threat actors used malvertising in three separate incidents observed between early February and early April 2026 to deliver the SmokedHam (aka Parcel RAT, SharpRhino, and WorkersDevBackdoor) backdoor by masquerading it as installers for RVTools or Remote Desktop Manager (RDM). The malware is assessed to be a modified version of the open-source trojan known as ThunderShell. In at least one case, the attack led to the deployment of Qilin ransomware, but not before dropping employee monitoring and remote desktop solutions like Controlio, TeraMind, and Zoho Assist for persistent access, exfiltrating KeePass password databases, and conducting discovery and lateral movement. The adoption of legitimate dual-use tools is a concerning trend as it allows attackers to blend their actions into legitimate activity and reduce the risk of detection. The activity has been attributed with medium confidence to UNC2465, an affiliate of DarkSide, LockBit, and Hunters International. It also overlaps with a campaign detailed by Synacktiv and Field Effect in early 2025. APT lineage link uncoveredNew research has discovered that the threat actor known as Water Hydra (aka DarkCasino) is still active in 2026, with new evidence uncovering a previously unreported connection between evilgrou-tech, a commodity operator, and the hacking group. "The handle 'evilgrou' is assessed with moderate confidence to be a deliberate reference to EvilNum (Evil + [num -> grou]p), the predecessor APT group from which WaterHydra/DarkCasino splintered in late 2022," Breakglass Intelligence said. The strongest attribution indicator is a shared developer workspace path embedded in binaries associated with EvilNum and Water Hydra: "C:\Users\Administrator\Desktop\vaeeva\shellrundll.tlb." These two artifacts are separated by two years, one in July 2022 and the other in January 2024. Scientific software RCE riskCybersecurity researchers have disclosed security flaws in HDF5 software, a file format to manage, process, and store heterogeneous data, that could be exploited to compromise a vulnerable system. "The discovered vulnerabilities, based on a stack buffer overflow, could allow threat actors to overwrite memory and compromise target systems for stealing highly classified research data, industrial espionage, or a foothold into the internal network," ThreatLeap's co-founder, Leon Juranic, said. "In practice, this means the vulnerability could be exploited by a single specially crafted malicious input file and, as a result, an entire system could get compromised." The issues were addressed in October 2025 following responsible disclosure. Brute-force surge on edge devicesSecurity researchers have detected a "sharp rise" in brute-force attempts to hijack SonicWall and FortiGate devices between January and March 2026, with the vast majority (88%) appearing to originate from the Middle East. Most attempts were unsuccessful, either blocked outright by security tools or directed at invalid usernames. "Attackers are aggressively scanning and testing perimeter devices for weak or exposed credentials," Barracuda Networks said. "Even when attacks fail, persistent probing raises the risk that a single weak password or misconfiguration could lead to compromise." Fraud network evades sanctionsTriad Nexus, a sprawling cybercrime ecosystem acting as the backbone of scams, money laundering, and illicit gambling operations since at least 2020, has been observed using geographic fencing and laundering its infrastructure through "clean" front companies to acquire accounts at major enterprise cloud providers (Amazon, Cloudflare, Google, and Microsoft) in an attempt to distance itself from Funnull, a Philippines-based company that was sanctioned by the U.S. last year. Simultaneously, the group has expanded into the Spanish, Vietnamese, and Indonesian markets using localized templates to target these regions. Besides engaging in fraud, the group specializes in high-fidelity brand impersonation, weaponizing the digital identities of Global 2000 companies to dupe victims. "The network has industrialized brand theft on a global scale; its catalog includes 'pixel-perfect' clones of everything from high-end luxury goods to public services," Silent Push said. "Despite federal sanctions in 2025, the group has reinstated its global fraud engine, shifting its focus toward emerging markets while maintaining a persistent threat to Western enterprise assets." Triad Nexus is estimated to be responsible for over $200 million in reported losses, primarily fueled by pig butchering and virtual currency scams. That's a wrap for this week. If anything here made you pause, good. Go check your patches, side-eye your dependencies, and maybe don't trust that app just because it's sitting in an official store. The basics still matter more than most people want to admit. We'll be back next Thursday with whatever fresh chaos the internet cooks up. Until then, stay sharp and keep your logs close. See you on the other side.
thehackernews.comApr 16, 2026extracted
CISO Conversations: Ross McKerchar, CISO at Sophos
Ross McKerchar began his Sophos career as the firm’s first security engineer 18 years ago and is now the company’s CISO. We discussed his journey and the role of the CISO. “Like most youngsters, I played video games as a child. By the time I was 16, I was already convinced that IT would be a good, solid career – so I went on to take a computer science degree at the University of Edinburgh.” But then came a realization. “I’m probably going to offend a lot of people with this, but much of IT is quite boring.” When you talk about IT, people’s eyes glaze over, he continues. But if you talk about cybercrime, they become engaged. “It’s whole of world rather than just the box in the computer room. It’s geopolitical, it’s adversarial, and it affects everybody, everywhere.” Conflict, he adds, makes for good stories – so, he shifted his interest from IT to cybersecurity. The path to leadership and team management How and why did he become a leader in cybersecurity? There is always a question over whether leadership is a genetic quality or something that can be learned: nature, or nurture – or both. McKerchar’s short answer is that it can be learned, but only if you enjoy it. For himself, he suggests, there was an element of both growing into it, and growing with it. “When I joined Sophos 18 years ago, I was basically the first internal cybersecurity employee. In that sense, I was always the leader – of a team of one. Now I am the CISO with a much larger team.” Along that route, he has had to acquire or learn skills that cannot be gained from a degree in computer science: how to recruit quality team members in an age typically described as a skills gap; how to manage that team to provide optimum performance; and how to maintain the team at that optimum performance. “The skills gap is real,” he says, “but I think it is mischaracterized both in number and effect. The cybersecurity profession is growing faster than most others. So, in this sense there is an ever-increasing demand. Education is responding with more training in security fundamentals, so there are more people looking for work in cybersecurity.” The problem is the demand is not for the people straight out of college with a piece of paper but no experience, but for people with both experience and combined emotional and business intelligence. The skills gap is at the senior level rather than the graduate level. Part of this is the continuing tendency for companies to ramp up security only after an attack. As a result, the security team suddenly leaps from two to a dozen in rapid time – and at such times, the employer wants seasoned professionals rather than newbie grads. This creates a double problem for CISOs. Firstly, although there are more people looking for positions, the positions available are not looking for those people – those positions are more attractive to the people you already have. This is the second problem: managing and maintaining the existing team. “You have to hang on to your team members because they could go – they could leave and get another job tomorrow.” So, finding a good team is hard, but keeping it is just as hard. McKerchar’s approach is to encourage his team members to be the best version of themselves possible. “You hire smart people to tell you what to do. The role of the leader is to get the obstacles out of their way so they can do just that.” This doesn’t mean absolute carte blanche for the team. The leader must keep a light touch on the tiller to keep the team and its direction in line with the company’s business objectives. But the aim is to manage a happy and fulfilled team, because happy people stay when unhappy people leave. However, the one constant in cybersecurity is change. There’s this new thing called AI. And one of the most often touted effects of AI will be an increase in the automation of expertise, and a corresponding reduction of the need for human experts – and by extension, a narrowing of the skills gap. McKerchar is reserving judgment. “I spend a lot of time talking to my CISO peers,” he explains, “and I have to say the current narrative we’re hearing from the media and business leaders is very different from the one I’m hearing from peers.” He suggests that whatever reduction in hiring we’ve seen so far has been from firms taking a gamble – betting that in a year’s time they won’t need the hire, so they’re not doing it now. He also suspects that some firms are now reversing that bet. “It’s been an interesting time. The LLMs are trained on public data, and it’s a challenge to get them to work well within an organization where organizational rather than public context is everything in triaging alerts. My human ops analysts really understand the business, and where to go and who to speak to – they almost have a sixth sense over whether an alert is more or less serious than is obvious. AI will get there, but it’s not there yet.” It’s tempting to describe current AI as high in knowledge, but low in understanding. Nevertheless, adversarial use of AI is something that all defenders are watching closely. Cybersecurity is, by its nature, largely reactive. It is the attacker that is proactive, always looking for and developing new ways to attack; and the defender that must react with new ways to defend against new and previously unknown attack methodologies. AI is still a developing technology, and nobody yet knows its future capabilities. “That’s the million dollar question,” says McKerchar. “Where’s it going to land?” He gives two suggestions. The first is the current primary adversarial use of AI: developing more advanced lures for phishing. “There is some evidence of it being used to automate attacks at scale, but the quality of the phishing isn’t yet at the level of a sophisticated attacker. It’s just the volume that has been significantly increased.” He is more concerned with AI’s ability to find new vulnerabilities, and the attackers are bound to use this ability. Finding zero days is expensive, so when they are found by attackers, they tend to be used somewhat sparingly against high value targets with supply chain potential. But if the cost of the zero day is reduced and there are more of them, they will be used against smaller firms with weaker defenses. Those smaller firms with proprietary software are not typical targets for zero days; but as the cost of zero days comes down, so their attractiveness will go up. Mental health This doesn’t change the reactive nature of cyber defense – the difficulty is that it will increase the pressure on defenders through increased volume and sophistication of attacks. And this adds to the work of the CISO. Both the CISO and the security team will need to cope with increasing pressure. This isn’t new, but it’s getting worse. And sustained pressure is a primary cause of the mental health issue known as burnout. “Burnout is a real thing in cybersecurity,” comments McKerchar. It is complete mental exhaustion and withdrawal from work, and is described by the World Health Organization as ‘a syndrome conceptualized as resulting from chronic workplace stress that has not been successfully managed.’ Cybermindz uses a technique known as I-Rest to treat burnout, which affects both CISOs and the entire security team. I-Rest is also used by the military to treat PTSD, so it is tempting to consider burnout as a form of slow burn PTSD caused by long term unmitigated stress. But as with all illnesses, prevention is better than cure. “Take my own situation,” continues McKerchar. “I’ve been continuously on call for 18 years.” He applies the same formula to the entire cybersecurity workforce, from the day each employee starts employment until now, and still ongoing. “The worst thing about cybersecurity is there’s nearly always something brewing that makes you uneasy – and it always seems to get worse on a Friday.” Being on call in cybersecurity is 24/7, including every Saturday and Sunday. “Even when not in the office, there’s this constant unease that something could blow up at any time.” Preventing burnout requires reducing base stress levels and ensuring periods of zero stress. “You can’t expect people to put in a sprint when they’re running a constant marathon. So, I try to reduce the workload and increase the fun element. It’s not simply a case of insisting on decent work hours but also allowing people to work on the projects they want to work on – so the fun stuff as well as the critical projects.” Even without burnout, people’s effective IQ drops through simple tiredness. “The last thing you need is a team that is sitting there and operating at 60% of their intellect when they’re trying to do the most important work of their careers. So, when we have a big incident, it is important that we define shift rotations and handovers and prevent people from overworking. There’s always some who just want to work – they want to keep going. But identifying them and making sure they don’t feel all the weight is solely on their shoulders, and insisting they understand that they must work in a sustainable fashion because we need them sharp – that’s very important for me.” Managing stress levels, raising spirits, and avoiding constant tiredness is McKerchar’s way to prevent burnout. Hacking back A separate recurring theme in cybersecurity is whether cyber defenders should have the same right of retaliation as kinetic defenders. Few neutral observers question the right of Ukraine to retaliate in kind following the Russian invasion of 2022. Should cyber defenders have the same right following a cyberattack (a cyber invasion of their systems)? That is, should there be a right to hack back? It’s a perennial question, but the consensus is that such a right belongs only to the government and not to individual companies. That said, McKerchar and Sophos took the question to its limits in a project it calls Pacific Rim. It discovered Chinese hackers attacking Sophos firewalls, and increased its own observation and telemetry while improving its firewalls’ security. Over time, it discovered a compromised device that was being used by the attackers to develop exploits. It responded by putting its own kernel implant on the device so that it could monitor the attackers’ activity. At a superficial level, this implant could be viewed as a form of hacking back even though it involved a local rather than foreign device – but it wasn’t ‘hacking’. Sophos obtained legal counsel and liaised with both the US NSA and the UK NCSC to ensure conformance with privacy regulations, and legality through the compromised device’s EULA with Sophos. “I wouldn’t call it ‘hacking back’,” says McKerchar, “but we took some unusually robust actions to defend ourselves against this adversary. It’s more an example of walking the line, surveilling the adversaries while they developed exploits on our own devices, but keeping our customers safe from the actions we took.” Mentoring Advice, or ‘mentoring’ in the professional jargon, is another important facet of a CISO’s role. While not written into the job description, most CISOs happily advise members of their team on how to succeed with their own ambitions. This begs one question: what was the best mentoring, or advice, this CISO received in the early stages of his career? For McKerchar, it was the simple statement, “Executives don’t like surprises.” It didn’t sound profound, but he came to realize it was all about communication. Security must often deliver bad news to, or highlight failings in, other departments. How you deliver that news is important. “How you communicate these issues and how you bring people on board and get them working with you is remarkably hard. You must have good relationships. They must trust you, and you must be able to have one-on-one conversations first – there’s almost an order of how you want to tell people and it’s almost like a saving-face thing. That simple bit of advice helped me understand the importance of stakeholder and relationship management.” ‘Communication’ and ‘trust’ were recurring themes throughout our conversation with McKerchar. The advice he gives to his own team is individual, depending upon the person concerned. But the most common is, “Understand what it is you really want to achieve. People,” he continues, “tend to tell you what they think you want to hear. They’ll typically say, ‘I want to be a CISO, a leader’.” They don’t necessarily know whether they want to be a hands-on technical leader, or a hands-off theorist, a business leader, or a consultant. They’re basically just saying ‘I want to be a success’. But you must know the destination before you can choose the best route to get there. His second piece of advice is not to concentrate purely on technical skills. “I see so many people who just over-index on technical skills and don’t build up the emotional intelligence, the cross-functional execution and communication skills required to get stuff done in a large organization. That’s the number one thing I see holding people back.” Threats We always close these conversations with a simple question: what are the biggest threats we’ll likely face over the next few years? Certain themes are relatively consistent, such as AI. But McKerchar diverges. “I should probably say ‘AI’, but I’m going to say ‘Trust’; and especially within the cybersecurity industry. I think the cybersecurity industry has a bad and growing trust problem. And the reason is a distinct and continuing trend for cybersecurity products to be the cause of breaches.” He has a point. Recent examples include F5, SonicWall, Okta, Barracuda ESG, Codecov, MOVEit, Kaseya, 3CX, and of course SolarWinds. “As someone deep in the cybersecurity industry, the obvious response could be to stand aside and look on with some weird form of schadenfreude at the tribulations of our competitors. But the real problem is it creates a trust issue for the whole industry. Collectively, we need to up our game in how we build and develop our own products; and I don’t know how that’s going to happen, because the market incentives don’t typically push vendors in that direction.” If customers cannot trust the security products they use to defend themselves, everybody suffers – and this concern perhaps helps to explain the extreme measures he and his firm took to protect his own products, and his clients, from Chinese APTs during the Pacific Rim episode. Related: CISO Conversations: Are Microsoft’s Deputy CISOs a Signpost to the Future? Related: CISO Conversations: Maarten Van Horenbeeck, SVP & Chief Security Officer at Adobe Related: CISO Conversations: Nick McKenzie (Bugcrowd) and Chris Evans (HackerOne)
securityweek.comApr 15, 2026extracted
Researchers Spot Surge in Brute-Force Attacks from Middle East
Security researchers have detected a “sharp rise” in brute-force attempts to hijack SonicWall and Fortinet devices, with the vast majority (88%) appearing to come from the Middle East. Barracuda said most of these attempts were unsuccessful as they were either blocked outright by security tools or directed at invalid usernames. Although these attacks may simply have been routed through servers and networks in the region, the timing would seem to coincide with US and Israeli hostilities against Iran. There have been various reports of attacks from Iranian-affiliated hackers over recent weeks, including raids against US critical infrastructure providers and medtech firms. The line between state-backed efforts and financially motivated cybercrime is increasingly blurred, as evidenced by the re-emergence of the Pay2Key ransomware group. Edge devices such as the VPNs and firewall appliances manufactured by vendors like SonicWall and Fortinet are a popular target for attack given that they are internet-facing but also provide a foothold inside corporate networks. Barracuda said over half (56%) of all confirmed incidents from February to March related to this type of brute-force attack. “Attackers are aggressively scanning and testing perimeter devices for weak or exposed credentials,” warned Barracuda senior cybersecurity analyst, Laila Mubashar. “Even when attacks fail, persistent probing raises the risk that a single weak password or misconfiguration could lead to compromise.” She urged organizations to: Enforce strong, unique passwords on all network and security devices Enable multi-factor authentication (MFA) on all VPNs, firewalls and remote access services Monitor and investigate repeated failed login attempts Restrict management interfaces to trusted IP ranges where possible Rise in ClickFix Attacks Barracuda also sounded the alarm over a surge in a category of social engineering attacks known as “ClickFix,” in which users are tricked into copying and executing a malicious script in a bid to fix a non-existent technical issue. Mubashar explained that such attacks exploit user trust and anxiety. “The attackers use familiar elements and language such as pop-ups, prompts and running a fix,” she added. “Because ClickFix attacks rely on duping users into adding malicious commands themselves, such attacks are harder for automated security systems to spot.” Organizations should improve end-user education, restrict who can run PowerShell, scripts or command-line tools, and deploy tools to monitor for unusual behavior, Barracuda advised.
infosecurity-magazine.comApr 15, 2026extracted
RSAC 2026 Conference Announcements Summary (Days 3-4)
As hundreds of vendors descend on San Francisco for the RSAC 2026 Conference, the sheer volume of news can be overwhelming. To help you navigate the noise, SecurityWeek is providing a daily digest of the most significant announcements. Below is our curated roundup of essential news from the third and fourth days of the event (as well as some announcements we may have missed in the previous days). Roundups of announcements from day 1, day 2, and the days leading up to the conference are also available. Accenture has introduced Cyber.AI, a new cybersecurity solution that uses Anthropic’s Claude model as a central reasoning engine to automate security workflows. The platform integrates a library of autonomous agents to synthesize security data and provide contextual insights throughout the security lifecycle. It features a specialized component called Agent Shield to monitor and govern these autonomous agents in real-time to ensure they adhere to defined organizational policies. Akamai and Bolster AI detect brand impersonation and phishing Bolster AI and Akamai have teamed up to help organizations detect and disrupt brand impersonation and phishing campaigns targeting their customers. The new Brand Guardian solution combines Akamai’s global internet infrastructure with Bolster’s AI-driven fraud detection and automated takedown technology to detect impersonation campaigns earlier, observe attacks from the victim’s perspective, disrupt campaigns using automated investigation and takedown workflows, and understand campaign impact. Arctic Wolf Labs has analyzed over 22,000 AI‑assisted malware samples and found that a significant share of this malware is novel and harder to catch with traditional tools—39% initially evaded signature-based detection. While AI increases the scale of threats, most activity is not tied to sophisticated or known actors, and the resulting malware can still be detected with the right layered defenses. Barracuda Networks has announced enhancements to its BarracudaONE cybersecurity platform, along with a revamped global Partner Success Program, aimed at strengthening cyber resilience and supporting partner growth. The platform updates boost protection across email, network access, and generative AI usage. Barracuda has overhauled its Partner Success Program, creating a unified model for MSPs, resellers, and hybrid partners with expanded benefits and incentives. CrowdStrike announced the Charlotte AI AgentWorks ecosystem for building secure agents, with launch partners including Accenture, AWS, Anthropic, Deloitte, Kroll, NVIDIA, OpenAI, Salesforce, and Telefónica Tech. The ecosystem enables customers to leverage CrowdStrike’s no-code development platform and frontier AI models to securely build, orchestrate, and scale custom security agents, while opening new opportunities for partners to create agentic security businesses on the Falcon platform. CyberProof MDR analysts and threat researchers have identified a significant surge in PXA Stealer activity targeting global financial institutions during Q1 2026. These campaigns primarily leverage phishing emails containing malicious URLs that trigger the download of compromised ZIP attachments. Threat actors have demonstrated high levels of adaptability, utilizing diverse lures ranging from curriculum vitae and Adobe Photoshop installers to tax forms and legal documentation. Following the 2025 takedowns of major infostealers such as Lumma, Rhadamanthys, and RedLine, CyberProof observed that PXA Stealer activity has filled the resulting vacuum, seeing an estimated growth of 8-10%. Cyber Sierra announced a new collaboration with ST Engineering’s Cyber business to help organisations bring together AI‑driven governance and frontline cybersecurity operations for continuous, outcome-focused cyber resilience. DigiCert has introduced several updates to its Document Trust Manager platform to streamline digital signing workflows and enhance key security. The system now features centralized key management (eliminating the need for physical tokens by providing secure cloud-based storage for signing certificates). New unified workflows provide enterprise-wide visibility into signing activities (allowing administrators to monitor document integrity and track usage across the organization). The platform also supports various global PKI standards to ensure compliance with regional regulatory requirements for cross-border digital transactions. Ironscales announced ‘Email Attack of the Day,’ an ongoing email threat intelligence blog series spotlighting recent, real phishing attacks caught by the organization’s adaptive AI and its community of 30,000+ security professionals. Each post breaks down one attack — what it looked like, why it worked, and what users can do about it. The company also introduced new email security agents that anticipate, investigate, and prepare for advanced phishing attacks. Menlo Security has released a platform designed to monitor and control the activities of autonomous AI agents operating within web browsers. The platform provides visibility into agent-driven web sessions to prevent unauthorized data exfiltration and ensure compliance with corporate governance standards. The solution allows organizations to define granular permissions for AI agents. Minimus announced a new open source program that provides maintainers with free access to hardened container images, SBOM generation and analysis, and real-time threat intelligence. The initiative aims to close the security gap for open source projects that underpin critical infrastructure but lack enterprise-grade supply-chain security tooling. Accepted projects can integrate Minimus images into their pipelines to reduce attack surface, gain visibility into dependencies, and accelerate vulnerability remediation. Nile has updated its networking platform to incorporate “datacenter-class” security features designed to limit lateral movement within campus and branch environments. The architecture utilizes AI-driven automation to enforce granular micro-segmentation. By integrating these controls directly into the network fabric, the system aims to contain potential breaches by reducing the available attack surface. Singapore-based pQCee has introduced a crypto-agile Cryptography Next Generation (CNG) provider for Microsoft Windows. It allows enterprises, governments, and regulated industries to rapidly adopt post-quantum cryptographic algorithms, comply with national security requirements, and prepare for integration with emerging quantum hardware. The solution provides seamless support for custom post-quantum algorithms and implementations directly within Windows. Protos Labs has introduced a free tier of Protos AI, its agentic AI platform designed to automate the collection and analysis of cyber threat intelligence (CTI). The system utilizes specialized AI agents to execute tasks across the CTI lifecycle (including planning, evidence collection, and citation-backed reporting). The platform is model-agnostic and functions independently of existing security stacks to build ‘organizational intelligence memory’ by linking threat entities across historical investigations. Human analysts maintain control by approving investigation plans and validating the agents’ outputs before dissemination. Quokka Q-scout now integrates with Microsoft Sentinel to centralize mobile application risk intelligence across Microsoft Intune-managed devices. The connector automatically ingests app inventories from Intune, analyzes them using Quokka’s mobile app vetting engines, and streams security, privacy, and compliance risk findings into Sentinel. The Qualys Threat Research Unit (TRU) released what it described as the largest remediation study ever conducted, examining more than 1 billion CISA KEV records across over 10,000 organizations spanning four years. The study found that vulnerability volume has increased 6.5x in the last three years, while exploitation timelines have collapsed to -1 days. Despite processing more tickets, security teams left 63% of critical vulnerabilities open on day 7 in 2025, a deterioration from 56% in 2022. Out of 52 actively weaponized vulnerabilities that were analyzed, half were exploited before public disclosure. Singapore-based Scantist has announced the US launch of PAIStrike, an autonomous penetration testing platform designed to validate real-world security risks. PAIStrike functions as a coordinated multi-agent system that autonomously analyzes targets, devises multi-step attack strategies, executes exploits, evaluates results, and dynamically adjusts its tactics in real time. Skyhigh Security announced new capabilities for its Security Service Edge (SSE) platform. The company introduced new offerings and updates to strengthen its platform, including Next-Generation SSE Hybrid and Secure Browser Controls solutions, along with updates to Skyhigh DSPM to create a unified view of data risk across multi-vendor environments. Vorlon has launched two new products, AI Agent Flight Recorder and AI Agent Action Center, to provide forensics and coordinated response for enterprise AI and SaaS environments. The Flight Recorder uses intelligent simulation technology to capture a continuous audit trail of agent actions across various identities, APIs, and data classifications. To address identified risks, the Action Center prioritizes security findings and routes remediation guidance to relevant stakeholders. These tools integrate with existing security workflows, including SIEM and SOAR platforms.
securityweek.comMar 27, 2026extracted
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks Telecommunications providers around the world have been dealing with the burrowing efforts of the China-linked APTs for many years now. To help them identify hard-to-detect implants used by the China-based group dubbed Red Menshen, Rapid7 researchers have released a scanning script. BPFdoor US, Canadian, European and Asian telcos have been repeatedly hit by the infamous Salt Typhoon group in the past few years. Red Menshen has been previously observed using the BPFDoor implant/backdoor when targeting telecommunications providers across Asia and the Middle East, as well as organizations in the finance and retail sectors. Initial access is usually gained by exploiting known vulnerabilities in edge networking devices and VPN products or by leveraging compromised accounts. But, once inside, Red Menshen attackers are retaining long-term access by placing hard-to-detect kernel-level implants like BPFdoor and passive backdoors like TinyShell. “What makes BPFdoor particularly unique is its ability to operate at the kernel level without exposing a traditional network footprint,” Christiaan Beek, VP of Cyber Intelligence at Rapid7, told Help Net Security. This unconventional Linux malware abuses Berkeley Packet Filter (BPF) functionality to inspect network traffic directly inside the kernel, and passively listens for specially crafted network packets (aka “magic packets”) that will activate it. BPFDoor activation relying on magic packets (Source: Rapid7) Rapid7 researchers fittingly describe this type of implant as “sleeper cells” – waiting to spring into action when called, but otherwise laying dormant and blending into the environment. When triggered, BPFdoor spawns a bind shell or reverse shell. The researchers have analyzed a number of BPFdoor samples and have discovered that older and newer variants: Use code to masquerade as legitimate system services that run bare-metal infrastructure commonly deployed in telecom environments Spoof core containerization components Are capable of monitoring telecom-native protocols such as the Stream Control Transmission Protocol Don’t just rely on magic packets to spring into action, but can also be triggered with packets embedded within seemingly legitimate (encrypted) HTTPS traffic Use older or non-standard encryption routines to confuse inspection systems Use specially crafted Internet Control Message Protocol (ICMP) payloads to signal back to the operator, but also to pass execution instructions from one compromised host to another These techniques target different security boundaries, “from TLS inspection at the edge to IDS detection in transit and endpoint monitoring on the host, illustrating a deliberate effort to operate across the full defensive stack,” the researchers pointed out. A BPFDoor detection script BPFdoor isn’t the only “magic packet” malware out there: there’s the SEASPY backdoor targeting Barracuda Networks’ Email Security Gateway appliances, and the J-magic backdoor that’s been loaded by attackers into enterprise-grade Juniper router. Symbiote, a Linux userland-level rootkit/backdoor, is also capable of kernel packet filtering and hiding malicious network traffic from packet capture tools. In complex and noisy telecom environments, implants like BPFdoor are difficult to catch as – according to Rapid7 – many organizations lack visibility into kernel-level operations, raw packet filtering behavior, and anomalous high-port network activity on Linux systems. “Unlike most backdoors, [BPFdoor] doesn’t rely on open ports or persistent connections. You’re essentially trying to identify malicious behavior hidden inside otherwise normal network traffic. It’s like looking for a needle that looks and smells like hay, while the haystack itself keeps changing,” Beek added. Company researchers have therefore created a scanning script designed to detect known/analyzed BPFDoor variants across Linux environments, and are offering it to defenders. “The script is highly effective at identifying known patterns and behaviours we’ve validated in real samples,” Beek told us. That said, it can miss highly stealthy or evolving variants and may flag unusual but legitimate activity, so it should be used as part of a broader detection strategy. Unfortunately, the point of this type of threat is that organizations can’t be 100% certain that they’ve removed them all. “These threats shift the conversation from ‘Did we remove it?’ to ‘Do we have enough visibility to trust the system again?’,” he added. As their research is ongoing, Rapid7 may or may not create a detection tool for similar threats like Symbiote. “Rather than chasing individual malware families, we’re focusing on detecting the underlying techniques such as kernel-level stealth and covert network behaviour across multiple threats,” Beek concluded. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comMar 26, 2026extracted
Iran-Linked Pay2Key Ransomware Group Re-Emerges
Security experts have warned that an Iranian ransomware group has returned with enhanced evasion, execution and anti-forensics capabilities. Previously linked to Tehran and usually targeting victims aligned with the regime’s interests, Pay2Key has been active since 2020. However, a new report from Halcyon and Beazley Security warned that “recent US-Iran tensions appear to have accelerated activity from the group.” The report dissected a new attack on a US healthcare provider which appeared to show an evolving set of TTPs. It’s unclear whether the group bought access from an initial access broker or performed reconnaissance on the victim itself. However, with a foothold in the network, the actors used TeamViewer to establish “interactive access” and then began harvesting passwords for lateral movement, using Mimikatz, LaZagne, and ExtPassword. They then used “Advanced IP Scanner" and ns.exe (presumed to be NetScan) to find hosts and validate credentials, the report explained. “The threat actors used harvested credentials to pivot across systems, and interacted with Active Directory via dsa.msc, the built-in AD ‘Users and Computers’ console. We believe this was to prevent tooling from automatically flagging the access as anomalous or suspicious,” it continued. “We believe this was used to identify accounts to be used in concert with ransomware deployment as well as accessing an assortment of backup-related software on victim hosts. Backup systems enumerated include IBackup, Barracuda Yosemite, and Windows Server Backup.” Ransomware execution was performed through a self-extracting 7zip archive (SFX), abc.exe, which is consistent with previous campaigns. Encryption of the entire infrastructure took just three hours. The group also deployed a "No Defender" evasion toolkit, which it then removed to hide its tracks. There was no evidence of data exfiltration, which the report authors claimed “could be due to targeted destruction of evidence by the group.” Questions Over Iran Links The attack follows a previous campaign analyzed by Morphisec that coincided with US missile strikes on Iran last year. Since July 2025, the group has received more than $8m in ransom payments linked to 170 victims. This could indicate that Pay2key remains an Iranian-linked operation whose attacks intensify during periods of geopolitical tension involving the country – but it’s not a given. “The group's attempted sale of its entire operation in late 2025, combined with observed ties to Russian-speaking threat actors on criminal forums, raises unresolved questions about the current ownership, operational control and future trajectory of the group's RaaS platform,” the Halcyon report noted. Whatever the ownership, however, network defenders should be aware of the threat it poses, the report concluded. “The group does not always appear to prioritize extortion and financial gain over the destruction of victim environments for strategic impact,” it said. “Defenders should treat these findings as a clear signal that Pay2Key remains an active, unpredictable, and politically motivated threat whose tactics and objectives warrant ongoing monitoring and proactive intelligence sharing across the security community.”
infosecurity-magazine.comMar 26, 2026extracted
Barracuda strengthens cyber resilience with BarracudaONE platform updates
Barracuda strengthens cyber resilience with BarracudaONE platform updates Barracuda Networks has announced advancements to the BarracudaONE cybersecurity platform and Barracuda Partner Success Program. The latest innovations strengthen cyber resilience across email, network access and generative AI usage, while the enhanced partner program delivers new benefits, incentives and tools that help partners accelerate growth and profitability. “Email and identity‑based attacks are intensifying at an unprecedented pace, and generative AI is introducing an entirely new layer of risk,” said Rohit Ghai, Chief Executive Officer at Barracuda. “With our newest BarracudaONE and partner program enhancements, we’re accelerating innovation and delivering on our commitment to provide a platform that is easy to buy, deploy and use as well as being partner-first and partner-only. We’re harnessing AI to empower organizations to keep pace with a rapidly evolving threat landscape and build lasting resilience with confidence.” Advancing cyber resilience BarracudaONE delivers resilience for organizations, including managed service providers (MSPs) and their customers, through an intelligent, and open ecosystem. New advancements include: Email security for Google Workspace: Barracuda Email Protection neutralizes phishing, account takeover and other attacks with expanded impersonation protection and automated incident response for Google Workspace. Organizations benefit from consistent, compliant email security across both Microsoft 365 and Google Workspace, reducing risk, complexity and recovery time. Network edge security: Barracuda SecureEdge Access introduces a cloud‑delivered, fully integrated secure service edge solution that brings together secure internet access, zero trust application access, firewall‑as‑a‑service, and visibility and policy controls for generative AI usage. This streamlined, easy to deploy offering strengthens defenses across distributed environments while reducing risk, complexity and tool sprawl. Generative AI risk visibility: Barracuda AI Security provides safe, compliant oversight of generative AI usage. Included at no additional cost within BarracudaONE, this new capability offers visibility into shadow AI activity, risk scoring and policy enforcement to block or redirect noncompliant use. Centralized, multitenant dashboards help organizations reduce data exposure and improve AI governance. Accelerating partner growth Barracuda has modernized its global Partner Success Program to support how partners operate, rolling MSPs and resellers into one unified, flexible program. The new fit‑for‑purpose model supports multiple routes to market and makes it easier for partners to grow faster with BarracudaONE. Unified tiering expands benefits and incentives to all partners. A set of foundational benefits is available to all partners, with new “boost benefits” tailored to maximize value based on a partner’s chosen route to market. A refreshed rebate structure drives predictable profitability, while an overhauled certification curriculum and the new Barracuda Mastery Program deepens technical expertise and sharpens service differentiation. New Partner Success teams and high‑value support plans rolling out in the coming months will further strengthen partner engagement and accelerate customer outcomes. The new AI‑powered partner portal delivers an integrated experience for all partner types with guided onboarding, automated deal registration, data‑driven dashboards, personalized learning paths, simplified MDF tracking, and streamlined access to co‑brandable assets and enablement resources. With greater visibility into requirements, benefits, and progression, partners can unlock even more value across the program. AI‑driven marketing automation capabilities are also in development to help partners scale their go‑to‑market efforts.
helpnetsecurity.comMar 25, 2026extracted
Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
Microsoft has warned of fresh campaigns that are capitalizing on the upcoming tax season in the U.S. to harvest credentials and deliver malware. The email campaigns take advantage of the urgency and time-sensitive nature of emails to send phishing messages masquerading as refund notices, payroll forms, filing reminders, and requests from tax professionals to deceive recipients into opening malicious attachments, scanning QR code, or interacting with suspicious links. "Many campaigns target individuals for personal and financial data theft, but others specifically target accountants and other professionals who handle sensitive documents, have access to financial data, and are accustomed to receiving tax-related emails during this period," the Microsoft Threat Intelligence and Microsoft Defender Security Research teams said in a report published last week. While some of these efforts direct users to sketchy pages designed through Phishing-as-a-service (PhaaS) platforms, others result in the deployment of legitimate remote monitoring and management tools (RMMs), such as ConnectWise ScreenConnect, Datto, and SimpleHelp, enabling the attackers to gain persistent access to compromised devices. The details of some of the campaigns are below - Using Certified Public Accountant (CPA) lures to deliver phishing pages associated with the Energy365 PhaaS kit to capture victims' email and password. The Energy365 phishing kit is estimated to be sending hundreds of thousands of malicious emails on a daily basis. Using QR code and W2 lures to target approximately 100 organizations, mainly in the manufacturing, retail, and healthcare industries located in the U.S., to direct users to phishing pages mimicking the Microsoft 365 sign-in pages and built using the SneakyLog (aka Kratos) PhaaS platform to siphon their credentials and two-factor authentication (2FA) codes. Using tax-themed domains for use in phishing campaigns that trick users into clicking on bogus links under the pretext of accessing updated tax forms, only to distribute ScreenConnect. Impersonating the Internal Revenue Service (IRS) with a cryptocurrency lure that specifically targeted the higher education sector in the U.S., instructing recipients to download a "Cryptocurrency Tax Form 1099" by accessing a malicious domain ("irs-doc[.]com" or "gov-irs216[.]net") to deliver ScreenConnect or SimpleHelp. Targeting accountants and related organizations, asking for help to file their taxes by sending a malicious link that leads to the installation of Datto. Microsoft said it also observed a large-scale phishing campaign on February 10, 2026, in which more than 29,000 users across 10,000 organizations were affected. About 95% of the targets were located in the U.S., spanning industries like financial services (19%), technology and software (18%), and retail and consumer goods (15%). "The emails impersonated the IRS, claiming that potentially irregular tax returns had been filed under the recipient's Electronic Filing Identification Number (EFIN). Recipients were instructed to review these returns by downloading a purportedly legitimate 'IRS Transcript Viewer,'" the tech giant said. The emails, which were sent through Amazon Simple Email Service (SES), contained a "Download IRS Transcript View 5.1" button that, when clicked, redirected users to smartvault[.]im, a domain masquerading as SmartVault, a well-known document management and sharing platform. The phishing site relied on Cloudflare to keep bots and automated scanners at bay, thus ensuring that only human users are served the main payload: a maliciously packaged ScreenConnect that grants the attackers remote access to their systems and facilitates data theft, credential harvesting, and further post‑exploitation activity. To stay safe against these attacks, organizations are recommended to enforce 2FA on all users, implement conditional access policies, monitor and scan incoming emails and visited websites, and prevent users from accessing the malicious domains. The development coincides with the discovery of several campaigns that have been found to drop remote access malware or conduct data theft - Using fake Google Meet and Zoom pages to lure users into fraudulent video calls that ultimately deliver remote-access software like Teramind, a legitimate employee monitoring platform, by means of a bogus software update. Using a fraudulent website that leverages the Avast branding to trick French-speaking users into handing over their full credit card details as part of a refund scam. Using a typosquatted website impersonating the official Telegram download portal ("telegrgam[.]com") to distribute trojanized installers that, in addition to dropping a legitimate Telegram installer, execute a DLL responsible for launching an in-memory payload. The malware then initiates communication with its command-and-control infrastructure to receive instructions, download updated components, and maintain persistent access. Abusing Microsoft Azure Monitor alert notifications to deliver callback phishing emails that use invoice and unauthorized-payment lures. "Attackers create malicious Azure Monitor alert rules, embedding scam content in the alert description, including fake billing details and attacker-controlled support phone numbers," LevelBlue said. "Victims are then added to the Action Group linked to the alert rule, causing Azure to send the phishing message from the legitimate sender address [email protected]." Using quotation-themed lures in phishing emails to deliver a JavaScript dropper that connects to an external server to download a PowerShell script, which launches the trusted Microsoft application "Aspnet_compiler.exe" and injects into it an XWorm 7.1 payload via reflective DLL injection. The updated malware comes with a .NET-developed component engineered for stealth and persistence. Similar requests for quotation lures have also been used to trigger a fileless Remcos RAT infection chain. Using phishing emails and ClickFix ploys to deliver NetSupport RAT and gain unauthorized system access, exfiltrate data, and deploy additional malware. Using Microsoft Application Registration Redirect URI's ("login.microsoftonline[.]com") in phishing emails to abuse trust relationships and bypass email spam filters to redirect users to phishing websites that capture victims' credentials and 2FA codes. Abusing legitimate URL rewriting services from Avanan, Barracuda, Bitdefender, Cisco, INKY, Mimecast, Proofpoint, Sophos, and Trend Micro to conceal malicious URLs in phishing emails evades detection. "Threat actors have increasingly adopted multi-vendor chained redirection in their phishing campaigns," LevelBlue said. "Earlier activity typically relied on a single rewriting service, but newer campaigns stack multiple layers of already‑rewritten links. This nesting makes it significantly harder for security platforms to reconstruct the full redirect path and identify the final malicious destination." Using malicious ZIP files impersonating a wide range of software, including artificial intelligence (AI) image generators, voice-changing tools, stock-market trading utilities, game mods, VPNs, and emulators, to deliver Salat Stealer or MeshAgent, along with a cryptocurrency miner. The campaign has specifically targeted users in the U.S., the U.K., India, Brazil, France, Canada, and Australia. Using digital invitation lures sent via phishing emails to divert users to a fake Cloudflare CAPTCHA page that delivers a VBScript, which then runs PowerShell code to fetch an evasive .NET loader dubbed SILENTCONNECT from Google Drive to eventually deliver ScreenConnect. The findings follow an uptick in RMM adoption by threat actors, with the abuse of such tools surging 277% year-over-year, according to a recent report published by Huntress. One notable tactic involves the daisy-chaining of distinct RMM tools to fragment telemetry, distribute persistence, and complicate attribution and containment efforts, the company added. "As these tools are used by legitimate IT departments, they are typically overlooked and considered 'trusted' in most corporate environments," Elastic Security Labs researchers Daniel Stepanic and Salim Bitam said. "Organizations must stay vigilant, auditing their environments for unauthorized RMM usage."
thehackernews.comMar 23, 2026extracted
AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks
New research from internet infrastructure giant Akamai shows that layer 7 (application layer) DDoS attacks have increased in volume while Layer 3 (network layer) and layer 4 (transport layer) attacks have increased in scale. These, together with increasing API and web application attacks have converged into a new operating model for attackers. The latest State of the Internet Report from Akamai finds three major developments over the last year: DDoS attacks continue but evolve; API attacks increase, driven largely (but not solely) by growth in corporate use of agentic AI; and criminal use of AI as a force multiplier makes attacks cheaper, more sophisticated, stealthier and more difficult to attribute. These are no longer singular attacks. Web app attacks, API abuse, bot activity and DDoS attacks appear as parts of the same campaign. “Convergence has shifted from an emerging trend to an operating model,” warns Brent Maynard, senior director for cybersecurity strategy at Akamai. DDoS attacks DDoS attacks continue to increase, both in quantity and effect. Over the last few years, the traditional layer 3 and layer 4 attacks have been joined by newer layer 7 attacks (which have increased by 104% over the last three years). The former floods the network and transport layers, ultimately disrupting company/customer interaction. The latter attacks APIs and web apps and are easier to launch via botnets and AI. They disrupt the victim’s operations, without necessarily causing visible downtime, making them difficult to detect. Layer 3 and layer 4 attacks have increased at a slower rate, but have achieved massive scale. Mirai remains the primary culprit but has been joined by variants and copycat botnets – some of which are offered as commercial DDoS for hire services. Hacktivism remains the primary motivation, and with ongoing political tensions throughout EMEA, this is unlikely to stop. With the US/Iran conflict, it may grow in North America this year. However, we cannot ignore the possibility of inter-company rivalry and competition also being or becoming a separate motivation. Convergence of attack capabilities can be seen in the appearance of both DDoS categories appearing in a single attack. Akamai pointed to “A customer that experienced a dynamic attack powered by a TurboMirai variant that shifted between Layers 3 and 4 and Layer 7.” A different type of convergence is seen in Qilin, a Russia-linked RaaS group that has now reportedly added DDoS to its toolkit, and is currently the top ransomware threat targeting the US. “Qilin has updated its program and capabilities regularly,” reported Barracuda separately. “Throughout 2025, it has added spam campaigns, DDoS attack capabilities, automated network propagation, and automated ransom negotiation from within the affiliate panel.” API attacks APIs are among the most exposed entry points into the enterprise environment. Eighty-seven percent of companies experienced an API-related security incident in 2025. “APIs are now the prime targets of exploitation,” comments Akamai. API attacks can also be used to increase the size of level 3 and 4 DDoS attacks. In June 2025, Akamai described, “how unsanitized JSON in API requests allowed attackers to run arbitrary commands, compromise exposed servers, and enroll them into DDoS‑capable botnets that receive instructions from remote command and control infrastructure to launch DDoS attacks.” Kaspersky blogged similarly around the same time. API attacks are also one of the hardest to detect, especially courtesy of SaaS web apps. Web apps increasingly include agentic AI with multiple APIs. But in the haste to improve their products above the competition, SaaS can add agentic but omit to keep their customers fully cognizant; so, SaaS apps can simultaneously increase complexity and reduce visibility into the software being used. This is shadow AI. When the shadow AI includes undocumented APIs, it complicates and increases the existing shadow API problem. This combination of increased use of APIs in SaaS apps together with the growth of API attacks in general has fueled an ongoing growth in web attack volume, up by 73% from the beginning of 2025 through the end of 2025. “Adversaries continuously probe enterprise environments, from customer-facing websites to back-end APIs, for exploitable security gaps that can lead to full-scale breaches,” reports Akamai. “From an attacker’s perspective,” it writes, “for every web application there are APIs that expose functions and (potentially) data. The more vulnerable and easier the apps and APIs are to compromise, the quicker the threat actors can reach their objectives. The rise of AI agents that consume APIs to interact with the real world amplifies the problem.” Steve Winterfeld, advisory CISO at Akamai, explains, “APIs are becoming more common. Companies are rapidly moving their infrastructure to APIs, and they’re also moving rapidly to AI. But as they do this, there are problems. Whenever you have transformation, you have difficulty with security. It’s just natural. So, you see API attacks up by 113% because that’s where the greatest return on investment for the attacker lives, along with the weakest security.” “As a CISO,” says Winterfeld, “this report highlights the need for me to review my risk portfolio. Is my API program solid? Do I know what the business is doing with AI? Have I validated that my DDoS protections can handle the latest and greatest of these, including the layer 7 attacks that degrade my performance rather than stop my operation? Can I handle these new huge areas?” The whole report is a testament to the need for security itself to converge. Just as, for attackers, “Convergence has shifted from an emerging trend to an operating model” by combining and blending web app attacks, API abuse, bot activity and DDoS attacks, so too must defenders converge their resources. It is no longer sufficient to have one team concentrating on API security, another focused on genAI and LLMs, and another concentrating on web attacks – they need to converge and integrate to maximize protection against this new attack operating model. Related: Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbps Related: TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks Related: API Threats Grow in Scale as AI Expands the Blast Radius Related: Cyber Insights 2026: API Security – Harder to Secure, Impossible to Ignore
securityweek.comMar 17, 2026extracted
How Pirated Software Turns Helpful Employees Into Malware Delivery Agents
Getting your hands on free software may seem attractive, but is often dangerous. Employees welcome opportunities to improve their work and benefit their employers. This can include downloading free versions of apparently useful apps that normally require a paid license to use. Sadly, many of these are pirated and / or cracked versions containing malware. Barracuda reports, “Over the last month, Barracuda’s SOC tools and analysts have detected multiple instances of users trying to download and activate pirate or cracked versions of software and unauthorized installers onto corporate endpoints.” These are apps not included in the company’s ‘allowed software list’. The employee understands he or she is doing something illicit, so disguises, or at least doesn’t highlight the activity. If the installation process requests that anti-virus should be turned off, it may be accepted as part of the process of quietly installing an unsanctioned app. But the process is likely to be installing more than the app. While it might indicate normal installation, it may also quietly be installing malware that could hide itself before the anti-virus is turned back on. “Pirate (illegally copied) and cracked (tampered) versions of software often include malicious content and can lead to malware infections, credential theft, cryptominers, session hijacking, software compromise, ransomware and more,” warns Barracuda. If the malware is an infostealer, it could activate, perform its purpose and be gone before it can be detected. The best defense is prevention. Recognizing warning signs such as unexpected executables in user accessible locations, such as ‘Downloads’ folders could be a red flag. But executables are likely to be given unsuspicious names, deliberately chosen to sound legitimate and look reassuring and routine. Activate.exe, activate.x86.exe and activate.x64.exe are typical examples. “In most malicious cases, ‘activate.exe’ doesn’t actually activate anything. Instead, it loads malware, droppers that can install additional malware, or acts as a wrap for launching hidden payloads,” warns Barracuda. This is social engineering with an advantage. Any employee that takes the bait (intending only to benefit the company with an improved work rate) is likely to assist the attacker in the delivery before it quietly drops the payload. Cleaning the system after infection can be complex. The original rogue software and activator files should be removed, and the installer, crack, keygen and extracted folders should be deleted. Scan for any malware (while understanding that it may be too late to find all of it) and undo any licensing bypass changes. It is probable that the device will need to be reimaged or rebuilt; for example, if system files or core application binaries were replaced, or you cannot confidently undo all changes made by the crack. Detection and prevention is required before the malware payload is triggered. Recovery is complex and tedious. What is clear is that none of this may be fully realizable without technology assistance. Detection and prevention would benefit from behavioral analysis, while recovery requires assistance rather than reliance on obvious visibility. “Employees downloading free, unofficial or unlicensed software to their company devices represent a major security risk, as they can become the entry points for serious security incidents,” says Laila Mubashar, senior cybersecurity analyst at Barracuda. “Organizations urgently need to put safeguards in place to protect employees from themselves.” In short, preventing of the consequence of pirated apps focuses on the same requirements for limiting any social engineering: user awareness training to recognize the threat; good management/staff communication channels (in this case so that employees can voice their wishes and management can consider adding the desired app to its ‘allowed’ list; and technology backup for detecting unusual behavior and blocking and if necessary cleaning up after installation. Related: Stealthy Mac Malware Delivered via Pirated Apps Related: Cyber Insights 2026: Social Engineering Related: Going Into the Deep End: Social Engineering and the AI Flood
securityweek.comMar 4, 2026extracted
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024 Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Security at AI speed: The new CISO reality The CISO role has changed significantly over the past decade, but according to John White, EMEA Field CISO, Torq, the most disruptive shift is accountability driven by agentic AI. In this Help Net Security interview, White explains how security leaders must design and govern hybrid workforces where humans and AI agents operate side by side, making decisions and acting at scale. He notes that automation is moving beyond simple task execution into real-time insight and response. REMnux v8 brings AI integration to the Linux malware analysis toolkit REMnux, a specialized Linux distribution for malware analysis, has released version 8 with a rebuilt platform based on Ubuntu 24.04 and a new capability aimed at connecting AI agents directly to its toolset. Your encrypted data is already being stolen Quantum computing is often treated as a distant, theoretical cybersecurity issue. According to Ronit Ghose, Global Head, Future of Finance of Citi Institute, that mindset is already putting financial institutions at risk. The biggest misconception, he says, is that quantum threats begin on a single future Q-day, when quantum machines suddenly crack encryption. In reality, adversaries can harvest encrypted data today and decrypt it later, creating long-term exposure for banks handling sensitive identity and transaction data. SecureClaw: Dual stack open-source security plugin and skill for OpenClaw SecureClaw is an open-source project that adds security auditing and rule-based controls to OpenClaw agent environments. The tool is published by Adversa AI and is designed to work with OpenClaw and related agents such as Moltbot and Clawdbot. Everyone uses open source, but patching still moves too slowly Enterprise security teams rely on open source across infrastructure, development pipelines, and production applications, even when they do not track it as a separate category of technology. Open source has become a default building block in many environments, and the operational risks now look like standard enterprise security problems: patch delays, version sprawl, and aging platforms that stay online longer than planned. The defense industrial base is a prime target for cyber disruption Cyber threats against the defense industrial base (DIB) are intensifying, with adversaries shifting from traditional espionage toward operations designed to disrupt production capacity and compromise supply chains. In this Help Net Security interview, Luke McNamara, Deputy Chief Analyst, Google Threat Intelligence Group, explains how attackers target the broader defense ecosystem and why identity has become the new security boundary. One stolen credential is all it takes to compromise everything Attackers often gain access through routine workflows like email logins, browser sessions, and SaaS integrations. A single stolen credential can give them a quick path to move across systems when access permissions are broad and visibility is fragmented. That pattern appears across more than 750 incident response engagements covered in Unit 42’s Global Incident Response Report 2026. The CISO view of fraud risk across the retail payment ecosystem In this Help Net Security interview, Paul Suarez, VP and CISO at Casey’s, explains how his team manages patching and upgrades for fuel payment systems with long hardware lifecycles. He also discusses risks tied to QR code payments and outlines why loyalty abuse can be hard to spot. Suarez shares how Casey’s monitors payment systems across stores, corporate networks, and third-party processors. Google patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441) Google released a security update for Chrome to address a high-severity zero‑day vulnerability (CVE-2026-2441) on Friday. CVE-2026-2441 is a use-after-free bug in the CSS processing component of Google Chrome, which allows a remote attacker “to execute arbitrary code inside a sandbox via a crafted HTML page.” OpenClaw creator Peter Steinberger joins OpenAI Peter Steinberger, the Austrian software developer who vibe coded the popular OpenClaw autonomous AI agent, has joined OpenAI. The reason why Steinberger chose OpenAI to achieve this goal is, professedly, his lack of interest in building a company and his wish to “change the world” – and do it quickly. Firmware-level Android backdoor found on tablets from multiple manufacturers A new Android backdoor embedded directly in device firmware can quietly take control of apps and harvest data, Kaspersky researchers found. The malware, named Keenadu, was discovered during an investigation into earlier Android threats and appears to have been inserted during the firmware build process, not after devices reached users.  Design weaknesses in major password managers enable vault attacks, researchers say Can cloud-based password managers that claim “zero-knowledge encryption” keep users’ passwords safe even if their encrypted-vault servers are compromised? Researchers at ETH Zurich and Università della Svizzera italiana set out to answer that question, and the answer is (unfortunately) no. Notepad++ secures update channel in wake of supply chain compromise Notepad++, the popular text and source code editor for Windows whose update mechanism was hijacked last year, has been updated to prevent similar attacks in the future. The hijacking of the update mechanism was confirmed earlier this month by Notepad++ maintainer Don Ho. Scammers exploit trust in Atlassian Jira to target organizations Threat actors have leveraged legitimate email notification feature of Atlassian Jira to deliver localized scam emails at scale. From late December 2025 through late January 2026, victims were targeted with spam emails from legitimate-looking Atlassian Jira Cloud addresses. China-linked hackers exploited Dell zero-day since 2024 (CVE-2026-22769) A suspected China-linked cyberespionage group has been covertly exploiting a critical zero-day flaw (CVE-2026-22769) in Dell’s RecoverPoint for Virtual Machines software since at least mid-2024, according to new research from Google’s threat intelligence team and Mandiant. The attackers deployed stealthy backdoors (BRICKSTORM and GRIMBOLT), a webshell (SLAYSTYLE) and maintained long-term access inside targeted networks. Bug in widely used VoIP phones allows stealthy network footholds, call interception (CVE-2026-2329) A critical security vulnerability (CVE-2026-2329) in Grandstream VoIP phones could let hackers remotely take full control of the devices and even intercept calls, Rapid7 researchers discovered. Data on 1.2 million French bank accounts accessed in registry breach In late January 2026, a malicious intruder accessed France’s national bank account registry, FICOBA, enabling them to view information tied to 1.2 million accounts, the Ministry of the Economy and Finance disclosed on Wednesday. TV5 Monde reported that the perpetrator (or perpetrators) obtained login credentials belonging to a civil cervant authorized to use the database and then used those credentials to explore its contents. Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119) Microsoft has disclosed a privilege-escalation vulnerability in Windows Admin Center (WAC), a browser-based platform widely used by IT administrators and infrastructure teams to manage Windows clients, servers, clusters, Hyper-V hosts and virtual machines, as well as Active Directory-joined systems. Criminals create business website to sell RAT disguised as RMM tool A RAT masquerading as legitimate remote monitoring and management (RMM) software is being sold to cybercriminals as a service, Proofpoint researchers recently discovered. The fake RMM tool, called TrustConnect, was being marketed via an LLM-created website parked on trustconnectsoftware[.]com, supposedly belonging to “TrustConnect Software PTY LTD”. LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi The Acronis Threat Research Unit (TRU) has identified a new and significantly enhanced version of the LockBit ransomware, LockBit 5.0, currently being deployed in active campaigns. The latest variant demonstrates expanded cross-platform capabilities, enabling attackers to target Windows, Linux, and VMware ESXi systems within a single coordinated attack. Don’t panic over CISA’s KEV list, use it smarter In this Help Net Security video, Tod Beardsley, VP of Security Research at runZero, explains what CISA’s Known Exploited Vulnerabilities (KEV) Catalog is and how security teams should use it. He shares his perspective as a former section chief for KEV at CISA and breaks down common misunderstandings about what the list represents. Cybersecurity in cross-border logistics operations In this Help Net Security video, Dieter Van Putte, CTO at Landmark Global, discusses how cybersecurity has become a core part of global supply chain operations. He explains that logistics is now also about data moving between carriers, customs authorities, warehouses, brokers, and customers. That constant flow increases risk and expands the attack surface. In GitHub’s advisory pipeline, some advisories move faster than others GitHub Security Advisories are used to distribute vulnerability information in open-source projects and security tools. A new study finds that only a portion of those advisories ever pass through GitHub’s formal review process. Android 17 beta brings privacy, security, and performance changes Google has released the first beta of Android 17, giving developers an early view of changes to core app behavior, platform tooling, performance, media handling, and connectivity. The company plans to move quickly from this beta toward the Platform Stability milestone, targeted for March, where final APIs and behavior definitions for apps will be delivered. UK sets course for stricter AI chatbot regulation The UK government has announced immediate action to force AI chatbot providers to comply with laws requiring online platforms to protect children from illegal and harmful content. Providers that fail to meet these duties will face legal consequences. Microsoft equips CISOs and AI risk leaders with a new security tool Microsoft released Security Dashboard for AI in public preview for enterprise environments. The dashboard aggregates posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into a single view within security tools. Phobos ransomware affiliate arrested in Poland Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) detained a 47-year-old man suspected of creating, acquiring, and sharing computer programs used to unlawfully obtain information stored in computer systems. He faces a potential prison sentence of up to five years. Pressure builds on Grok AI, Ireland launches investigation The Irish Data Protection Commission (DPC) opened an investigation into X over concerns that its Grok AI chatbot was used to generate sexualized deepfakes. The investigation focuses on the apparent creation and publication of potentially harmful, non-consensual intimate or sexualised images on X using generative AI tools linked to the platform’s Grok LLM. Claude Sonnet 4.6 launches with improved coding and expanded developer tools Anthropic released Claude Sonnet 4.6, marking its second major AI launch in less than two weeks. According to Anthropic, Sonnet 4.6 delivers improved coding skills to more users. Tasks that once required an Opus-class model, including economically valuable office work, are handled by Sonnet 4.6. The model also brings improvements in computer use capabilities compared to earlier Sonnet versions. Attackers keep finding the same gaps in security programs Attackers keep getting in, often through the same predictable weak spots: identity systems, third-party access, and poorly secured perimeter devices. A new threat report from Barracuda based on Managed XDR telemetry from 2025 shows that many successful incidents still start with basic access and configuration failures, not advanced malware. Microsoft signals breakthrough in data storage that can last for generations Microsoft announced progress on Project Silica, its research initiative focused on developing durable, long-term quartz glass-based data storage technology. Rising global data volumes increase the need for storage that can last for generations. Researchers believe this technology could preserve information for up to 10,000 years. UK sounds alarm on rising cyber risks to businesses The UK government launched a national campaign urging businesses to strengthen basic cyber defenses. The initiative follows new figures highlighting the scale of the threat. Serious cyber incidents cost businesses an average of £195,000, with about half of small firms experiencing one in the past 12 months, officials say. Open-source benchmark EVMbench tests how well AI agents handle smart contract exploits EVMbench is a new open-source benchmark designed to test AI agents on practical smart contract security tasks. The benchmark was developed by OpenAI and Paradigm, and it focuses on real-world vulnerability patterns drawn from audited codebases and contest reports. Adidas investigates alleged data breach affecting 815,000 records Adidas confirmed it is investigating a possible data breach involving one of its third-party customer service providers. The company stated that there is no indication its IT infrastructure, e-commerce platforms, or consumer data were impacted by the incident. Poland restricts Chinese-made cars at protected military sites Poland’s military leadership has decided that cars manufactured in the People’s Republic of China will no longer cross the gates of sensitive military bases. The decision follows a risk analysis focused on the growing integration of digital systems in cars and the potential for uncontrolled acquisition and use of data by those systems. 651 arrested, $4.3 million recovered in African cybercrime sweep Operation Red Card 2.0, supported by INTERPOL and involving law enforcement agencies from 16 African countries, led to 651 arrests and the recovery of more than $4.3 million from online scams. Running from 8 December 2025 to 30 January 2026, the operation targeted networks behind high-yield investment fraud, mobile money scams and fraudulent loan applications that caused more than $45 million in losses. Man gets five years for aiding North Korean IT employment scam Ukrainian national Oleksandr Didenko, 29, was sentenced in U.S. District Court to 5 years in prison for an identity theft scheme that enabled North Korean workers to secure fraudulent employment. Ex-Google engineers charged with orchestrating high-tech secrets extraction A federal grand jury has indicted three Silicon Valley engineers on charges in a scheme to steal trade secrets from Google and other leading technology companies. MOS: Open-source modular OS for servers and homelabs A growing number of homelab builders and small server operators are testing an open source operating system that combines basic server management, storage control, and container services under a web interface. MOS is a free modular OS built on a Devuan base that provides a web UI and API for system monitoring, storage pooling, container orchestration, and virtualization. Apple privacy labels often don’t match what Chinese smart home apps do Smart home devices in many homes collect audio, video, and location data. The apps that control those devices often focus on the account owner, even when the technology also captures guests, neighbors, and other people who never agreed to be monitored. New research examined whether Chinese smart home apps provide privacy protections for these bystanders. Vim 9.2 adds scripting updates, diff improvements, and experimental Wayland support Vim 9.2 adds a range of incremental changes focused on scripting, usability, and cross-platform support. The update includes improvements to completion behavior, expanded Vim9 language features, and new options for diff mode. ChatGPT gets new security feature to fight prompt injection attacks OpenAI has introduced Lockdown Mode and Elevated Risk labels in ChatGPT to help users and organizations reduce the risk of prompt injection attacks and other advanced security threats, particularly when using features that interact with external systems. OT teams are losing the time advantage against industrial threat actors In many industrial environments, internet-facing gateways, remote access appliances, and boundary systems sit close enough to production networks that attackers can move from IT intrusion to operational disruption with limited resistance. Dragos’ 2026 OT/ICS Year in Review describes a threat landscape where adversaries are spending more time learning how physical processes work and less time treating OT access as a passive foothold. AWS coding agents gain new plugin support across development tools AI coding assistants have become a routine part of many development workflows, helping engineers write, test, and deploy code from IDEs or command line interfaces. One recent change in this ecosystem makes it possible for those agents to interact with AWS in a broader set of ways by adding a library of plugins that give agents specific AWS knowledge and actions. Microsoft Defender update lets SOC teams manage, vet response tools Microsoft introduced library management in Microsoft Defender to help security analysts working with live response manage scripts and tools they use to triage, investigate and remediate threats. The library management interface allows analysts to organize their investigation tools and manage everything without waiting for an active session. Consumers feel less judged by AI debt collectors Debt collection agencies are starting to use automated voice systems and AI-driven messaging to handle consumer calls. These systems help scale outreach, reduce call center staffing demands, and offer 24/7 service. A new study covering 11 European countries found that this shift changes how consumers emotionally experience debt collection, especially around stigma and empathy. Men sentenced to 8 years in $1.3 million computer intrusion and tax fraud scheme Matthew A. Akande, a Nigerian national, was sentenced by a U.S. District Court to eight years in prison, followed by three years of supervised release, for his role in a scheme to break into Massachusetts tax preparation firms’ computer networks and file fraudulent tax returns. The operation generated over $1.3 million in fraudulent tax refunds. Public mobile networks are being weaponized for combat drone operations On June 1, 2025, Ukraine launched drone strikes on five Russian airfields, damaging or destroying aircraft. More than 100 explosive drones used mobile networks to transmit data, receive instructions, and send images. Enea researchers analyzed the growing use of mobile-connected drones in conflict and the implications for national infrastructure. PromptSpy: First Android malware to use generative AI in its execution flow ESET researchers have discovered PromptSpy, the first known Android malware to abuse generative AI as part of its execution flow in order to achieve persistence. This marks the first time generative AI has been deployed in this way. Uptime Kuma: Open-source monitoring tool Service availability monitoring remains a daily operational requirement across IT teams, SaaS providers, and internal infrastructure groups. Many environments rely on automated checks and alerting to track outages, latency issues, and service degradation across web applications and network endpoints. Uptime Kuma is an open-source uptime monitoring project that supports this type of operational monitoring through a self-hosted deployment model. Quantum security is turning into a supply chain problem Supplier onboarding, invoice processing, and procurement platforms run on encrypted data flows that were built for long-term trust. In many organizations, that trust still depends on cryptographic standards like RSA and elliptic curve cryptography (ECC), even as security teams begin planning for a post-quantum world. A recent apexanalytix research report argues that supply chain leaders are already operating inside a quantum risk window, even though large-scale quantum computing remains years away. LINK“>Google cleans house, bans 80,000 developer accounts from the Play Store Google prevented more than 1.75 million policy-violating apps from being published on Google Play and banned over 80,000 developer accounts that attempted to publish harmful apps in 2025. Developer verification, mandatory pre-review checks, and testing requirements in the Google Play ecosystem have reduced entry points for bad actors. LLMs change their answers based on who’s asking AI chatbots may deliver unequal answers depending on who is asking the question. A new study from the MIT Center for Constructive Communication finds that LLMs provide less accurate information, increase refusal rates, and sometimes adopt a different tone when users appear less educated, less fluent in English, or from particular countries. Applying green energy tax policies to improve cybersecurity For years, governments have focused only on the stick of compliance when they could leverage the carrot of tax incentives. Theoretically, compliance fines and penalties should act as a deterrent that improves accountability and reduces data breaches. However, many vendors often assume compliance risk rather than securing data effectively. The era of the Digital Parasite: Why stealth has replaced ransomware For years, ransomware encryption signaled a breach. When systems locked up, defenders knew an attack had occurred. Data from Picus Security’s Red Report 2026 shows attackers shifting their strategy from disruption to persistence. Cybersecurity jobs available right now: February 17, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: February 20, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Compliance Scorecard, Impart Security, Redpanda, and Virtana.
helpnetsecurity.comFeb 22, 2026extracted
Attackers keep finding the same gaps in security programs
Attackers keep finding the same gaps in security programs Attackers keep getting in, often through the same predictable weak spots: identity systems, third-party access, and poorly secured perimeter devices. A new threat report from Barracuda based on Managed XDR telemetry from 2025 shows that many successful incidents still start with basic access and configuration failures, not advanced malware. The report draws on more than two trillion IT events, nearly 600,000 security alerts, and more than 300,000 protected assets monitored over the year. Barracuda’s SOC triaged around 53,000 high-severity threats through its SOAR platform. Key findings (Source: Barracuda) Identity alerts lead the detection list Suspicious logins were the most common detection type across monitored environments. The most frequently detected event was a Microsoft 365 anomalous login, with 42,859 detections over the last 12 months. Microsoft 365 “impossible travel” alerts followed at 22,343 detections. These detections typically indicate credential theft, compromised accounts, or attackers testing access from new locations. The pattern suggests identity-based compromise remains one of the most reliable entry points into enterprise environments. Other top detections included account takeover sign-ins, endpoint agent disabled alerts, and attempts blocked by access policy due to new geolocation. Brute-force attempts appeared lower on the list, though the report’s incident data shows password spraying remains common once attackers identify exposed services. Privilege escalation blends into routine admin work Once attackers gain a foothold, privilege escalation becomes a priority. Barracuda observed suspicious privilege manipulation activity across Windows environments, Microsoft 365 tenants, and firewall systems. The most common activity was adding a user to a Windows group with high-risk security rights, accounting for 42% of privilege escalation detections. Another 27% involved removing a user from such a group, an action that can indicate cleanup after an escalation attempt. Microsoft 365 privilege escalations were also common. Adding a user as a global administrator accounted for 16% of suspicious events, while removing a global administrator accounted for 12%. Firewall privilege escalation also appeared, including FortiGate firewall admin additions. These actions often resemble normal IT operations, which makes them harder to detect through traditional alerting. Attackers increasingly rely on legitimate tools and standard workflows to stay hidden. Remote management tools are a growing risk Remote monitoring and management tools and remote access systems continue to attract attackers. Barracuda reported incidents involving abuse of SonicWall SSL-VPN, ScreenConnect, RDP, PsExec, AnyDesk, and firewall VPN services. One incident described a malicious executable that attempted to register itself as a Windows service for persistence. It also tried to install ScreenConnect through PowerShell, using a trusted remote management tool as part of the compromise chain. Another incident involved Akira ransomware, where attackers installed Datto RMM after gaining access to a domain controller. The activity resembled routine IT automation, blending into expected backup or maintenance behavior. Third-party access plays a major role in incidents Supply chain exposure and third-party access accounted for a large share of security incidents. Researchers found that 66% of incidents involved the supply chain or a third party, up from 45% in 2024. Third-party access often persists longer than intended, especially when vendor accounts remain active after a contract ends. In one ransomware case involving Akira, attackers entered through an account created for a vendor that was never deactivated. They later pivoted to an unprotected server and launched ransomware. The recurring theme is that access governance failures can create long-lived entry points that remain invisible until they are exploited. Vulnerability exposure is still dominated by old crypto flaws Outdated encryption and certificate issues remained common. The top detected network vulnerabilities included untrusted security certificates, certificate name mismatch, weak encryption checks, and self-signed certificates. Legacy cryptography is still widespread. The most detected CVE was CVE-2013-2566, an RC4 encryption weakness. Other frequently detected CVEs included CVE-2019-11072 in lighttpd and CVE-2024-6387 in OpenSSH, which carried a critical severity rating. Across all detected vulnerabilities, researchers recorded 2,525 unique vulnerabilities and 4,146 critical vulnerabilities. About 11% of vulnerabilities had a known exploit. Misconfiguration leaves tools disabled when they matter most Misconfiguration and disabled protections played a major role in incidents. Researchers found that endpoint protection agents accounted for 94% of disabled security feature detections. MFA disabling accounted for 3.62%, safe link rule disabling for 1.4%, and safe attachment rule disabling for 0.6%. Every security incident Barracuda responded to involved at least one unprotected or rogue endpoint. That data points to a recurring operational issue: unmanaged devices and inconsistent enforcement of endpoint coverage continue to undermine security controls across networks. “What makes targets vulnerable is often easy to overlook. A single rogue device, an account that wasn’t disabled when someone left, a dormant application that hasn’t been updated, or a misconfigured security feature. Attackers only need to find one to succeed,” said Merium Khalid, Director, SOC Offensive Security at Barracuda. Ransomware keeps exploiting perimeter devices Ransomware remained one of the most consistent threats in 2025. Researchers identified 13,514 indicators of ransomware activity over the year, with steady volume across months. Ransomware impact increased year over year. The proportion of organizations impacted by ransomware each month ranged from 5.1% to 10.9% in 2025, compared with 1.5% to 5.6% in 2024. Firewalls played a central role in ransomware intrusions. Barracuda found that 90% of ransomware incidents exploited firewalls, either through a CVE or a vulnerable account. Once lateral movement begins, ransomware deployment becomes likely. Researchers reported that 96% of incidents involving lateral movement ended with ransomware being released. Attack speed also varied widely. The fastest ransomware attack observed went from breach to encryption in three hours, with some cases reaching lateral movement in 10 minutes. Other intrusions lasted weeks or months, giving attackers time to exfiltrate data and prepare ransomware deployment.
helpnetsecurity.comFeb 19, 2026extracted
Brutus: Open-source credential testing tool for offensive security
Brutus: Open-source credential testing tool for offensive security Brutus is an open-source, multi-protocol credential testing tool written in pure Go. Designed to replace legacy tools that have long frustrated penetration testers with dependency headaches and integration gaps, Brutus ships as a single binary with zero external dependencies and native support for the JSON-based reconnaissance pipelines that define offensive security. Solving a real workflow problem Credential testing should be straightforward: you have a list of services and a set of credentials, and you need to find out what works. In practice, operators spend more time wrangling dependencies, parsing inconsistent output, and writing glue scripts than actually testing credentials. Tools like THC Hydra and Medusa have served the security community for years, but they carry significant friction: complex dependency chains that break across platforms, compilation issues on every new jump box, and no native integration with the structured recon workflows that teams rely on. Brutus was purpose-built to close that gap. Reconnaissance flows through tools like naabu for port scanning and fingerprintx for service identification, with everything structured as JSON streams. Credential testing was the broken link in that chain. With Brutus, operators can pipe discovered services directly into credential testing and get structured results back, with no format conversion, no manual parsing, no platform-specific workarounds. What Brutus brings to the table Brutus supports 22 protocols out of the box: All of this ships in a single binary that runs identically on Linux, macOS, and Windows with no external libraries or compilation required. One feature that consistently draws attention from practitioners is the embedded SSH bad key testing. Brutus carries the Rapid7 ssh-badkeys and HashiCorp Vagrant key collections compiled directly into the binary, with no external key files to manage. Every SSH service is automatically tested against known-compromised keys from vendors including F5 BIG-IP, ExaGrid, Barracuda, Ceragon, and Array Networks, each paired with its default username and tracked by CVE where applicable. On internal assessments, operators know there are Vagrant boxes or appliances running factory keys somewhere in the environment, but testing for them comprehensively has always been tedious enough to get deprioritized. With Brutus, it happens automatically as part of the normal workflow, and what used to be a half-day side project now comes for free. The embedded key collection is a starting point, and the team is hoping the community will contribute additional bad keys encountered in the wild. Beyond the CLI, Brutus also functions as a Go library, allowing developers to import it directly into custom security automation tools without shelling out to external processes. AI-powered credential discovery Perhaps the most ambitious feature is the experimental AI integration. Using Claude’s vision capabilities paired with headless browser control, Brutus tackles a problem that has never had a good automated solution: unidentified web admin panels. On any internal assessment, operators encounter dozens of login pages on non-standard ports, including switches, storage appliances, IPMI consoles, and monitoring tools. Traditionally, that means a manual process of screenshotting each page, identifying the product, searching for default credentials, and testing one at a time. Brutus automates the entire cycle. It renders the page in a headless browser, uses AI vision to identify the appliance or application, researches likely default credentials, then controls the browser to fill in the login form and test them. The approach handles JavaScript-rendered forms, CSRF tokens, and multi-step logins, all the things that break traditional form-filling tools. For HTTP Basic Auth targets, Brutus captures HTTP headers, identifies the device from server information and authentication realm data, and tests suggested credential pairs automatically. What is next On the AI front, the team is focused on optimizing the agentic features for scale. Per-target credential discovery works well, but across hundreds of HTTP services the latency and cost of LLM calls add up. Smarter batching, device identification caching, and reducing redundant API calls are all in development. The team believes that embedding agentic AI into security tooling will shift from experimental to expected as inference costs continue to fall. A key initiative is building a community-driven templating system, similar in spirit to Nuclei templates, that lets practitioners define default credentials for specific appliances and devices. The vision is that AI becomes the fallback for targets not covered by existing templates, and better yet, the AI can develop new templates on the fly as it identifies uncatalogued appliances, making the tool self-improving over time. On the protocol side, RDP remains the top priority. The team built an RDP implementation once using Rust FFI but pulled it because it was not reliable enough to ship. The path forward includes NLA detection and testing for common findings like Sticky Keys backdoors on internal assessments. Rather than ship a broken protocol, the team chose to maintain the core promise: everything in the tool just works. Brutus is open source and available now on GitHub. The team welcomes community contributions, particularly additional SSH bad keys from appliances and vendor products encountered in the wild. Must read: 40 open-source tools redefining how security teams secure the stack Firmware scanning time, cost, and where teams run EMBA Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comFeb 13, 2026extracted
CISA gives federal agencies one year to rip out end-of-life devices
CISA gives federal agencies one year to rip out end-of-life devices Federal civilian agencies have been ordered to remove end-of-life devices within 12 months due to widespread exploitation campaigns by sophisticated hackers. The U.S. cyber defense agency issued an operational directive on Thursday mandating federal agencies to “remove any hardware and software devices that is no longer supported by its original equipment manufacturer.” “Unsupported devices pose a serious risk to federal systems and should never remain on enterprise networks,” said Cybersecurity and Infrastructure Security Agency (CISA) Acting Director Madhu Gottumukkala. CISA said cyber threat actors are increasingly exploiting edge devices that no longer receive vendor updates to firmware or other security patches. The devices — which include load balancers, firewalls, routers, switches, wireless access points, network security appliances, internet of things (IoT) edge devices and more — are “especially vulnerable to persistent cyber threat actors exploiting a new or known vulnerability.” CISA Executive Assistant Director for Cybersecurity Nick Andersen told reporters during a press call the attackers targeting edge devices “include those with ties to nation-states.” He declined to name which countries were involved or explain what specific incidents prompted the directive. “This isn't a response to any one incident or compromise, but a recognition that unsupported devices just pose such a serious risk to federal systems,” he explained. Federal civilian agencies will have three months to provide CISA with an inventory of all devices in their networks that are on a provided list of end-of-life devices. After one year, all of the identified devices will have to be decommissioned and within two years, a process has to be created for continuous discovery of all edge devices that may be end-of-life. Federal agencies are also ordered to update all devices and replace end-of-life ones with devices that can receive security updates. CISA created an EOS Edge Device List that contains information on devices that are already end-of-service or will be in the coming months. CISA said it would not be publishing the list of end-of-life devices publicly. “Practicing good cyber hygiene starts with eliminating unsupported edge devices,” Andersen said. CISA said it will assist any agency that needs help and will track the progress of compliance. The agency did not say what specific threat actors or incidents precipitated the directive. The directive makes reference to “recent public reports of campaigns targeting certain vendors” but Andersen declined to elaborate on which reports were being referenced. Edge devices have long been the preferred entry point for attackers seeking to break into networks and nation state actors from China and Russia have launched multiple campaigns aimed specifically at devices from companies like Barracuda, Ivanti, Fortinet and more. In its directive, CISA said the U.S. “faces persistent cyber campaigns” that are “often enabled by unsupported devices that physically reside on the edge of an organization’s network perimeter.” They added that the exploitation campaigns CISA is aware of are “substantial and constant, resulting in a significant threat to federal property.” “Recent public reports of campaigns targeting certain vendors highlight actors' attempts to use these devices as a means to pivot into [Federal Civilian Executive Branch Agencies] information system networks,” the federal cybersecurity watchdog said. “Edge devices are attractive targets due to their extensive reach into an organization's network and integrations with identity management systems. These devices are especially vulnerable to cyber exploits targeting newly discovered, unpatched vulnerabilities.” Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaFeb 5, 2026extracted
Cyber Insights 2026: Malware and Cyberattacks in the Age of AI
The big takeaway from 2026 onward is the arrival and increasingly effective use of AI, and especially agentic AI, that will revolutionize the attack scenario. The only question is how quickly. Michael Freeman, head of threat intelligence at Armis, predicts, “By mid-2026, at least one major global enterprise will fall to a breach caused or significantly advanced by a fully autonomous agentic AI system.” These systems, he continues, “use reinforcement learning and multi-agent coordination to autonomously plan, adapt, and execute an entire attack lifecycle: from reconnaissance and payload generation to lateral movement and exfiltration. They continuously adjust their approach based on real-time feedback. A single operator will now be able to simply point a swarm of agents at a target.” The UK’s NCSC is slightly more reserved: “The development of fully automated, end-to-end advanced cyberattacks is unlikely [before] 2027. Skilled cyber actors will need to remain in the loop. But skilled cyber actors will almost certainly continue to experiment with automation of elements of the attack chain…” Both opinions could be accurate. We don’t yet know how the adversarial use of AI will pan out over the next few years. What we do know is that attacks will increase in volume, speed and targeting, assisted by artificial intelligence. Malware, malicious attacks and AI Effects Almost every segment of an attack chain can be automated by AI. One example is the speed with which attackers will reverse engineer a newly released patch, develop an exploit for the vulnerability and discover which companies are vulnerable almost certainly before the average company can initiate the patch. A second example could be the delivery of finely targeted attacks at the scale of traditional spray and pray attacks. “Malware is becoming far more targeted and personal. Attackers are moving away from mass ‘spray and pray’ tactics and are focusing on specific individuals, organizations, or systems,” says Mehran Farimani, CEO at RapidFort. “By using data gathered from social media, breaches, and online behavior,” he continues, “they can craft attacks that look legitimate and exploit very specific vulnerabilities. Future malware will feel smarter and stealthier, adapting to defenses, learning from user habits, and blending into normal activity.” “Forget ‘spray and pray’,” adds Shaun Cooney, CPTO at Promon, “this is more akin to mass targeting with a sniper rifle.” James Wickett, CEO at DryRun Security, adds the low cost of using AI to the advance of precision targeting. “The economics have flipped,” he says. “The cost to go from vulnerability discovery to exploit used to be weeks and thousands of dollars. Now it’s near zero. So instead of mass ‘spray and pray’ campaigns, we’ll get micro-targeted attacks built for a single system, a single company, maybe even a single developer.” A third example is the media’s headline threat from AI – the automation of the complete attack lifecycle from vulnerability detection, exploit production, to malware payload delivery and data exfiltration. Cory Michal, CSO of AppOmni, calls it the rise of ‘vibe-hacking’. “We’ve observed attackers using AI to automatically generate data extraction code, reconnaissance scripts, and even adversary-in-the-middle toolkits that adapt to defense. They’re essentially ‘vibe-hacking’ using generative AI to better mimic authentic behavior, refine social engineering lures, and accelerate the technical aspects of intrusion and exploitation.” When these components can be chained together under the orchestration of agentic AI, we will be closer to the one-click fully automated attack. “LLM-enabled malware has already moved from proof-of-concept to practice,” says Steve Stone, SVP of threat discovery & response at SentinelOne. “Our discovery of MalTerminal (the earliest known GPT4-powered malware capable of generating ransomware or reverse-shell code at runtime), along with ESET’s PromptLock sample and emerging campaigns like LameHug and PromptSteal, show how attackers are experimenting with AI to create polymorphic, self-evolving payloads.” These tools blur the line between code and conversation, he continued, “allowing malicious logic to be generated dynamically and evade traditional signatures.” AI agents can already prepare the stages while agentic AI will be the glue that chains them behind a single click. We’re not there yet, but the potential exists and that future will undoubtedly come. Ransomware Extortion will remain a primary purpose of malicious attacks simply because of its success. According to FinCEN, $2.1 billion was paid in ransoms during the three years 2022 to 2024. In 2023 the figure amounted to $1.1 billion (the all-time high) but subsided to $734 million in 2024. Two years can hardly be considered a trend, but many commenters believe that ransomware is slowly becoming less successful due to increased pressure against ransom payments and improved cyber defenses. Counter intuitively, if true, this ‘trend’ may be strengthened rather than reversed by the rise of AI. Jason Baker, managing security consultant of threat intelligence at GuidePoint Security, explains. “AI-generated ransomware, or other malware used for extortion, presents a problem for the users – namely, they are unlikely to fully understand how it works, or how to troubleshoot or debug issues.” Now imagine you’re an extortionist, he continues. “Your victim has paid, and your AI-generated decryption tool doesn’t work. How do you fix this? Do you have any incentive to fix it? And how long do people keep paying you ransoms once the word gets out that you can’t undo the damage you’ve done?” The return of DDoS? DDoS declined because of the success of ransomware – but it may return due to any decline in ransomware. “Attackers are reverting to one of their oldest and most disruptive tools: the denial-of-service attack. In 2026, we’ll see a record-setting resurgence of DDoS activity: the largest volumetric attack ever recorded, and the highest requests-per-second rate in history,” warns David Holmes, application security CTO at Thales. He notes that Imperva’s network is already seeing early signs: attacks that are 50% larger than anything we’ve seen before. “For threat actors, the playbook is simple. If they can’t extort you with encryption, they’ll take you offline instead. Organizations that spent the past few years fortifying against ransomware will now have to look outward again, reinforcing cloud-based DDoS protection and adaptive mitigation to withstand the next wave. The attackers haven’t disappeared; they’ve just changed tactics, and in 2026, they’ll come roaring back.” AI will play a major part in enabling and improving the efficiency of these DDoS attacks. The no-malware alternative The no-malware alternative isn’t completely no-malware, but the malware is limited to third party infostealers. “The defining shift in malware heading into 2026 is the consolidation of the entire attack chain around infostealers. They’ve become the entry point, the data broker, the reconnaissance layer, and the fuel for everything that comes after,” suggests the Flashpoint Analyst Team, noting that 1.8 billion credentials were stolen by infostealers in the first half of 2025. The Team continues, “AI-generated malware will get headlines, but threat actors don’t need fully autonomous malware when infostealers already automate the hardest part: initial compromise at scale.” Those same stealers no longer just collect passwords – they also collect session cookies, access tokens, host metadata, browser profiles and more. The attacker can assume the victim’s identity outright. Once inside the target network, a seasoned attacker can live off the land (LotL) effectively invisibly until data exfiltration without the use of any malware. This scenario is supported by Adrian Culley, senior sales engineer at SafeBreach. “The preferred method of intrusion is shifting universally toward Identity-led, malware-free Intrusions,” he says. “The focus on LotL TTPs allows intrusions to blend into normal network activity.” Infostealers can provide easy access, while LotL provides stealthy collection and exfiltration of data without requiring malware. Extortion may remain the priority motive, but “Think less ‘pay to decrypt’, and more ‘pay to stop leaks’,” suggests Yaz Bekkar, principal consulting architect XDR, at Barracuda Networks. The new criminal ecosystem Hacker levels Only sophisticated organized crime groups and nation state actors will have the immediate technical skill to realize the full potential of artificial intelligence. But AI is removing the entry barrier for new and unskilled hackers. As a result, there will be three distinct classes of bad actor in the future: elite nation state, organized crime, and a rapidly expanding script kiddie level. “The criminal ecosystem will change,” explains Bekkar. “With AI, you don’t need deep skills, you need ideas. As barriers to entry drop even further, more low-skilled actors will become more dangerous, faster. At the same time, the dominant gangs won’t disappear; instead, they’ll run ‘platforms’ and affiliate programs, renting out AI-driven kits.” “The barrier to entry has collapsed, giving amateur attackers far more reach,” says Farimani. The short term effect will be more efficient and more finely targeted attacks from the established cybercrime gangs and nation state actors, and a huge increase in less sophisticated attacks by the script kiddies. The overall effect of the script kiddie wave is unclear. Baker suggests, “Lower knowledge barriers will increase the volume of attacks but not necessarily the sophistication. Well-defended organizations will still be able to filter out the majority of unsophisticated attacks.” However, “While these individuals might not match nation-states in resources or intelligence-gathering, they will have unprecedented power to launch high-impact attacks. This democratization of capability means the overall threat volume and diversity will grow substantially,” warns Matt Gorham, leader of PwC’s cyber and risk innovation institute. “Could script kiddies operate like a nation-state? Not in terms of capability, but with stealer logs delivering turnkey access, the damage they can cause starts to look uncomfortably similar,” adds the Flashpoint Analyst Team. “Cyberattacks will be just as damaging as nation-state attacks next year,” says Dave Spencer, director of technical product management at Immersive. “Criminals don’t need to be sophisticated to cause harm. Look at Scattered Spider – teenagers calling help desks and resetting passwords. That’s not sophisticated.” But it has certainly been effective. DryRun’s Wickett: “AI won’t make everyone a hacker overnight, but it will close the gap between the script kiddie and a new, bespoke APT.” “As technology continues to democratize access to advanced capabilities,” continues Adam Darrah, VP of Intelligence at ZeroFox, “that gap will keep narrowing. The result is a much larger pool of actors, more noise, and more risk across the board.” The script kiddies will become better script kiddies. The criminal underworld One question remains: will the shakeup occurring in the active hacking world reshape the criminal underworld marketplace? “The big money will move from stolen identities to stolen code and trade secrets – things AI systems can directly weaponize or learn from,” suggests Wickett. “Instead of selling raw malware, people will sell tailored toolchains: prebuilt reconnaissance scripts, AI-driven exploit builders, and access kits for specific industries. The next underground marketplace isn’t going to look like a ransomware-as-a-service forum. It’s going to look more like GitHub for bad actors.” “Automation may disrupt middlemen but will also create new marketplaces for specialized AI malware, zero-day commoditization and tailored exfiltration services. As enterprise IP becomes more lucrative and easier to monetize, markets will likely shift toward high-value corporate IP and trade secrets alongside identity data,” agrees Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University. Dario Perfettibile, VP and GM of European operations at Kiteworks, suggests that the underworld marketplace will follow the AI-driven shift toward precision targeting. “This transformation will weaken dark web markets for bulk stolen credentials while elevating demand for curated access to specific data exchange platforms. Rather than selling millions of compromised accounts, criminals will broker targeted access to exchanges handling valuable IP, proprietary algorithms, or competitive intelligence.” GuidePoint Security’s Baker sees a similar relationship between underworld offerings and above ground operations. Invoking his view that hackers will worry about their ability to troubleshoot AI generated malware, “The need for reliable and fixable malware will likely remain, though its customer base may become more concentrated or limited,” he suggests. “Malware-as-a-Service remains a profitable business model and may be perceived as less likely to attract law enforcement scrutiny than directly conducting intrusions.” The demand for MaaS could even increase with the expected growth of script kiddie hackers who may not have the expertise to develop their own malware. Also mirroring the hacker migration to AI, Barracuda Networks’ Bekkar suggests, “AI turns commodity malware into something that’s effectively free-of-charge. Brokers pushing basic kits or generic access will become less relevant as the value shifts to what is now truly scarce: high-quality initial access, verified corporate data, bespoke exploits, and, above all, stolen intellectual property.” Charlie Eriksen, security researcher at Aikido Security, sees a downsizing. “Large data brokers are giving way to smaller groups trading specific types of stolen data or access. We’ve seen this pattern in several major supply-chain compromises that began with stolen publishing credentials. The market is shifting from trading stolen identities to trading stolen trust, and that is where much of the risk now lies.” The Flashpoint Analyst Team agrees with the ‘trust’ element, but not necessarily any downsizing. “Rather than weakening traditional access brokers, infostealers are transforming them. Instead of selling RDP or VPN access manually, brokers now move bulk identity profiles enriched with metadata: device specs, geolocation, corporate domains, session tokens, and host fingerprints.” Backed by the enormous and growing success of infostealers, “The marketplace is shifting from stolen credentials to full digital identities that allow high-confidence impersonation. Stolen IP, source code, and proprietary data are becoming more common in stealer logs because attackers are scraping developer tools, browser-stored secrets, and cloud app credentials directly from infected endpoints. Dark-web markets are starting to look more like identity-based supply chains.” The underworld marketplace will inevitably follow the above ground hacker demand, but both are currently in a state of flux. Cybersecurity defense in the age of AI attacks Jim Salter, senior management consultant at CyXcel, points to a comment from the UK’s NCSC: “Cybercriminal attackers target vulnerabilities, not sectors, so every organization with digital assets is a potential target.” He comments, “As reliance on digital infrastructure in companies of all sizes grows, the opportunity for cyber criminals to exploit vulnerabilities will also grow.” The incidence of potential vulnerabilities is also increasing, through the rapid deployment of vibe coding. Julie Davila, VP of product security at GitLab expands, “Next year will bring a tidal wave of security risk as adversarial agents lower the barriers to execute increasingly complex attacks. In other words, agents make it much easier to exploit any vulnerability within a system. The exploitation ‘likelihood lever’ for every vulnerability has just gone up.” She adds, “Organizations that have prioritized foundational security hygiene, including efficient patch management, will be better prepared to defend themselves and minimize existing risk across software environments and their software supply chain.” This is the ‘eat your cyber veggies’ exhortation from companies such as Cisco and Splunk. Eating vegetables is boring but essential for health. Cyber veggies are the cyber hygiene basics: patching, phishing-proof MFA, least privilege, segmentation backups, etcetera. Mick Baccio, global security advisor at Cisco Foundation AI, comments, “The building blocks of security, the cyber veggies, have been around for a long time; and if you don’t do them, bad things happen. They’re super applicable to things like AI and software development. There’s no silver bullet, of course, but it will solve a tremendous number of problems for things like account takeover, lateral movement, and the vulnerabilities that shouldn’t exist.” If you want to survive the malicious side of AI, it is essential that you start with the cyber veggies. But since there really is no silver bullet, you still need to layer additional security on top. “AI-enabled malware mutates its code, making traditional signature-based detection ineffective. Defenders need behavioral EDR that focuses on what malware does, not what it looks like,” says AppOmni’s Michal. “Detection should key in on unusual process creation, scripting activity, or unexpected outbound traffic especially to AI APIs like Gemini, Hugging Face or OpenAI.” He continues, “By correlating behavioral signals across endpoint, SaaS, and identity telemetry, organizations can spot when attackers are abusing AI and stop them before data is exfiltrated.” RapidFort’s Farimani stresses. “The focus of security teams must shift to minimizing exposure and reducing time-to-remediation, because the offensive side is already automated.” In short, “In 2026, cyber resilience will depend on out-learning, not just out-blocking, the adversary,” explains Kirsty Paine, field CTO at Splunk and fellow at WEF. “In 2026, we will see the rise of AI-enabled malware that can autonomously adapt in real time to evade detection. We’ve already seen hints of this from research proof of concepts like BlackMamba, but next year we can expect to see AI-enabled malware deployed in increasingly complicated attacks that learn, blend in, and modify their behavior based on environmental signals without a human operator ever touching the keyboard. This shift will reinforce the relevance of David Bianco’s ‘Pyramid of Pain’ where, as adversaries rely less on static artifacts at the bottom of the pyramid, defenders will have to move higher to focus on proactively disrupting attacker tools, behaviors, and TTPs.” Final thoughts From 2026 onward, organizations will need to double down on the importance of their cybersecurity. It’s not that artificial intelligence will invent new threats, but it will find and exploit vulnerabilities with greater stealth considerably faster and in greater volumes than we have seen before. We will need to concentrate on the basics. We must eat our cyber veggies; and then we must overlay additional layers of security. We will need to use our own AI to detect and block the attackers’ use of AI; while simultaneously ensuring they cannot turn our systems against us by hijacking our agentic AI’s APIs, which we may not even know about. It ain’t gonna be easy, but it’s gotta be done if we want to survive and thrive. Related: The Wild West of Agentic AI – An Attack Surface CISOs Can’t Afford to Ignore Related: Beyond GenAI: Why Agentic AI Was the Real Conversation at RSA 2025 Related: AI Emerges as the Hope—and Risk—for Overloaded SOCs
securityweek.comFeb 2, 2026extracted
Cyber Insights 2026: Zero Trust and Following the Path
Ask ten experts to describe the current state of zero trust and you will get ten different answers. We asked dozens of experts. Zero trust is not a thing; it is an idea. It is not a product; it is a concept – it is a destination that has no precise route and may never be reached. But it is described very succinctly: trust nothing until the trust is justified. Justification starts with verifying every subject’s identity and authority. This is the single constant in all zero trust journeys: they start with the subject’s identity. Zero trust’s reliance on identity, and identity’s reliance on AI Two questions. Can you have zero trust without effective identity verification? No. Can you have effective identity verification in the age of AI? Maybe, and maybe not. There is universal agreement that you cannot have zero trust without effective identity management. “Zero trust is not possible without an identity-first approach – they are fundamentally interconnected. Trust cannot be verified if the identity itself cannot be verified,” says Rob Ainscough, chief identity security advisor at Silverfort. “Zero trust and identity management are inseparable. Without trustworthy, continuously verified identities, the whole model collapses,” adds Avinash Rajeev, cyber, data & tech risk leader, PwC US. But identity is no longer a simple concept in cyber. It could be human or a machine or a process. “Traditional IAM systems, built for humans, struggle to manage this explosion of non-human identities, blurring the line between trusted and untrusted entities,” comments Mick Leach, field CISO at Abnormal AI. One growing complexity comes from the continuing convergence of OT and IT. “In OT, managing identities across distributed, disconnected, and often credential-less systems remains a major hurdle,” explains Raed Albuliwi, CPO at Xona. “To truly achieve zero trust, organizations must extend identity-based security to the machines and services operating inside OT environments,” says Anusha Iyer, founder and CEO at Corsha. “The real breakthrough will be identity solutions that are OT-native: low-friction, infrastructure-agnostic, and enforceable at the session layer without rewriting plant architectures,” adds Albuliwi. “Zero trust for OT is not simply IT policy pushed down to OT. It is a new foundation for safe, resilient, and automated industrial operations,” continues Iyer. Beyond OT, identity is also being disrupted by the same disruptive force affecting the entirety of business and society: the rise of artificial intelligence (AI). And as elsewhere, AI can both assist and hinder defenders and assist attackers. Since identity is the fount of security, it is also the primary target of attackers. Phishing is a major attack method used by attackers to steal identities. The quality of phishing attacks has been supercharged by AI. This includes compelling backstories and very realistic voice and video deepfakes. John Kindervag, chief evangelist at Illumio (and often described as the ‘father of zero trust’), warns, “As deepfakes proliferate, cybercriminals will easily exploit authentication systems, especially since protocols like FIDO were never designed to counter such threats. In response, organizations will add new layers of control to make identity harder to bypass, but this will create so much friction that many will eventually rethink or even abandon traditional identity models altogether.” His concern is that AI will enable attackers to break the authentication of identities. “The core weakness of identity today is its inability to prevent attacks after authentication.” However, AI is not merely an attackers’ advantage, it is a defenders’ nightmare. The culprit here is the advance of agentic AI. “Today, few organizations have deployed agentic AI in production. But, as more companies begin to operationalize agentic AI at scale, its unpredictable interactions will expose a new class of identity and access management challenges,” explains Anand Srinivas, VP product and AI at 1Password. “Until now, identity, secrets and access management solutions have been siloed across different organizations responsible for application or workforce identity security,” he continues. “That worked when applications were deterministic, well-bounded entities all operating within centralized policy frameworks. However, agentic AI behaves as both traditional software and as a user that operates outside existing identity systems, thereby introducing new identity threat vectors.” That said, opinions on the state and promise of zero trust today and going forward will vary between different experts, largely depending upon whether they are glass half full or glass half empty people. Murat Balaban, CEO at Zenarmor, comments, “Without validated identity, context, and behavior, ‘never trust, always verify’ collapses. AI makes this harder and easier all at once; harder because synthetic identities and deepfakes distort signals, and easier because AI-driven analytics can detect behavioral anomalies faster than humans ever could.” Rajeev adds, “The rise of AI introduces both risk and opportunity. Deepfakes and synthetic identities can undermine trust, but AI-driven behavioral analytics and continuous authentication can strengthen it. Risk-based approaches – evaluating location, device health, and user behavior – let us scale protection intelligently.” David Bellini, CEO at CyberFOX, continues, “We can use AI to automate the very controls that overburden IT teams. Instead of relying on manual processes, we can use intelligent systems to manage privileges, verify identities, and block suspicious activities. The goal isn’t to add more work; it’s to make security invisible and effective.” The most common view is that recent and ongoing complications to identity management can be solved with modern technology, but only with care and commitment. There will always be failures, so identity management must project itself beyond the point of failure (the old perimeter). Microsegmentation within the network can enforce ongoing authentication and limit traversal to authorized areas, while anomaly detection can spot an identity doing something unusual for an authorized identity. “I believe by combining AI based behavior anomaly with identity and microsegmentation we are probably doing better than the attackers,” says Agnidipta Sarkar, chief evangelist at ColorTokens. Obstacles to achieving zero trust “Most organizations only start working toward zero trust after an auditor, insurance requirement, or compliance standard forces them to. That approach misses the point,” says Chris Boehm, field CTO at Zero Networks. “When security becomes about passing an audit, companies start checking boxes instead of changing habits. They implement multi-factor authentication, close a few ports, or segment part of the network, then declare success. It looks good on paper but rarely holds up in reality.” This is worth considering, since – as we shall see – there is a body of opinion that believes current delays in progressing zero trust will be minimized over the next few years through the force of compliance requirements and cyberinsurance instructions. Boehm warns that this may be a risky cause and effect. “It’s like a diet. You can start it because someone told you to, or you can live it because you want to be healthy. Only one approach lasts. We may never reach perfect zero trust, and that is fine. The point is not to finish but to stay consistent. Like a diet, the value comes from maintaining the practice, not from declaring it complete.” But what are those obstacles that will only be truly overcome by a complete change to our current security lifestyle? The first is simple: an ingrained belief that zero trust is an achievable destination. It isn’t. “We’ve been discussing zero trust for a long time as if it were a destination – like a secure digital city we could create and move into, protected from every form of danger. This couldn’t be further from the truth,” says Bellini. “For most companies, whether in the midmarket or in public institutions, true zero trust remains a form of nirvana, a goal that’s true but impossible to achieve.” He suggests that in 2026, “It is time we shift our discourse from perfection to progress. Working toward a state of zero trust is a journey – a day-by-day task – not a destination.” Zero trust may be a destination condition, but it will never be a box which we can check and from which we can move on. The route is riddled with obstacles. We know the current obstacles, but we should assume that there will be new obstacles even while we work on solving those we already face. Dario Perfettibile, VP and GM of European operations at Kiteworks, explains one of the most intractable – the legacy perimeter. “We will eventually get there, but timelines extend well beyond 2026 due to fundamental structural barriers. Private data exchanges must simultaneously secure data flows across partners’ legacy systems, cloud environments, and on-premise infrastructure, while maintaining operational compatibility with hundreds of exchange participants at varying security maturity levels.” He continues, “The perimeter remains organizationally embedded despite being technically dead. Forty-eight percent of businesses report difficulties integrating zero trust across hybrid environments because security teams, procurement processes, and partner contracts still assume network boundaries define trust zones.” The perimeter problem encompasses many of the difficulties that delay the journey to zero trust: lack of budget and reluctance to swap out legacy equipment and attitudes; security professionals’ failure to adequately explain the necessity for physical, attitudinal and organizational change; the complexity of what is required; and an ongoing user resistance to any change. “Many companies are facing budget constraints that limit their ability to invest in new technologies like ZTNA (zero trust network access) if they already have current solutions working, such as VPNs,” comments Jesus Cordero-Guzman, director at Barracuda. “Security budgets are commonly allocated to immediate needs rather than long-term strategic initiatives.” Balaban adds, “Legacy infrastructure resists segmentation, budgets favor visibility tools over architecture redesign, and users resist anything that slows them down.” Dwayne McDaniel, senior developer advocate at GitGuardian, notes that while everyone accepts the perimeter is dead, most organizational charts and budget lines reflect its continued existence. “Even more than a lack of funding, the thing holding most teams back from embracing new ways to work with identity is legacy architecture. We have a comfort level with old patterns, and users push back when access feels slower,” he says. Paul Nguyen, co-founder and co-CEO at Permiso, suggests that the necessary organizational change is more disruptive than any technology implementation. “CISOs must restructure teams, redefine responsibilities, update hiring practices, and change how teams collaborate.” The complexity of the ’new ways’ is seen in the need for ‘identity’ to expand from people to everything. “Workloads need cryptographic identities that are automatically issued and managed at scale. Every call between services needs to be authenticated and authorized based on that identity, not on network location. We are seeing wider adoption of frameworks like SPIFFE point in the right direction, where baked-in, workload-centric identity travels with the service, regardless of where it runs. Without that level of workload identity, zero trust collapses back into IP ranges, hostnames, and one-off exceptions, which is just the old perimeter model in new clothes,” he explains. Another reason for a delayed implementation is a resistance to change based on the comfort level of IT staff with their existing technologies, suggests Cordero-Guzman. But he adds, “The strongest resistance may come from ordinary employees who resist changes to their access methods, especially if they perceive ZTNA as cumbersome or if it disrupts their habits and workflows. This can often lead to pushback against new security implementations.” However, despite the overwhelming recognition of the blocks on the road toward zero trust, and the time it has taken to reach the current stage (remember that John Kindervag published his paper, No More Chewy Centers: Introducing The Zero Trust Model of Information Security 15 years ago), most security experts are confident that huge progress will be made in the coming years. Some believe the progress will be an organic recognition of the necessity, but many believe the progress will be forced. “These barriers will decline as modern identity-first platforms mature and as regulation and cyber insurance increasingly demand measurable zero trust progress,” says Nigel Gibbons, director and senior advisor at NCC Group. “An uninformed or confused customer does not buy. However, when an incident occurs that wakes them up, suddenly security becomes a priority. The same applies when an insurance policy renewal has new audit requirements. The purchase is then made for compliance reasons. If the insurance requirements continue on their path of sophistication, that is the best hope for SMBs to obtain better security. Just ask anyone why / when they finally applied MFA, and it will be one of the above reasons only,” expands David Redekop, CEO at ADAMnetworks. “I have also seen more budget reallocations over the last 12 to 18 months, as companies begin to invest in solutions that help with compliance and regulatory demands,” agrees Cordero-Guzman. “The catalyst in 2026 is regulation, insurance pressure, and board liability,” adds Aaron Painter, CEO at Nametag. There is a potential problem here. If the advance of zero trust is based on organic recognition of its benefits, that is good. But if the advance is forced solely by compliance necessity, it could be very bad. Regulations tend to lag behind necessity and also encourage check-box compliance. Check-box compliance tends to be the minimal necessary rather than the best solution. It reflects Boehm’s earlier diet metaphor: the danger of checking boxes rather than changing habits. The zero trust journey Most people believe in zero trust, and that is admirable. Many people believe it is achievable, and that is questionable. Some people believe they have achieved it, and that is doubtful. Zero trust is an aspiration at the end of a road that keeps shapeshifting. If we accept the premise that full zero trust cannot be definitively achieved, zero trust can only be measured as a position along the road; that is, partial zero trust. This raises a double-barreled question: is partial zero trust worth the effort, and / or does it encourage a false sense of security? Chris Radkowski, GRC Expert at Pathlock, has no doubt. “Yes, partial zero trust is absolutely worth the effort! Genuinely securing critical assets is important, even if you can’t secure everything. This dramatically improves your posture. Attackers might be able to gain access to your corporate networks, however with zero trust you might be able to prevent access to your crown jewels.” While most experts agree the journey is essential, and partial is better than nothing, that advice comes with a proviso: it can promote a false sense of security when a little zero trust is treated as full zero trust. “Organizations must remember that zero trust is not a single product; it’s a framework. The mistake that imbues a false sense of security is believing that one product fits all zero trust needs or that once you implement it, you don’t need to revisit it. That static thinking is where the real danger lies. Zero trust is a framework that needs to be continuously reviewed and adapted as users, applications, and threats change,” warns Negin Aminian, senior manager of cybersecurity strategy at Menlo Security. “Partial zero trust is like partial containment in a fire,” suggests Xona’s Albuliwi. “It may slow damage but won’t stop it. In OT especially, half measures can be dangerous. If you apply zero trust to remote access but still allow unmanaged OEM software or shared credentials inside the perimeter, you’ve created a soft underbelly. That said, incremental progress is better than inertia if leaders are clear-eyed about the remaining risk.” Asha Aminian, VP of marketing at Zenarmor, suggests, “Partial zero trust is infinitely better than none if it is intentional. The danger isn’t being incomplete; it is being inconsistent. Too many organizations stop at MFA or SSO and mistake access control for zero trust.” This is the crux. Not attempting zero trust because it is too difficult, too complex, or too costly, is dangerous. Companies should always attempt to migrate to zero trust, acknowledge that it is a long journey, acknowledge that there will always be more to do, and be fully aware of what remains to be done. Without this, there is a distinct danger of a false sense of security. “Partial zero trust is not a failure: it’s a foundation. While it can create a false sense of security if misunderstood, even limited implementations like least privilege access or segmented networks offer meaningful protection. The key is to validate posture continuously and close gaps as they emerge,” explains Garrett Hamilton, CEO & founder at Reach Security. “Treat zero trust like safety in aviation. You build procedures, you verify identity, and you learn from every incident. Perfection is not the goal. Continuous proof is,” adds Painter. “Partial zero trust is not a false sense of security if it is measurable. Publish the blast radius you reduced and the pathways you closed. If you cannot measure it, you are decorating. Just be honest about what remains open and make that list shorter every quarter.” Zero trust going forward Despite the impossibility of a definition of zero trust suitable for all companies in all industry verticals, confidence in its eventual achievement is high among many security experts – although what is meant by zero trust is ill-defined. “The era of implicit trust will end with 2025. In its place will be a culture of continuous verification and intelligence authentication. Forward thinking organizations will recognize identity as the new perimeter and understand that safeguarding it – as well as that of every vendor, partner and supplier they work with – is fundamental to reputation and growth,” says Dan Schiappa, president, technology and services at Arctic Wolf. “In 2026, zero trust won’t just be a security model, it will be a corporate lifestyle and a defining principle of digital leadership,” he adds. “In 2026, zero trust will be less about conceptual frameworks and more about operational architecture, especially within the LAN. Enterprise networks will enforce identity, segmentation, and policy as continuous behaviors rather than scheduled tasks. The LAN itself will become intelligent and adaptive – managed as a service where AI continuously verifies trust, optimizes performance, and mitigates anomalies,” says Shashi Kiran, chief go-to-market officer at Nile. “Successful identity management is possible in 2026, but only through a layered approach. Organizations will need adaptive authentication that verifies the elements that make us human through multi-factor authentication and risk scoring,” says Adam Boynton, senior security strategy manager, EMEIA at Jamf. “True zero trust requires comprehensive identity security: continuous discovery of all identities (human, non-human, AI), verification of every access request, enforcement of least-privilege across all identity types, behavioral monitoring for all identities. Few organizations will attempt this in 2026,” warns Nguyen. “Will they get there? Yes, but over a longer timeline. Organizations will achieve comprehensive zero trust by 2027-2029, not 2026. The journey is longer because the organizational and technical complexity exceeds most expectations,” he adds. Bert Kashyap, co-founder and CEO at SecureW2, says, “In 2026, the internal debate will no longer be ‘Should we do zero trust?’. It will be ‘How fast can we remove each remaining pocket of implicit trust?’. Teams that rely on legacy models will fall behind. Teams that build continuous verification into their architecture will see a smaller blast radius, faster detection, and more predictable operations.” Keith McCammon, co-founder at Red Canary (acquired by Zscaler), sees necessity forcing a change of pace. “In 2026, zero trust principles and implementation will shift from ambition to necessity. Security budgets are tightening, SOC teams aren’t growing, and identity-based threats are multiplying. The pressure to do more with less will force organizations to simplify, not expand toolsets or headcount. As a result, zero trust will move from a long-term aspiration to the first practical step in defense.” Ariel Parnes, former IDF 8200 cyber unit colonel and COO at Mitiga, is less confident of success. “The biggest security incidents in 2026 will stem from compromised identities within supposedly zero trust environments.” He continues, “The illusion of control will persist until identity management becomes contextual and adaptive, powered by AI that can interpret intent, not just credentials. This will redefine what ‘trust’ means in a world where access is always conditional, and compromise often comes from within.” All of these different expectations for zero trust now and into the future, where nobody is wrong and nobody can be completely right, stem from the difficulty in explaining the nature of zero trust. We describe zero trust as a concept, as a destination, as an aspiration, as a journey. The truth is it is none (and all) of these. Zero trust is a way of life – a constant acceptance that all implicit trust must be replaced by explicit trust, wherever, whenever, and however it occurs. There is no single product nor final destination for a way of life – it is continuous, ongoing, forever – and essential. Related: Zero Trust Is 15 Years Old — Why Full Adoption Is Worth the Struggle Related: Cloudflare Expands Zero Trust Capabilities with Acquisition of BastionZero Related: Cutting Through the Noise: What is Zero Trust Security? Related: CISA Publishes New Guidance for Achieving Zero Trust Maturity
securityweek.comJan 29, 2026extracted
Evolución del incidente de seguridad en BreachForums
Evolución del incidente de seguridad en BreachForums 27/01/2026 Mar, 27/01/2026 - 16:27 En enero de 2026 salieron a la luz las primeras informaciones sobre una importante filtración de datos que afectó a BreachForums, un conocido foro vinculado a actividades de ciberdelincuencia y compraventa de información robada. Diversos medios especializados en ciberseguridad comenzaron a informar sobre la aparición de una base de datos atribuida a la plataforma, lo que generó una rápida reacción tanto dentro de la comunidad, como entre los propios operadores del foro.  La filtración consta de una base de datos con información de aproximadamente 325.000 usuarios registrados en BreachForums, incluidos sus “metadatos extraídos de la base de datos MySQL”. Los datos filtrados incluirían nombres de usuario, direcciones de correo electrónico, identificadores internos y contraseñas cifradas, aunque no en texto plano. Los administradores del sitio negaron inicialmente una intrusión reciente y afirmaron que los datos procedían de una copia antigua expuesta accidentalmente meses atrás durante tareas de mantenimiento. Como medida de contención, se revisaron sistemas internos y se insistió en que los métodos de cifrados empleados limitaban el impacto real de la filtración. A día de hoy, el suceso se considera cerrado desde el punto de vista técnico, aunque sigue siendo objeto de análisis y debate en la comunidad de ciberseguridad. No se ha confirmado la existencia de un comunicado oficial, pero sí interés por parte de investigadores y fuerzas del orden debido al valor potencial de los datos filtrados.    Referencias 10/01/2026 hackread.com Database of 323,986 BreachForums Users Leaked as Admin Disputes Scope 12/01/2026 theregister.com Infamous BreachForums forum breached, spilling data on 325K users 13/01/2026 itsecurityguru.org BreachForums Data Leak Raises Fresh Questions Over Credibility 26/01/2026 barracuda.com BreachForums disclosure surfaces falling out among ShinyHunters thieves Etiquetas Cibercrimen Ciberdelito Filtración de datos
incibe.esJan 27, 2026extracted
Sicurezza email sotto pressione: raddoppiano i kit di phishing nel 2025
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comJan 26, 2026extracted
Cavi sottomarini, i nuovi grandi progetti per plasmare la connettività mondiale
Dall’Europa all’Asia-Pacifico, passando per Africa e Artico: ecco i progetti che hanno plasmato la connettività globale nel 2025. Il 2025 ha ribadito una verità ormai incontrovertibile: il futuro del digitale e della connettività mondiale viaggia sotto la superficie del mare. Per quanto invisibili, i cavi sottomarini sono le arterie dell’economia digitale dalle quali è ormai impossibile prescindere. L’anno che si è appena concluso ha segnato uno dei periodi più intensi della storia della connettività sottomarina, confermando la centralità strategica di queste infrastrutture critiche nell’economia, nella sicurezza e nella sovranità digitale dei Paesi. Quello che ha caratterizzato il 2025 non è stata solamente la mole di nuovi progetti, quanto l’intenzione dietro di essi. Particolare attenzione, infatti, è stata riservata alle strategie digitali nazionali, alla resilienza delle infrastrutture alla luce dei contesti geopolitici, all’espansione dell’AI e del cloud. L’ultimo anno, infatti, ha messo in evidenza anche le fragilità delle reti globali. Le molteplici interruzioni dei cavi nel Mar Rosso sono l’emblema dell’urgenza di diversificare le rotte e rafforzare la capacità di riparazione rapida. Non a caso, i governi e le alleanze regionali hanno intensificato gli investimenti in queste infrastrutture, con un approccio legato alla sicurezza e alla difesa,in risposta e prevenzione di turbolenze geopolitiche. Nel suo recente report, Subsea Cables by Telecom Review ha proposto un “wrapped” di fine anno a livello regionale, offrendo una panoramica dei progetti chiave del 2025. Come è stato il 2025 in Europa? Per quanto riguarda l’Europa e il Mediterraneo, si è assistito a un incremento dei progetti dedicati all’espansione delle capacità digitali. In particolare, si è distinto il Medusa Subsea Cable System che, mettendo in connessione le due sponde del Mare Nostrum, crea un corridoio che va dal Mar Rosso all’Oceano Atlantico. Un rinnovato focus sulla resilienza regionale e il desiderio di individuare percorsi alternativi tra Europa, Asia e Africa è stato promosso da progetti come BlueMed, Magna Grecia, Barracuda e Kardesa. Parallelamente, poi, iniziative come il Baltic Sea Digital Ring di GlobalConnect e il collegamento sottomarino tra il Belgio e il Regno Unito lanciato da EXA Infrastructure hanno riservato una spiccata attenzione al rafforzamento della connettività intraeuropea. A livello intercontinentale, invece, protagonisti sono stati l’espansione di EllaLink di NetIX dall’Europa al Sud America, e l’annuncio da parte di Amazon Web Services (AWS) di Fastnet, il nuovo cavo transatlantico in fibra ottica che collegherà entro il 2028 il Maryland, negli Stati Uniti, a Cork, in Irlanda. Come è stato il 2025 in Africa e Medio Oriente? L’Africa è andata progressivamente consolidando la propria posizione come uno dei principali mercati di crescita a livello globale, trovando terreno fertile per l’innovazione digitale. Protagonista della regione è, in questo caso, il colossale progetto 2Africa, che con i suoi 45,000 chilometri di cavi è attualmente il sistema più lungo al mondo. A sottolineare ulteriormente l’impegno dei governi locali e delle aziende private per garantire una crescita duratura e inclusiva, spiccano l’espansione di SEACOM 2.0 e i progetti DARE1 e Daraja. Il Medio Oriente nel 2025 ha rafforzato ulteriormente la sua posizione come crocevia digitale strategico. Centrale, nello specifico, è il ruolo dell’Egitto, che con Telecom Egypt ha contribuito all’attivazione dei segmenti mediterranei del sopraccitato 2Africa, ha collaborato al sistema sottomarino Asia-Africa-Europa-2 (AAE-2) ed è intervenuto supportando diversi corridoi nel Mar Rosso e nel Mediterraneo. Il 2025 ha visto anche l’affermarsi delle ambizioni dell’Arabia Saudita che, per posizione geografica, funge da ponte per i cavi che collegano Europa, Asia e Africa. Tra le iniziative più significative ci sono l’approdo del cavo Africa-1 e il Mobily Red Sea Cable (MRSC). Anche l’Oman si è ulteriormente rafforzato come punto strategico di approdo e transito, grazie all’attivazione dell’Oman Emirates Gateway (OEG), al lancio del Salalah Data Center e alla partecipazione a sistemi sia regionali che intercontinentali. Come è stato il 2025 nel Pacifico? Tuttavia, il mercato sottomarino più dinamico al mondo è stato, anche nel 2025, la regione dell’Asia Pacifica. Un ruolo di primo piano è spettato al Giappone. Il tutto, grazie ai numerosi progetti in atto: il Japan-Korea Submarine Cable (JAKO), il Southeast Asia-Japan Cable 2 (SJC2), E2A e AUG East, a testimonianza della volontà del paese di diversificare i punti di approdo e ridurre il rischio di concentrazione. Particolare vitalità si è registrata nelle aree del Sudest asiatico e delle isole dell’Indo-Pacifico, regioni in cui connettività e stabilità regionale si intrecciano, anche alla luce delle tensioni geopolitiche nell’area. Qui, significativi sono i ruoli delle Filippine, con il progetto Apricot, e dell’Australia, fortemente coinvolta nei sistemi della Papua Nuova Guinea e delle Isole Salomone. E in Artide e Antartide? Nel 2025 è emerso poi l’incontenibile interesse per le rotte di frontiera. Da un lato l’Arctic Way Cable System, in risposta alla crescente domanda di connettività sicura nelle regioni settentrionali, offrendo nuove opzioni per l’accesso digitale nell’Artico. Dal capo opposto, invece, si sono avviati studi per esplorare la fattibilità di una rotta Cile-Antartide. Queste visioni per la diversificazione trans-artica, ovviamente a lungo termine, riflettono l’influenza che i cambiamenti climatici, gli equilibri geopolitici, la ricerca scientifica e l’innovazione tecnologica hanno sulle scelte infrastrutturali.
cybersecitalia.itJan 14, 2026extracted
Loading 34 more…