Mandiant

Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity

Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity 2026-09-10 at 07:03 By Mirko Zorz Amazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in September 2022, and he has worked against cyber threats in the public […]

Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity Read More »

Threat actors are giving AI agents a bigger role in cyberattacks

Threat actors are giving AI agents a bigger role in cyberattacks 2026-09-08 at 17:55 By Sinisa Markovic AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response […]

Threat actors are giving AI agents a bigger role in cyberattacks Read More »

Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Google’s AI security agents found 100+ critical software vulnerabilities in just two days 2026-08-19 at 12:03 By Sinisa Markovic Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during […]

Google’s AI security agents found 100+ critical software vulnerabilities in just two days Read More »

Google changes how it names cyber threat actors

Google changes how it names cyber threat actors 2026-07-27 at 16:08 By Sinisa Markovic Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes […]

Google changes how it names cyber threat actors Read More »

Cisco SD-WAN Zero-Day Exploited Months Before Patching

Cisco SD-WAN Zero-Day Exploited Months Before Patching 2026-06-25 at 09:08 By Eduard Kovacs CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco SD-WAN Zero-Day Exploited Months Before Patching Read More »

Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)

Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) 2026-06-05 at 15:49 By Zeljka Zorz A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers. “To exploit this vulnerability, an attacker must have netadmin privileges on an affected system. This would require […]

Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) Read More »

Google AI Threat Defense targets attackers using AI to find flaws faster

Google AI Threat Defense targets attackers using AI to find flaws faster 2026-05-27 at 17:23 By Anamarija Pogorelec Google Cloud introduced AI Threat Defense, an automated cybersecurity platform that combines several of the company’s security assets to find, prioritize, and patch software vulnerabilities at machine speed. The product is aimed at enterprises contending with attackers […]

Google AI Threat Defense targets attackers using AI to find flaws faster Read More »

Google researchers uncover criminal zero-day exploit likely built with AI

Google researchers uncover criminal zero-day exploit likely built with AI 2026-05-11 at 16:48 By Mirko Zorz Google’s threat intelligence researchers have linked a zero-day exploit to AI-assisted development by a criminal group. The exploit targeted a popular open-source web-based system administration tool. It allowed attackers to bypass two-factor authentication once they had valid user credentials. […]

Google researchers uncover criminal zero-day exploit likely built with AI Read More »

Software supply chain hacks trigger wave of intrusions, data theft

Software supply chain hacks trigger wave of intrusions, data theft 2026-04-02 at 18:58 By Zeljka Zorz After linking the Axios npm supply chain attack to North Korean hackers, Google researchers warned that “hundreds of thousands of stolen secrets could potentially be circulating” as a result of this and the Trivy, KICS, LiteLLM, and Telnyx supply […]

Software supply chain hacks trigger wave of intrusions, data theft Read More »

North Korean hackers linked to Axios npm supply chain compromise

North Korean hackers linked to Axios npm supply chain compromise 2026-04-01 at 18:56 By Zeljka Zorz The software supply chain attack that resulted in the compromise of npm packages of Axios, an extremely popular HTTP client library, is believed to be the work of financially-motivated North Korean attackers. Links to UNC1069 On March 31, 2026, […]

North Korean hackers linked to Axios npm supply chain compromise Read More »

M-Trends 2026: Initial Access Handoff Shrinks From Hours to 22 Seconds

M-Trends 2026: Initial Access Handoff Shrinks From Hours to 22 Seconds 2026-03-23 at 17:17 By Eduard Kovacs The latest M-Trends report is based on insights from over 500,000 hours of Mandiant incident response investigations in 2025. The post M-Trends 2026: Initial Access Handoff Shrinks From Hours to 22 Seconds appeared first on SecurityWeek. This article […]

M-Trends 2026: Initial Access Handoff Shrinks From Hours to 22 Seconds Read More »

Kevin Mandia’s Armadin Launches With $190 Million in Funding

Kevin Mandia’s Armadin Launches With $190 Million in Funding 2026-03-10 at 16:33 By Kevin Townsend Armadin uses AI-powered red teaming to find and exploit weaknesses in the same way that attackers attack them. The post Kevin Mandia’s Armadin Launches With $190 Million in Funding appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Kevin Mandia’s Armadin Launches With $190 Million in Funding Read More »

Coruna: Spy-grade iOS exploit kit powering financial crime

Coruna: Spy-grade iOS exploit kit powering financial crime 2026-03-03 at 21:02 By Zeljka Zorz A powerful iOS exploit kit has circulated among multiple threat actors over the past year, moving from a commercial surveillance operation to state-linked espionage campaigns and, ultimately, ended into the hands of financially motivated hackers, according to new research from Google’s […]

Coruna: Spy-grade iOS exploit kit powering financial crime Read More »

ShinyHunters flip the script on MFA in new data theft attacks

ShinyHunters flip the script on MFA in new data theft attacks 2026-02-02 at 18:50 By Zeljka Zorz Multi-factor authentication (MFA) is supposed to defend against phishing attacks, but threat actors operating under the ShinyHunters banner are using it as a pretext in ongoing social engineering attacks aimed at bypassing it. Among those successfully targeted in […]

ShinyHunters flip the script on MFA in new data theft attacks Read More »

WinRAR vulnerability still a go-to tool for hackers, Mandiant warns

WinRAR vulnerability still a go-to tool for hackers, Mandiant warns 2026-01-28 at 17:02 By Zeljka Zorz State-sponsored hackers and financially motivated attackers continue leveraging a critical WinRAR vulnerability (CVE-2025-8088) that’s been fixed over half a year ago. CVE-2025-8088 is a path traversal vulnerability that can be exploited via maliciously crafted RAR archives. “The exploit chain […]

WinRAR vulnerability still a go-to tool for hackers, Mandiant warns Read More »

AuraInspector: Open-source tool to audit Salesforce Aura access control misconfigurations

AuraInspector: Open-source tool to audit Salesforce Aura access control misconfigurations 2026-01-13 at 17:45 By Anamarija Pogorelec Google and its Mandiant threat intelligence unit have released AuraInspector, an open-source tool aimed at auditing data access paths in Salesforce Experience Cloud applications. The tool focuses on the Aura framework, which underpins many Salesforce user interfaces and plays […]

AuraInspector: Open-source tool to audit Salesforce Aura access control misconfigurations Read More »

Gainsight breach: Salesforce details attack window, issues investigation guidance

Gainsight breach: Salesforce details attack window, issues investigation guidance 2025-11-26 at 16:30 By Zeljka Zorz The number of Salesforce customers affected by the recent compromise of Gainsight-published applications is yet to be publicly confirmed, but Salesforce released indicators of compromise (IoCs) and simultaneously shed some light on when the attack likely started. The provided list […]

Gainsight breach: Salesforce details attack window, issues investigation guidance Read More »

Salesforce Gainsight compromise: Early findings and customer guidance

Salesforce Gainsight compromise: Early findings and customer guidance 2025-11-21 at 14:16 By Zeljka Zorz In the wake of Salesforce’s announcement about “unusual activity involving Gainsight-published applications” and the company’s revocation of access and refresh tokens associated with them, Gainsight has been doing a good job keeping customers updated on current investigation findings. On the status […]

Salesforce Gainsight compromise: Early findings and customer guidance Read More »

Salesforce investigates new incident echoing Salesloft Drift compromise

Salesforce investigates new incident echoing Salesloft Drift compromise 2025-11-20 at 23:14 By Zeljka Zorz In what may be a repeat of the Salesloft Drift supply chain compromise, Salesforce confirmed that they’ve identified unusual activity involving Gainsight-published apps connected to Salesforce. “Our investigation indicates this activity may have enabled unauthorized access to certain customers’ Salesforce data […]

Salesforce investigates new incident echoing Salesloft Drift compromise Read More »

Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480)

Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480) 2025-11-11 at 14:47 By Zeljka Zorz Attackers have exploited a now-fixed vulnerability (CVE-2025-12480) in the Gladinet Triofox secure file sharing and remote access platform while it was still a zero-day, Mandiant revealed on Monday. CVE-2025-12480 exploitation and attack details Gladinet’s Triofox solution is used by medium and large […]

Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480) Read More »

Scroll to Top