Threat Intelligence

Iran Readied Cyberattack Capabilities for Response Prior to Epic Fury

Iran Readied Cyberattack Capabilities for Response Prior to Epic Fury 2026-03-19 at 18:19 By Kevin Townsend Analysis reveals a six-month buildup of Iran-linked cyber infrastructure, including US-based shell companies, designed to weather kinetic strikes and ensure the resilience of its global hacking operations. The post Iran Readied Cyberattack Capabilities for Response Prior to Epic Fury […]

Iran Readied Cyberattack Capabilities for Response Prior to Epic Fury Read More »

AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks

AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks 2026-03-17 at 12:32 By Kevin Townsend Akamai warns that Layer 7 DDoS, API abuse and AI-powered attacks are merging into coordinated, multi-vector campaigns that are harder to detect and defend against. The post AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks

AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks Read More »

The Ultimate Guide to Dark Web Monitoring in 2026: Protect Your Data Before Attackers Strike

The Ultimate Guide to Dark Web Monitoring in 2026: Protect Your Data Before Attackers Strike 2026-03-13 at 16:29 By Ashish Khaitan In 2026, cyber threats are originating on the dark web, where stolen credentials, exploit kits, and attack plans are bought and sold before they ever reach corporate networks. Organizations are turning to dark web

The Ultimate Guide to Dark Web Monitoring in 2026: Protect Your Data Before Attackers Strike Read More »

The Human IOC: Why Security Professionals Struggle with Social Vetting

The Human IOC: Why Security Professionals Struggle with Social Vetting 2026-03-12 at 14:30 By Joshua Goldfarb Applying SOC-level rigor to the rumors, politics, and ‘human intel’ can make or break a security team. The post The Human IOC: Why Security Professionals Struggle with Social Vetting appeared first on SecurityWeek. This article is an excerpt from

The Human IOC: Why Security Professionals Struggle with Social Vetting Read More »

Agentic attack chains advance as infostealers flood criminal markets

Agentic attack chains advance as infostealers flood criminal markets 2026-03-12 at 08:35 By Mirko Zorz Cybercriminals spent much of 2025 automating their operations, shifting from one-off attacks to systems that can run entire intrusion cycles with minimal human input. Data collected from criminal forums, illicit marketplaces, and underground chat services shows a threat environment where

Agentic attack chains advance as infostealers flood criminal markets Read More »

Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks

Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks 2026-03-09 at 15:37 By Ashish Khaitan Cybersecurity agencies across the Pacific region are sharing concerns about the ransomware group INC Ransom’s expanding activities and the growing influence of its affiliate network. A joint advisory issued by the Australian Cyber Security Centre (ACSC), National

Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks Read More »

The Blast Radius Problem: Stolen Credentials are Weaponizing Agentic AI

The Blast Radius Problem: Stolen Credentials are Weaponizing Agentic AI 2026-02-25 at 18:16 By Kevin Townsend More than half (56%) of the 400,000 vulnerabilities IBM X-Force tracked in 2025 required no authentication before exploitation. The post The Blast Radius Problem: Stolen Credentials are Weaponizing Agentic AI appeared first on SecurityWeek. This article is an excerpt

The Blast Radius Problem: Stolen Credentials are Weaponizing Agentic AI Read More »

Airline brands become launchpads for phishing, crypto fraud

Airline brands become launchpads for phishing, crypto fraud 2026-02-25 at 08:05 By Sinisa Markovic Airline brands sit at the center of peak travel booking cycles, loyalty programs, and high value transactions. Criminal groups continue to register thousands of lookalike domains tied to these brands, targeting travelers, employees, and business partners. Recent threat intelligence from BforeAI’s

Airline brands become launchpads for phishing, crypto fraud Read More »

Edge systems take the brunt of internet-wide exploitation attempts

Edge systems take the brunt of internet-wide exploitation attempts 2026-02-25 at 07:18 By Anamarija Pogorelec Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across

Edge systems take the brunt of internet-wide exploitation attempts Read More »

How the Protective Security Policy Framework Shapes Australia’s Commonwealth Cyber Security Strategy 

How the Protective Security Policy Framework Shapes Australia’s Commonwealth Cyber Security Strategy  2026-02-16 at 13:41 By Ashish Khaitan The Australian government has intensified efforts to protect digital infrastructure across all Commonwealth entities. Two recent publications, the 2024–25 Protective Security Policy Framework (PSPF) Assessment Report and the 2025 Commonwealth Cyber Security Posture Report, offer a comprehensive snapshot of current achievements, challenges, and future priorities in government cyber resilience.  The PSPF Assessment Report highlights

How the Protective Security Policy Framework Shapes Australia’s Commonwealth Cyber Security Strategy  Read More »

SpiderLabs Ransomware Tracker Update January 2025: Qilin Continues as Dominant Threat Group

SpiderLabs Ransomware Tracker Update January 2025: Qilin Continues as Dominant Threat Group 2026-02-03 at 17:02 By The January 2026 edition of LevelBlue SpiderLabs ransomware tracker noted a sharp fall in the number of attacks launched compared to December 2025. Qilin remained the top attacker, but there was a reshuffling of the remaining top five attackers

SpiderLabs Ransomware Tracker Update January 2025: Qilin Continues as Dominant Threat Group Read More »

OPNsense 26.1 brings updates to open-source firewall management

OPNsense 26.1 brings updates to open-source firewall management 2026-01-29 at 01:17 By Anamarija Pogorelec OPNsense, the open-source firewall and network security platform, reached version 26.1, adding a range of updates affecting management, traffic visibility, automation interfaces, and core services. Changes in firewall management and APIs Version 26.1, code-named Witty Woodpecker, introduces revisions to the firewall

OPNsense 26.1 brings updates to open-source firewall management Read More »

Cyber Insights 2026: Threat Hunting in an Age of Automation and AI

Cyber Insights 2026: Threat Hunting in an Age of Automation and AI 2026-01-26 at 14:37 By Kevin Townsend Understanding how threat hunting differs from reactive security provides a deeper understanding of the role, while hinting at how it will evolve in the future. The post Cyber Insights 2026: Threat Hunting in an Age of Automation

Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Read More »

Critical Infrastructure Attacks Became Routine for Hacktivists in 2025

Critical Infrastructure Attacks Became Routine for Hacktivists in 2025 2026-01-20 at 14:24 By Ashish Khaitan Hacktivists moved well beyond their traditional DDoS attacks and website defacements in 2025, increasingly targeting industrial control systems (ICS), ransomware, breaches, and data leaks, as their sophistication and alignment with nation-state interests grew.  That was one of the conclusions in Cyble’s exhaustive new 2025 Threat Landscape report, from which this blog was adapted. 

Critical Infrastructure Attacks Became Routine for Hacktivists in 2025 Read More »

Cyber Insights 2026: Information Sharing

Cyber Insights 2026: Information Sharing 2026-01-19 at 17:21 By Kevin Townsend Information sharing is necessary for efficient cybersecurity, and is widespread; but never quite perfect in practice. The post Cyber Insights 2026: Information Sharing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cyber Insights 2026: Information Sharing Read More »

Ransomware and Supply Chain Attacks Soared in 2025

Ransomware and Supply Chain Attacks Soared in 2025 2026-01-16 at 10:25 By Ashish Khaitan Overview  Ransomware and supply chain attacks soared in 2025, and persistently elevated attack levels suggest that the global threat landscape will remain perilous heading into 2026.  Cyble recorded 6,604 ransomware attacks in 2025, up 52% from the 4,346 attacks claimed by ransomware groups in 2024. The year ended with a near-record 731 ransomware attacks in December, second only to February 2025’s record totals (chart below).  Supply

Ransomware and Supply Chain Attacks Soared in 2025 Read More »

Enterprise security faces a three-front war: cybercrime, AI misuse, and supply chains

Enterprise security faces a three-front war: cybercrime, AI misuse, and supply chains 2026-01-13 at 11:04 By Anamarija Pogorelec Security teams are dealing with pressures tied to AI use, geopolitical instability, and expanding cybercrime that reach beyond technical controls, according to findings from the World Economic Forum’s Global Cybersecurity Outlook 2026. AI drives risk growth and

Enterprise security faces a three-front war: cybercrime, AI misuse, and supply chains Read More »

What security teams can learn from torrent metadata

What security teams can learn from torrent metadata 2026-01-12 at 08:10 By Mirko Zorz Security teams often spend time sorting through logs and alerts that point to activity happening outside corporate networks. Torrent traffic shows up in investigations tied to policy violations, insider risk, and criminal activity. A new research paper looks at that same

What security teams can learn from torrent metadata Read More »

UTMStack: Open-source unified threat management platform

UTMStack: Open-source unified threat management platform 2025-12-10 at 08:52 By Sinisa Markovic UTMStack is an open-source unified threat management platform that brings SIEM and XDR features into one system. The project focuses on real time correlation of log data, threat intelligence, and malware activity patterns gathered from different sources. The goal is to help organizations

UTMStack: Open-source unified threat management platform Read More »

Scroll to Top