Normal view

There are new articles available, click to refresh the page.
Yesterday — 22 July 2026IT Security

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.

Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective

22 July 2026 at 12:05

Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape.

The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for threat intelligence that informs strategic decision-making rather than simply providing indicators of compromise.

According to Bridewell, organisations are looking beyond traditional security monitoring as ransomware groups become more organised, attackers exploit trusted services and social engineering campaigns become more sophisticated. Rather than reacting to incidents, businesses want intelligence that helps them anticipate threats, understand adversaries and focus security resources where they will have the greatest impact.

Led by Gavin Knapp, Head of Cyber Threat Intelligence, BCON Collective will provide strategic, operational and tactical intelligence designed to support more informed security decision-making. The team works across areas including threat detection, vulnerability prioritisation, incident response and long-term cyber resilience planning.

“Threat intelligence has become its own discipline within cybersecurity,” said Anthony Young, CEO of Bridewell. “Organisations are progressing to see it as not just something that sits alongside security operations, rather they expect it to shape strategic decisions, inform vulnerability management and strengthen incident response.

“Gavin and the team have built an exceptional reputation for producing intelligence that is both technically rigorous and genuinely actionable. As customer demand for these services continues to grow, it made sense to give this capability its own identity while keeping it firmly rooted within Bridewell’s wider cybersecurity expertise.”

Bridewell said its CTI team has built a reputation for producing original threat research covering emerging cyber threats and attacker activity. Recent research has examined ransomware groups including DragonForce, the tactics used by Scattered Spider during attacks against major UK retailers, emerging phishing techniques such as FileFix and ConsentFix, and nation-state activity linked to North Korea.

Knapp believes the real value of threat intelligence lies in helping organisations cut through the volume of available data.

“The biggest misconception about threat intelligence is that it’s about collecting more information. It isn’t. It’s about reducing uncertainty,” he said. “Every security team already has more data than it can realistically process. The challenge is knowing which threats actually matter, which risks deserve immediate attention and where to focus before attackers make the decision for you.

“Most importantly our threat research, threat intelligence and collaboration with both Bridewell offensive security, threat detection, and response capabilities allows us to provide the key components of a threat informed defense to our CNI client base.

“BCON Collective reflects the evolution of the work we’ve already been doing for our clients. It gives our threat research and intelligence capability its own identity and creates a platform through which we can share more of our research, collaborate more closely with customers and continue helping organisations stay one step ahead of an increasingly complex threat landscape.”

Alongside its advisory services, BCON Collective will expand its programme of original threat research, annual intelligence reports, threat actor profiling and strategic intelligence briefings for organisations operating across critical national infrastructure, the public sector and commercial sectors.

The post Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective appeared first on IT Security Guru.

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns

22 July 2026 at 06:16

Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the overall trajectory of ransomware activity continues to point upwards.

The report recorded 665 ransomware attacks in June alone, with the industrials sector once again the most heavily targeted, accounting for 30% of attacks across the quarter and 28% in June. Consumer Discretionary and Information Technology rounded out the top three targeted sectors for the quarter.

North America remained the most targeted region, absorbing 44% of all Q2 attacks and 41% of June’s total, followed by Europe (26% for the quarter, 23% in June) and Asia. Qilin held its position as the most active ransomware group for a fifth consecutive quarter, linked to 14% of all Q2 attacks (301 victims), ahead of The Gentlemen (238 victims) and DragonForce (145 victims). NCC Group also flagged the emergence of KryBit, a new Ransomware-as-a-Service operation that claimed 56 victims in its first full quarter of activity.

VPNs remain a favoured entry point

The report’s spotlight section highlights corporate VPNs and internet-facing edge devices as the ransomware ecosystem’s most exploited entry point so far in 2026. Groups including Akira, Qilin and The Gentlemen have all been observed exploiting vulnerabilities in products from vendors such as Fortinet, SonicWall, Citrix and Check Point to bypass authentication and gain a foothold inside victim networks.

NCC Group said vulnerabilities affecting VPN products account for around 15% of the 150-plus Threat Intelligence Alerts it has issued so far this year, many rated high or critical severity. The report also points to “FortiBleed,” a large-scale credential exposure incident uncovered in June affecting roughly half of all publicly exposed FortiGate devices, as a development likely to fuel further exploitation in the coming months.

Software supply chain under sustained assault

Alongside the ransomware data, NCC Group’s analysts describe a marked escalation in attacks against the software development ecosystem during Q2, with campaigns hitting GitHub Actions, npm, PyPI, Docker Hub, Open VSX and the Visual Studio Code Marketplace. The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.

The report warns that these campaigns exploit “transitive trust” in software supply chains, turning maintainer accounts, CI/CD tokens and cloud credentials into high-value targets, with effects that can cascade well beyond the organisation initially compromised.

“A board-level issue”

Matt Hull, VP and Head of Cyber Intelligence and Response at NCC Group, said supply chain attacks remain one of the most attractive routes for threat actors to inflict significant operational, financial, and reputational damage, and that businesses need continuous, rather than ad hoc, monitoring and resilience.

“Although there has not been a material rise in ransomware volume in the last quarter,” Hull said, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. He added that organisations must treat cyber security as the board-level issue it is, pointing to geopolitical tensions and rapidly evolving AI capabilities as compounding pressures on defenders.

NCC Group’s report also examines the deepening professionalisation of ransomware operations such as The Gentlemen, a rapidly-scaling RaaS group whose leaked internal database revealed structured negotiation tactics and a dedicated suite of EDR-disabling tools distributed to affiliates. Separately, the report notes a growing convergence between commodity infostealer malware and higher-end intrusion tradecraft, with new variants adopting rootkit-style concealment, browser-extension-based credential theft, and off-host decryption to evade detection.

The full report also covers geopolitical developments, including rising China-Taiwan tensions, Belarus’s shifting posture toward Russia, and Ireland’s incoming EU Council presidency, which NCC Group assesses could shape targeting patterns for state-linked threat actors in the second half of the year.

The post Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns appeared first on IT Security Guru.

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns

22 July 2026 at 05:56

A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims.

The “Cyber Threat Landscape: UK & Ireland” report, published by threat intelligence firm CYFIRMA, finds that financially motivated cybercriminals and state-aligned actors are frequently targeting the same sectors, finance, telecoms, technology, healthcare and government, and warns that cybercrime, espionage and geopolitical disruption are becoming harder to tell apart.

Russia, China, North Korea and Iran all in the mix

According to the report, Russia remains the most immediate geopolitical cyber threat to the region, with Russian-linked groups focused on critical infrastructure, undersea cables and disinformation tied to the ongoing war in Ukraine. China is flagged as the more significant long-term concern, with state-linked groups pursuing intellectual property theft and “living off the land” techniques designed to maintain quiet, persistent access inside critical networks.

The report also names several state-sponsored groups actively targeting the UK, including Russia’s APT28 (Fancy Bear) and APT29 (Cozy Bear), and China-linked APT15 and GALLIUM. It highlights a recent APT28 campaign that hijacks vulnerable home and small-office routers to redirect DNS traffic, quietly harvesting credentials and login tokens from unsuspecting users. North Korea’s Lazarus Group is also named in connection with fake job-offer lures targeting European defence and drone manufacturers, part of the long-running “Operation DreamJob” campaign.

Ransomware still dominates, with the UK bearing the brunt

Ransomware remains the most visible threat. CYFIRMA’s data shows Qilin as the most active gang targeting the region between January and May 2026, followed by DragonForce, The Gentlemen and Cl0p, with the UK absorbing the overwhelming majority of recorded victims. Ireland saw far fewer incidents, but the report notes that groups including The Gentlemen, Qilin and Interlock have all claimed Irish victims, and activity there peaked sharply in May 2026.

Professional services, manufacturing, real estate and IT emerged as the sectors hit hardest by ransomware, the report finds, with most groups now relying on double extortion, encrypting systems while also stealing data to threaten public leaks if a ransom isn’t paid.

Financially motivated crews get creative with social engineering

The report also details the tactics of financially motivated groups such as FIN6, which has been posing as job seekers on LinkedIn and Indeed to trick recruiters into opening fake résumé links laced with malware, and Scattered Spider, which continues to abuse identity and access management systems by impersonating employees to helpdesk staff in order to reset credentials or bypass multi-factor authentication.

Dark web trade in UK and Irish data continues unabated

Beyond ransomware, the report catalogues a steady stream of underground forum listings offering UK and Irish personal data for sale throughout 2026 — including an alleged 120-million-record database from a UK gambling platform, a combo list of more than 657,000 UK email-password pairs, and a dataset said to contain 734,000 UK student records. CYFIRMA says this reflects a growing emphasis among criminal groups on monetising stolen data and credentials rather than relying solely on encryption-based extortion.

Critical vulnerabilities add to the pressure

The report also flags a cluster of critical vulnerabilities disclosed during the period, including several rated 9.0 or above in the n8n workflow automation platform, Cisco’s Secure Firewall ASA and FTD software, Fortinet’s FortiOS and FortiProxy products, and VMware’s ESXi and Workstation platforms — several of which have already been linked to active exploitation.

What organisations should do

CYFIRMA’s recommendations for organisations in both countries include:

  • Accelerating patching of internet-facing systems, VPNs and edge devices, which remain the most common entry point for both ransomware crews and state-backed actors.
  • Enforcing phishing-resistant multi-factor authentication and tightening helpdesk identity-verification processes to blunt social engineering attacks like those used by Scattered Spider and FIN6.
  • Testing ransomware and DDoS response plans, including backup recoverability, given the sustained pace of attacks on critical infrastructure and public services.
  • Increasing scrutiny of third-party and vendor access, as supply chain compromise continues to be used to reach multiple organisations through a single trusted relationship.

The report’s overall message is one of convergence: as ransomware operators, spies and hacktivists increasingly pursue overlapping goals through similar tools and techniques, CYFIRMA argues that organisations can no longer treat these as separate risks to be managed in isolation.

The full research report can be found here: https://www.cyfirma.com/research/cyber-threat-landscape-uk-ireland/

The post Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns appeared first on IT Security Guru.

Before yesterdayIT Security

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

21 July 2026 at 11:01

Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations.

The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform as it looks to improve visibility, simplify administration and better secure access across its international infrastructure.

Asite provides cloud-based collaboration software for the construction industry, helping organisations manage projects ranging from digital twins and 3D models to document control and supplier collaboration. With more than 500 employees and data centres spanning nine global locations, the company required a more consistent approach to managing privileged accounts, passwords and machine identities.

According to the case study, Asite was looking to overcome the limitations of browser-based password managers alongside legacy privileged access management (PAM) and secrets management tools, which it found expensive and complex to maintain. The company also needed to securely extend privileged access controls to third-party suppliers and external partners working on customer projects.

“The deployment of KeeperPAM was extremely easy, one of the best in my experience,” said Tiago Rosado, Chief Information Security Officer at Asite. “I wish other tools were as easy to deploy.”

As part of the rollout, Asite standardised password management across its workforce using Keeper’s platform, replacing browser-based password managers with centrally managed credential controls. The organisation also implemented Keeper BreachWatch to identify compromised credentials exposed on the dark web, while Keeper Secrets Manager automated the creation and rotation of secrets and encryption keys, reducing reliance on long-lived credentials.

Keeper said the deployment reflects a broader challenge facing organisations managing privileged access across distributed IT environments. Its 2026 research found that 34% of UK employees reuse passwords across multiple accounts, while 36% of UK respondents said enforcing strong password and credential practices remains either extremely or very challenging for IT and security teams.

The vendor positions KeeperPAM as a unified, cloud-native platform that combines enterprise password management, secrets management, privileged session management, endpoint privilege management, secure remote access and dark web monitoring within a single zero-trust architecture.

“Privileged access management has become a critical control layer for any organisation operating across distributed infrastructure and third-party ecosystems,” said Darren Guccione, CEO and Co-founder of Keeper Security. “Asite’s deployment of KeeperPAM demonstrates how organisations can move from fragmented, costly legacy tools to a unified platform that enforces least-privilege access, automates provisioning and delivers the visibility their security team needs, without the complexity that has historically made PAM difficult to scale.”

The full customer case study is available on the Keeper Security website.

The post KeeperPAM strengthens privileged access management for global construction SaaS provider Asite appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the report‘s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

“In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

“Many organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

21 July 2026 at 06:30

One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have continued working with suppliers despite known resilience or security concerns.

The figures come from the Data Health Check 2026, Databarracks’ annual survey of 500 UK IT decision-makers, which has tracked IT resilience since 2008. This year’s report paints a picture of organisations that recognise the danger posed by their supply chains, but frequently feel unable to act on that knowledge.

In many cases, the research suggests, businesses simply lack viable alternatives. More than a quarter of respondents (26%) identified “dependence on suppliers” as a main barrier to improving their organisation’s resilience.

Awareness without action

The Data Health Check found that supplier assessment is now standard practice for most organisations. Almost nine in ten businesses (89%) assess supplier resilience at the point of onboarding, and the majority (61%) go further by conducting assessments annually, quarterly, or continuously.

Despite this due diligence, the risk clearly persists once a supplier relationship is underway. “Supply chain vulnerabilities” was named as one of the top three IT resilience challenges organisations expect to face over the next five years, cited by 23% of respondents – behind only AI-driven cyber threats (46%) and ransomware attacks (26%).

The data also shows a clear link between known risk and real-world impact. Organisations that knowingly continued working with risky suppliers were more than four times as likely to experience a supplier-originated cyber incident: 43% of those organisations went on to suffer an incident, compared with just 10% of organisations that had not knowingly worked with risky suppliers.

“Treat your critical suppliers like you would your own business”

Commenting on the findings, Chris Butler, Resilience Director at Databarracks, said that supply chain resilience remains one of the most persistent weaknesses in UK organisations’ defences. “This year’s findings indicate that supply chain resilience remains a critical pain point for many businesses, which the majority are aware of and which continues to be exploited by attackers. When something goes wrong at a key supplier, the cascade effects can be profound for businesses throughout the chain.”

“Despite good intentions around assessing supplier resilience, most companies don’t fully understand the depth of complexity in their supply chains. Often they’ll know who their core suppliers are, but beyond that, visibility drops away.”

“The traditional approach to assessment has long been tick-box based, with compliance questionnaires growing longer every year. This approach creates a false sense of assurance rather than real resilience.”

Butler argued that genuine improvement requires businesses to move beyond paper-based assurance and to take direct ownership of the risk that suppliers pose to their operations. “To truly manage your supply chain continuity, it’s vital to actually get visibility of the situation. Business leaders need to treat supplier resilience as part of their own resilience, not somebody else’s problem. It’s a bit of a cliché but for good reason: you really need to treat your critical suppliers like you would your own business.”

He also urged organisations to take a more collaborative approach where smaller or less mature suppliers cannot be easily replaced. “Where there isn’t a viable alternative and your existing suppliers don’t have in-house business continuity skills, offer to help. Include your suppliers in your business continuity exercises and give them the chance to rehearse with you. It’s important to practice the response to disruption together rather than in isolation. Doing this will benefit you in the long run.”

Additionally, Jamie Akhtar, CEO and Co-Founder of CyberSmart, added: “This research highlights the severe impact supply-chain attacks are having on businesses of all sizes. It is concerning that one in four businesses has experienced a cyberattack through its supply chain, but what’s even more concerning is that almost half knowingly continue to work with suppliers that have identified security weaknesses. The findings show how difficult it can be for organisations to remain secure. Businesses must manage their own security, but also the security and resilience of their supplies as well.”

“Organisations, especially SMEs, should treat suppliers as part of their own security perimeter. They should assess third-party risks before onboarding, restrict access to essential systems and data, enforce multi-factor authentication, keep software patched and maintain tested backups. Regular supplier reviews and shared incident-response plans can also reduce disruption if a partner is compromised,” Akhtar continued. 

Part of a wider resilience picture

The supply chain findings sit within a broader Data Health Check 2026 report that shows organisations bracing for a harsher resilience environment. The study found that 65% of organisations now believe a serious cyber attack could threaten their survival, while cyber remains the leading cause of IT downtime for the fourth year running, cited by 30% of organisations as their biggest cause of outages.

The report also found reasons for optimism. Business continuity planning has reached a new high, with 90% of organisations now holding a plan and four in five of those kept up to date. Ransomware resilience is also improving: although one in four organisations (25%) experienced a ransomware attack in the last 12 months, only 18% of those affected paid the ransom, while 59% recovered from backups instead.

Databarracks said the overall findings point to “integrating IT and business resilience” as the most-cited priority for organisations in 2026, reflecting a growing recognition that modern incidents – including those originating in the supply chain – rarely respect the boundaries between cyber security, IT operations, business continuity and executive decision-making.

The post 1 in 4 businesses hit by cyber attacks through their supply chain in the last year appeared first on IT Security Guru.

DigiCert expands its EMEA channel strategy with Ignition Technology

21 July 2026 at 06:19

DigiCert, a global leader in intelligent trust, has announced a strategic distribution partnership with Ignition Technology to scale its presence across EMEA, accelerate market entry and expand partner-led growth.

Through the partnership, Ignition will bring DigiCert ONE® to customers and partners across the UK and Ireland, DACH, France, Benelux and the Nordics. DigiCert’s comprehensive platform unifies PKI, DNS and automated certificate lifecycle management, helping organisations establish trust across machine identities, software, devices, digital content, and AI agents, while reducing outages, strengthening compliance and supporting the transition to post quantum cryptography.

“Across EMEA, organisations are facing increasingly complex security, operational and regulatory challenges as they embrace AI, modernise infrastructure and prepare for the post quantum era,” said Sean Remnant, Chief Strategy Officer, Ignition Technology. ”They don’t need more disconnected tools. They need a platform that simplifies complexity, helps them move faster and gives them confidence they’re ready for what’s next.”

“This partnership is about creating high impact, scalable growth across EMEA,” said Paul Holt, Group Vice President, EMEA at DigiCert. ”Ignition understands how to build markets, grow partner ecosystems and execute at pace. Together, we’ll help more organisations build the confidence to embrace AI, automate trust at scale and prepare for the post quantum era.”

The partnership reinforces DigiCert’s commitment to growing its channel across EMEA, enabling partners to help organisations simplify security, strengthen resilience and prepare with confidence for the AI and post quantum era.

The post DigiCert expands its EMEA channel strategy with Ignition Technology appeared first on IT Security Guru.

95% of Security Teams Blindsided by Vulnerabilities Between Tests

21 July 2026 at 06:02

The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises.

The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found that 95% had discovered high or critical vulnerabilities outside their scheduled testing windows within the past year. Of those, 42% said this had happened at least once a month, underscoring a widening gap between how quickly enterprise environments change and how infrequently they are actually tested.

Three connected gaps

Synack’s researchers point to three related problems undermining enterprise security assurance. The first is a coverage gap: 38% of respondents said at least a quarter of their critical attack surface had gone independently tested or validated for more than 90 days.

The second is what the report calls an AI trust gap. Despite growing enthusiasm for AI-assisted testing, 79% of respondents said they would not act on an AI-generated finding without a human validating it first.

The third is a maturity gap: only 15% of respondents described their security testing and validation programme as continuous, despite continuous testing being the most commonly cited method (named by 22%) for confirming whether a finding is actually exploitable.

One CISO who took part in the study summed up the operational impact: “It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.”

AI expands coverage, but humans are still needed to prove exploitability

The research suggests enterprises are keen for AI to take on a bigger role in reconnaissance, surfacing potential vulnerabilities and expanding testing coverage, but are far less willing to let it operate without human oversight. Respondents said human expertise remains essential for validating exploitability, assessing severity and business risk, testing complex workflows, cutting down false positives, and communicating risk to stakeholders.

“Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent,” said Angela Heindl-Schober, Chief Marketing Officer at Synack. “The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution.”

The study also identifies the main barriers to continuous security validation, including compliance-driven test cycles, integration complexity, a lack of trust in automated findings, false positives, difficulty demonstrating return on investment, and unclear ownership across teams.

“Automation can surface more signals, but security teams need evidence, not noise,” said Mark Kuhr, Co-Founder and Chief Technology Officer at Synack. “Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do.”

A Human + AI model for continuous validation

Synack argues the findings reinforce the case for a combined Human + AI approach to security validation. Its Sara AI Pentesting offering uses what the company calls the Synack Autonomous Red Agent to scale reconnaissance and testing, while the Synack Red Team, a vetted network of more than 1,500 security researchers, is used to validate real-world exploitability, uncover chained attack paths, and provide context that automation alone cannot supply.

Together, the company says, the two approaches are designed to help organisations move away from periodic, point-in-time security snapshots and towards continuous security validation.

The post 95% of Security Teams Blindsided by Vulnerabilities Between Tests appeared first on IT Security Guru.

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

20 July 2026 at 09:27

Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.

The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.

Rather than requiring organisations to build governance frameworks from scratch, the Policy Hub provides a library of policies that can be activated immediately and customised to suit different environments. Salt describes the approach as similar to an “app store” for agentic security, allowing security teams to deploy pre-built governance policies across the infrastructure that supports AI agents.

The expanded library includes more than a dozen policies designed specifically for agentic AI, covering areas such as MCP server configuration, agent authorisation and the risks associated with autonomous agent behaviour. Other policies address data security, OAuth, API architecture, third-party risk and compliance with frameworks including GDPR, ISO 27001, HIPAA, PCI DSS and SOC 2.

According to Salt, 61 of the 100 policies are enabled automatically, while the remaining policies can be activated with a single click. Organisations can also create their own custom policies to extend governance beyond the pre-built library. The Policy Hub forms part of the Salt Agentic Security Platform, which provides visibility across what the company calls the Agentic Security Graph, encompassing LLMs, MCP servers, APIs and connected enterprise applications.

Michael Callahan, VP of Strategy and CMO at Salt Security, said many organisations recognise the need for AI governance but struggle to know where to begin. “When we launched the Policy Hub in 2024, the most common thing we heard from CISOs was, ‘We know we need posture governance, but we have no idea where to start.’ That question was killing governance programmes before they launched. The inclusion of 100 policies means that question now has a concrete answer. Security teams can walk in on day one with meaningful protection already active and it can be extended from there without limit.”

Salt said many of the policies were originally developed for API posture governance but now play a broader role as organisations deploy AI agents. As AI systems increasingly depend on APIs, identity platforms and MCP servers to perform actions, the company believes governance must extend across the entire agentic infrastructure rather than focusing solely on AI models or prompts.

The company also highlighted its MCP server discovery capabilities, introduced in 2025, which are supported by dedicated governance policies for identifying configuration issues and controlling how MCP servers interact with enterprise systems.

In June, Salt also launched Salt Code, extending the same governance engine into the software development lifecycle to apply policies to AI-generated code during development.

Aner Gelman, VP of Products at Salt Security, said boards are increasingly asking organisations to demonstrate how AI is being governed.

“The board question CISOs are being asked right now is not whether we have AI governance. It is whether we can prove it. Having 100 policies in active deployment is a concrete, operational answer to that question. Not a roadmap. Not a strategy. An active governance layer running today.”

The 100 pre-built policies are available immediately to customers using the Salt Agentic Security Platform.

The post Salt Security tackles AI governance challenge with 100 pre-built agentic security policies appeared first on IT Security Guru.

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

20 July 2026 at 08:58

Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.

The partnership brings together Critical Cloud’s Managed Runtime Assurance operating model with Tarian Labs’ offensive security specialists, whose experience spans government, defence and critical national infrastructure projects.

Managed Runtime Assurance focuses on the day-to-day operation of production applications, cloud platforms and AI systems, helping organisations maintain visibility, resilience, security, operational efficiency and compliance readiness. Instead of producing a report that reflects a single point in time, security findings become part of an ongoing cycle of remediation, retesting and evidence-based validation.

The service combines Critical Cloud’s Datadog-powered managed operating model with Tarian Labs’ independent testing capabilities through an Observe, Detect, Validate methodology. Critical Cloud manages monitoring, governance and runtime operations across production environments, while Tarian Labs performs penetration testing, cloud and infrastructure assessments, web application reviews, API testing and follow-up verification. Findings move directly into remediation before independent retesting confirms they have been addressed.

The partnership preserves clear separation of responsibilities. Tarian Labs owns testing methodology, findings, severity ratings and retesting, while Critical Cloud leads remediation and operational improvements. Every engagement is delivered under customer authorisation, agreed scope, defined rules of engagement and controlled evidence management.

“Detection without validation is hope, not assurance,” said James Smith, CEO of Critical Cloud. “Today’s regulated organisations need continuous proof that production controls continue to perform as intended, particularly as technology changes at an increasingly rapid pace.”

“A penetration test should be the beginning of improvement rather than the end of the process,” said Kevin Hanford, Co-Founder and CEO of Tarian Labs. “By linking independent testing with remediation and verification, we help organisations demonstrate that security risks have been effectively resolved.”

Continuous Runtime Security Validation is now available across the UK and Ireland, with a packaged joint offering planned for a later date. Future joint activities include fintech events in Wales and a live demonstration environment that illustrates the complete Observe, Detect, Validate lifecycle, including remediation, retesting and evidence of closure.

Critical Cloud is ISO 27001 certified, holds Cyber Essentials Plus, and is recognised as a Powered by Datadog accredited partner and Datadog Advanced Partner. Tarian Labs delivers engagements through CREST registered practitioners with final sign-off at NCSC-recognised CHECK Team Leader (CSTL-INF) level.

The post New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience appeared first on IT Security Guru.

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

20 July 2026 at 07:27

Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.

The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.

“The strongest pattern in the first half of 2026 was the way different threats converged around trust,” said Luis Corrons, Security Evangelist at Gen. Scams, account takeovers, malicious packages and AI agents, he said, all moved closer to the systems, workflows and permissions people already rely on, meaning attacks increasingly succeed before a victim ever reaches an obviously suspicious moment.

Tech support and imposter scams surge

Tech support scam detections reached 20.3 million blocked attacks in H1 2026, up 61.6% on the second half of 2025. Gen said part of the rise reflects newly introduced detection coverage, but also pointed to campaigns hosted on legitimate-looking cloud infrastructure, including ondigitalocean[.]app domains and fake Windows Defender error pages hosted on Google Cloud Storage in Germany and France. Windows users accounted for 92% of blocked tech support scam attacks, and the US, France, Germany, and Japan were the most targeted countries.

Government impersonation scams rose 387% to almost 1 million blocked attacks, with 81% of that activity concentrated in the United States. Family impersonation scams, often delivered by SMS to Android users and increasingly using AI voice cloning, rose 454.2% and were concentrated in the Netherlands, France, Ireland and Germany.

E-shop scams and fake online stores became one of the highest-volume categories tracked, with 114.2 million blocked attacks, up 109% half-over-half, including one variant using .click domains that alone accounted for more than 10 million blocks. “Fake tutorial” or “scam-yourself” attacks, which trick users into manually running malicious commands via fake CAPTCHA or verification prompts, rose 193% to 5.26 million blocked attempts.

Malvertising was also a major driver of activity, representing almost 30% of detections. Gen’s separate Scam Ad Machine research, examining 14.57 million ads across the EU and UK, found that nearly one in three were scam-related, generating more than 304 million impressions in under a month.

Localised banking trojans, infostealers and crypto-clippers

Regional malware campaigns leaned heavily on local-language lures. Banking trojan operators in Czechia, Slovakia and Poland used JavaScript droppers disguised as shipping notices and invoices, in some cases sent from already-compromised corporate mailboxes. RAT campaigns in Italy, Poland and Czechia used fake invoices, steganographic loaders and multi-stage PowerShell to deploy Remcos and Babylon RAT, among others.

Gen Threat Labs also identified Remus, a new 64-bit infostealer it attributes to the Lumma Stealer family, based on shared obfuscation, string-handling, and browser credential theft techniques, including a bypass of Chrome’s Application-Bound Encryption. Separately, researchers tracked a four-stage cryptocurrency infection chain ending in a Rust-based clipboard hijacker that monitors for wallet addresses across 21 blockchain types and silently swaps in attacker-controlled addresses. The same campaign used Binance Smart Chain to resolve command-and-control infrastructure via EtherHiding, making its infrastructure harder to take down than a conventional domain.

Software supply chain and a cracked-macOS-app wave

Gen documented multiple software supply chain incidents, including compromised npm and PyPI packages, hijacked maintainer accounts, and GitHub accounts abused to push malicious commits while preserving a convincing commit history. In one case, a compromised npm publishing token was used to push an unauthorised update to the Cline CLI that installed malware referred to as OpenClaw onto developer machines during an eight-hour window.

On macOS, Gen tracked a cracked-software distribution chain that pushed users toward mirror sites, torrents, forums, and Telegram channels, blocking roughly 108,000 launch attempts for these applications within 48 hours in a single wave. The payloads included cryptominers, infostealers, and backdoors, but Gen said the more significant issue was permission abuse: installation guides frequently instructed users to disable Gatekeeper and System Integrity Protection, or to grant Full Disk Access, thereby granting broad system access to unsigned binaries.

AI agents move from chatbot risk to execution risk

A significant portion of the report focuses on AI agents, which Gen says have shifted the security conversation because they turn model output into real-world action, fetching URLs, installing packages, editing files, or calling APIs, often with a user’s own credentials and local access.

The report cites an incident in which a Meta AI security researcher granted an AI agent access to her inbox to triage messages, and the agent began deleting emails while reportedly ignoring stop commands. Gen noted that this was reported by TechCrunch and could not be independently verified as forensic evidence, but said it illustrates how a misinterpreted instruction can have real consequences once an agent holds genuine permissions.

The report also references indirect prompt injection documented in the wild by Unit 42, where hidden instructions embedded in web content are later processed by an AI system, and separate research (“Double Agents”) identifying excessive default permissions in a cloud AI agent deployment that allowed a pivot into customer project resources.

Gen discusses its own response to agent risk at length, including a runtime enforcement tool called Sage that checks agent actions, shell commands, URL fetches, file writes, package installs, before they execute, alongside an Agent Trust Hub for pre-use verification, an Agent Detection and Response (ADR) capability, and a proposed cross-industry standard, AARTS, intended to give agent hosts a shared way to expose security-relevant events and enforcement points.

The report also touches on Anthropic’s Claude Mythos and Fable 5 models, noting Anthropic’s own disclosure that Mythos Preview could identify and exploit vulnerabilities in major operating systems and browsers when directed to, and that access to Fable 5 and Mythos 5 was briefly suspended in mid-2026 following a US export-control directive before being restored. Gen frames this as evidence that, once a model can materially accelerate cyber work, questions of who can access it and under what safeguards become part of the security picture, not just the model’s behaviour.

Privacy: persistent access, not just breaches

Gen blocked an average of 310.8 million tracking attempts per month in H1 2026, around 1.9 billion over the half-year. The report highlights GhostPairing, an attack that abuses WhatsApp’s legitimate device-linking feature to trick users into approving an attacker-controlled browser as a linked device, giving the attacker an authorised session that can persist until manually revoked.

The report also raises AI agent memory as an emerging privacy boundary, citing research papers describing backdoored agents that exfiltrate stored user context via disguised tool calls, and separately flags recent FTC settlements and actions against location-data brokers Kochava and Mobilewalla for selling sensitive location data without consent.

Identity and financial fraud: exposure moves fast toward misuse

Gen recorded 18,618 breach events affecting its customers in H1 2026, up 94.5% on the prior half-year, while breach notification alerts with an identified source sent to Norton and LifeLock users rose 628.1% to 3.3 million. February alone accounted for roughly a third of all H1 breach notifications, a spike Gen links partly to the Under Armour breach reported in January 2026, which public reporting said affected around 72 million email addresses.

Downstream financial signals also rose sharply: credit inquiry alerts reached 460,000 in June; depository activity alerts rose 734%; credit activity alerts rose more than tenfold; and web skimming attacks blocked at checkout pages rose 212% to 996,300. Gen also flags a distinct pattern of first-party fraud, in which real, verified accounts, created by people recruited online with promises of quick cash, are later handed over to fraud operators for cash advance abuse, wallet funding or money mule activity, making the behaviour harder to catch at onboarding.

The takeaway

Gen’s overall conclusion is that few of the H1 2026 attacks relied on classic red flags such as poor grammar or obviously suspicious links. Instead, they were built around real reservation details, compromised-but-legitimate mailboxes, trusted update paths and permissions that users had already granted. The report argues that protection increasingly has to sit at the point where trust is granted or transferred, before a payment page, before a package installs, before an AI agent is allowed to act, rather than relying on users to spot the danger themselves.

The post Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust appeared first on IT Security Guru.

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

20 July 2026 at 06:32

A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.

The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.

A calendar as a dead drop

HOLLOWGRAPH is a lightweight implant that understands only two instructions, get and send, but carries them out entirely through trusted Microsoft cloud infrastructure rather than attacker-owned servers. Group-IB’s analysis describes the compromised mailbox’s calendar being used as a two-way dead drop: operators plant instructions by creating calendar events, and the malware exfiltrates stolen files by creating its own events with encrypted attachments.

To keep the mailbox owner from noticing anything unusual, every event created by the malware is dated far into the future, specifically 13 May 2050, with the stolen or tasking data hidden inside file attachments rather than the event body. Get requests search for events with a subject line referencing a task ID, while send operations upload encrypted data in chunks named “File{n}.txt” before renaming the event to an operator-recognisable tag.

DNS tunnelling keeps credentials fresh

Alongside the calendar-based C2 channel, HOLLOWGRAPH maintains a separate communications path used solely to refresh the Microsoft Entra ID (formerly Azure AD) credentials it needs to continue authenticating to the Graph API. Group-IB found that the malware performs DNS tunnelling, issuing IPv6 AAAA record lookups against an attacker-controlled domain, cloudlanecdn[.]com, to retrieve updated tenant IDs, client IDs, client secrets, and mailbox details, which it then writes to a configuration file on disk disguised as an ordinary log file, logAzure.txt.

According to the write-up, length-indicating queries and data-carrying queries are distinguished by naming convention, with each returned IPv6 address smuggling 14 usable bytes of payload that the malware reassembles into plaintext credential data. This DNS channel, researchers noted, is not itself encrypted.

Communications sent through the Graph API channel, by contrast, are protected with hybrid RSA and AES-256-GCM encryption, and the malware uses separate RSA key pairs for inbound tasking and outbound exfiltration, keeping the two directions cryptographically independent of one another.

Linked to the Cavern framework and possibly Lyceum

Group-IB said several technical characteristics tie HOLLOWGRAPH to the Cavern framework, including a matching command syntax and observed tasking that mirrors Cavern’s known structure, among them a “toggle debug logging” self-command used elsewhere by the framework.

The researchers stopped short of attributing the campaign to a specific, previously known threat actor, but noted overlaps with malware previously associated with Lyceum, a group considered a sub-cluster of the Iranian threat actor OilRig. Group-IB said Cavern’s modular backdoor functionality closely resembles a .NET backdoor used by Lyceum in early 2025, including shared command codes and a similar approach to loading plugin modules from disk on demand. The firm characterised this potential link as low confidence.

A small, disciplined set of victims

Group-IB said it identified at least 12 systems infected with HOLLOWGRAPH, of which only around three were actively exchanging data with the attacker at the time of analysis. The earliest observed communication between a victim and the attacker was recorded on 3 June 2026, with the most recent seen on 9 July 2026, indicating the malware has been in active use since at least early June.

Researchers said the small victim count, combined with the fact that the compromised mailbox used for exfiltration belongs to an Israeli organisation and that malware samples were uploaded for analysis from Israel, points to a deliberately narrow, targeted espionage operation rather than opportunistic mass compromise.

Why it matters

The use of legitimate cloud services for C2 is a well-established evasion tactic, but HOLLOWGRAPH’s approach of hiding both tasking and exfiltrated data inside calendar event attachments, dated decades into the future, illustrates how creatively threat actors are exploiting everyday collaboration features to slip past perimeter and email-security defences. Because the traffic runs entirely through Microsoft’s own infrastructure and a legitimately authenticated (if compromised) account, it can be difficult for defenders to distinguish from normal Microsoft 365 usage without close inspection of Graph API activity and mailbox audit logs.

Recommendations

Group-IB has urged organisations, particularly those operating in or connected to Israel, to:

  • Hunt for indicators associated with HOLLOWGRAPH and the Cavern framework, including the domain cloudlanecdn[.]com and the configuration file logAzure.txt.
  • Monitor Microsoft Graph API activity and mailbox audit logs for anomalous calendar operations performed by an application rather than a user, including event creation, attachment uploads and subject-line changes.
  • Watch for calendar artefacts consistent with the malware, such as events dated to 2050-05-13, GUID-only subjects, or subjects following the “Event ID:” or “Boss{..}ID{..}” naming patterns with “File{n}.txt” attachments.
  • Restrict, monitor and audit OAuth2 applications using client credentials, and alert on the creation of new client secrets.
  • Enforce Conditional Access policies, regular credential rotation and anomalous-token detection across Microsoft 365 and Entra ID environments.
  • Deploy DNS monitoring capable of spotting tunnelling activity, such as unusually frequent AAAA queries or long, high-entropy subdomains, and route outbound DNS through controlled, filtered resolvers.

Group-IB said it will continue to track the evolution of the Cavern framework, adding that the sophistication of HOLLOWGRAPH, combined with its narrow targeting, points to a capable and well-resourced adversary, even though the specific group behind the campaign remains unconfirmed. More information can be found here: https://www.group-ib.com/blog/hollowgraph-microsoft-365/

The post Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites appeared first on IT Security Guru.

The Good, the Bad and the Ugly in Cybersecurity – Week 29

17 July 2026 at 12:40

The Good | Authorities Sanction Cybercriminals & Dismantle Russian Bulletproof Hosting Infrastructure

The EU and the United Kingdom have jointly sanctioned multiple Russian individuals and entities for targeting government networks and critical infrastructure across Europe. The sanctions specifically target senior Russia military intelligence (GRU) officers and operators, as well as four entities linked to the Federal Security Service (FSB).

Officials say that the Russian government actively utilizes these state-sponsored units alongside recruited cybercriminals and private companies to systematically destabilize international partners and compromise key infrastructure across the continent.

From the U.S. Treasury Department, two individuals and a virtual private network (VPN) provider face sanctions for actively enabling ransomware attacks against American organizations.

OFAC designated First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for supplying infrastructure that helped cybercriminals obscure their identities and manage stolen data. The service, which law enforcement dismantled last May, notoriously ignored abuse complaints and maintained zero user logs.

Yegeniy Silayev was also sanctioned for developing cryptors designed to conceal malware. Investigators estimate these specific tools and services directly facilitated billions of dollars in financial losses across critical sectors.

U.S. Federal prosecutors also unsealed indictments this week against three Russian nationals for operating bulletproof hosting services that facilitated over $62 million in global ransomware damages.

Defendants Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin allegedly managed “Media Land” and “ML Cloud”, providing essential infrastructure to syndicates like Lockbit, Play, and Blacksuit. These hosting platforms actively shielded cybercriminals by disregarding victim complaints and ignoring law enforcement takedown requests.

To disrupt this supply chain, the State Department is offering a $10 million reward for actionable information regarding foreign government links to these hosting providers.

The Bad | Attackers Trojanize Popular Remote User Platforms to Deploy Starland Malware

Cybersecurity researchers identified a financially-motivated Russian threat actor tracked as UAT-11795. Active since June 2025, the actor has utilized trojanized applications to harvest user credentials and cryptocurrency while primarily targeting users across the United States, Germany, Romania, and Venezuela.

To distribute their payloads, UAT-11795 operators disguise malicious installers as legitimate software, including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. Researchers suspect the attackers likely deploy these files via ClickFix social engineering.

The infection chain typically starts when a victim executes a malicious HTA file. This file retrieves an altered NSIS installer harboring a hidden Python loader disguised as a standard text document. The loader then modifies the Windows Registry to ensure persistent access before decrypting and deploying the Starland remote access trojan (RAT).

Upon execution, Starland verifies whether it is operating within a sandbox before creating scheduled tasks and attempting to escalate its system privileges. The malware scans compromised systems for browser data, cryptocurrency wallet assets, detailed system configurations, any antivirus products, and Active Directory infrastructure such as domain structure and controllers.

Beyond data theft, Starland possesses extensive capabilities to capture desktop screenshots, execute arbitrary shell commands, and fetch secondary payloads. Depending on system architecture, the malware can inject a 64-bit shellcode chain to deliver the CastleStealer information stealer or a 32-bit chain to deploy the Remcos remote access trojan.

UAT-11795-controlled Telegram channels (Source: Cisco Talos)

To maintain resilient command and control (C2) communications, the operators integrate a redundancy mechanism that queries a Polygon smart contract for a fallback domain, and control two Telegram bots to receive notification beacons, including messages with the victim’s machine fingerprints and cryptowallet inventories.

Users are reminded to avoid executing unidentified commands online and should only download confirmed software from official vendor sources.

The Ugly | Nearly 300 Imposter GitHub Repositories Distribute Infostealing Malware to Collect Sensitive Data

Threat actors have published almost 300 fabricated GitHub repositories to distribute an information stealer from the BoryptGrab malware family. The actors systematically impersonated premium security products, cryptocurrency tools, and developer utilities to deceive victims searching for free software downloads.

As part of the lure, the malicious landing pages employ highly sophisticated client-side scripts that parse referral URLs to render customized branding and spoofed trust badges, significantly increasing the likelihood of successful social engineering.

Once a targeted victim clicks the download link, the infrastructure delivers a constantly rotating ZIP archive containing a legitimate, signed WinGUP updater paired with a trojanized dynamic link library file. When the user executes the updater, the program side-loads the malicious file, which then decodes and reflectively executes the BoryptGrab-variant payload directly into system memory.

Operating without establishing long-term persistence, the malware is designed to exfiltrate maximum data in a single execution cycle. The stealer targets passwords, payment details, and session cookies across 19 different web browsers and 32 cryptocurrency wallet brands, alongside messaging tokens from Discord, Steam, and Telegram.

The infostealer’s execution workflow (Source: Arctic Wolf)

To maximize collection, operators utilize direct code injection to bypass Chrome’s native App-Bound Encryption. All newly harvested data is compressed and routed to a Russian-based C2 server. Although the malware leaves behind forensic evidence by failing to wipe temporary staging directories, the scale of the impersonation campaign poses significant risks to unsuspecting developers.

GitHub has already removed a large portion of the false repositories, though several of the malicious redirector pages remain actively online. Researchers advise users to independently verify software authenticity and exercise extreme caution when navigating unofficial portals, sharing this YARA rule to help detect BoryptGrab activity and IoCs.

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

17 July 2026 at 10:27

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.

The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek.

CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging

17 July 2026 at 05:43

More than three-quarters of European CISOs believe their C-suite doesn’t fully understand the cyber risk posed by their own employees, a gap that’s widening just as AI makes attacks on human judgement faster, more convincing and harder to spot.

That’s according to new research from MetaCompliance, the human cyber risk management firm, which polled 200 CISOs across the UK, France, Germany and Sweden. The picture it paints is of security leaders trying to hold the line on human-layer risk without the consistent senior backing, clear ownership, or shared understanding they need to do so.

AI is changing what CISOs are worried about

The survey found that among CISOs who feel less confident about their organisation’s cyber resilience than they did a year ago, AI-enabled social engineering was the single biggest reason cited, named by almost half of that group. It’s a sign that attackers are moving away from crude, easily-spotted phishing and towards convincing impersonation and fraud attempts generated at scale.

Employees, unsurprisingly, remain squarely in the firing line. More than two in three CISOs still rank their own staff as the biggest security risk to the business, suggesting AI isn’t creating a new problem so much as turbocharging an old one.

Specific concerns bear that out:

  • Over 40% of CISOs are worried AI is increasing the speed and impact of social engineering attacks
  • 40% fear staff are feeding sensitive data into generative AI tools
  • 41% are concerned about malicious insiders using AI to enable fraud, cybercrime or data theft
  • In the UK specifically, deepfake impersonation stands out as a top worry — more than half of UK CISOs flagged it as a major threat, the highest figure of any country in the study

Support from the top doesn’t stick

Where the research gets more uncomfortable for boardrooms is on backing. Almost four in five CISOs (79%) say leadership enthusiasm for security awareness programmes tends to fade once the initial push is over, and 76% say they’re stuck trying to satisfy different stakeholders who all want different human-risk metrics. Roughly a quarter point to cross-functional alignment as one of the areas they feel least confident managing.

James Mackay, CEO of MetaCompliance, said AI has changed the stakes: “Attackers are no longer relying on obvious scams or poorly written phishing emails. They can now create highly convincing impersonation attempts, social engineering attacks and fraudulent communications at scale.”

He argued that puts a premium on sustained executive engagement rather than one-off initiatives: “Human cyber risk is no longer just an awareness issue or a training issue; it is a strategic business risk… If leadership support fades after the initial push, organisations are left exposed.”

Where CISOs go from here

Improving resilience against AI-driven social engineering is now a stated priority for the year ahead, with close to a quarter of CISOs naming it as a key focus. Mackay suggested the shift needs to be structural rather than seasonal: organisations that fare best will treat human risk as an ongoing management discipline rather than a periodic training exercise, giving employees real-time, contextual support at the moment a risky decision is actually being made, rather than relying solely on annual training modules.

The findings come at a moment when AI-generated phishing, deepfake voice and video, and synthetic impersonation are becoming difficult to distinguish from genuine communications — putting fresh pressure on security teams to secure top-level buy-in before the next wave of attacks arrives.

The post CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging appeared first on IT Security Guru.

Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages

15 July 2026 at 07:37

Swiss encrypted communications provider Proton has launched a dedicated business continuity service, aimed at helping organisations keep email and video communications running when their primary IT infrastructure fails or is taken offline.

The service is built around Proton Mail and Proton Meet, and is designed to give security and IT teams a pre-configured fallback they can activate quickly during an outage, a ransomware incident, or a third-party service disruption, without requiring staff to install new software or reset credentials under pressure.

Proton said the launch responds to a threat landscape in which outages are increasingly frequent, ransomware is spreading further into the small and mid-sized business market, and organisations face growing exposure to decisions made by US-based cloud and software providers, which remain legally bound to comply with US government directives, including those restricting service to customers outside the United States.

The company argues this exposes a structural weakness common to many security architectures: because so much business email and collaboration software ultimately runs on a small number of hyperscale platforms, chiefly Amazon Web Services, Microsoft Azure and Google Cloud, a single infrastructure failure or access restriction can take down communications across otherwise unrelated organisations simultaneously.

How it works

Under Proton’s model, organisations set up two tiers of accounts in advance. Active accounts assigned to IT administrators, business continuity coordinators, and senior leadership remain configurable and testable at any time. Dormant accounts, provisioned for the wider workforce at a reduced cost, remain inactive in the background, tied to the correct user identity and permission group until needed.

When an incident is declared, an administrator makes a single DNS change, repointing the organisation’s MX record to Proton’s mail servers instead of its usual provider. Dormant accounts are activated when employees log in with credentials or access links distributed by their administrator, after which the whole team can continue operating on Proton’s infrastructure, which the company says is fully separate from Google, Microsoft and AWS.

Organisations can also pre-configure their existing email domain inside Proton Mail, or set up a secondary domain to test failover in advance, allowing continuity plans to be rehearsed before they are ever needed.

A security case built on jurisdiction and encryption

Proton is positioning the service as much on legal and jurisdictional grounds as on technical ones. The company’s infrastructure and legal base sit in Switzerland, which it describes as neutral territory outside both the Big Tech ecosystem and US regulatory reach. Proton Mail and Proton Meet use end-to-end encryption, and the company points to a decade-long uptime record, underpinned by a 99.95 percent service-level agreement, as evidence of its resilience credentials.

Raphael Auphan, Chief Operating Officer at Proton, said organisations increasingly need to plan for disruption that is political as well as technical in origin. “Whether it’s in a week or a year, preparing now will make the difference between a managed response and an operational crisis,” Auphan said.

Proton already counts more than 100,000 organisations as Proton Mail users, and offers an Easy Switch for Business tool for firms migrating their primary email service outright. The new continuity offering is aimed instead at organisations that want an emergency fallback without giving up their existing primary provider.

Security teams considering the service will need to weigh the operational overhead of maintaining dormant accounts and rehearsed failover processes against the risk reduction it offers — a trade-off likely to depend on an organisation’s existing business continuity maturity and its risk appetite around single-vendor dependency.

The post Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages appeared first on IT Security Guru.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

14 July 2026 at 12:28

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

❌
❌