Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security Guru

4 Ways Organisations Create Non-Human Insider Risk

By: The Gurus
10 September 2026 at 11:55

As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without direct human oversight.

The danger rarely stems from one obvious security failure. Instead, it emerges when several weaknesses overlap. Here are four common ways organisations inadvertently create non-human insider risk:

1. Persistent access

Long-lived API keys, OAuth tokens, service accounts and standing privileges give agents constant access long after it is needed.

2. Excessive privilege

Many agents can read, write, modify, approve, delete or deploy far more than their actual tasks require.

3. Untrusted input

Agents consume information from emails, support tickets, documents, chat conversations, websites and repositories. If attackers can influence those inputs, they may also influence the agent’s decisions.

4. Limited behavioural monitoring

Many organisations can tell that an AI agent performed an action. Far fewer can determine whether that action actually made sense. Logging tells us what happened, understanding whether it should have happened is a different challenge altogether.

You can read the full blog from Erich Kron, CISO Advisor at KnowBe4. Stay tuned for part 2 where Erich will reveal what security teams should do to stay secure.

The post 4 Ways Organisations Create Non-Human Insider Risk appeared first on IT Security Guru.

Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair

10 September 2026 at 08:34

UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services.

Gamble brings nearly 30 years of board-level technology leadership and will work with Core to Cloud on its strategic, advisory and commercial direction across the UK enterprise and mid-market sectors.

His appointment adds further experience to the company’s Advisory Board, which includes senior security leaders from major UK organisations.

From cybersecurity buyer to advisor

Gamble spent six years as Group CIO and Chief Transformation Officer at Currys PLC, where his responsibilities included large-scale technology transformation and cyber risk.

His career has also included senior CIO positions at Dyson, Sony Electronics and Essentra PLC. That experience means Gamble has spent much of his career on the customer side of the cybersecurity market, buying and managing the types of services Core to Cloud now provides.

“I spent the better part of three decades as a buyer of cybersecurity services, and the experience left me with a clear view of where the market falls short,” Gamble said.

“Most organisations understand that cyber risk is real. Far fewer have a security function that can communicate that risk clearly at board level, or a partner that moves fast enough to keep pace with the threat.”

Gamble said Core to Cloud stood out because of its focus on proactive security, adding that he intends to help the business scale its model as a challenger to conventional managed security service providers.

Supporting Core to Cloud’s next stage of growth

Based in Cirencester, Core to Cloud works with more than 150 organisations across sectors including the NHS, retail, financial services and critical national infrastructure.

Its services span Managed Detection and Response, Third-Party Cyber Risk Management, Security Assurance, Dark Web Monitoring and Threat Intelligence, and Cyber Crisis Simulation.

James Cunningham, CEO and Founder of Core to Cloud, said Gamble’s experience at the intersection of technology, risk and commercial strategy would bring a new perspective to the company.

“He understands what good security looks like from the inside and brings a depth of experience and perspective that will be hugely valuable as we continue to grow,” Cunningham said.

“We have an ambitious business, a strong customer base and services we genuinely believe in. Having Andy chair our board will help us build on those foundations, challenge our thinking and accelerate the next stage of Core to Cloud’s growth.”

The post Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair appeared first on IT Security Guru.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

9 September 2026 at 10:20

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here. 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers

28 August 2026 at 09:05

Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising concerns about how the stolen information could now be exploited by cybercriminals.

The incident affected customer information associated with Manchester Airport, London Stansted and East Midlands Airport. Data connected to car park, lounge and Fast Track bookings, as well as airport Wi-Fi registrations, was reportedly accessed.

Email addresses, phone numbers, postcodes and vehicle registration details are among the information affected. However, payment information was not compromised, while airport operations, passenger safety and aviation security were unaffected.

While this limits the immediate operational impact, security experts warn that the combination of information exposed could prove particularly useful for targeted phishing, impersonation and social engineering.

Stolen data could make scams much harder to spot

Simon Pamplin, CTO at Certes, said the fact that operations were unaffected should not distract from the significance of the data exposure.

“Around 8.7 million customer records have reportedly been accessed, including email addresses, phone numbers, postcodes and vehicle registration details. Individually these may appear relatively innocuous, but together they create a detailed dataset that can be extremely useful for targeted phishing, impersonation and social engineering.”

The context surrounding the information could make it especially valuable. Criminals could potentially create fraudulent parking notices, travel communications or airport-related messages containing enough genuine information to appear legitimate.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, described the combination of information as a “precise targeting profile” for criminals.

“Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story,” he said.

Carole Reeves, Director of Security Operations at ANS, agreed that the absence of payment information should not lead customers to underestimate the risk.

“Attackers do not always need financial credentials from the initial breach. They can use the information they have to impersonate a trusted organisation and manipulate someone into revealing further personal or financial details.”

Aviation sector faces growing cyber pressure

Graeme Stewart, Head of Public Sector at Check Point Software, said the incident should serve as a warning to the wider aviation industry.

“The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised,” he said.

Knowledge of a customer’s relationship with an airport could potentially be used to create fake parking refunds, Fast Track problems or communications about the breach itself.

“Aviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake,” Stewart added.

Complex airport ecosystems create additional risks

The attack also raises questions about the complex technology ecosystems supporting modern airports.

Nathan Davies-Webb, Principal Consultant at Acumen Cyber, said airport groups sit at the centre of numerous booking, parking, loyalty, payment and internet connectivity services, many of which can be operated by subsidiaries or third-party suppliers.

“That’s a sensible commercial model but it creates an uncomfortable reality for security. A breach like this one in a shared upstream system can expose customer data from multiple services at multiple airports simultaneously.”

Davies-Webb also highlighted the speed of MAG’s response, with public disclosure roughly 48 hours after it became aware of the incident.

“Either way, it’s a better disclosure posture than we’ve seen from organisations involved in some comparable incidents, and MAG will probably benefit from having been quick and open here,” he said.

Tim Williams, CEO at Quod Orbis, also pointed to the importance of visibility beyond an organisation’s core systems.

“While the systems targeted were car parking, lounge bookings and WiFi sign-ups, they were not responsible for flight operations; they formed part of the wider digital environment through which customers interact within the airport,” Williams said.

He argued that security teams need visibility across systems, applications and third-party services so that risks can be identified before they become incidents.

“Rapid response can contain an incident, but having visibility across the wider technology and third-party ecosystem can help organisations identify potential weaknesses earlier, understand their exposure and strengthen their defences before an incident occurs.”

Knowing what data was accessed matters

The breach also highlights the importance of understanding exactly what information has been exposed once an attacker gains access.

Jerry Caviston, CEO at Archive360, said good data governance can provide organisations with the traceability needed during an incident.

“Having good data governance is like having CCTV footage of what data was touched and when,” he said.

Maintaining an event audit history can help organisations trace compromised information back to its original source and provide affected customers with clearer information about the risks they face.

Pamplin argues organisations should go further by attaching security directly to the data.

“We have to work on the assumption that systems will eventually be accessed. The objective should be that when this happens, sensitive data remains encrypted and unusable outside its authorised context,” he said.

“If an attacker can steal information but cannot read or exploit it, the value of the breach changes fundamentally.”

Customers should prepare for follow-on attacks

The immediate concern for affected customers is what criminals could do with the information next.

Jamie Akhtar, CEO and Co-Founder of CyberSmart, advised customers to be particularly cautious of unexpected emails, calls or texts claiming to relate to airport or travel services.

“Avoid clicking links or sharing personal information in unsolicited messages and, where possible, verify communications independently through an organisation’s official website or app,” he said.

Shankar Haridas, UK Business Head at ManageEngine, warned that the original breach could be followed by attacks designed to exploit customers’ trust in MAG.

“A breach like this doesn’t end when the data is taken. A flood of cloaked attacks, dressed up in the airport’s name is next,” he said.

“With 8.7 million email addresses, phone numbers and postcodes now in criminal hands, every ‘confirm your booking’ or ‘update your car park payment’ message must be questioned.”

Brian Higgins, Security Specialist at Comparitech, added that AI is making it easier for criminals to aggregate breached information and find new ways of monetising it.

“As AI makes data aggregation swift and easy, consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways,” he said.

For those potentially affected, the consequences of the MAG cyberattack may therefore continue long after the initial incident has been contained. Emails or messages referencing airport parking, lounge access, Fast Track services or travel details could contain genuine personal information, making the next wave of scams considerably harder to recognise.

The post Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers appeared first on IT Security Guru.

Iran-Linked Hackers Blamed for UK Energy Cyberattack

25 August 2026 at 14:45

A cyberattack reportedly linked to Iran forced a small UK energy generator offline for four days, raising fresh concerns about the security of the country’s critical infrastructure and smaller operators that may sit outside existing regulatory thresholds.

The UK government has confirmed that a small-scale generator was affected by a cyber incident in July. It stressed that the facility represented a tiny proportion of overall generation capacity and that the wider UK energy system was never at risk.

The government has not publicly attributed the attack or named the affected site. However, reports have linked the incident to hackers affiliated with Iran.

Following the incident, the Department for Energy Security and Net Zero (DESNZ) and National Cyber Security Centre (NCSC) have been engaging with energy companies over the cyber threat facing the sector.

Small target, bigger security questions

While the facility itself was small, cybersecurity experts warn that its size should not distract from the fact that a cyber incident reportedly caused several days of operational disruption.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said attackers are unlikely to care whether an operator meets the threshold to be considered critical infrastructure.

“If it can be disrupted, it can be targeted,” Patel said. “The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.”

Patel said the incident raises questions about whether smaller operators have sufficient monitoring, containment and recovery capabilities.

“There is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.”

Attribution remains uncertain

Despite reports linking the incident to Iran, Cian Heasley, Principal Consultant at Acumen Cyber, cautioned against concluding before further evidence emerges.

“Attribution for the incident is by no means concrete; the Iran link originates from press reporting while the UK government has declined to attribute blame or name the site affected,” Heasley said.

He argued that the more important lesson for the energy sector is what the incident demonstrates about the potential vulnerability of smaller energy assets.

“The significance of this incident lies in the precedent rather than the impact. A successful, if limited, intrusion into a power-generating asset demonstrates intent and a degree of capability against British energy infrastructure.”

Heasley said operators should focus on OT security fundamentals, including removing industrial controllers from direct internet exposure, strengthening credential management, separating IT and OT environments, and testing manual fallback and recovery procedures.

Graeme Stewart, head of public sector at Check Point, said the incident should concern organizations responsible for keeping essential services running.

“The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat,” Stewart said. “The far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.”

He warned that the bigger question is what happens if a future target is larger or more deeply connected to essential services such as electricity, water, transport, or communications.

“We cannot build our resilience around the assumption that every attacker will be stopped at the door,” he said. “Operators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread.”

The distributed energy system creates new risks

Martin Riley, Chief Technology Officer at Bridewell, said the small size of the facility is precisely why the incident deserves attention.

“The reported attack on a UK gas-fired peaker plant should not be dismissed because the site was small. It should be studied because the site was small,” Riley said.

The UK’s energy system increasingly depends on smaller generators, renewable energy assets and battery storage systems. Many are unmanned and remotely operated.

Riley warned that capacity thresholds mean some smaller operators can fall outside formal cybersecurity regimes even as their collective importance to the energy system grows.

“In an energy system that is deliberately becoming distributed, reliant on thousands of smaller, unmanned, remotely operated generators, secure by design and defence in depth cannot remain conference slideware.”

Neena Sharma, Cybersecurity Expert at Filigran, made a similar point, arguing that critical infrastructure risk is becoming increasingly distributed.

“Critical infrastructure risk isn’t concentrated at the ‘crown jewel’ substations anymore, it’s distributed across hundreds of smaller, less-monitored assets that scale with the energy transition,” Sharma said.

Weak credentials remain a concern

The exact attack path used against the UK generator has not been disclosed.

However, Sai Molige, Senior Manager of Threat Hunting at Forescout, pointed to a familiar weakness seen in attacks against industrial environments.

“Two countries and two sectors faced the same underlying condition: a controller is reachable from the internet and protected by weak, default, or unchanged credentials,” Molige said.

He argued that one of the continuing challenges for operators is translating broad security warnings into an accurate understanding of whether their own environments contain vulnerable or exposed technology.

Supply Chain Risk Adds Another Layer

The incident also comes as the UK looks to tighten security across energy supply chains, where dependence on individual suppliers and technologies can create additional risks.

Jamie Akhtar, CEO and Co-founder of CyberSmart, said supply chain risk is not simply about whether an individual supplier can be compromised.

“If one vendor, country or narrow group of manufacturers underpins equipment that operators cannot quickly replace, that dependency can become a national-security issue,” Akhtar said.

This can be particularly difficult in operational technology environments, where equipment may remain in use for decades and replacing it can require complex integration work.

Akhtar said operators need to consider whether a supplier creates an unacceptable security exposure, whether it can realistically be replaced and whether removing it could create a greater short-term risk to operations.

“The strategic aim should be resilience, not a compliance exercise or a change of logo on the equipment,” he added. “Operators need enough diversity, control and recovery capability to keep essential services running if a supplier is compromised, unavailable or deemed too risky to trust.”

Resilience becomes the priority

The incident comes as the UK looks to strengthen cyber resilience across its energy sector and address risks within increasingly complex supply chains.

For Patel, the central lesson is that organizations cannot judge resilience solely by whether an attacker successfully gains access.

“The real measure of cyber resilience is no longer simply whether you can prevent an intrusion,” he said. “It’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis.”

With the wider grid unaffected, the July incident was limited in impact, but the disruption provides a timely warning that smaller assets can still present attractive targets and that cyber resilience needs to extend beyond the largest operators in the UK’s energy infrastructure.

The post Iran-Linked Hackers Blamed for UK Energy Cyberattack appeared first on IT Security Guru.

The Hidden Risk in Data Transfer

19 August 2026 at 11:13

Cybersecurity has become one of the most defining business challenges of recent times. Organisations have invested heavily in protecting their networks, securing cloud environments and strengthening identity and access management. At the same time, organisations are under increasing pressure to prove they are handling sensitive information securely, not just storing it safely but protecting it throughout its journey.

Yet despite this progress, one area continues to receive far less attention than it deserves: how data is shared.

Most organisations have become very good at protecting data while it is stored. Files are encrypted, key handling is properly managed, access is restricted and systems are monitored around the clock. However, once that information needs to leave the organisation, whether it’s being sent to a customer, supplier, auditor or business partner, the controls often become less robust.

Every day, organisations exchange contracts, financial information, employee records, legal documents and commercially sensitive files. More often than not, this happens via email attachments or cloud-based file-sharing services because they are familiar and convenient. The problem is that convenience does not always equal security.

Email remains one of the most common routes for cyber attacks. Phishing, spoofed domains, malicious attachments and business email compromise continue to account for a significant proportion of successful breaches. However, most incidents do not involve a sophisticated bad actor. The official UK annual Cyber Security Breaches Survey continues to show the majority of incidents stem from everyday mistakes.  An email sent to the wrong recipient, an attachment forwarded outside the organisation or a file shared with overly broad permissions can expose sensitive information in seconds.

Human error remains one of the biggest cyber risks organisations face, particularly as businesses become increasingly connected. Information now flows constantly between employees, customers, suppliers, consultants and regulators. Every transfer creates another opportunity for something to go wrong.

What is often overlooked is that securing data is not just about protecting where it is stored. It is also about understanding the journey it takes.

Many organisations assume that because they operate in the UK, their sensitive information remains within UK borders. In reality, emails and attachments may be routed through multiple countries and cloud infrastructures before arriving at their destination. While this is often an invisible part of modern digital communications, it raises important questions around governance, compliance and data sovereignty.

For organisations operating in regulated sectors, this matters. Financial services firms, local authorities, healthcare providers and legal organisations are increasingly expected to demonstrate not only that data is protected, but also that it is managed responsibly throughout its entire lifecycle. Knowing where information is stored is only part of the picture. Understanding where it travels, who has access to it and how it is controlled has become equally important.

This is why conversations around geofencing and data sovereignty are gaining momentum. Rather than simply encrypting information and hoping for the best, organisations are beginning to ask whether they should have greater control over where sensitive data is permitted to travel. If businesses routinely place restrictions on the movement of physical assets, it seems only logical that they should apply similar thinking to digital information.

At the same time, regulators and auditors are asking more searching questions about how organisations exchange information with third parties. They want to understand how access is controlled, whether there is a complete audit trail and what safeguards exist once information leaves the organisation. These are no longer technical questions reserved for IT teams. They are governance issues that increasingly involve compliance, procurement, risk and senior leadership.

There is also a growing disconnect between the way organisations work and the security controls they have in place. Hybrid working, cloud collaboration and increasingly complex supply chains mean information rarely stays within a single organisation. Yet many businesses continue to rely on processes that were designed for a very different way of working.

This is where a change in mindset is needed.

Cybersecurity should not end when a document is saved securely on a server or in the cloud. Information is often at its most vulnerable when it is moving between people, organisations and systems. Protecting data in transit should therefore be considered just as important as protecting data at rest.

That does not mean making it harder for employees to do their jobs. Quite the opposite. Security should support the way people work, allowing information to be shared safely without creating unnecessary barriers or encouraging workarounds that introduce even greater risk.

Organisations need to take a more holistic view of information security. Protecting sensitive data means understanding its entire lifecycle, from creation and storage through to sharing, collaboration and eventual deletion. It means knowing not only who can access information, but where that information is travelling and whether that journey aligns with the organisation’s security, compliance and governance obligations.

Threats aren’t standing still, and neither are regulators. Focusing only on data that’s sitting in storage means missing one of the biggest holes in your security. It’s not enough to just lock data away; it needs to stay safe wherever it travels.

*DOQEX provides a secure data exchange and email gateway platform that helps businesses protect confidential information.

 

The post The Hidden Risk in Data Transfer appeared first on IT Security Guru.

Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School

19 August 2026 at 09:48

Education has overtaken every other industry to become the most targeted sector for cyberattacks worldwide, according to new research from Check Point, with threat actors ramping up activity in the run-up to the new academic year.

Between January and July 2026, schools, colleges, universities and research institutes faced an average of 4,696 weekly cyberattacks per organisation, an 8% rise on the same period in 2025 and more than double the cross-industry average of 2,150 weekly attacks. Education topped all 23 industries tracked by Check Point, recording attack volumes roughly 70% higher than government, the next most-targeted sector. In July alone, weekly attacks against education organisations climbed to 4,848, up 14% year-on-year, as the new term approached.

Regional picture: Europe among the fastest-growing hotspots

APAC recorded the highest overall volume, with organisations facing an average of 7,452 weekly attacks between January and July. But Europe and Latin America saw the sharpest year-on-year growth, up 18% (to 4,759 weekly attacks) and 42% (to 4,299 weekly attacks) respectively, a trend researchers link to the sector’s growing reliance on cloud platforms, digital learning tools and online collaboration systems that widen the potential attack surface. A successful breach, they note, can ripple out beyond the institution itself to affect students, parents, research partners, government bodies and third-party suppliers connected to the education ecosystem.

Attackers building dedicated ‘back-to-school’ infrastructure

To track how threat actors prepare for the academic calendar, Check Point Research monitored newly registered domains containing education-related terms such as “school”, “university”, “college” and “student”. In July 2026 alone, researchers identified 18,954 newly registered education-themed domains, up 5% month-on-month and 3% year-on-year.

More striking is the rise in malicious activity among those registrations. Check Point ThreatCloud data shows that in June 2026, one in every 305 newly registered education-related domains was flagged as malicious; by July, that ratio had worsened to one in every 226. Examples uncovered include deceptive domains such as education-gov[.]com, students-portal[.]com, and checkmyschool[.]org, built to mimic legitimate education and government institutions. Researchers also identified coordinated registration campaigns, including a set of ten student loan-themed domains following a studentloansYYYY.com pattern spanning 2026 to 2035, and a network of 48 bootcamp-student domains, evidence, the researchers say, of large-scale, automated registration activity aimed squarely at students and prospective learners.

Phishing campaigns target students and staff directly

Beyond domain registration, researchers documented active campaigns exploiting the seasonal surge in online activity from students, parents and institutions. One scheme used the domain studentdiscount[.]online to impersonate a major US retail chain’s student rewards promotion, dangling a fake $750 reward before redirecting victims to fraudulent offers and gambling-related content.

Researchers also uncovered malicious PDF campaigns impersonating specific schools, routing victims through multiple compromised websites before landing on counterfeit Microsoft 365 and OneDrive login pages designed to harvest credentials. A separate case involved a malicious URL hosted on a compromised school website in Bangladesh, flagged by multiple threat intelligence sources as an information-stealer and malware distribution point; the page had previously displayed a fake Spotify-branded CAPTCHA, a technique often used to deliver malware or dodge automated security analysis.

Taken together, the findings point to a consistent tactic: abusing trusted brands, compromised legitimate websites and familiar academic workflows to make phishing lures more convincing and credential theft more effective.

What institutions should do before term starts

The back-to-school period is a prime opportunity for attackers, thanks to the spike in digital activity that comes with new student onboarding, document sharing, financial transactions and higher email volumes. Researchers recommend institutions act now, ahead of the return, to:

  • Train staff and students to recognise phishing emails, fake reward offers and suspicious login pages
  • Verify website addresses carefully before entering credentials or personal information
  • Enable multi-factor authentication (MFA) on Microsoft 365, email and academic systems
  • Regularly update and patch devices, learning platforms and administrative systems
  • Monitor newly registered domains for education-themed impersonation attempts
  • Review access permissions and secure sensitive student, research and administrative data

As cybercriminals continue to align their campaigns with the academic calendar, researchers say cybersecurity needs to become a core part of back-to-school preparedness and not an afterthought once term is already underway. The data suggests attackers are targeting not just schools and universities, but the wider ecosystem of students, families, and partners that surrounds them.

The post Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School appeared first on IT Security Guru.

Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to £100,000

19 August 2026 at 06:55

The Premier League has introduced mandatory cybersecurity requirements for its clubs for the first time, with non-compliant clubs facing fines of up to £100,000. The rules, which apply from the start of the 2026-27 season, mark a shift away from the league’s previous non-prescriptive security guidance towards a formal framework with fixed deadlines and evidence-based assessment.

Enforcement will sit within the Premier League’s existing disciplinary framework rather than a standalone sanctions regime. The board can issue a reprimand, impose a fine through its summary jurisdiction, or refer a suspected breach to an independent commission. Sources briefed on the matter say points deductions are not on the table for cybersecurity non-compliance.

A Phased Rollout to 2029

The framework covers four core areas: backups, incident response, risk management and security assurance, with later phases adding tested requirements around clubs’ ability to recover from a cyber incident.

Implementation is staged across three phases, with the first set of measures due by April 30, 2027, and further requirements following in April 2028 and April 2029. Clubs must file an interim compliance assessment by January 10 each season and a final assessment with supporting evidence by April 30. Any club found non-compliant at the interim stage has 28 days to submit a remediation plan to the league. The Premier League can also request further evidence at any point and may grant dispensations from specific requirements in exceptional circumstances.

The standards were signed off by clubs at the league’s Annual General Meeting in June, following a two-season consultation period, and are explicitly framed as a preventative measure rather than a response to any specific incident.

Industry Reaction: Right Direction, But Is the Timeline Too Slow?

Security vendors have broadly welcomed the move but raised concerns that both the financial penalty and the multi-year rollout may not match the pace at which clubs are being targeted.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the size of the fine needs to be seen in context: “£100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.” He also questioned the pace of the rollout, describing the phased timeline of April 2027, 2028 and 2029 as “pragmatic but slow given the threat environment,” adding that “waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.”

Patel was more positive about the substance of the framework itself, calling the shift from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions “a meaningful structural shift,” and praising the choice of foundations: “backups, incident response, risk management, and recovery testing are exactly the right foundations.” He singled out the league’s proactive stance for particular credit: “most governing bodies wait for the headline incident. This one didn’t.” His central caveat was around enforcement: “the real test is enforcement appetite. Rules without credible consequences change nothing.”

Cian Heasley, Principal Consultant at Acumen Cyber, also welcomed the move, arguing that formal standards are overdue given the combination of sensitive data, financial transactions and operational systems held by football clubs.

“Moving from advisory guidance to enforceable standards creates much-needed accountability, and the financial incentive will inevitably help drive action,” he said.

For Heasley, however, the £100,000 penalty is less important than requiring clubs to demonstrate that they can withstand and recover from an attack. “The £100,000 ceiling is modest against the true cost of a serious incident and the amounts of money tied up in football clubs, so the value lies less in the sanction and more in compelling clubs to build tested backups, incident response and recovery capability before they are needed.”

He also welcomed the introduction of defined standards and deadlines, but cautioned that the requirements need to be clear enough to avoid ambiguity. “The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.”

Jamie Akhtar, CEO and co-founder of CyberSmart, framed the rules as part of a broader trend of cybersecurity becoming a governance issue rather than a purely technical one: “cybersecurity is moving from being viewed primarily as an IT responsibility to becoming an enforceable element of club governance.” He pointed to the scale of data and operational systems clubs now manage, “football clubs hold significant volumes of sensitive supporter, employee and player data, while also relying on systems for ticketing, payments, stadium access and match-day operations,” and argued the new mandatory areas reflect how quickly a cyber incident can escalate: “a serious cyber incident can quickly become an operational, financial and reputational crisis.”

Akhtar was clear that compliance alone should not be the end goal. Clubs, he said, need “clear board-level ownership of cyber risk, an accurate inventory of critical systems and data, tested and segregated backups, rehearsed incident-response and recovery plans, strong identity and access controls, and effective oversight of third-party suppliers,” alongside continuous evidence-gathering that controls are actually working. His conclusion: “the organisations that treat the new requirements as a minimum baseline for resilience, rather than simply a regulatory hurdle, will be in the strongest position when an attack inevitably tests those controls.”

Football Has Already Seen the Consequences

The risks are not theoretical. In November 2024, Italian club Bologna FC confirmed a ransomware attack claimed by the RansomHub group. After the club refused to pay the ransom, the attackers published stolen data on the dark web, reportedly including information relating to players and sponsors.

More recently, Ajax was named among the organisations affected by the CEVA Logistics breach, where customer information was exposed through a third-party shipping provider rather than through a direct compromise of the club.

Heasley said, “The incidents demonstrate both the direct and supply-chain risks facing football clubs. The Bologna attack, in particular, shows why resilience and data minimisation matter when stolen information can be used as leverage and subsequently published if negotiations fail.”

Why It Matters

The rules make the Premier League one of the first major sports bodies globally to formally mandate cybersecurity controls across its member organisations, rather than relying on voluntary guidance. With the first compliance deadline less than a year away, clubs will need to move quickly on board-level accountability, backup and recovery testing, and third-party risk oversight; areas that, as both commentators note, are straightforward to name but considerably harder to operationalise and evidence under a compliance deadline.

The post Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to £100,000 appeared first on IT Security Guru.

WorkNest Secure Launches Continuous Vulnerability Scanning with GuardNest

30 July 2026 at 09:36

WorkNest Secure has expanded its GuardNest platform with continuous vulnerability scanning, giving organisations ongoing visibility into security weaknesses rather than relying solely on periodic penetration tests.

The new capability is designed to help businesses monitor vulnerabilities across internet-facing systems, web applications, and internal environments, providing continuous oversight of their attack surface as threats and infrastructure evolve.

The launch comes as organisations face increasing pressure from customers, insurers, and regulators to demonstrate continuous vulnerability management and stronger cyber resilience.

Moving beyond annual penetration testing

While penetration testing remains a critical part of any cybersecurity strategy, WorkNest Secure says annual or point-in-time assessments no longer provide a complete picture of an organisation’s security posture.

The enhanced GuardNest platform combines automated vulnerability scanning with expert analysis and remediation support, allowing organisations to identify vulnerabilities as they emerge and prioritise the issues that present the greatest business risk.

Organisations can schedule scans, monitor vulnerabilities in real time, and manage remediation activities through a single dashboard.

The platform now supports external vulnerability scanning, internal vulnerability scanning, web application scanning, and agent-based internal scanning, allowing customers to tailor the service to their environment and compliance requirements.

Simplifying vulnerability management

Alongside continuous scanning, GuardNest introduces new remediation workflows designed to help security and IT teams manage vulnerabilities more effectively.

Organisations can assign remediation tasks, define service level targets based on vulnerability severity, and track progress through to resolution. Automated escalation and SLA tracking are intended to ensure vulnerabilities are actively managed rather than simply recorded in reports.

The platform also includes live dashboards, historical trend reporting, and automated reporting that can support compliance initiatives, cyber insurance renewals, customer due diligence, and certifications including ISO 27001, Cyber Essentials Plus, and PCI DSS.

Helping organizations focus on what matters

Kirsty Fowler, Managing Director of WorkNest Secure, said organisations need greater visibility into their cyber risks as environments continue to change.

“Cyber threats do not operate to an annual schedule, yet many organisations are still relying on point-in-time assessments to understand their security posture,” Fowler said.

“New vulnerabilities emerge every day and infrastructure changes constantly, so businesses need visibility of their risks as they exist today, not six months ago.”

She added that the new functionality is intended to reduce the complexity of vulnerability management by combining automation with expert support.

“By combining automated scanning with expert support and practical remediation guidance, we help organisations cut through the noise, understand what matters most, and know exactly where action is needed,” Fowler said.

Responding to changing security needs

The launch reflects a broader shift in how organisations approach cybersecurity investment, with many moving away from one-off security projects in favour of continuous monitoring and ongoing risk management.

WorkNest Secure said the new functionality is available immediately either as a standalone vulnerability management service or as part of existing GuardNest packages.

The latest release builds on the redesign of the GuardNest platform in 2025, which introduced a more collaborative and user-friendly approach to vulnerability management, penetration testing, and remediation.

The post WorkNest Secure Launches Continuous Vulnerability Scanning with GuardNest appeared first on IT Security Guru.

KnowBe4 Unveils Custom AI Video Builder

By: The Gurus
24 July 2026 at 08:52

KnowBe4 has expanded its AI-powered security awareness training platform with the launch of Custom AI Video Builder, a new capability designed to help organisations rapidly create tailored cybersecurity training videos in response to emerging threats.

The feature, developed as part of KnowBe4’s strategic partnership with AI video platform Synthesia, enables security teams to generate custom training videos in minutes and deploy them directly into their security awareness programmes without leaving the KnowBe4 platform.

The launch comes as cybercriminals ramp up usage of generative AI to create highly targeted social engineering campaigns aimed at specific industries, job roles and regions. According to KnowBe4, organisations need to be able to update awareness training at a similar pace in order to keep employees prepared for evolving attack techniques.

Available through KnowBe4’s ModStore, the new feature includes a prepaid Synthesia Starter licence (worth $250 per year) allowing customers to create up to 120 minutes of AI-generated video annually. Users can choose from more than 120 AI avatars and produce content in over 160 languages and dialects.

The capability integrates directly with KnowBe4’s existing Content Creation Agent, allowing administrators to add studio-quality video to AI-generated text-based training. Alongside the recently launched Deepfake Training Content Agent, the new release forms part of the company’s broader AI-native content customisation suite.

“Generative AI has given attackers the ability to build campaigns around the exact policies, roles and regions where training doesn’t yet exist,” said Greg Kras, Chief Product Officer, KnowBe4. “Custom AI Video Builder closes that window by putting studio-quality video production directly inside the KnowBe4 platform, so customers can go from a new threat to a finished training module without waiting on a production cycle. It’s one more way we’re helping security teams match the speed of the threats they’re defending against.”

Among the key features are automated publishing of completed videos into the ModStore’s Uploaded Content library, removing the need to manually download and upload SCORM packages, and AI-powered dubbing that enables organisations to localise training for employees around the world.

Custom AI Video Builder is available immediately to customers on KnowBe4’s Platinum, Diamond, Training-Only Diamond, SAT Foundation and SAT Advanced subscriptions.

The announcement follows further recognition for KnowBe4, after the company received an award in the email security category earlier this month.

The post KnowBe4 Unveils Custom AI Video Builder appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the report‘s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

“In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

“Many organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

14 July 2026 at 12:28

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense

10 July 2026 at 07:24

The National Cyber Security Centre (NCSC) has unveiled plans for Cyber Shield, an ambitious initiative that aims to use agentic artificial intelligence to transform the nation’s cyber defenses and counter increasingly sophisticated cyber threats. The proposal forms part of a broader effort by the NCSC and the Department for Science, Innovation and Technology (DSIT) to build a national scale, AI powered cyber defense capability that can detect, analyze, and eventually respond to attacks at machine speed.

According to the NCSC, Cyber Shield will initially focus on using AI to identify vulnerabilities and detect threats before progressing toward automated mitigation, coordinated threat intelligence sharing, and national level response capabilities. The initiative is intended to help defenders keep pace with attackers who are increasingly using artificial intelligence to accelerate reconnaissance, vulnerability discovery, and exploitation.

AI changes the cyber defense equation

Rik Ferguson, Vice President of Security Intelligence at Forescout, believes the proposal reflects the reality of today’s threat landscape.

“The NCSC’s Cyber Shield proposal feels like a logical and necessary step, especially if we view it through the lens of ‘Assume Autonomy,'” Ferguson said.

“The core assumption should no longer be that autonomous cyberattacks are a distant or speculative problem. We should assume that adversaries will increasingly use AI agents to automate reconnaissance, vulnerability discovery, exploit development, credential attacks, lateral movement, and adaptation once inside an environment.”

Ferguson said security teams operating at human speed will struggle to defend against machine speed attacks, particularly across critical infrastructure, healthcare, and government networks.

“A national scale AI cyber shield is therefore not just about adding AI to existing security workflows. It is about building defensive systems that can detect, prioritize, and help contain threats at the same tempo at which AI enabled attackers can operate.”

However, he cautioned that autonomy must be implemented carefully.

“The opportunity is strongest where AI can improve visibility, correlation, triage, exposure management, and early intervention. The risk comes when automated systems act without sufficient context, governance, or operational guardrails.”

He added that AI alone cannot solve long-standing cybersecurity problems.

“AI can help defenders move faster, but it cannot compensate for poor asset visibility, weak segmentation, unpatched systems, or unclear ownership of cyber risk.”

Governance will be critical

Shane Barney, Chief Information Security Officer at Keeper Security, also welcomed the initiative but warned that the success of Cyber Shield will depend on strong governance.

“Cyber Shield is the right instinct, and it is arriving at a genuinely dangerous moment for both organizations and the wider public,” Barney said.

“Attackers are already using AI to compress reconnaissance and exploitation into minutes, and the NCSC is correct that human speed defense cannot keep pace with machine speed offense.”

Barney argued that many successful cyberattacks still rely on basic security weaknesses.

“Most successful attacks still exploit basic, preventable failures, including outdated systems, unpatched software, and weak access controls. No amount of agentic AI changes that equation if the underlying identity and access foundations are not solid.”

He also highlighted a potential new risk created by AI itself.

“Red and blue AI agents are themselves privileged non-human identities, granted authority to scan networks, share intelligence, and eventually remediate vulnerabilities autonomously.”

According to Barney, those AI agents will require the same security controls as privileged human administrators, including least privilege access, just in time provisioning, and complete visibility into their activity.

“An AI agent with unmanaged privileged access is not a defense. It is the next incident.”

A collaborative approach

The NCSC said Cyber Shield will rely on close collaboration between government, industry, academia, and critical infrastructure operators. Trusted information sharing and explainable AI will be central to the initiative as it evolves from vulnerability discovery toward coordinated national cyber defense.

While the idea of a Cyber Shield remains a long-term vision, security leaders broadly agree that AI will play an increasingly important role in defending against AI-driven cyberattacks. The challenge now will be ensuring those capabilities are introduced with the governance, transparency, and foundational security controls needed to make them effective.

The post UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense appeared first on IT Security Guru.

Registration Now Open for International Cyber Expo 2026

7 July 2026 at 08:29

Registration is now open for International Cyber Expo 2026, one of the UK’s flagship two-day cybersecurity events which set to return to Olympia London on 29–30 September 2026, bringing together thousands of security professionals, technology providers and policymakers to explore the latest developments shaping the cyber landscape.

With cyber threats at a peak and the convergence of physical and digital security becomes increasingly important, International Cyber Expo has established itself as a key meeting place for the global cybersecurity community. The event provides a platform for organisations to discover emerging technologies, share best practice and discuss the strategies needed to strengthen cyber resilience.

This year’s edition is expected to welcome a diverse audience of CISOs, CTOs, IT directors, government representatives, security architects and risk professionals, alongside leading cybersecurity vendors showcasing the latest innovations in threat detection, incident response, identity management, cloud security, AI-driven defence and critical infrastructure protection.

Visitors will have the opportunity to explore a comprehensive exhibition featuring established technology providers and innovative startups, while benefiting from an extensive conference programme designed to address the challenges facing today’s security leaders. From ransomware and supply chain attacks to artificial intelligence, operational resilience and regulatory compliance, the agenda will focus on the issues currently defining the cybersecurity industry.

One of the event’s major attractions continues to be its thought leadership programme, where industry experts, policymakers and practitioners will share practical insights through keynote presentations, panel discussions and technical sessions. The Global Cyber Summit is designed to provide attendees with actionable advice that can be applied within their own organisations, whether they are responsible for enterprise security strategies or protecting critical national infrastructure.

Networking also remains a central part of the International Cyber Expo experience. With thousands of cybersecurity professionals expected to attend, the event offers opportunities to build new partnerships, connect with peers and engage directly with solution providers in an environment dedicated to knowledge sharing and collaboration.

The continued convergence of cyber and physical security is also expected to feature prominently throughout the event. As organisations increasingly manage interconnected digital and operational environments, collaboration between cybersecurity teams, physical security specialists and government stakeholders has become more important than ever. International Cyber Expo provides a forum for these conversations alongside its co-located event, International Security Expo, while highlighting technologies that support a more integrated approach to organisational resilience.

With registration now officially open, attendees are encouraged to secure their place early and begin planning their visit ahead of what promises to be one of Europe’s most significant cybersecurity events of the year.

To register for FREE, click here

The post Registration Now Open for International Cyber Expo 2026 appeared first on IT Security Guru.

❌
❌