❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security Guru

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the reportβ€˜s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

β€œAI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

β€œIn observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

β€œAs attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

β€œMany organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

14 July 2026 at 12:28

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense

10 July 2026 at 07:24

The National Cyber Security Centre (NCSC) has unveiled plans for Cyber Shield, an ambitious initiative that aims to use agentic artificial intelligence to transform the nation’s cyber defenses and counter increasingly sophisticated cyber threats. The proposal forms part of a broader effort by the NCSC and the Department for Science, Innovation and Technology (DSIT) to build a national scale, AI powered cyber defense capability that can detect, analyze, and eventually respond to attacks at machine speed.

According to the NCSC, Cyber Shield will initially focus on using AI to identify vulnerabilities and detect threats before progressing toward automated mitigation, coordinated threat intelligence sharing, and national level response capabilities. The initiative is intended to help defenders keep pace with attackers who are increasingly using artificial intelligence to accelerate reconnaissance, vulnerability discovery, and exploitation.

AI changes the cyber defense equation

Rik Ferguson, Vice President of Security Intelligence at Forescout, believes the proposal reflects the reality of today’s threat landscape.

β€œThe NCSC’s Cyber Shield proposal feels like a logical and necessary step, especially if we view it through the lens of β€˜Assume Autonomy,'” Ferguson said.

β€œThe core assumption should no longer be that autonomous cyberattacks are a distant or speculative problem. We should assume that adversaries will increasingly use AI agents to automate reconnaissance, vulnerability discovery, exploit development, credential attacks, lateral movement, and adaptation once inside an environment.”

Ferguson said security teams operating at human speed will struggle to defend against machine speed attacks, particularly across critical infrastructure, healthcare, and government networks.

β€œA national scale AI cyber shield is therefore not just about adding AI to existing security workflows. It is about building defensive systems that can detect, prioritize, and help contain threats at the same tempo at which AI enabled attackers can operate.”

However, he cautioned that autonomy must be implemented carefully.

β€œThe opportunity is strongest where AI can improve visibility, correlation, triage, exposure management, and early intervention. The risk comes when automated systems act without sufficient context, governance, or operational guardrails.”

He added that AI alone cannot solve long-standing cybersecurity problems.

β€œAI can help defenders move faster, but it cannot compensate for poor asset visibility, weak segmentation, unpatched systems, or unclear ownership of cyber risk.”

Governance will be critical

Shane Barney, Chief Information Security Officer at Keeper Security, also welcomed the initiative but warned that the success of Cyber Shield will depend on strong governance.

β€œCyber Shield is the right instinct, and it is arriving at a genuinely dangerous moment for both organizations and the wider public,” Barney said.

β€œAttackers are already using AI to compress reconnaissance and exploitation into minutes, and the NCSC is correct that human speed defense cannot keep pace with machine speed offense.”

Barney argued that many successful cyberattacks still rely on basic security weaknesses.

β€œMost successful attacks still exploit basic, preventable failures, including outdated systems, unpatched software, and weak access controls. No amount of agentic AI changes that equation if the underlying identity and access foundations are not solid.”

He also highlighted a potential new risk created by AI itself.

β€œRed and blue AI agents are themselves privileged non-human identities, granted authority to scan networks, share intelligence, and eventually remediate vulnerabilities autonomously.”

According to Barney, those AI agents will require the same security controls as privileged human administrators, including least privilege access, just in time provisioning, and complete visibility into their activity.

β€œAn AI agent with unmanaged privileged access is not a defense. It is the next incident.”

A collaborative approach

The NCSC said Cyber Shield will rely on close collaboration between government, industry, academia, and critical infrastructure operators. Trusted information sharing and explainable AI will be central to the initiative as it evolves from vulnerability discovery toward coordinated national cyber defense.

While the idea of a Cyber Shield remains a long-term vision, security leaders broadly agree that AI will play an increasingly important role in defending against AI-driven cyberattacks. The challenge now will be ensuring those capabilities are introduced with the governance, transparency, and foundational security controls needed to make them effective.

The post UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense appeared first on IT Security Guru.

Registration Now Open for International Cyber Expo 2026

7 July 2026 at 08:29

Registration is now open for International Cyber Expo 2026, one of the UK’s flagship two-day cybersecurity events which set to return to Olympia London on 29–30 September 2026, bringing together thousands of security professionals, technology providers and policymakers to explore the latest developments shaping the cyber landscape.

With cyber threats at a peak and the convergence of physical and digital security becomes increasingly important, International Cyber Expo has established itself as a key meeting place for the global cybersecurity community. The event provides a platform for organisations to discover emerging technologies, share best practice and discuss the strategies needed to strengthen cyber resilience.

This year’s edition is expected to welcome a diverse audience of CISOs, CTOs, IT directors, government representatives, security architects and risk professionals, alongside leading cybersecurity vendors showcasing the latest innovations in threat detection, incident response, identity management, cloud security, AI-driven defence and critical infrastructure protection.

Visitors will have the opportunity to explore a comprehensive exhibition featuring established technology providers and innovative startups, while benefiting from an extensive conference programme designed to address the challenges facing today’s security leaders. From ransomware and supply chain attacks to artificial intelligence, operational resilience and regulatory compliance, the agenda will focus on the issues currently defining the cybersecurity industry.

One of the event’s major attractions continues to be its thought leadership programme, where industry experts, policymakers and practitioners will share practical insights through keynote presentations, panel discussions and technical sessions. The Global Cyber Summit is designed to provide attendees with actionable advice that can be applied within their own organisations, whether they are responsible for enterprise security strategies or protecting critical national infrastructure.

Networking also remains a central part of the International Cyber Expo experience. With thousands of cybersecurity professionals expected to attend, the event offers opportunities to build new partnerships, connect with peers and engage directly with solution providers in an environment dedicated to knowledge sharing and collaboration.

The continued convergence of cyber and physical security is also expected to feature prominently throughout the event. As organisations increasingly manage interconnected digital and operational environments, collaboration between cybersecurity teams, physical security specialists and government stakeholders has become more important than ever. International Cyber Expo provides a forum for these conversations alongside its co-located event, International Security Expo, while highlighting technologies that support a more integrated approach to organisational resilience.

With registration now officially open, attendees are encouraged to secure their place early and begin planning their visit ahead of what promises to be one of Europe’s most significant cybersecurity events of the year.

To register for FREE, click here.Β 

The post Registration Now Open for International Cyber Expo 2026 appeared first on IT Security Guru.

Check Point Brings Cloud Firewall to AWS European Sovereign Cloud

1 July 2026 at 07:59

Check Point Software has announced that its Cloud Firewall offering is now available on the AWS European Sovereign Cloud, as the cybersecurity giant becomes an official partner for Amazon’s new independent European cloud infrastructure.

The move is designed to help European organisations meet increasingly stringent data residency and operational autonomy requirements under EU regulatory frameworks, without sacrificing the performance and security capabilities they rely on from AWS.

The AWS European Sovereign Cloud is a fully featured, independently operated cloud environment backed by technical controls, sovereign assurances, and legal protections tailored to the needs of European governments and enterprises. Crucially, the infrastructure is located entirely within the EU and operates independently from existing AWS regions, a distinction that matters significantly for regulated industries handling sensitive workloads.

Check Point’s integration into the platform extends its prevention-first security model across network, workload, and application layers, with the company’s AI-powered threat intelligence carried over into the sovereign environment. Customers are promised the same availability and performance they would expect from standard AWS deployments, while gaining the added assurance of EU-based data sovereignty.

Joaquin Reixa, Vice President for Western Europe at Check Point Software Technologies, said the partnership addresses a growing compliance challenge for organisations operating under EU regulatory requirements. β€œCheck Point’s Cloud Firewall solution on this independent cloud infrastructure enables our customers to run their most sensitive workloads with operational autonomy and data residency entirely within the EU,” he said. β€œWith Check Point’s prevention-first security and AI-powered threat intelligence, plus the sovereignty controls and technical assurances of AWS, we’re delivering the compliance support and innovation our customers need to accelerate their digital transformation while meeting stringent regulatory requirements.”

The AWS European Sovereign Cloud offers customers access to the same service portfolio, APIs, and innovations as standard AWS regions, including the AWS Nitro System, while maintaining the independent operational structure required by many public-sector and enterprise customers in Europe.

The announcement comes at a time of heightened regulatory scrutiny around cloud infrastructure in the EU, with frameworks such as GDPR and evolving digital sovereignty legislation pushing organisations to demand greater transparency and control over where their data lives and who can access it.

The post Check Point Brings Cloud Firewall to AWS European Sovereign Cloud appeared first on IT Security Guru.

❌
❌