❌

Reading view

There are new articles available, click to refresh the page.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the reportβ€˜s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

β€œAI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

β€œIn observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

β€œAs attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

β€œMany organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville

The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity appeared first on SecurityWeek.

Hacking US Elections: The First Tranche of Declassified Election Integrity Documents

Why Every Cybersecurity Professional Should Read the Original Records By Gary S. Miliefsky Publisher, Cyber Defense Magazine For more than a decade, cybersecurity professionals have watched researchers at DEF CON’s...

The post Hacking US Elections: The First Tranche of Declassified Election Integrity Documents appeared first on Cyber Defense Magazine.

Inside β€œGold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure

What is Gold Eagle? A new federal cybersecurity hub called Gold Eagle was created to combat the growing threat of cyberattacks powered by artificial intelligence. The initiative is led through...

The post Inside β€œGold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure appeared first on Cyber Defense Magazine.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense

The National Cyber Security Centre (NCSC) has unveiled plans for Cyber Shield, an ambitious initiative that aims to use agentic artificial intelligence to transform the nation’s cyber defenses and counter increasingly sophisticated cyber threats. The proposal forms part of a broader effort by the NCSC and the Department for Science, Innovation and Technology (DSIT) to build a national scale, AI powered cyber defense capability that can detect, analyze, and eventually respond to attacks at machine speed.

According to the NCSC, Cyber Shield will initially focus on using AI to identify vulnerabilities and detect threats before progressing toward automated mitigation, coordinated threat intelligence sharing, and national level response capabilities. The initiative is intended to help defenders keep pace with attackers who are increasingly using artificial intelligence to accelerate reconnaissance, vulnerability discovery, and exploitation.

AI changes the cyber defense equation

Rik Ferguson, Vice President of Security Intelligence at Forescout, believes the proposal reflects the reality of today’s threat landscape.

β€œThe NCSC’s Cyber Shield proposal feels like a logical and necessary step, especially if we view it through the lens of β€˜Assume Autonomy,'” Ferguson said.

β€œThe core assumption should no longer be that autonomous cyberattacks are a distant or speculative problem. We should assume that adversaries will increasingly use AI agents to automate reconnaissance, vulnerability discovery, exploit development, credential attacks, lateral movement, and adaptation once inside an environment.”

Ferguson said security teams operating at human speed will struggle to defend against machine speed attacks, particularly across critical infrastructure, healthcare, and government networks.

β€œA national scale AI cyber shield is therefore not just about adding AI to existing security workflows. It is about building defensive systems that can detect, prioritize, and help contain threats at the same tempo at which AI enabled attackers can operate.”

However, he cautioned that autonomy must be implemented carefully.

β€œThe opportunity is strongest where AI can improve visibility, correlation, triage, exposure management, and early intervention. The risk comes when automated systems act without sufficient context, governance, or operational guardrails.”

He added that AI alone cannot solve long-standing cybersecurity problems.

β€œAI can help defenders move faster, but it cannot compensate for poor asset visibility, weak segmentation, unpatched systems, or unclear ownership of cyber risk.”

Governance will be critical

Shane Barney, Chief Information Security Officer at Keeper Security, also welcomed the initiative but warned that the success of Cyber Shield will depend on strong governance.

β€œCyber Shield is the right instinct, and it is arriving at a genuinely dangerous moment for both organizations and the wider public,” Barney said.

β€œAttackers are already using AI to compress reconnaissance and exploitation into minutes, and the NCSC is correct that human speed defense cannot keep pace with machine speed offense.”

Barney argued that many successful cyberattacks still rely on basic security weaknesses.

β€œMost successful attacks still exploit basic, preventable failures, including outdated systems, unpatched software, and weak access controls. No amount of agentic AI changes that equation if the underlying identity and access foundations are not solid.”

He also highlighted a potential new risk created by AI itself.

β€œRed and blue AI agents are themselves privileged non-human identities, granted authority to scan networks, share intelligence, and eventually remediate vulnerabilities autonomously.”

According to Barney, those AI agents will require the same security controls as privileged human administrators, including least privilege access, just in time provisioning, and complete visibility into their activity.

β€œAn AI agent with unmanaged privileged access is not a defense. It is the next incident.”

A collaborative approach

The NCSC said Cyber Shield will rely on close collaboration between government, industry, academia, and critical infrastructure operators. Trusted information sharing and explainable AI will be central to the initiative as it evolves from vulnerability discovery toward coordinated national cyber defense.

While the idea of a Cyber Shield remains a long-term vision, security leaders broadly agree that AI will play an increasingly important role in defending against AI-driven cyberattacks. The challenge now will be ensuring those capabilities are introduced with the governance, transparency, and foundational security controls needed to make them effective.

The post UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense appeared first on IT Security Guru.

Registration Now Open for International Cyber Expo 2026

Registration is now open for International Cyber Expo 2026, one of the UK’s flagship two-day cybersecurity events which set to return to Olympia London on 29–30 September 2026, bringing together thousands of security professionals, technology providers and policymakers to explore the latest developments shaping the cyber landscape.

With cyber threats at a peak and the convergence of physical and digital security becomes increasingly important, International Cyber Expo has established itself as a key meeting place for the global cybersecurity community. The event provides a platform for organisations to discover emerging technologies, share best practice and discuss the strategies needed to strengthen cyber resilience.

This year’s edition is expected to welcome a diverse audience of CISOs, CTOs, IT directors, government representatives, security architects and risk professionals, alongside leading cybersecurity vendors showcasing the latest innovations in threat detection, incident response, identity management, cloud security, AI-driven defence and critical infrastructure protection.

Visitors will have the opportunity to explore a comprehensive exhibition featuring established technology providers and innovative startups, while benefiting from an extensive conference programme designed to address the challenges facing today’s security leaders. From ransomware and supply chain attacks to artificial intelligence, operational resilience and regulatory compliance, the agenda will focus on the issues currently defining the cybersecurity industry.

One of the event’s major attractions continues to be its thought leadership programme, where industry experts, policymakers and practitioners will share practical insights through keynote presentations, panel discussions and technical sessions. The Global Cyber Summit is designed to provide attendees with actionable advice that can be applied within their own organisations, whether they are responsible for enterprise security strategies or protecting critical national infrastructure.

Networking also remains a central part of the International Cyber Expo experience. With thousands of cybersecurity professionals expected to attend, the event offers opportunities to build new partnerships, connect with peers and engage directly with solution providers in an environment dedicated to knowledge sharing and collaboration.

The continued convergence of cyber and physical security is also expected to feature prominently throughout the event. As organisations increasingly manage interconnected digital and operational environments, collaboration between cybersecurity teams, physical security specialists and government stakeholders has become more important than ever. International Cyber Expo provides a forum for these conversations alongside its co-located event, International Security Expo, while highlighting technologies that support a more integrated approach to organisational resilience.

With registration now officially open, attendees are encouraged to secure their place early and begin planning their visit ahead of what promises to be one of Europe’s most significant cybersecurity events of the year.

To register for FREE, click here.Β 

The post Registration Now Open for International Cyber Expo 2026 appeared first on IT Security Guru.

❌