Reading view

There are new articles available, click to refresh the page.

Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective

Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape.

The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for threat intelligence that informs strategic decision-making rather than simply providing indicators of compromise.

According to Bridewell, organisations are looking beyond traditional security monitoring as ransomware groups become more organised, attackers exploit trusted services and social engineering campaigns become more sophisticated. Rather than reacting to incidents, businesses want intelligence that helps them anticipate threats, understand adversaries and focus security resources where they will have the greatest impact.

Led by Gavin Knapp, Head of Cyber Threat Intelligence, BCON Collective will provide strategic, operational and tactical intelligence designed to support more informed security decision-making. The team works across areas including threat detection, vulnerability prioritisation, incident response and long-term cyber resilience planning.

“Threat intelligence has become its own discipline within cybersecurity,” said Anthony Young, CEO of Bridewell. “Organisations are progressing to see it as not just something that sits alongside security operations, rather they expect it to shape strategic decisions, inform vulnerability management and strengthen incident response.

“Gavin and the team have built an exceptional reputation for producing intelligence that is both technically rigorous and genuinely actionable. As customer demand for these services continues to grow, it made sense to give this capability its own identity while keeping it firmly rooted within Bridewell’s wider cybersecurity expertise.”

Bridewell said its CTI team has built a reputation for producing original threat research covering emerging cyber threats and attacker activity. Recent research has examined ransomware groups including DragonForce, the tactics used by Scattered Spider during attacks against major UK retailers, emerging phishing techniques such as FileFix and ConsentFix, and nation-state activity linked to North Korea.

Knapp believes the real value of threat intelligence lies in helping organisations cut through the volume of available data.

“The biggest misconception about threat intelligence is that it’s about collecting more information. It isn’t. It’s about reducing uncertainty,” he said. “Every security team already has more data than it can realistically process. The challenge is knowing which threats actually matter, which risks deserve immediate attention and where to focus before attackers make the decision for you.

“Most importantly our threat research, threat intelligence and collaboration with both Bridewell offensive security, threat detection, and response capabilities allows us to provide the key components of a threat informed defense to our CNI client base.

“BCON Collective reflects the evolution of the work we’ve already been doing for our clients. It gives our threat research and intelligence capability its own identity and creates a platform through which we can share more of our research, collaborate more closely with customers and continue helping organisations stay one step ahead of an increasingly complex threat landscape.”

Alongside its advisory services, BCON Collective will expand its programme of original threat research, annual intelligence reports, threat actor profiling and strategic intelligence briefings for organisations operating across critical national infrastructure, the public sector and commercial sectors.

The post Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective appeared first on IT Security Guru.

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns

Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the overall trajectory of ransomware activity continues to point upwards.

The report recorded 665 ransomware attacks in June alone, with the industrials sector once again the most heavily targeted, accounting for 30% of attacks across the quarter and 28% in June. Consumer Discretionary and Information Technology rounded out the top three targeted sectors for the quarter.

North America remained the most targeted region, absorbing 44% of all Q2 attacks and 41% of June’s total, followed by Europe (26% for the quarter, 23% in June) and Asia. Qilin held its position as the most active ransomware group for a fifth consecutive quarter, linked to 14% of all Q2 attacks (301 victims), ahead of The Gentlemen (238 victims) and DragonForce (145 victims). NCC Group also flagged the emergence of KryBit, a new Ransomware-as-a-Service operation that claimed 56 victims in its first full quarter of activity.

VPNs remain a favoured entry point

The report’s spotlight section highlights corporate VPNs and internet-facing edge devices as the ransomware ecosystem’s most exploited entry point so far in 2026. Groups including Akira, Qilin and The Gentlemen have all been observed exploiting vulnerabilities in products from vendors such as Fortinet, SonicWall, Citrix and Check Point to bypass authentication and gain a foothold inside victim networks.

NCC Group said vulnerabilities affecting VPN products account for around 15% of the 150-plus Threat Intelligence Alerts it has issued so far this year, many rated high or critical severity. The report also points to “FortiBleed,” a large-scale credential exposure incident uncovered in June affecting roughly half of all publicly exposed FortiGate devices, as a development likely to fuel further exploitation in the coming months.

Software supply chain under sustained assault

Alongside the ransomware data, NCC Group’s analysts describe a marked escalation in attacks against the software development ecosystem during Q2, with campaigns hitting GitHub Actions, npm, PyPI, Docker Hub, Open VSX and the Visual Studio Code Marketplace. The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.

The report warns that these campaigns exploit “transitive trust” in software supply chains, turning maintainer accounts, CI/CD tokens and cloud credentials into high-value targets, with effects that can cascade well beyond the organisation initially compromised.

“A board-level issue”

Matt Hull, VP and Head of Cyber Intelligence and Response at NCC Group, said supply chain attacks remain one of the most attractive routes for threat actors to inflict significant operational, financial, and reputational damage, and that businesses need continuous, rather than ad hoc, monitoring and resilience.

“Although there has not been a material rise in ransomware volume in the last quarter,” Hull said, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. He added that organisations must treat cyber security as the board-level issue it is, pointing to geopolitical tensions and rapidly evolving AI capabilities as compounding pressures on defenders.

NCC Group’s report also examines the deepening professionalisation of ransomware operations such as The Gentlemen, a rapidly-scaling RaaS group whose leaked internal database revealed structured negotiation tactics and a dedicated suite of EDR-disabling tools distributed to affiliates. Separately, the report notes a growing convergence between commodity infostealer malware and higher-end intrusion tradecraft, with new variants adopting rootkit-style concealment, browser-extension-based credential theft, and off-host decryption to evade detection.

The full report also covers geopolitical developments, including rising China-Taiwan tensions, Belarus’s shifting posture toward Russia, and Ireland’s incoming EU Council presidency, which NCC Group assesses could shape targeting patterns for state-linked threat actors in the second half of the year.

The post Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns appeared first on IT Security Guru.

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns

A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims.

The “Cyber Threat Landscape: UK & Ireland” report, published by threat intelligence firm CYFIRMA, finds that financially motivated cybercriminals and state-aligned actors are frequently targeting the same sectors, finance, telecoms, technology, healthcare and government, and warns that cybercrime, espionage and geopolitical disruption are becoming harder to tell apart.

Russia, China, North Korea and Iran all in the mix

According to the report, Russia remains the most immediate geopolitical cyber threat to the region, with Russian-linked groups focused on critical infrastructure, undersea cables and disinformation tied to the ongoing war in Ukraine. China is flagged as the more significant long-term concern, with state-linked groups pursuing intellectual property theft and “living off the land” techniques designed to maintain quiet, persistent access inside critical networks.

The report also names several state-sponsored groups actively targeting the UK, including Russia’s APT28 (Fancy Bear) and APT29 (Cozy Bear), and China-linked APT15 and GALLIUM. It highlights a recent APT28 campaign that hijacks vulnerable home and small-office routers to redirect DNS traffic, quietly harvesting credentials and login tokens from unsuspecting users. North Korea’s Lazarus Group is also named in connection with fake job-offer lures targeting European defence and drone manufacturers, part of the long-running “Operation DreamJob” campaign.

Ransomware still dominates, with the UK bearing the brunt

Ransomware remains the most visible threat. CYFIRMA’s data shows Qilin as the most active gang targeting the region between January and May 2026, followed by DragonForce, The Gentlemen and Cl0p, with the UK absorbing the overwhelming majority of recorded victims. Ireland saw far fewer incidents, but the report notes that groups including The Gentlemen, Qilin and Interlock have all claimed Irish victims, and activity there peaked sharply in May 2026.

Professional services, manufacturing, real estate and IT emerged as the sectors hit hardest by ransomware, the report finds, with most groups now relying on double extortion, encrypting systems while also stealing data to threaten public leaks if a ransom isn’t paid.

Financially motivated crews get creative with social engineering

The report also details the tactics of financially motivated groups such as FIN6, which has been posing as job seekers on LinkedIn and Indeed to trick recruiters into opening fake résumé links laced with malware, and Scattered Spider, which continues to abuse identity and access management systems by impersonating employees to helpdesk staff in order to reset credentials or bypass multi-factor authentication.

Dark web trade in UK and Irish data continues unabated

Beyond ransomware, the report catalogues a steady stream of underground forum listings offering UK and Irish personal data for sale throughout 2026 — including an alleged 120-million-record database from a UK gambling platform, a combo list of more than 657,000 UK email-password pairs, and a dataset said to contain 734,000 UK student records. CYFIRMA says this reflects a growing emphasis among criminal groups on monetising stolen data and credentials rather than relying solely on encryption-based extortion.

Critical vulnerabilities add to the pressure

The report also flags a cluster of critical vulnerabilities disclosed during the period, including several rated 9.0 or above in the n8n workflow automation platform, Cisco’s Secure Firewall ASA and FTD software, Fortinet’s FortiOS and FortiProxy products, and VMware’s ESXi and Workstation platforms — several of which have already been linked to active exploitation.

What organisations should do

CYFIRMA’s recommendations for organisations in both countries include:

  • Accelerating patching of internet-facing systems, VPNs and edge devices, which remain the most common entry point for both ransomware crews and state-backed actors.
  • Enforcing phishing-resistant multi-factor authentication and tightening helpdesk identity-verification processes to blunt social engineering attacks like those used by Scattered Spider and FIN6.
  • Testing ransomware and DDoS response plans, including backup recoverability, given the sustained pace of attacks on critical infrastructure and public services.
  • Increasing scrutiny of third-party and vendor access, as supply chain compromise continues to be used to reach multiple organisations through a single trusted relationship.

The report’s overall message is one of convergence: as ransomware operators, spies and hacktivists increasingly pursue overlapping goals through similar tools and techniques, CYFIRMA argues that organisations can no longer treat these as separate risks to be managed in isolation.

The full research report can be found here: https://www.cyfirma.com/research/cyber-threat-landscape-uk-ireland/

The post Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns appeared first on IT Security Guru.

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations.

The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform as it looks to improve visibility, simplify administration and better secure access across its international infrastructure.

Asite provides cloud-based collaboration software for the construction industry, helping organisations manage projects ranging from digital twins and 3D models to document control and supplier collaboration. With more than 500 employees and data centres spanning nine global locations, the company required a more consistent approach to managing privileged accounts, passwords and machine identities.

According to the case study, Asite was looking to overcome the limitations of browser-based password managers alongside legacy privileged access management (PAM) and secrets management tools, which it found expensive and complex to maintain. The company also needed to securely extend privileged access controls to third-party suppliers and external partners working on customer projects.

“The deployment of KeeperPAM was extremely easy, one of the best in my experience,” said Tiago Rosado, Chief Information Security Officer at Asite. “I wish other tools were as easy to deploy.”

As part of the rollout, Asite standardised password management across its workforce using Keeper’s platform, replacing browser-based password managers with centrally managed credential controls. The organisation also implemented Keeper BreachWatch to identify compromised credentials exposed on the dark web, while Keeper Secrets Manager automated the creation and rotation of secrets and encryption keys, reducing reliance on long-lived credentials.

Keeper said the deployment reflects a broader challenge facing organisations managing privileged access across distributed IT environments. Its 2026 research found that 34% of UK employees reuse passwords across multiple accounts, while 36% of UK respondents said enforcing strong password and credential practices remains either extremely or very challenging for IT and security teams.

The vendor positions KeeperPAM as a unified, cloud-native platform that combines enterprise password management, secrets management, privileged session management, endpoint privilege management, secure remote access and dark web monitoring within a single zero-trust architecture.

“Privileged access management has become a critical control layer for any organisation operating across distributed infrastructure and third-party ecosystems,” said Darren Guccione, CEO and Co-founder of Keeper Security. “Asite’s deployment of KeeperPAM demonstrates how organisations can move from fragmented, costly legacy tools to a unified platform that enforces least-privilege access, automates provisioning and delivers the visibility their security team needs, without the complexity that has historically made PAM difficult to scale.”

The full customer case study is available on the Keeper Security website.

The post KeeperPAM strengthens privileged access management for global construction SaaS provider Asite appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the report‘s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

“In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

“Many organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have continued working with suppliers despite known resilience or security concerns.

The figures come from the Data Health Check 2026, Databarracks’ annual survey of 500 UK IT decision-makers, which has tracked IT resilience since 2008. This year’s report paints a picture of organisations that recognise the danger posed by their supply chains, but frequently feel unable to act on that knowledge.

In many cases, the research suggests, businesses simply lack viable alternatives. More than a quarter of respondents (26%) identified “dependence on suppliers” as a main barrier to improving their organisation’s resilience.

Awareness without action

The Data Health Check found that supplier assessment is now standard practice for most organisations. Almost nine in ten businesses (89%) assess supplier resilience at the point of onboarding, and the majority (61%) go further by conducting assessments annually, quarterly, or continuously.

Despite this due diligence, the risk clearly persists once a supplier relationship is underway. “Supply chain vulnerabilities” was named as one of the top three IT resilience challenges organisations expect to face over the next five years, cited by 23% of respondents – behind only AI-driven cyber threats (46%) and ransomware attacks (26%).

The data also shows a clear link between known risk and real-world impact. Organisations that knowingly continued working with risky suppliers were more than four times as likely to experience a supplier-originated cyber incident: 43% of those organisations went on to suffer an incident, compared with just 10% of organisations that had not knowingly worked with risky suppliers.

“Treat your critical suppliers like you would your own business”

Commenting on the findings, Chris Butler, Resilience Director at Databarracks, said that supply chain resilience remains one of the most persistent weaknesses in UK organisations’ defences. “This year’s findings indicate that supply chain resilience remains a critical pain point for many businesses, which the majority are aware of and which continues to be exploited by attackers. When something goes wrong at a key supplier, the cascade effects can be profound for businesses throughout the chain.”

“Despite good intentions around assessing supplier resilience, most companies don’t fully understand the depth of complexity in their supply chains. Often they’ll know who their core suppliers are, but beyond that, visibility drops away.”

“The traditional approach to assessment has long been tick-box based, with compliance questionnaires growing longer every year. This approach creates a false sense of assurance rather than real resilience.”

Butler argued that genuine improvement requires businesses to move beyond paper-based assurance and to take direct ownership of the risk that suppliers pose to their operations. “To truly manage your supply chain continuity, it’s vital to actually get visibility of the situation. Business leaders need to treat supplier resilience as part of their own resilience, not somebody else’s problem. It’s a bit of a cliché but for good reason: you really need to treat your critical suppliers like you would your own business.”

He also urged organisations to take a more collaborative approach where smaller or less mature suppliers cannot be easily replaced. “Where there isn’t a viable alternative and your existing suppliers don’t have in-house business continuity skills, offer to help. Include your suppliers in your business continuity exercises and give them the chance to rehearse with you. It’s important to practice the response to disruption together rather than in isolation. Doing this will benefit you in the long run.”

Additionally, Jamie Akhtar, CEO and Co-Founder of CyberSmart, added: “This research highlights the severe impact supply-chain attacks are having on businesses of all sizes. It is concerning that one in four businesses has experienced a cyberattack through its supply chain, but what’s even more concerning is that almost half knowingly continue to work with suppliers that have identified security weaknesses. The findings show how difficult it can be for organisations to remain secure. Businesses must manage their own security, but also the security and resilience of their supplies as well.”

“Organisations, especially SMEs, should treat suppliers as part of their own security perimeter. They should assess third-party risks before onboarding, restrict access to essential systems and data, enforce multi-factor authentication, keep software patched and maintain tested backups. Regular supplier reviews and shared incident-response plans can also reduce disruption if a partner is compromised,” Akhtar continued. 

Part of a wider resilience picture

The supply chain findings sit within a broader Data Health Check 2026 report that shows organisations bracing for a harsher resilience environment. The study found that 65% of organisations now believe a serious cyber attack could threaten their survival, while cyber remains the leading cause of IT downtime for the fourth year running, cited by 30% of organisations as their biggest cause of outages.

The report also found reasons for optimism. Business continuity planning has reached a new high, with 90% of organisations now holding a plan and four in five of those kept up to date. Ransomware resilience is also improving: although one in four organisations (25%) experienced a ransomware attack in the last 12 months, only 18% of those affected paid the ransom, while 59% recovered from backups instead.

Databarracks said the overall findings point to “integrating IT and business resilience” as the most-cited priority for organisations in 2026, reflecting a growing recognition that modern incidents – including those originating in the supply chain – rarely respect the boundaries between cyber security, IT operations, business continuity and executive decision-making.

The post 1 in 4 businesses hit by cyber attacks through their supply chain in the last year appeared first on IT Security Guru.

DigiCert expands its EMEA channel strategy with Ignition Technology

DigiCert, a global leader in intelligent trust, has announced a strategic distribution partnership with Ignition Technology to scale its presence across EMEA, accelerate market entry and expand partner-led growth.

Through the partnership, Ignition will bring DigiCert ONE® to customers and partners across the UK and Ireland, DACH, France, Benelux and the Nordics. DigiCert’s comprehensive platform unifies PKI, DNS and automated certificate lifecycle management, helping organisations establish trust across machine identities, software, devices, digital content, and AI agents, while reducing outages, strengthening compliance and supporting the transition to post quantum cryptography.

“Across EMEA, organisations are facing increasingly complex security, operational and regulatory challenges as they embrace AI, modernise infrastructure and prepare for the post quantum era,” said Sean Remnant, Chief Strategy Officer, Ignition Technology. ”They don’t need more disconnected tools. They need a platform that simplifies complexity, helps them move faster and gives them confidence they’re ready for what’s next.”

“This partnership is about creating high impact, scalable growth across EMEA,” said Paul Holt, Group Vice President, EMEA at DigiCert. ”Ignition understands how to build markets, grow partner ecosystems and execute at pace. Together, we’ll help more organisations build the confidence to embrace AI, automate trust at scale and prepare for the post quantum era.”

The partnership reinforces DigiCert’s commitment to growing its channel across EMEA, enabling partners to help organisations simplify security, strengthen resilience and prepare with confidence for the AI and post quantum era.

The post DigiCert expands its EMEA channel strategy with Ignition Technology appeared first on IT Security Guru.

95% of Security Teams Blindsided by Vulnerabilities Between Tests

The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises.

The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found that 95% had discovered high or critical vulnerabilities outside their scheduled testing windows within the past year. Of those, 42% said this had happened at least once a month, underscoring a widening gap between how quickly enterprise environments change and how infrequently they are actually tested.

Three connected gaps

Synack’s researchers point to three related problems undermining enterprise security assurance. The first is a coverage gap: 38% of respondents said at least a quarter of their critical attack surface had gone independently tested or validated for more than 90 days.

The second is what the report calls an AI trust gap. Despite growing enthusiasm for AI-assisted testing, 79% of respondents said they would not act on an AI-generated finding without a human validating it first.

The third is a maturity gap: only 15% of respondents described their security testing and validation programme as continuous, despite continuous testing being the most commonly cited method (named by 22%) for confirming whether a finding is actually exploitable.

One CISO who took part in the study summed up the operational impact: “It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.”

AI expands coverage, but humans are still needed to prove exploitability

The research suggests enterprises are keen for AI to take on a bigger role in reconnaissance, surfacing potential vulnerabilities and expanding testing coverage, but are far less willing to let it operate without human oversight. Respondents said human expertise remains essential for validating exploitability, assessing severity and business risk, testing complex workflows, cutting down false positives, and communicating risk to stakeholders.

“Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent,” said Angela Heindl-Schober, Chief Marketing Officer at Synack. “The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution.”

The study also identifies the main barriers to continuous security validation, including compliance-driven test cycles, integration complexity, a lack of trust in automated findings, false positives, difficulty demonstrating return on investment, and unclear ownership across teams.

“Automation can surface more signals, but security teams need evidence, not noise,” said Mark Kuhr, Co-Founder and Chief Technology Officer at Synack. “Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do.”

A Human + AI model for continuous validation

Synack argues the findings reinforce the case for a combined Human + AI approach to security validation. Its Sara AI Pentesting offering uses what the company calls the Synack Autonomous Red Agent to scale reconnaissance and testing, while the Synack Red Team, a vetted network of more than 1,500 security researchers, is used to validate real-world exploitability, uncover chained attack paths, and provide context that automation alone cannot supply.

Together, the company says, the two approaches are designed to help organisations move away from periodic, point-in-time security snapshots and towards continuous security validation.

The post 95% of Security Teams Blindsided by Vulnerabilities Between Tests appeared first on IT Security Guru.

What Does the Cyber Industry Want to See From the New UK Government?

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.

The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.

Rather than requiring organisations to build governance frameworks from scratch, the Policy Hub provides a library of policies that can be activated immediately and customised to suit different environments. Salt describes the approach as similar to an “app store” for agentic security, allowing security teams to deploy pre-built governance policies across the infrastructure that supports AI agents.

The expanded library includes more than a dozen policies designed specifically for agentic AI, covering areas such as MCP server configuration, agent authorisation and the risks associated with autonomous agent behaviour. Other policies address data security, OAuth, API architecture, third-party risk and compliance with frameworks including GDPR, ISO 27001, HIPAA, PCI DSS and SOC 2.

According to Salt, 61 of the 100 policies are enabled automatically, while the remaining policies can be activated with a single click. Organisations can also create their own custom policies to extend governance beyond the pre-built library. The Policy Hub forms part of the Salt Agentic Security Platform, which provides visibility across what the company calls the Agentic Security Graph, encompassing LLMs, MCP servers, APIs and connected enterprise applications.

Michael Callahan, VP of Strategy and CMO at Salt Security, said many organisations recognise the need for AI governance but struggle to know where to begin. “When we launched the Policy Hub in 2024, the most common thing we heard from CISOs was, ‘We know we need posture governance, but we have no idea where to start.’ That question was killing governance programmes before they launched. The inclusion of 100 policies means that question now has a concrete answer. Security teams can walk in on day one with meaningful protection already active and it can be extended from there without limit.”

Salt said many of the policies were originally developed for API posture governance but now play a broader role as organisations deploy AI agents. As AI systems increasingly depend on APIs, identity platforms and MCP servers to perform actions, the company believes governance must extend across the entire agentic infrastructure rather than focusing solely on AI models or prompts.

The company also highlighted its MCP server discovery capabilities, introduced in 2025, which are supported by dedicated governance policies for identifying configuration issues and controlling how MCP servers interact with enterprise systems.

In June, Salt also launched Salt Code, extending the same governance engine into the software development lifecycle to apply policies to AI-generated code during development.

Aner Gelman, VP of Products at Salt Security, said boards are increasingly asking organisations to demonstrate how AI is being governed.

“The board question CISOs are being asked right now is not whether we have AI governance. It is whether we can prove it. Having 100 policies in active deployment is a concrete, operational answer to that question. Not a roadmap. Not a strategy. An active governance layer running today.”

The 100 pre-built policies are available immediately to customers using the Salt Agentic Security Platform.

The post Salt Security tackles AI governance challenge with 100 pre-built agentic security policies appeared first on IT Security Guru.

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.

The partnership brings together Critical Cloud’s Managed Runtime Assurance operating model with Tarian Labs’ offensive security specialists, whose experience spans government, defence and critical national infrastructure projects.

Managed Runtime Assurance focuses on the day-to-day operation of production applications, cloud platforms and AI systems, helping organisations maintain visibility, resilience, security, operational efficiency and compliance readiness. Instead of producing a report that reflects a single point in time, security findings become part of an ongoing cycle of remediation, retesting and evidence-based validation.

The service combines Critical Cloud’s Datadog-powered managed operating model with Tarian Labs’ independent testing capabilities through an Observe, Detect, Validate methodology. Critical Cloud manages monitoring, governance and runtime operations across production environments, while Tarian Labs performs penetration testing, cloud and infrastructure assessments, web application reviews, API testing and follow-up verification. Findings move directly into remediation before independent retesting confirms they have been addressed.

The partnership preserves clear separation of responsibilities. Tarian Labs owns testing methodology, findings, severity ratings and retesting, while Critical Cloud leads remediation and operational improvements. Every engagement is delivered under customer authorisation, agreed scope, defined rules of engagement and controlled evidence management.

“Detection without validation is hope, not assurance,” said James Smith, CEO of Critical Cloud. “Today’s regulated organisations need continuous proof that production controls continue to perform as intended, particularly as technology changes at an increasingly rapid pace.”

“A penetration test should be the beginning of improvement rather than the end of the process,” said Kevin Hanford, Co-Founder and CEO of Tarian Labs. “By linking independent testing with remediation and verification, we help organisations demonstrate that security risks have been effectively resolved.”

Continuous Runtime Security Validation is now available across the UK and Ireland, with a packaged joint offering planned for a later date. Future joint activities include fintech events in Wales and a live demonstration environment that illustrates the complete Observe, Detect, Validate lifecycle, including remediation, retesting and evidence of closure.

Critical Cloud is ISO 27001 certified, holds Cyber Essentials Plus, and is recognised as a Powered by Datadog accredited partner and Datadog Advanced Partner. Tarian Labs delivers engagements through CREST registered practitioners with final sign-off at NCSC-recognised CHECK Team Leader (CSTL-INF) level.

The post New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience appeared first on IT Security Guru.

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.

The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.

“The strongest pattern in the first half of 2026 was the way different threats converged around trust,” said Luis Corrons, Security Evangelist at Gen. Scams, account takeovers, malicious packages and AI agents, he said, all moved closer to the systems, workflows and permissions people already rely on, meaning attacks increasingly succeed before a victim ever reaches an obviously suspicious moment.

Tech support and imposter scams surge

Tech support scam detections reached 20.3 million blocked attacks in H1 2026, up 61.6% on the second half of 2025. Gen said part of the rise reflects newly introduced detection coverage, but also pointed to campaigns hosted on legitimate-looking cloud infrastructure, including ondigitalocean[.]app domains and fake Windows Defender error pages hosted on Google Cloud Storage in Germany and France. Windows users accounted for 92% of blocked tech support scam attacks, and the US, France, Germany, and Japan were the most targeted countries.

Government impersonation scams rose 387% to almost 1 million blocked attacks, with 81% of that activity concentrated in the United States. Family impersonation scams, often delivered by SMS to Android users and increasingly using AI voice cloning, rose 454.2% and were concentrated in the Netherlands, France, Ireland and Germany.

E-shop scams and fake online stores became one of the highest-volume categories tracked, with 114.2 million blocked attacks, up 109% half-over-half, including one variant using .click domains that alone accounted for more than 10 million blocks. “Fake tutorial” or “scam-yourself” attacks, which trick users into manually running malicious commands via fake CAPTCHA or verification prompts, rose 193% to 5.26 million blocked attempts.

Malvertising was also a major driver of activity, representing almost 30% of detections. Gen’s separate Scam Ad Machine research, examining 14.57 million ads across the EU and UK, found that nearly one in three were scam-related, generating more than 304 million impressions in under a month.

Localised banking trojans, infostealers and crypto-clippers

Regional malware campaigns leaned heavily on local-language lures. Banking trojan operators in Czechia, Slovakia and Poland used JavaScript droppers disguised as shipping notices and invoices, in some cases sent from already-compromised corporate mailboxes. RAT campaigns in Italy, Poland and Czechia used fake invoices, steganographic loaders and multi-stage PowerShell to deploy Remcos and Babylon RAT, among others.

Gen Threat Labs also identified Remus, a new 64-bit infostealer it attributes to the Lumma Stealer family, based on shared obfuscation, string-handling, and browser credential theft techniques, including a bypass of Chrome’s Application-Bound Encryption. Separately, researchers tracked a four-stage cryptocurrency infection chain ending in a Rust-based clipboard hijacker that monitors for wallet addresses across 21 blockchain types and silently swaps in attacker-controlled addresses. The same campaign used Binance Smart Chain to resolve command-and-control infrastructure via EtherHiding, making its infrastructure harder to take down than a conventional domain.

Software supply chain and a cracked-macOS-app wave

Gen documented multiple software supply chain incidents, including compromised npm and PyPI packages, hijacked maintainer accounts, and GitHub accounts abused to push malicious commits while preserving a convincing commit history. In one case, a compromised npm publishing token was used to push an unauthorised update to the Cline CLI that installed malware referred to as OpenClaw onto developer machines during an eight-hour window.

On macOS, Gen tracked a cracked-software distribution chain that pushed users toward mirror sites, torrents, forums, and Telegram channels, blocking roughly 108,000 launch attempts for these applications within 48 hours in a single wave. The payloads included cryptominers, infostealers, and backdoors, but Gen said the more significant issue was permission abuse: installation guides frequently instructed users to disable Gatekeeper and System Integrity Protection, or to grant Full Disk Access, thereby granting broad system access to unsigned binaries.

AI agents move from chatbot risk to execution risk

A significant portion of the report focuses on AI agents, which Gen says have shifted the security conversation because they turn model output into real-world action, fetching URLs, installing packages, editing files, or calling APIs, often with a user’s own credentials and local access.

The report cites an incident in which a Meta AI security researcher granted an AI agent access to her inbox to triage messages, and the agent began deleting emails while reportedly ignoring stop commands. Gen noted that this was reported by TechCrunch and could not be independently verified as forensic evidence, but said it illustrates how a misinterpreted instruction can have real consequences once an agent holds genuine permissions.

The report also references indirect prompt injection documented in the wild by Unit 42, where hidden instructions embedded in web content are later processed by an AI system, and separate research (“Double Agents”) identifying excessive default permissions in a cloud AI agent deployment that allowed a pivot into customer project resources.

Gen discusses its own response to agent risk at length, including a runtime enforcement tool called Sage that checks agent actions, shell commands, URL fetches, file writes, package installs, before they execute, alongside an Agent Trust Hub for pre-use verification, an Agent Detection and Response (ADR) capability, and a proposed cross-industry standard, AARTS, intended to give agent hosts a shared way to expose security-relevant events and enforcement points.

The report also touches on Anthropic’s Claude Mythos and Fable 5 models, noting Anthropic’s own disclosure that Mythos Preview could identify and exploit vulnerabilities in major operating systems and browsers when directed to, and that access to Fable 5 and Mythos 5 was briefly suspended in mid-2026 following a US export-control directive before being restored. Gen frames this as evidence that, once a model can materially accelerate cyber work, questions of who can access it and under what safeguards become part of the security picture, not just the model’s behaviour.

Privacy: persistent access, not just breaches

Gen blocked an average of 310.8 million tracking attempts per month in H1 2026, around 1.9 billion over the half-year. The report highlights GhostPairing, an attack that abuses WhatsApp’s legitimate device-linking feature to trick users into approving an attacker-controlled browser as a linked device, giving the attacker an authorised session that can persist until manually revoked.

The report also raises AI agent memory as an emerging privacy boundary, citing research papers describing backdoored agents that exfiltrate stored user context via disguised tool calls, and separately flags recent FTC settlements and actions against location-data brokers Kochava and Mobilewalla for selling sensitive location data without consent.

Identity and financial fraud: exposure moves fast toward misuse

Gen recorded 18,618 breach events affecting its customers in H1 2026, up 94.5% on the prior half-year, while breach notification alerts with an identified source sent to Norton and LifeLock users rose 628.1% to 3.3 million. February alone accounted for roughly a third of all H1 breach notifications, a spike Gen links partly to the Under Armour breach reported in January 2026, which public reporting said affected around 72 million email addresses.

Downstream financial signals also rose sharply: credit inquiry alerts reached 460,000 in June; depository activity alerts rose 734%; credit activity alerts rose more than tenfold; and web skimming attacks blocked at checkout pages rose 212% to 996,300. Gen also flags a distinct pattern of first-party fraud, in which real, verified accounts, created by people recruited online with promises of quick cash, are later handed over to fraud operators for cash advance abuse, wallet funding or money mule activity, making the behaviour harder to catch at onboarding.

The takeaway

Gen’s overall conclusion is that few of the H1 2026 attacks relied on classic red flags such as poor grammar or obviously suspicious links. Instead, they were built around real reservation details, compromised-but-legitimate mailboxes, trusted update paths and permissions that users had already granted. The report argues that protection increasingly has to sit at the point where trust is granted or transferred, before a payment page, before a package installs, before an AI agent is allowed to act, rather than relying on users to spot the danger themselves.

The post Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust appeared first on IT Security Guru.

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.

The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.

A calendar as a dead drop

HOLLOWGRAPH is a lightweight implant that understands only two instructions, get and send, but carries them out entirely through trusted Microsoft cloud infrastructure rather than attacker-owned servers. Group-IB’s analysis describes the compromised mailbox’s calendar being used as a two-way dead drop: operators plant instructions by creating calendar events, and the malware exfiltrates stolen files by creating its own events with encrypted attachments.

To keep the mailbox owner from noticing anything unusual, every event created by the malware is dated far into the future, specifically 13 May 2050, with the stolen or tasking data hidden inside file attachments rather than the event body. Get requests search for events with a subject line referencing a task ID, while send operations upload encrypted data in chunks named “File{n}.txt” before renaming the event to an operator-recognisable tag.

DNS tunnelling keeps credentials fresh

Alongside the calendar-based C2 channel, HOLLOWGRAPH maintains a separate communications path used solely to refresh the Microsoft Entra ID (formerly Azure AD) credentials it needs to continue authenticating to the Graph API. Group-IB found that the malware performs DNS tunnelling, issuing IPv6 AAAA record lookups against an attacker-controlled domain, cloudlanecdn[.]com, to retrieve updated tenant IDs, client IDs, client secrets, and mailbox details, which it then writes to a configuration file on disk disguised as an ordinary log file, logAzure.txt.

According to the write-up, length-indicating queries and data-carrying queries are distinguished by naming convention, with each returned IPv6 address smuggling 14 usable bytes of payload that the malware reassembles into plaintext credential data. This DNS channel, researchers noted, is not itself encrypted.

Communications sent through the Graph API channel, by contrast, are protected with hybrid RSA and AES-256-GCM encryption, and the malware uses separate RSA key pairs for inbound tasking and outbound exfiltration, keeping the two directions cryptographically independent of one another.

Linked to the Cavern framework and possibly Lyceum

Group-IB said several technical characteristics tie HOLLOWGRAPH to the Cavern framework, including a matching command syntax and observed tasking that mirrors Cavern’s known structure, among them a “toggle debug logging” self-command used elsewhere by the framework.

The researchers stopped short of attributing the campaign to a specific, previously known threat actor, but noted overlaps with malware previously associated with Lyceum, a group considered a sub-cluster of the Iranian threat actor OilRig. Group-IB said Cavern’s modular backdoor functionality closely resembles a .NET backdoor used by Lyceum in early 2025, including shared command codes and a similar approach to loading plugin modules from disk on demand. The firm characterised this potential link as low confidence.

A small, disciplined set of victims

Group-IB said it identified at least 12 systems infected with HOLLOWGRAPH, of which only around three were actively exchanging data with the attacker at the time of analysis. The earliest observed communication between a victim and the attacker was recorded on 3 June 2026, with the most recent seen on 9 July 2026, indicating the malware has been in active use since at least early June.

Researchers said the small victim count, combined with the fact that the compromised mailbox used for exfiltration belongs to an Israeli organisation and that malware samples were uploaded for analysis from Israel, points to a deliberately narrow, targeted espionage operation rather than opportunistic mass compromise.

Why it matters

The use of legitimate cloud services for C2 is a well-established evasion tactic, but HOLLOWGRAPH’s approach of hiding both tasking and exfiltrated data inside calendar event attachments, dated decades into the future, illustrates how creatively threat actors are exploiting everyday collaboration features to slip past perimeter and email-security defences. Because the traffic runs entirely through Microsoft’s own infrastructure and a legitimately authenticated (if compromised) account, it can be difficult for defenders to distinguish from normal Microsoft 365 usage without close inspection of Graph API activity and mailbox audit logs.

Recommendations

Group-IB has urged organisations, particularly those operating in or connected to Israel, to:

  • Hunt for indicators associated with HOLLOWGRAPH and the Cavern framework, including the domain cloudlanecdn[.]com and the configuration file logAzure.txt.
  • Monitor Microsoft Graph API activity and mailbox audit logs for anomalous calendar operations performed by an application rather than a user, including event creation, attachment uploads and subject-line changes.
  • Watch for calendar artefacts consistent with the malware, such as events dated to 2050-05-13, GUID-only subjects, or subjects following the “Event ID:” or “Boss{..}ID{..}” naming patterns with “File{n}.txt” attachments.
  • Restrict, monitor and audit OAuth2 applications using client credentials, and alert on the creation of new client secrets.
  • Enforce Conditional Access policies, regular credential rotation and anomalous-token detection across Microsoft 365 and Entra ID environments.
  • Deploy DNS monitoring capable of spotting tunnelling activity, such as unusually frequent AAAA queries or long, high-entropy subdomains, and route outbound DNS through controlled, filtered resolvers.

Group-IB said it will continue to track the evolution of the Cavern framework, adding that the sophistication of HOLLOWGRAPH, combined with its narrow targeting, points to a capable and well-resourced adversary, even though the specific group behind the campaign remains unconfirmed. More information can be found here: https://www.group-ib.com/blog/hollowgraph-microsoft-365/

The post Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites appeared first on IT Security Guru.

CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging

More than three-quarters of European CISOs believe their C-suite doesn’t fully understand the cyber risk posed by their own employees, a gap that’s widening just as AI makes attacks on human judgement faster, more convincing and harder to spot.

That’s according to new research from MetaCompliance, the human cyber risk management firm, which polled 200 CISOs across the UK, France, Germany and Sweden. The picture it paints is of security leaders trying to hold the line on human-layer risk without the consistent senior backing, clear ownership, or shared understanding they need to do so.

AI is changing what CISOs are worried about

The survey found that among CISOs who feel less confident about their organisation’s cyber resilience than they did a year ago, AI-enabled social engineering was the single biggest reason cited, named by almost half of that group. It’s a sign that attackers are moving away from crude, easily-spotted phishing and towards convincing impersonation and fraud attempts generated at scale.

Employees, unsurprisingly, remain squarely in the firing line. More than two in three CISOs still rank their own staff as the biggest security risk to the business, suggesting AI isn’t creating a new problem so much as turbocharging an old one.

Specific concerns bear that out:

  • Over 40% of CISOs are worried AI is increasing the speed and impact of social engineering attacks
  • 40% fear staff are feeding sensitive data into generative AI tools
  • 41% are concerned about malicious insiders using AI to enable fraud, cybercrime or data theft
  • In the UK specifically, deepfake impersonation stands out as a top worry — more than half of UK CISOs flagged it as a major threat, the highest figure of any country in the study

Support from the top doesn’t stick

Where the research gets more uncomfortable for boardrooms is on backing. Almost four in five CISOs (79%) say leadership enthusiasm for security awareness programmes tends to fade once the initial push is over, and 76% say they’re stuck trying to satisfy different stakeholders who all want different human-risk metrics. Roughly a quarter point to cross-functional alignment as one of the areas they feel least confident managing.

James Mackay, CEO of MetaCompliance, said AI has changed the stakes: “Attackers are no longer relying on obvious scams or poorly written phishing emails. They can now create highly convincing impersonation attempts, social engineering attacks and fraudulent communications at scale.”

He argued that puts a premium on sustained executive engagement rather than one-off initiatives: “Human cyber risk is no longer just an awareness issue or a training issue; it is a strategic business risk… If leadership support fades after the initial push, organisations are left exposed.”

Where CISOs go from here

Improving resilience against AI-driven social engineering is now a stated priority for the year ahead, with close to a quarter of CISOs naming it as a key focus. Mackay suggested the shift needs to be structural rather than seasonal: organisations that fare best will treat human risk as an ongoing management discipline rather than a periodic training exercise, giving employees real-time, contextual support at the moment a risky decision is actually being made, rather than relying solely on annual training modules.

The findings come at a moment when AI-generated phishing, deepfake voice and video, and synthetic impersonation are becoming difficult to distinguish from genuine communications — putting fresh pressure on security teams to secure top-level buy-in before the next wave of attacks arrives.

The post CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging appeared first on IT Security Guru.

Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages

Swiss encrypted communications provider Proton has launched a dedicated business continuity service, aimed at helping organisations keep email and video communications running when their primary IT infrastructure fails or is taken offline.

The service is built around Proton Mail and Proton Meet, and is designed to give security and IT teams a pre-configured fallback they can activate quickly during an outage, a ransomware incident, or a third-party service disruption, without requiring staff to install new software or reset credentials under pressure.

Proton said the launch responds to a threat landscape in which outages are increasingly frequent, ransomware is spreading further into the small and mid-sized business market, and organisations face growing exposure to decisions made by US-based cloud and software providers, which remain legally bound to comply with US government directives, including those restricting service to customers outside the United States.

The company argues this exposes a structural weakness common to many security architectures: because so much business email and collaboration software ultimately runs on a small number of hyperscale platforms, chiefly Amazon Web Services, Microsoft Azure and Google Cloud, a single infrastructure failure or access restriction can take down communications across otherwise unrelated organisations simultaneously.

How it works

Under Proton’s model, organisations set up two tiers of accounts in advance. Active accounts assigned to IT administrators, business continuity coordinators, and senior leadership remain configurable and testable at any time. Dormant accounts, provisioned for the wider workforce at a reduced cost, remain inactive in the background, tied to the correct user identity and permission group until needed.

When an incident is declared, an administrator makes a single DNS change, repointing the organisation’s MX record to Proton’s mail servers instead of its usual provider. Dormant accounts are activated when employees log in with credentials or access links distributed by their administrator, after which the whole team can continue operating on Proton’s infrastructure, which the company says is fully separate from Google, Microsoft and AWS.

Organisations can also pre-configure their existing email domain inside Proton Mail, or set up a secondary domain to test failover in advance, allowing continuity plans to be rehearsed before they are ever needed.

A security case built on jurisdiction and encryption

Proton is positioning the service as much on legal and jurisdictional grounds as on technical ones. The company’s infrastructure and legal base sit in Switzerland, which it describes as neutral territory outside both the Big Tech ecosystem and US regulatory reach. Proton Mail and Proton Meet use end-to-end encryption, and the company points to a decade-long uptime record, underpinned by a 99.95 percent service-level agreement, as evidence of its resilience credentials.

Raphael Auphan, Chief Operating Officer at Proton, said organisations increasingly need to plan for disruption that is political as well as technical in origin. “Whether it’s in a week or a year, preparing now will make the difference between a managed response and an operational crisis,” Auphan said.

Proton already counts more than 100,000 organisations as Proton Mail users, and offers an Easy Switch for Business tool for firms migrating their primary email service outright. The new continuity offering is aimed instead at organisations that want an emergency fallback without giving up their existing primary provider.

Security teams considering the service will need to weigh the operational overhead of maintaining dormant accounts and rehearsed failover processes against the risk reduction it offers — a trade-off likely to depend on an organisation’s existing business continuity maturity and its risk appetite around single-vendor dependency.

The post Proton Launches Business Continuity Service to Keep Firms Communicating Through Outages appeared first on IT Security Guru.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

Lidl Confirms Data Breach After Third-Party IT Provider Hack

Lidl has confirmed that a cyberattack on one of its third-party IT service providers exposed the personal data of online shop customers in Germany, Belgium and the Netherlands, the latest in a string of supply-chain breaches to hit major European retailers this year.

The discount supermarket chain, owned by Schwarz Group, said it was informed of the incident last week and moved to notify affected customers by email, as well as to publish breach notices on its German, Belgian and Dutch support websites. In its statement, Lidl said unknown individuals had briefly gained access to “a separately stored file containing customer data” and stolen part of it, stressing that “the online shop system itself was not affected.”

The incident is a reminder of how much of a retailer’s exposure now sits outside its own walls. Boris Cipot, principal security engineer at Black Duck, said, “This incident is a textbook reminder that your security posture is only as strong as your weakest third party. Even when a retailer’s own systems hold, a compromised service provider can expose millions of customers to identity fraud, phishing, and account takeover attacks. Personal data like names, birthdates, phone numbers, and email addresses may seem low risk in isolation, but combined they become a powerful toolkit for social engineering. Additionally, the downstream costs to consumers and brand trust can far outlast the incident itself.”

According to the company, the compromised data includes customers’ salutation, first and last name, phone number, email address, date of birth, and customer number. Lidl said it currently has no evidence that passwords, billing or delivery addresses, bank details or other payment information were affected, and that customer accounts themselves had not been compromised. The retailer added that the affected IT service provider responded immediately and took steps to restore full security to its systems.

Paul Bischoff, Consumer Privacy Advocate at Comparitech, argued the nature of the stolen data limits the immediate danger, though phishing remains a real risk: “Although the breach is unfortunate, the compromised data doesn’t pose a direct threat to victims’ money or identities. It doesn’t contain credit cards or Social Security numbers, for example. Scammers could use the data to launch tailored phishing attacks and other scams, so be on the lookout for malicious emails and text messages. Scammers might pose as Lidl or a related company to trick victims into clicking malicious links.”

Cipot was more measured about how the company has handled disclosure so far, while cautioning that the real test is still to come: “Lidl deserves credit for moving quickly to notify customers and being transparent about what they don’t yet know, including the possibility that passwords, addresses, and payment data could be involved. That kind of candor presents the appropriate posture under GDPR. The real test now is follow-through: how quickly they complete the forensic investigation, how clearly they communicate updates as the scope becomes known, and how rigorously they reassess the security requirements they place on their service providers going forward.”

Lidl has filed a police report, engaged external IT forensic experts to investigate the scope of the incident, and notified the relevant data protection authorities, including the Dutch and Belgian Data Protection Authorities. The company has not named the compromised service provider or disclosed how many customers were affected. As of writing, no threat actor has publicly claimed responsibility.

Lidl, Europe’s largest food retailer, operates around 12,900 stores across 32 countries in Europe and the US and employs more than 376,000 people. The breach adds it to a growing list of retailers hit by supply-chain and third-party attacks over the past year, including Marks & Spencer, Co-op, Louis Vuitton, Pandora and Harrods, several of which have been linked to the Scattered Spider hacking group. Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the pattern has become too consistent to ignore: “Another major retailer, another third-party service provider breach. The pattern is consistent enough now that it needs calling out clearly; one of the weakest points in most organisations’ security posture isn’t their own systems, it’s the extended ecosystem of service providers that touch customer data peripherally.”

Lidl has urged customers to be alert for phishing attempts, telling them to verify the authenticity of any sender before disclosing information or clicking links, and to watch out for messages referencing their Lidl account or recent orders. Patel echoed that advice directly to anyone who has shopped with the retailer online: “If you’ve shopped on Lidl’s online store in Germany, Belgium, or the Netherlands, treat this as a prompt to act. Change your Lidl account password immediately, and if you’ve used the same password anywhere else, change it there too. Password reuse remains the single most effective way attackers turn one breach into multiple account compromises. If you receive any communication claiming to be from Lidl asking you to verify details or click a link, contact Lidl directly through their official website rather than responding.”

Cipot offered similar guidance, with a reminder that stolen data of this kind tends to resurface in scams long after the headlines fade: “Customers should treat this as a wake-up call, not just a notification. Change your Lidl password immediately (and any password reused elsewhere), enable multi-factor authentication wherever it’s offered, and be on high alert for phishing emails, texts, or calls that reference your Lidl account or recent orders. Attackers will absolutely weaponize this stolen data to craft convincing scams in the weeks and months ahead. Monitor your bank and card statements closely and consider a credit freeze if you’re in a jurisdiction where that’s available.”

The post Lidl Confirms Data Breach After Third-Party IT Provider Hack appeared first on IT Security Guru.

Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis

Black Duck has rolled out a set of AI-driven and compliance-focused updates to Coverity, its static application security testing (SAST) tool, as the application security vendor looks to align the two-decade-old product with both the rise of AI-assisted coding and tightening European regulation.

The release marks the first time AI-powered features have shipped in Coverity, and Black Duck was keen to stress that the new capabilities can be run against a customer’s own choice of large language model, rather than a vendor-hosted service. The company said this was designed to give security and development teams control over where code and scan data are processed, a point it framed as particularly relevant for regulated industries and organisations with strict data governance requirements.

AI features aimed at cutting false positives

Chief among the additions is an AI-assisted issue triage capability, which Black Duck says is tuned to reduce false positives in C and C++ findings, a long-standing pain point for teams working in those languages, while also improving triage accuracy across the rest of Coverity’s supported languages.

Coverity has also gained a Model Context Protocol (MCP) server, allowing AI coding agents to trigger local Coverity scans and pull security and quality findings directly into their workflow. Black Duck’s pitch is that this lets agentic tools act on deterministic, reproducible scan output rather than relying purely on a model’s own probabilistic judgement of whether code is safe.

A new checker adds AI-powered detection of Insecure Direct Object Reference (IDOR) flaws in JavaScript and TypeScript codebases. IDOR vulnerabilities occur when an application exposes internal identifiers, such as user IDs, database keys or filenames, without properly checking that the requester is authorised to access them, a class of bug that has featured heavily in API-related breach disclosures.

Positioning for the Cyber Resilience Act

With reporting deadlines under the EU Cyber Resilience Act approaching, Black Duck used the update to introduce two compliance-oriented features. A new Security Impact Lens lets users sort and filter findings by security priority, bringing to security triage the kind of prioritisation Coverity has historically applied to code quality issues. Alongside it, a CRA-aligned checker option is intended to map scan results more directly to the vulnerability management and cybersecurity obligations set out in the regulation.

The update also extends language coverage to Rust 1.92, and introduces a refreshed user interface with reworked navigation and issue filtering, which Black Duck says is intended to speed up triage for teams working through large volumes of findings.

“Coverity has set the gold standard for static analysis for more than two decades, and we’re raising the bar by pairing its deterministic precision with the speed of AI, meeting customers where modern software development is heading,” said Dipto Chakravarty, Chief Product & Technology Officer at Black Duck.

“Code today is written, reviewed, and shipped by agents, and businesses have to move at machine speed to stay ahead,” Chakravarty added, arguing the update delivers AI-driven triage without sacrificing auditability, agentic workflow integration via the MCP server, and tooling that makes CRA readiness “operational, not aspirational.”

Black Duck said all of the new capabilities are now generally available to existing Coverity customers, who gain access to the AI-powered features without changes to the deterministic, auditable scanning the product is built around. Further detail is available via the Coverity Documentation Portal.

The post Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis appeared first on IT Security Guru.

UK Cyber Attacks Climb 34% as Ransomware Leadership Shifts, Check Point Research Reveals

UK organisations faced an average of 1,589 cyber attacks per week in June 2026, a 34% increase compared with the same month last year, according to new threat intelligence from Check Point Research, the intelligence arm of Check Point Software Technologies.

The UK figure outpaces the global trend line. Worldwide, organisations experienced an average of 2,270 weekly attacks in June, up 17% year on year and 10% month on month, as a brief lull in May gave way to a broad rebound across regions and industries. Rather than concentrating in one geography or sector, the increase in attack volume appeared almost everywhere at once, a pattern researchers say points to attackers widening their targeting rather than intensifying pressure on a single weak point.

“June’s data shows a broad rebound in cyber activity, not a single isolated spike,” said Omer Dembinsky, Data Research Manager at Check Point Research. “Attackers are widening their reach across regions and industries, while ransomware groups continue to reorganise and scale. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

Education, Government and Telecommunications remained the most targeted sectors globally. Education organisations faced an average of 4,816 weekly attacks, up 16% year on year, with open campus networks and constrained security budgets continuing to make schools and universities attractive targets. Government followed at 2,836 weekly attacks (up 5%), while Telecommunications recorded 2,835 (up 13%).

Regionally, Latin America remained the most heavily targeted, with 3,501 weekly attacks on average, a 27% year-on-year rise. Europe posted one of the sharpest regional increases globally at 22%, a trend the UK figures sit within and, on this data, exceed.

Ransomware activity intensified sharply in June, with 646 attacks recorded, a 33% rise on June 2025. Business Services remained the most targeted industry, accounting for 31% of reported victims, followed by Consumer Goods and Services (16%) and Industrial Manufacturing (14%). Government’s share of ransomware victims has climbed steadily, from 4.0% in April to 5.4% in June.

The most notable development was at the group level. The Gentlemen, a ransomware-as-a-service operation founded in mid-2025, overtook Qilin to become the most active ransomware group, responsible for 17% of published attacks compared with Qilin’s 11%. LockBit also surged, rising from 1% of published attacks in May to 7% in June, making it the third most prevalent group.

Check Point Research attributes The Gentlemen’s rapid rise to an unusual dual model: the group functions simultaneously as a RaaS provider and an Initial Access Broker, giving affiliates self-service access to an estimated 14,000 pre-exploited FortiGate devices tied to CVE-2024-55591. Researchers have linked the group to more than 320 confirmed data-leak-site victims, with an estimated 1,570+ actual compromises, placing it among the top seven ransomware threats globally within a year of launch. Its targeting is notably atypical, with the US accounting for only 12% of victims against a 50% ecosystem average, reflecting a victim-selection model driven by device availability rather than deliberate geographic targeting. The group’s cross-platform lockers target Windows, Linux and ESXi environments, and a May 2026 operator communication signalled a shift from blunt-force BYOVD-based EDR killing toward more surgical userland evasion techniques.

GenAI-related exposure also remained a persistent risk through June. Check Point Research found that 1 in every 26 enterprise GenAI prompts carried a high risk of sensitive data leakage, a global exposure rate of 3.9%, affecting 85% of organisations that regularly use GenAI tools. A further 27% of prompts contained potentially sensitive information. Healthcare and Medical organisations carried the highest exposure at 5.7%, followed by Telecommunications and Business Services at 5.1% each. Personal data was the most common category of sensitive information exposed, appearing across 80% of affected organisations.

With UK attack volumes rising faster than the global average, researchers say the combination of broader attacker targeting, a reshuffled ransomware leaderboard and steady GenAI-related exposure underscores the case for prevention-first security architectures that span network, cloud, endpoint and user activity.

The post UK Cyber Attacks Climb 34% as Ransomware Leadership Shifts, Check Point Research Reveals appeared first on IT Security Guru.

UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense

The National Cyber Security Centre (NCSC) has unveiled plans for Cyber Shield, an ambitious initiative that aims to use agentic artificial intelligence to transform the nation’s cyber defenses and counter increasingly sophisticated cyber threats. The proposal forms part of a broader effort by the NCSC and the Department for Science, Innovation and Technology (DSIT) to build a national scale, AI powered cyber defense capability that can detect, analyze, and eventually respond to attacks at machine speed.

According to the NCSC, Cyber Shield will initially focus on using AI to identify vulnerabilities and detect threats before progressing toward automated mitigation, coordinated threat intelligence sharing, and national level response capabilities. The initiative is intended to help defenders keep pace with attackers who are increasingly using artificial intelligence to accelerate reconnaissance, vulnerability discovery, and exploitation.

AI changes the cyber defense equation

Rik Ferguson, Vice President of Security Intelligence at Forescout, believes the proposal reflects the reality of today’s threat landscape.

“The NCSC’s Cyber Shield proposal feels like a logical and necessary step, especially if we view it through the lens of ‘Assume Autonomy,'” Ferguson said.

“The core assumption should no longer be that autonomous cyberattacks are a distant or speculative problem. We should assume that adversaries will increasingly use AI agents to automate reconnaissance, vulnerability discovery, exploit development, credential attacks, lateral movement, and adaptation once inside an environment.”

Ferguson said security teams operating at human speed will struggle to defend against machine speed attacks, particularly across critical infrastructure, healthcare, and government networks.

“A national scale AI cyber shield is therefore not just about adding AI to existing security workflows. It is about building defensive systems that can detect, prioritize, and help contain threats at the same tempo at which AI enabled attackers can operate.”

However, he cautioned that autonomy must be implemented carefully.

“The opportunity is strongest where AI can improve visibility, correlation, triage, exposure management, and early intervention. The risk comes when automated systems act without sufficient context, governance, or operational guardrails.”

He added that AI alone cannot solve long-standing cybersecurity problems.

“AI can help defenders move faster, but it cannot compensate for poor asset visibility, weak segmentation, unpatched systems, or unclear ownership of cyber risk.”

Governance will be critical

Shane Barney, Chief Information Security Officer at Keeper Security, also welcomed the initiative but warned that the success of Cyber Shield will depend on strong governance.

“Cyber Shield is the right instinct, and it is arriving at a genuinely dangerous moment for both organizations and the wider public,” Barney said.

“Attackers are already using AI to compress reconnaissance and exploitation into minutes, and the NCSC is correct that human speed defense cannot keep pace with machine speed offense.”

Barney argued that many successful cyberattacks still rely on basic security weaknesses.

“Most successful attacks still exploit basic, preventable failures, including outdated systems, unpatched software, and weak access controls. No amount of agentic AI changes that equation if the underlying identity and access foundations are not solid.”

He also highlighted a potential new risk created by AI itself.

“Red and blue AI agents are themselves privileged non-human identities, granted authority to scan networks, share intelligence, and eventually remediate vulnerabilities autonomously.”

According to Barney, those AI agents will require the same security controls as privileged human administrators, including least privilege access, just in time provisioning, and complete visibility into their activity.

“An AI agent with unmanaged privileged access is not a defense. It is the next incident.”

A collaborative approach

The NCSC said Cyber Shield will rely on close collaboration between government, industry, academia, and critical infrastructure operators. Trusted information sharing and explainable AI will be central to the initiative as it evolves from vulnerability discovery toward coordinated national cyber defense.

While the idea of a Cyber Shield remains a long-term vision, security leaders broadly agree that AI will play an increasingly important role in defending against AI-driven cyberattacks. The challenge now will be ensuring those capabilities are introduced with the governance, transparency, and foundational security controls needed to make them effective.

The post UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense appeared first on IT Security Guru.

❌