Reading view

There are new articles available, click to refresh the page.

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns

Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the overall trajectory of ransomware activity continues to point upwards.

The report recorded 665 ransomware attacks in June alone, with the industrials sector once again the most heavily targeted, accounting for 30% of attacks across the quarter and 28% in June. Consumer Discretionary and Information Technology rounded out the top three targeted sectors for the quarter.

North America remained the most targeted region, absorbing 44% of all Q2 attacks and 41% of June’s total, followed by Europe (26% for the quarter, 23% in June) and Asia. Qilin held its position as the most active ransomware group for a fifth consecutive quarter, linked to 14% of all Q2 attacks (301 victims), ahead of The Gentlemen (238 victims) and DragonForce (145 victims). NCC Group also flagged the emergence of KryBit, a new Ransomware-as-a-Service operation that claimed 56 victims in its first full quarter of activity.

VPNs remain a favoured entry point

The report’s spotlight section highlights corporate VPNs and internet-facing edge devices as the ransomware ecosystem’s most exploited entry point so far in 2026. Groups including Akira, Qilin and The Gentlemen have all been observed exploiting vulnerabilities in products from vendors such as Fortinet, SonicWall, Citrix and Check Point to bypass authentication and gain a foothold inside victim networks.

NCC Group said vulnerabilities affecting VPN products account for around 15% of the 150-plus Threat Intelligence Alerts it has issued so far this year, many rated high or critical severity. The report also points to “FortiBleed,” a large-scale credential exposure incident uncovered in June affecting roughly half of all publicly exposed FortiGate devices, as a development likely to fuel further exploitation in the coming months.

Software supply chain under sustained assault

Alongside the ransomware data, NCC Group’s analysts describe a marked escalation in attacks against the software development ecosystem during Q2, with campaigns hitting GitHub Actions, npm, PyPI, Docker Hub, Open VSX and the Visual Studio Code Marketplace. The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.

The report warns that these campaigns exploit “transitive trust” in software supply chains, turning maintainer accounts, CI/CD tokens and cloud credentials into high-value targets, with effects that can cascade well beyond the organisation initially compromised.

“A board-level issue”

Matt Hull, VP and Head of Cyber Intelligence and Response at NCC Group, said supply chain attacks remain one of the most attractive routes for threat actors to inflict significant operational, financial, and reputational damage, and that businesses need continuous, rather than ad hoc, monitoring and resilience.

“Although there has not been a material rise in ransomware volume in the last quarter,” Hull said, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. He added that organisations must treat cyber security as the board-level issue it is, pointing to geopolitical tensions and rapidly evolving AI capabilities as compounding pressures on defenders.

NCC Group’s report also examines the deepening professionalisation of ransomware operations such as The Gentlemen, a rapidly-scaling RaaS group whose leaked internal database revealed structured negotiation tactics and a dedicated suite of EDR-disabling tools distributed to affiliates. Separately, the report notes a growing convergence between commodity infostealer malware and higher-end intrusion tradecraft, with new variants adopting rootkit-style concealment, browser-extension-based credential theft, and off-host decryption to evade detection.

The full report also covers geopolitical developments, including rising China-Taiwan tensions, Belarus’s shifting posture toward Russia, and Ireland’s incoming EU Council presidency, which NCC Group assesses could shape targeting patterns for state-linked threat actors in the second half of the year.

The post Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns appeared first on IT Security Guru.

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns

A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims.

The “Cyber Threat Landscape: UK & Ireland” report, published by threat intelligence firm CYFIRMA, finds that financially motivated cybercriminals and state-aligned actors are frequently targeting the same sectors, finance, telecoms, technology, healthcare and government, and warns that cybercrime, espionage and geopolitical disruption are becoming harder to tell apart.

Russia, China, North Korea and Iran all in the mix

According to the report, Russia remains the most immediate geopolitical cyber threat to the region, with Russian-linked groups focused on critical infrastructure, undersea cables and disinformation tied to the ongoing war in Ukraine. China is flagged as the more significant long-term concern, with state-linked groups pursuing intellectual property theft and “living off the land” techniques designed to maintain quiet, persistent access inside critical networks.

The report also names several state-sponsored groups actively targeting the UK, including Russia’s APT28 (Fancy Bear) and APT29 (Cozy Bear), and China-linked APT15 and GALLIUM. It highlights a recent APT28 campaign that hijacks vulnerable home and small-office routers to redirect DNS traffic, quietly harvesting credentials and login tokens from unsuspecting users. North Korea’s Lazarus Group is also named in connection with fake job-offer lures targeting European defence and drone manufacturers, part of the long-running “Operation DreamJob” campaign.

Ransomware still dominates, with the UK bearing the brunt

Ransomware remains the most visible threat. CYFIRMA’s data shows Qilin as the most active gang targeting the region between January and May 2026, followed by DragonForce, The Gentlemen and Cl0p, with the UK absorbing the overwhelming majority of recorded victims. Ireland saw far fewer incidents, but the report notes that groups including The Gentlemen, Qilin and Interlock have all claimed Irish victims, and activity there peaked sharply in May 2026.

Professional services, manufacturing, real estate and IT emerged as the sectors hit hardest by ransomware, the report finds, with most groups now relying on double extortion, encrypting systems while also stealing data to threaten public leaks if a ransom isn’t paid.

Financially motivated crews get creative with social engineering

The report also details the tactics of financially motivated groups such as FIN6, which has been posing as job seekers on LinkedIn and Indeed to trick recruiters into opening fake résumé links laced with malware, and Scattered Spider, which continues to abuse identity and access management systems by impersonating employees to helpdesk staff in order to reset credentials or bypass multi-factor authentication.

Dark web trade in UK and Irish data continues unabated

Beyond ransomware, the report catalogues a steady stream of underground forum listings offering UK and Irish personal data for sale throughout 2026 — including an alleged 120-million-record database from a UK gambling platform, a combo list of more than 657,000 UK email-password pairs, and a dataset said to contain 734,000 UK student records. CYFIRMA says this reflects a growing emphasis among criminal groups on monetising stolen data and credentials rather than relying solely on encryption-based extortion.

Critical vulnerabilities add to the pressure

The report also flags a cluster of critical vulnerabilities disclosed during the period, including several rated 9.0 or above in the n8n workflow automation platform, Cisco’s Secure Firewall ASA and FTD software, Fortinet’s FortiOS and FortiProxy products, and VMware’s ESXi and Workstation platforms — several of which have already been linked to active exploitation.

What organisations should do

CYFIRMA’s recommendations for organisations in both countries include:

  • Accelerating patching of internet-facing systems, VPNs and edge devices, which remain the most common entry point for both ransomware crews and state-backed actors.
  • Enforcing phishing-resistant multi-factor authentication and tightening helpdesk identity-verification processes to blunt social engineering attacks like those used by Scattered Spider and FIN6.
  • Testing ransomware and DDoS response plans, including backup recoverability, given the sustained pace of attacks on critical infrastructure and public services.
  • Increasing scrutiny of third-party and vendor access, as supply chain compromise continues to be used to reach multiple organisations through a single trusted relationship.

The report’s overall message is one of convergence: as ransomware operators, spies and hacktivists increasingly pursue overlapping goals through similar tools and techniques, CYFIRMA argues that organisations can no longer treat these as separate risks to be managed in isolation.

The full research report can be found here: https://www.cyfirma.com/research/cyber-threat-landscape-uk-ireland/

The post Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns appeared first on IT Security Guru.

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have continued working with suppliers despite known resilience or security concerns.

The figures come from the Data Health Check 2026, Databarracks’ annual survey of 500 UK IT decision-makers, which has tracked IT resilience since 2008. This year’s report paints a picture of organisations that recognise the danger posed by their supply chains, but frequently feel unable to act on that knowledge.

In many cases, the research suggests, businesses simply lack viable alternatives. More than a quarter of respondents (26%) identified “dependence on suppliers” as a main barrier to improving their organisation’s resilience.

Awareness without action

The Data Health Check found that supplier assessment is now standard practice for most organisations. Almost nine in ten businesses (89%) assess supplier resilience at the point of onboarding, and the majority (61%) go further by conducting assessments annually, quarterly, or continuously.

Despite this due diligence, the risk clearly persists once a supplier relationship is underway. “Supply chain vulnerabilities” was named as one of the top three IT resilience challenges organisations expect to face over the next five years, cited by 23% of respondents – behind only AI-driven cyber threats (46%) and ransomware attacks (26%).

The data also shows a clear link between known risk and real-world impact. Organisations that knowingly continued working with risky suppliers were more than four times as likely to experience a supplier-originated cyber incident: 43% of those organisations went on to suffer an incident, compared with just 10% of organisations that had not knowingly worked with risky suppliers.

“Treat your critical suppliers like you would your own business”

Commenting on the findings, Chris Butler, Resilience Director at Databarracks, said that supply chain resilience remains one of the most persistent weaknesses in UK organisations’ defences. “This year’s findings indicate that supply chain resilience remains a critical pain point for many businesses, which the majority are aware of and which continues to be exploited by attackers. When something goes wrong at a key supplier, the cascade effects can be profound for businesses throughout the chain.”

“Despite good intentions around assessing supplier resilience, most companies don’t fully understand the depth of complexity in their supply chains. Often they’ll know who their core suppliers are, but beyond that, visibility drops away.”

“The traditional approach to assessment has long been tick-box based, with compliance questionnaires growing longer every year. This approach creates a false sense of assurance rather than real resilience.”

Butler argued that genuine improvement requires businesses to move beyond paper-based assurance and to take direct ownership of the risk that suppliers pose to their operations. “To truly manage your supply chain continuity, it’s vital to actually get visibility of the situation. Business leaders need to treat supplier resilience as part of their own resilience, not somebody else’s problem. It’s a bit of a cliché but for good reason: you really need to treat your critical suppliers like you would your own business.”

He also urged organisations to take a more collaborative approach where smaller or less mature suppliers cannot be easily replaced. “Where there isn’t a viable alternative and your existing suppliers don’t have in-house business continuity skills, offer to help. Include your suppliers in your business continuity exercises and give them the chance to rehearse with you. It’s important to practice the response to disruption together rather than in isolation. Doing this will benefit you in the long run.”

Additionally, Jamie Akhtar, CEO and Co-Founder of CyberSmart, added: “This research highlights the severe impact supply-chain attacks are having on businesses of all sizes. It is concerning that one in four businesses has experienced a cyberattack through its supply chain, but what’s even more concerning is that almost half knowingly continue to work with suppliers that have identified security weaknesses. The findings show how difficult it can be for organisations to remain secure. Businesses must manage their own security, but also the security and resilience of their supplies as well.”

“Organisations, especially SMEs, should treat suppliers as part of their own security perimeter. They should assess third-party risks before onboarding, restrict access to essential systems and data, enforce multi-factor authentication, keep software patched and maintain tested backups. Regular supplier reviews and shared incident-response plans can also reduce disruption if a partner is compromised,” Akhtar continued. 

Part of a wider resilience picture

The supply chain findings sit within a broader Data Health Check 2026 report that shows organisations bracing for a harsher resilience environment. The study found that 65% of organisations now believe a serious cyber attack could threaten their survival, while cyber remains the leading cause of IT downtime for the fourth year running, cited by 30% of organisations as their biggest cause of outages.

The report also found reasons for optimism. Business continuity planning has reached a new high, with 90% of organisations now holding a plan and four in five of those kept up to date. Ransomware resilience is also improving: although one in four organisations (25%) experienced a ransomware attack in the last 12 months, only 18% of those affected paid the ransom, while 59% recovered from backups instead.

Databarracks said the overall findings point to “integrating IT and business resilience” as the most-cited priority for organisations in 2026, reflecting a growing recognition that modern incidents – including those originating in the supply chain – rarely respect the boundaries between cyber security, IT operations, business continuity and executive decision-making.

The post 1 in 4 businesses hit by cyber attacks through their supply chain in the last year appeared first on IT Security Guru.

DigiCert expands its EMEA channel strategy with Ignition Technology

DigiCert, a global leader in intelligent trust, has announced a strategic distribution partnership with Ignition Technology to scale its presence across EMEA, accelerate market entry and expand partner-led growth.

Through the partnership, Ignition will bring DigiCert ONE® to customers and partners across the UK and Ireland, DACH, France, Benelux and the Nordics. DigiCert’s comprehensive platform unifies PKI, DNS and automated certificate lifecycle management, helping organisations establish trust across machine identities, software, devices, digital content, and AI agents, while reducing outages, strengthening compliance and supporting the transition to post quantum cryptography.

“Across EMEA, organisations are facing increasingly complex security, operational and regulatory challenges as they embrace AI, modernise infrastructure and prepare for the post quantum era,” said Sean Remnant, Chief Strategy Officer, Ignition Technology. ”They don’t need more disconnected tools. They need a platform that simplifies complexity, helps them move faster and gives them confidence they’re ready for what’s next.”

“This partnership is about creating high impact, scalable growth across EMEA,” said Paul Holt, Group Vice President, EMEA at DigiCert. ”Ignition understands how to build markets, grow partner ecosystems and execute at pace. Together, we’ll help more organisations build the confidence to embrace AI, automate trust at scale and prepare for the post quantum era.”

The partnership reinforces DigiCert’s commitment to growing its channel across EMEA, enabling partners to help organisations simplify security, strengthen resilience and prepare with confidence for the AI and post quantum era.

The post DigiCert expands its EMEA channel strategy with Ignition Technology appeared first on IT Security Guru.

95% of Security Teams Blindsided by Vulnerabilities Between Tests

The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises.

The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found that 95% had discovered high or critical vulnerabilities outside their scheduled testing windows within the past year. Of those, 42% said this had happened at least once a month, underscoring a widening gap between how quickly enterprise environments change and how infrequently they are actually tested.

Three connected gaps

Synack’s researchers point to three related problems undermining enterprise security assurance. The first is a coverage gap: 38% of respondents said at least a quarter of their critical attack surface had gone independently tested or validated for more than 90 days.

The second is what the report calls an AI trust gap. Despite growing enthusiasm for AI-assisted testing, 79% of respondents said they would not act on an AI-generated finding without a human validating it first.

The third is a maturity gap: only 15% of respondents described their security testing and validation programme as continuous, despite continuous testing being the most commonly cited method (named by 22%) for confirming whether a finding is actually exploitable.

One CISO who took part in the study summed up the operational impact: “It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.”

AI expands coverage, but humans are still needed to prove exploitability

The research suggests enterprises are keen for AI to take on a bigger role in reconnaissance, surfacing potential vulnerabilities and expanding testing coverage, but are far less willing to let it operate without human oversight. Respondents said human expertise remains essential for validating exploitability, assessing severity and business risk, testing complex workflows, cutting down false positives, and communicating risk to stakeholders.

“Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent,” said Angela Heindl-Schober, Chief Marketing Officer at Synack. “The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution.”

The study also identifies the main barriers to continuous security validation, including compliance-driven test cycles, integration complexity, a lack of trust in automated findings, false positives, difficulty demonstrating return on investment, and unclear ownership across teams.

“Automation can surface more signals, but security teams need evidence, not noise,” said Mark Kuhr, Co-Founder and Chief Technology Officer at Synack. “Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do.”

A Human + AI model for continuous validation

Synack argues the findings reinforce the case for a combined Human + AI approach to security validation. Its Sara AI Pentesting offering uses what the company calls the Synack Autonomous Red Agent to scale reconnaissance and testing, while the Synack Red Team, a vetted network of more than 1,500 security researchers, is used to validate real-world exploitability, uncover chained attack paths, and provide context that automation alone cannot supply.

Together, the company says, the two approaches are designed to help organisations move away from periodic, point-in-time security snapshots and towards continuous security validation.

The post 95% of Security Teams Blindsided by Vulnerabilities Between Tests appeared first on IT Security Guru.

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.

The partnership brings together Critical Cloud’s Managed Runtime Assurance operating model with Tarian Labs’ offensive security specialists, whose experience spans government, defence and critical national infrastructure projects.

Managed Runtime Assurance focuses on the day-to-day operation of production applications, cloud platforms and AI systems, helping organisations maintain visibility, resilience, security, operational efficiency and compliance readiness. Instead of producing a report that reflects a single point in time, security findings become part of an ongoing cycle of remediation, retesting and evidence-based validation.

The service combines Critical Cloud’s Datadog-powered managed operating model with Tarian Labs’ independent testing capabilities through an Observe, Detect, Validate methodology. Critical Cloud manages monitoring, governance and runtime operations across production environments, while Tarian Labs performs penetration testing, cloud and infrastructure assessments, web application reviews, API testing and follow-up verification. Findings move directly into remediation before independent retesting confirms they have been addressed.

The partnership preserves clear separation of responsibilities. Tarian Labs owns testing methodology, findings, severity ratings and retesting, while Critical Cloud leads remediation and operational improvements. Every engagement is delivered under customer authorisation, agreed scope, defined rules of engagement and controlled evidence management.

“Detection without validation is hope, not assurance,” said James Smith, CEO of Critical Cloud. “Today’s regulated organisations need continuous proof that production controls continue to perform as intended, particularly as technology changes at an increasingly rapid pace.”

“A penetration test should be the beginning of improvement rather than the end of the process,” said Kevin Hanford, Co-Founder and CEO of Tarian Labs. “By linking independent testing with remediation and verification, we help organisations demonstrate that security risks have been effectively resolved.”

Continuous Runtime Security Validation is now available across the UK and Ireland, with a packaged joint offering planned for a later date. Future joint activities include fintech events in Wales and a live demonstration environment that illustrates the complete Observe, Detect, Validate lifecycle, including remediation, retesting and evidence of closure.

Critical Cloud is ISO 27001 certified, holds Cyber Essentials Plus, and is recognised as a Powered by Datadog accredited partner and Datadog Advanced Partner. Tarian Labs delivers engagements through CREST registered practitioners with final sign-off at NCSC-recognised CHECK Team Leader (CSTL-INF) level.

The post New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience appeared first on IT Security Guru.

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.

The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.

“The strongest pattern in the first half of 2026 was the way different threats converged around trust,” said Luis Corrons, Security Evangelist at Gen. Scams, account takeovers, malicious packages and AI agents, he said, all moved closer to the systems, workflows and permissions people already rely on, meaning attacks increasingly succeed before a victim ever reaches an obviously suspicious moment.

Tech support and imposter scams surge

Tech support scam detections reached 20.3 million blocked attacks in H1 2026, up 61.6% on the second half of 2025. Gen said part of the rise reflects newly introduced detection coverage, but also pointed to campaigns hosted on legitimate-looking cloud infrastructure, including ondigitalocean[.]app domains and fake Windows Defender error pages hosted on Google Cloud Storage in Germany and France. Windows users accounted for 92% of blocked tech support scam attacks, and the US, France, Germany, and Japan were the most targeted countries.

Government impersonation scams rose 387% to almost 1 million blocked attacks, with 81% of that activity concentrated in the United States. Family impersonation scams, often delivered by SMS to Android users and increasingly using AI voice cloning, rose 454.2% and were concentrated in the Netherlands, France, Ireland and Germany.

E-shop scams and fake online stores became one of the highest-volume categories tracked, with 114.2 million blocked attacks, up 109% half-over-half, including one variant using .click domains that alone accounted for more than 10 million blocks. “Fake tutorial” or “scam-yourself” attacks, which trick users into manually running malicious commands via fake CAPTCHA or verification prompts, rose 193% to 5.26 million blocked attempts.

Malvertising was also a major driver of activity, representing almost 30% of detections. Gen’s separate Scam Ad Machine research, examining 14.57 million ads across the EU and UK, found that nearly one in three were scam-related, generating more than 304 million impressions in under a month.

Localised banking trojans, infostealers and crypto-clippers

Regional malware campaigns leaned heavily on local-language lures. Banking trojan operators in Czechia, Slovakia and Poland used JavaScript droppers disguised as shipping notices and invoices, in some cases sent from already-compromised corporate mailboxes. RAT campaigns in Italy, Poland and Czechia used fake invoices, steganographic loaders and multi-stage PowerShell to deploy Remcos and Babylon RAT, among others.

Gen Threat Labs also identified Remus, a new 64-bit infostealer it attributes to the Lumma Stealer family, based on shared obfuscation, string-handling, and browser credential theft techniques, including a bypass of Chrome’s Application-Bound Encryption. Separately, researchers tracked a four-stage cryptocurrency infection chain ending in a Rust-based clipboard hijacker that monitors for wallet addresses across 21 blockchain types and silently swaps in attacker-controlled addresses. The same campaign used Binance Smart Chain to resolve command-and-control infrastructure via EtherHiding, making its infrastructure harder to take down than a conventional domain.

Software supply chain and a cracked-macOS-app wave

Gen documented multiple software supply chain incidents, including compromised npm and PyPI packages, hijacked maintainer accounts, and GitHub accounts abused to push malicious commits while preserving a convincing commit history. In one case, a compromised npm publishing token was used to push an unauthorised update to the Cline CLI that installed malware referred to as OpenClaw onto developer machines during an eight-hour window.

On macOS, Gen tracked a cracked-software distribution chain that pushed users toward mirror sites, torrents, forums, and Telegram channels, blocking roughly 108,000 launch attempts for these applications within 48 hours in a single wave. The payloads included cryptominers, infostealers, and backdoors, but Gen said the more significant issue was permission abuse: installation guides frequently instructed users to disable Gatekeeper and System Integrity Protection, or to grant Full Disk Access, thereby granting broad system access to unsigned binaries.

AI agents move from chatbot risk to execution risk

A significant portion of the report focuses on AI agents, which Gen says have shifted the security conversation because they turn model output into real-world action, fetching URLs, installing packages, editing files, or calling APIs, often with a user’s own credentials and local access.

The report cites an incident in which a Meta AI security researcher granted an AI agent access to her inbox to triage messages, and the agent began deleting emails while reportedly ignoring stop commands. Gen noted that this was reported by TechCrunch and could not be independently verified as forensic evidence, but said it illustrates how a misinterpreted instruction can have real consequences once an agent holds genuine permissions.

The report also references indirect prompt injection documented in the wild by Unit 42, where hidden instructions embedded in web content are later processed by an AI system, and separate research (“Double Agents”) identifying excessive default permissions in a cloud AI agent deployment that allowed a pivot into customer project resources.

Gen discusses its own response to agent risk at length, including a runtime enforcement tool called Sage that checks agent actions, shell commands, URL fetches, file writes, package installs, before they execute, alongside an Agent Trust Hub for pre-use verification, an Agent Detection and Response (ADR) capability, and a proposed cross-industry standard, AARTS, intended to give agent hosts a shared way to expose security-relevant events and enforcement points.

The report also touches on Anthropic’s Claude Mythos and Fable 5 models, noting Anthropic’s own disclosure that Mythos Preview could identify and exploit vulnerabilities in major operating systems and browsers when directed to, and that access to Fable 5 and Mythos 5 was briefly suspended in mid-2026 following a US export-control directive before being restored. Gen frames this as evidence that, once a model can materially accelerate cyber work, questions of who can access it and under what safeguards become part of the security picture, not just the model’s behaviour.

Privacy: persistent access, not just breaches

Gen blocked an average of 310.8 million tracking attempts per month in H1 2026, around 1.9 billion over the half-year. The report highlights GhostPairing, an attack that abuses WhatsApp’s legitimate device-linking feature to trick users into approving an attacker-controlled browser as a linked device, giving the attacker an authorised session that can persist until manually revoked.

The report also raises AI agent memory as an emerging privacy boundary, citing research papers describing backdoored agents that exfiltrate stored user context via disguised tool calls, and separately flags recent FTC settlements and actions against location-data brokers Kochava and Mobilewalla for selling sensitive location data without consent.

Identity and financial fraud: exposure moves fast toward misuse

Gen recorded 18,618 breach events affecting its customers in H1 2026, up 94.5% on the prior half-year, while breach notification alerts with an identified source sent to Norton and LifeLock users rose 628.1% to 3.3 million. February alone accounted for roughly a third of all H1 breach notifications, a spike Gen links partly to the Under Armour breach reported in January 2026, which public reporting said affected around 72 million email addresses.

Downstream financial signals also rose sharply: credit inquiry alerts reached 460,000 in June; depository activity alerts rose 734%; credit activity alerts rose more than tenfold; and web skimming attacks blocked at checkout pages rose 212% to 996,300. Gen also flags a distinct pattern of first-party fraud, in which real, verified accounts, created by people recruited online with promises of quick cash, are later handed over to fraud operators for cash advance abuse, wallet funding or money mule activity, making the behaviour harder to catch at onboarding.

The takeaway

Gen’s overall conclusion is that few of the H1 2026 attacks relied on classic red flags such as poor grammar or obviously suspicious links. Instead, they were built around real reservation details, compromised-but-legitimate mailboxes, trusted update paths and permissions that users had already granted. The report argues that protection increasingly has to sit at the point where trust is granted or transferred, before a payment page, before a package installs, before an AI agent is allowed to act, rather than relying on users to spot the danger themselves.

The post Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust appeared first on IT Security Guru.

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.

The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.

A calendar as a dead drop

HOLLOWGRAPH is a lightweight implant that understands only two instructions, get and send, but carries them out entirely through trusted Microsoft cloud infrastructure rather than attacker-owned servers. Group-IB’s analysis describes the compromised mailbox’s calendar being used as a two-way dead drop: operators plant instructions by creating calendar events, and the malware exfiltrates stolen files by creating its own events with encrypted attachments.

To keep the mailbox owner from noticing anything unusual, every event created by the malware is dated far into the future, specifically 13 May 2050, with the stolen or tasking data hidden inside file attachments rather than the event body. Get requests search for events with a subject line referencing a task ID, while send operations upload encrypted data in chunks named “File{n}.txt” before renaming the event to an operator-recognisable tag.

DNS tunnelling keeps credentials fresh

Alongside the calendar-based C2 channel, HOLLOWGRAPH maintains a separate communications path used solely to refresh the Microsoft Entra ID (formerly Azure AD) credentials it needs to continue authenticating to the Graph API. Group-IB found that the malware performs DNS tunnelling, issuing IPv6 AAAA record lookups against an attacker-controlled domain, cloudlanecdn[.]com, to retrieve updated tenant IDs, client IDs, client secrets, and mailbox details, which it then writes to a configuration file on disk disguised as an ordinary log file, logAzure.txt.

According to the write-up, length-indicating queries and data-carrying queries are distinguished by naming convention, with each returned IPv6 address smuggling 14 usable bytes of payload that the malware reassembles into plaintext credential data. This DNS channel, researchers noted, is not itself encrypted.

Communications sent through the Graph API channel, by contrast, are protected with hybrid RSA and AES-256-GCM encryption, and the malware uses separate RSA key pairs for inbound tasking and outbound exfiltration, keeping the two directions cryptographically independent of one another.

Linked to the Cavern framework and possibly Lyceum

Group-IB said several technical characteristics tie HOLLOWGRAPH to the Cavern framework, including a matching command syntax and observed tasking that mirrors Cavern’s known structure, among them a “toggle debug logging” self-command used elsewhere by the framework.

The researchers stopped short of attributing the campaign to a specific, previously known threat actor, but noted overlaps with malware previously associated with Lyceum, a group considered a sub-cluster of the Iranian threat actor OilRig. Group-IB said Cavern’s modular backdoor functionality closely resembles a .NET backdoor used by Lyceum in early 2025, including shared command codes and a similar approach to loading plugin modules from disk on demand. The firm characterised this potential link as low confidence.

A small, disciplined set of victims

Group-IB said it identified at least 12 systems infected with HOLLOWGRAPH, of which only around three were actively exchanging data with the attacker at the time of analysis. The earliest observed communication between a victim and the attacker was recorded on 3 June 2026, with the most recent seen on 9 July 2026, indicating the malware has been in active use since at least early June.

Researchers said the small victim count, combined with the fact that the compromised mailbox used for exfiltration belongs to an Israeli organisation and that malware samples were uploaded for analysis from Israel, points to a deliberately narrow, targeted espionage operation rather than opportunistic mass compromise.

Why it matters

The use of legitimate cloud services for C2 is a well-established evasion tactic, but HOLLOWGRAPH’s approach of hiding both tasking and exfiltrated data inside calendar event attachments, dated decades into the future, illustrates how creatively threat actors are exploiting everyday collaboration features to slip past perimeter and email-security defences. Because the traffic runs entirely through Microsoft’s own infrastructure and a legitimately authenticated (if compromised) account, it can be difficult for defenders to distinguish from normal Microsoft 365 usage without close inspection of Graph API activity and mailbox audit logs.

Recommendations

Group-IB has urged organisations, particularly those operating in or connected to Israel, to:

  • Hunt for indicators associated with HOLLOWGRAPH and the Cavern framework, including the domain cloudlanecdn[.]com and the configuration file logAzure.txt.
  • Monitor Microsoft Graph API activity and mailbox audit logs for anomalous calendar operations performed by an application rather than a user, including event creation, attachment uploads and subject-line changes.
  • Watch for calendar artefacts consistent with the malware, such as events dated to 2050-05-13, GUID-only subjects, or subjects following the “Event ID:” or “Boss{..}ID{..}” naming patterns with “File{n}.txt” attachments.
  • Restrict, monitor and audit OAuth2 applications using client credentials, and alert on the creation of new client secrets.
  • Enforce Conditional Access policies, regular credential rotation and anomalous-token detection across Microsoft 365 and Entra ID environments.
  • Deploy DNS monitoring capable of spotting tunnelling activity, such as unusually frequent AAAA queries or long, high-entropy subdomains, and route outbound DNS through controlled, filtered resolvers.

Group-IB said it will continue to track the evolution of the Cavern framework, adding that the sophistication of HOLLOWGRAPH, combined with its narrow targeting, points to a capable and well-resourced adversary, even though the specific group behind the campaign remains unconfirmed. More information can be found here: https://www.group-ib.com/blog/hollowgraph-microsoft-365/

The post Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites appeared first on IT Security Guru.

❌