❌

Reading view

There are new articles available, click to refresh the page.

Forescout Expands Global Investment in Channel Partners

Forescout has expanded its investment in its global partner ecosystem to strengthen technical expertise and help partners support customers managing increasingly complex IT, OT, IoT, and IoMT environments.

Nearly 100% of Forescout’s customer business is transacted through partners, making the channel a central part of the cybersecurity company’s growth strategy. Its latest investment includes the ongoing Mission: Possible enablement roadshow and the continued support of several partners in its Envision Partner Program.

Mission:Possible reaches partners worldwide

Launched in May, Mission:Possible represents the largest investment in channel engagement in Forescout’s history.

The programme is targeting 90 cities across more than 40 countries, with content available in 22 languages. More than 1,300 people have attended events so far, with Forescout expecting to engage over 2,000 partner professionals by the end of September.

Through technical education, hands-on discussions and local engagement, the programme is designed to give partners the expertise needed to help customers address emerging risks, including those associated with frontier AI and complex cyber-physical environments.

Partners advance through Envision programme

Forescout has also recognised several organisations that have reached new levels within its Envision Partner Program.

TIC Defense has advanced from Authorised Training Partner to Silver Reseller, while Trace3, Upstart Cyber and Sidif have moved from Silver to Gold Reseller status.

NTT Australia, Hitachi Sunway Information Systems Malaysia, DOR Information Technologies Israel and Computacenter Germany have all progressed from Gold to Platinum Reseller.

David Creed, Vice President of Worldwide Channel Sales at Forescout, said the company is continuing to raise expectations around technical capability, certifications, customer success and business performance.

β€œWe’re proud to recognise these partners who have demonstrated exceptional commitment to customer success, technical excellence, partner enablement, and business growth while helping organisations meaningfully reduce cyber risk across converged IT, OT, IoT and IoMT environments,” he said.

Milo Sanchez, Senior Practice Director at Trace3, said Forescout’s technical investment and collaborative approach had helped the company better support its clients and grow the partnership.

Channel expertise becomes increasingly important

Forescout said partners are playing a growing role in helping organisations improve visibility and respond to threats across connected environments.

According to the company, organisations using its technology have reported discovering 50% more unknown IoT devices and reducing median breach containment time by 98.7%. The average time required to identify unknown, unmanaged and unauthorised assets has also fallen from 41 hours to six minutes.

The company’s channel programme has also received industry recognition, with the Envision Partner Program included in CRN’s Partner Program Guide and Forescout executives recognised in CRN’s Channel Chiefs and Channel Leaders EMEA lists.

The post Forescout Expands Global Investment in Channel Partners appeared first on IT Security Guru.

Forescout Research Tests Whether AI Can Create PLC Attacks

New research from Forescout’s Vedere Labs has demonstrated how artificial intelligence could begin to lower the barriers to developing sophisticated cyberattacks against industrial systems.

The research set out to answer a potentially important question for operational technology (OT) security: can AI successfully adapt a remote code execution (RCE) exploit developed for one programmable logic controller (PLC) so that it works against another?

Researchers tested this by using AI to help port an existing RCE exploit between two WAGO PLC models. The experiment was ultimately successful, demonstrating that AI can assist with highly specialised exploit development in embedded environments.

However, the results also showed that AI is not yet capable of doing this independently.

AI still needed significant human help

Throughout the experiment, researchers had to guide the AI through false leads, incorrect assumptions and technical dead ends.

Developing the final exploit took eight hours and 32 minutes and consumed $535.74 in API tokens, highlighting the cost and human involvement still required.

Once reliable code execution had been achieved, however, the process accelerated considerably. AI was able to produce multiple working network payloads within minutes.

This difference is important. While AI may still struggle with the most complex stages of exploit development, it could rapidly automate subsequent stages once the initial technical barriers have been overcome.

The experiment also demonstrated the risks of allowing AI to operate against physical technology. When researchers attempted to develop a command-and-control implant, the PLC was permanently bricked.

What happens as AI improves?

The findings raise wider questions about the future security of industrial and critical infrastructure.

PLC exploitation requires specialist knowledge of hardware, firmware, architectures and industrial protocols, creating a relatively high technical barrier for attackers. AI could gradually begin to reduce that barrier.

As models become more capable, the time, expertise and cost required to adapt an existing exploit across families of related industrial devices could fall significantly.

That could also change how organisations assess vulnerabilities. A weakness considered difficult or expensive to exploit today may become considerably more accessible as AI-assisted offensive capabilities improve.

For critical infrastructure operators, the bigger question is therefore not whether AI can autonomously develop sophisticated PLC attacks today. Forescout’s experiment shows that it cannot yet do so reliably.

Instead, organisations need to consider what happens when increasingly autonomous exploit development meets large numbers of exposed industrial devices and the technical barriers protecting them begin to disappear.

Read the full Forescout Vedere Labs research here.Β 

The post Forescout Research Tests Whether AI Can Create PLC Attacks appeared first on IT Security Guru.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the reportβ€˜s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

β€œAI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

β€œIn observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

β€œAs attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

β€œMany organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards

New research from Forescout has uncovered a sophisticated phishing campaign that uses fake seasonal eCard invitations to trick victims into installing legitimate remote management software, giving attackers long-term access to compromised devices.

The campaign, dubbed SeasonalInvite by Forescout Research’s Vedere Labs, has been active since at least January 2026 and demonstrates how cybercriminals are increasingly combining social engineering, trusted enterprise software, and AI assisted development techniques to evade traditional security defences.

The full research is available here: SeasonalInvite research

Fake eCards lure victims

According to the report, the attackers use phishing emails disguised as seasonal eCard invitations to persuade users to install legitimate Remote Monitoring and Management (RMM) tools.

Rather than deploying traditional malware, the campaign abuses commercially available software that is commonly used by IT administrators for remote support. Once installed, the tools provide attackers with persistent remote access to compromised systems.

The campaign targets both Windows and macOS users.

During its investigation, Forescout confirmed the abuse of four legitimate RMM platforms:

  • ConnectWise ScreenConnect
  • LogMeIn Resolve
  • Kaseya
  • O&O Syspectr

Because these applications are widely trusted within enterprise environments, they are less likely to trigger traditional security controls.

Hundreds of phishing domains identified

Researchers identified a large infrastructure supporting the campaign, including 959 domains themed around electronic greeting cards.

The attackers also operated a sophisticated Traffic Distribution System (TDS) consisting of 2,658 gate pages. The infrastructure was designed to direct legitimate victims to phishing websites while preventing automated security scanners from detecting malicious content.

According to Forescout, this approach makes the campaign significantly harder for security researchers and automated detection systems to identify.

Evidence points to AI generated phishing pages

One of the report’s most notable findings is evidence suggesting the phishing kit itself was created with the assistance of artificial intelligence.

Researchers found indicators that the phishing pages contained AI generated code, leading them to believe the threat actor used a large language model to build delivery pages and quickly adapt the campaign over time.

The findings reflect a growing trend of cybercriminals using AI to accelerate phishing operations, reduce development time, and rapidly generate convincing attack infrastructure.

Trusted software becomes the attack vector

Forescout said SeasonalInvite demonstrates how attackers are shifting away from custom malware in favour of abusing legitimate enterprise tools that organisations already trust.

By combining social engineering with legitimate remote management software and AI assisted development, threat actors can bypass many traditional endpoint security controls while maintaining long-term access to victim devices.

The researchers warn that organisations should not rely solely on malware detection to identify these attacks. Instead, they recommend monitoring for the unauthorised installation and use of remote management tools, strengthening phishing awareness training, and implementing controls that can detect suspicious behaviour rather than simply malicious files.

As attackers continue to refine their techniques, campaigns like SeasonalInvite highlight how trusted software and artificial intelligence are becoming powerful tools in the modern cybercriminal’s arsenal.

The post Forescout Uncovers AI Assisted Phishing Campaign Using Fake eCards appeared first on IT Security Guru.

❌