Normal view

There are new articles available, click to refresh the page.
Yesterday — 21 July 2026Main stream

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the report‘s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

“In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

“Many organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

Before yesterdayMain stream

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense

10 July 2026 at 07:24

The National Cyber Security Centre (NCSC) has unveiled plans for Cyber Shield, an ambitious initiative that aims to use agentic artificial intelligence to transform the nation’s cyber defenses and counter increasingly sophisticated cyber threats. The proposal forms part of a broader effort by the NCSC and the Department for Science, Innovation and Technology (DSIT) to build a national scale, AI powered cyber defense capability that can detect, analyze, and eventually respond to attacks at machine speed.

According to the NCSC, Cyber Shield will initially focus on using AI to identify vulnerabilities and detect threats before progressing toward automated mitigation, coordinated threat intelligence sharing, and national level response capabilities. The initiative is intended to help defenders keep pace with attackers who are increasingly using artificial intelligence to accelerate reconnaissance, vulnerability discovery, and exploitation.

AI changes the cyber defense equation

Rik Ferguson, Vice President of Security Intelligence at Forescout, believes the proposal reflects the reality of today’s threat landscape.

“The NCSC’s Cyber Shield proposal feels like a logical and necessary step, especially if we view it through the lens of ‘Assume Autonomy,'” Ferguson said.

“The core assumption should no longer be that autonomous cyberattacks are a distant or speculative problem. We should assume that adversaries will increasingly use AI agents to automate reconnaissance, vulnerability discovery, exploit development, credential attacks, lateral movement, and adaptation once inside an environment.”

Ferguson said security teams operating at human speed will struggle to defend against machine speed attacks, particularly across critical infrastructure, healthcare, and government networks.

“A national scale AI cyber shield is therefore not just about adding AI to existing security workflows. It is about building defensive systems that can detect, prioritize, and help contain threats at the same tempo at which AI enabled attackers can operate.”

However, he cautioned that autonomy must be implemented carefully.

“The opportunity is strongest where AI can improve visibility, correlation, triage, exposure management, and early intervention. The risk comes when automated systems act without sufficient context, governance, or operational guardrails.”

He added that AI alone cannot solve long-standing cybersecurity problems.

“AI can help defenders move faster, but it cannot compensate for poor asset visibility, weak segmentation, unpatched systems, or unclear ownership of cyber risk.”

Governance will be critical

Shane Barney, Chief Information Security Officer at Keeper Security, also welcomed the initiative but warned that the success of Cyber Shield will depend on strong governance.

“Cyber Shield is the right instinct, and it is arriving at a genuinely dangerous moment for both organizations and the wider public,” Barney said.

“Attackers are already using AI to compress reconnaissance and exploitation into minutes, and the NCSC is correct that human speed defense cannot keep pace with machine speed offense.”

Barney argued that many successful cyberattacks still rely on basic security weaknesses.

“Most successful attacks still exploit basic, preventable failures, including outdated systems, unpatched software, and weak access controls. No amount of agentic AI changes that equation if the underlying identity and access foundations are not solid.”

He also highlighted a potential new risk created by AI itself.

“Red and blue AI agents are themselves privileged non-human identities, granted authority to scan networks, share intelligence, and eventually remediate vulnerabilities autonomously.”

According to Barney, those AI agents will require the same security controls as privileged human administrators, including least privilege access, just in time provisioning, and complete visibility into their activity.

“An AI agent with unmanaged privileged access is not a defense. It is the next incident.”

A collaborative approach

The NCSC said Cyber Shield will rely on close collaboration between government, industry, academia, and critical infrastructure operators. Trusted information sharing and explainable AI will be central to the initiative as it evolves from vulnerability discovery toward coordinated national cyber defense.

While the idea of a Cyber Shield remains a long-term vision, security leaders broadly agree that AI will play an increasingly important role in defending against AI-driven cyberattacks. The challenge now will be ensuring those capabilities are introduced with the governance, transparency, and foundational security controls needed to make them effective.

The post UK Government Unveils AI Powered Cyber Shield to Strengthen National Cyber Defense appeared first on IT Security Guru.

Q&A: Solving Synthetic Media Challenges Before All Trust is Lost

1 July 2026 at 05:14

Synthetic media has moved from technical curiosity to mainstream threat in just a few years, with deepfakes now cheap enough to produce that a free app and a handful of seconds of scraped audio can generate convincing fakes. The consequences stretch well beyond political misinformation: corporate fraud running into tens of millions of dollars, biometric security checks being bypassed, and a largely under-reported epidemic of non-consensual intimate imagery. As regulation in the EU, UK and US begins to catch up with the scale of the problem, the question facing businesses and platforms alike is no longer whether synthetic media is a risk, but how quickly they can build the means to verify what they see and hear. 

We sat down with Ruth Azar-Knupffer, Co-founder of VerifyLabs.AI, to unpack the detection arms race, the regulatory landscape now taking shape, and why she believes treating verification as infrastructure rather than a single party’s responsibility is the only way organisations will stay ahead of the threat. 

How widespread is synthetic media on social platforms today, and how has that changed in the last two or three years?  

“It has gone from curiosity to a feature of the landscape. The most widely cited figures put roughly 500,000 deepfakes shared across social platforms in 2023, with estimates of around 8 million by the end of 2025 — close to 900% growth a year. Voice is the part most people underestimate: Pindrop recorded voice deepfakes rising nearly 700% year-on-year in 2024.  

The change over two or three years is not really about volume, though. It is about access and quality. Three years ago a convincing fake took skill, time and a decent machine. Today it takes a free app and a few seconds of someone’s voice scraped off a podcast or an earnings call. And the output now clears the bar where ordinary viewers can no longer tell. Studies consistently find that most people can no longer reliably distinguish a high-quality fake video from a real one. We have crossed from ‘spot the fake’ into ‘assume nothing.’” 

As deepfake generation gets more sophisticated, how do verification technologies keep pace? Is it a winnable race?  

“It is winnable, but not in the way people want it to be. There is no finish line where deepfakes are ‘solved.’ It is an arms race in the same sense that anti-virus or spam filtering is — you win by staying operationally ahead, not by ending the contest.  

The mistake is to chase artefacts alone — the tell-tale blink, the warped ear, the audio glitch. Those tells close fast with every new model. The more durable approach is layered: detection models that look at signals humans cannot, combined with provenance — knowing where a piece of content came from and whether it has been altered since capture. Standards like C2PA and the content-labelling rules now coming through regulation push verification upstream, to the point of creation. Detection at the point of consumption will always matter, but if the only defence is catching fakes after they spread, you are permanently a step behind”. 

Beyond political misinformation, what are the most damaging real-world consequences that people might not be thinking about?  

“Politics get the headlines; the money and the harm are elsewhere.  

The corporate one is fraud. The Arup case — a finance employee in Hong Kong wired roughly $25.6 million after a video call in which every “colleague,” including the CFO, was synthetic — is the example everyone cites, and it will not hold the record for long. Deloitte projects generative-AI-enabled fraud in the US alone rising from around $12 billion in 2023 to $40 billion by 2027.  

Then there is an identity. Deepfakes are now used to defeat the biometric checks banks rely on; bypass attempts on liveness detection have jumped more than 700%.  

But the consequence people think about least is the most personal. A vast and under-reported category of malicious deepfakes is non-consensual intimate imagery, which overwhelmingly targets women and girls. The recent investigations into “nudify” tools are a glimpse of the scale. That is the human cost that rarely makes cybersecurity panel”. 

Where does the burden of detection fall — platforms, users, or third-party verifiers? Who should own this problem? 

“No single party can own it, and pretending otherwise is how it falls through the cracks.  

Platforms have to carry detection and provenance at scale, because that is where content travels and they are the only ones with the reach. Independent verifiers — and yes, that includes us — exist because nobody should be asked to mark their own homework; you need assessment that is auditable and not conflicted by who owns the content. And users need tools simple enough to actually use, plus the basic literacy to know the question is worth asking.  

Think of it as infrastructure rather than ownership. Nobody ‘owns’ road safety — you have manufacturers, regulators, and drivers, each responsible for a layer. Verification is the same. The failure mode is everyone assuming someone else has it covered”. 

Even without a specific viral incident, does the existence of the technology erode trust in authentic content?  

“Yes, and this is the part that worries me most. You do not need a single famous fake to do the damage. Once people know convincing fakes are possible, the ground shifts under everything.  

The sharper danger is the inverse of what most people picture. It is not only that false things get believed — it is that true things get dismissed. Real footage of genuine wrongdoing can now be waved away with ‘that’s a deepfake.’ Researchers call it the liar’s dividend, and it is corrosive precisely because it requires no technical skill at all. The World Economic Forum has ranked AI-amplified misinformation among the top global risks for good reason: when audio and video stop being trusted by default, a shared basis for facts starts to dissolve”. 

In a breaking-news environment where content spreads in minutes, how do you balance verification speed with the accuracy to make a call with confidence?  

“You stop pretending the answer is binary. The honest output of any serious system is a probability with evidence attached, not a stamp that says ‘fake’ or ‘real.’ 

In a fast-moving story we work in tiers. An initial automated assessment can return in seconds and is enough to flag something as warranting caution. A higher-confidence judgement — the kind you would attach your name to — takes longer and may involve human review. The skill is being explicit about which one you are giving and never letting speed inflate certainty.  

The cost of getting it wrong runs both ways. Miss a fake and it spreads; wrongly brand something authentic as synthetic and you have manufactured a different harm. In breaking news the responsible move is often a clearly labelled provisional read, openly updated, rather than a confident verdict you cannot yet support”.  

Is verification a tool for journalists and enterprises, or does it need to reach everyday users to move the needle?  

“Both, but the needle only really moves at consumer scale. Newsrooms and enterprises are the early, high-stakes adopters, and they should be. They are not where the volume of harm sits.  

Most people encounter synthetic media on a phone, in a feed, in a message from a relative — not in a verification suite. If checking authenticity is harder than sharing, sharing wins every time. That is why we built VerifyLabs to be API-first and to work across iOS, Android and the browser: the verification has to live where people already are, not in a specialist tool they will never open. A capability locked inside enterprise contracts protects institutions while leaving the public exposed. Closing that gap is the actual job”.  

What does the regulatory landscape look like, and are laws keeping up?  

“It is moving faster than people assume, though unevenly.  

The EU is setting the pace. Under the AI Act, Article 50 requires AI-generated or substantially manipulated content to be clearly disclosed and machine-detectable, with the relevant obligations landing in August 2026. Breaching those transparency duties carries fines of up to €15 million or 3% of global turnover; the headline €35 million or 7% figure people quote applies to the Act’s prohibited practices, not to synthetic-media labelling. A Code of Practice on transparency — including a proposed common ‘AI’ label for synthetic content — is being finalised alongside it.  

The UK has gone further than disclosure. Sharing non-consensual intimate deepfakes was already criminal under the Online Safety Act; since February 2026 it has also been a criminal offence to create one, or to ask someone else to, under the Data (Use and Access) Act 2025. Creation, not just distribution, now carries liability. In the US there is no single federal framework, but the Take It Down Act mandates 48-hour removal of non-consensual intimate imagery, the Defiance Act — which would give victims a federal civil right of action — has passed the Senate and is awaiting the House, and more than 45 states have their own laws.  

Are laws keeping up? On disclosure and on naming harms, increasingly yes. On enforcement, no. A duty to label synthetic content means little if neither the regulator nor the platform has a reliable way to tell what is synthetic in the first place. Rules without the means to detect and prove manipulation are obligations on paper. The legislation needs detection infrastructure underneath it, or it has no teeth”. 

What happens when legitimate content gets flagged as synthetic, and how do you think about the reputational risk of a false accusation?  

“This is the hardest problem in the field, and the one I judge our own seriousness by.  

A false positive and a false negative are not symmetric in their consequences. Miss a fake and you have failed to catch something; wrongly brand a real video as fabricated and you have actively defamed someone and handed every genuine bad actor a ready-made excuse. The second error can be more damaging than the first.  

So the discipline is to never issue a bare ‘fake’ verdict. We return a confidence assessment with the evidence behind it, set conservative thresholds, route uncertain cases to human review, and treat the right to challenge a result as part of the product, not an afterthought. Verification that cannot show its working, or that hides behind a binary label, does not deserve to be trusted — and we do not want it to be”. 

What does the threat landscape look like in five years, and what should organisations be preparing for now that most aren’t?  

“Three things are coming. Real-time, interactive deepfakes good enough to hold a live video call — the Arup attack, but on demand and at scale. Fully synthetic identities engineered to pass the KYC and biometric checks that gate finance and onboarding. And provenance becoming default infrastructure, with content signed at the point of capture, much as HTTPS quietly became standard for the web.  

What most organisations are not doing yet is treating this as an operational risk rather than an awareness topic. Concretely: build verification and provenance into the workflows that matter; mandate out-of-band confirmation for payments and sensitive instructions, so no transfer is ever authorised on the strength of a voice or a face alone; and run drills, not slideshows — a face your employee recognises asking for money behaves nothing like an awareness module.  

The uncomfortable truth is that business has always run on a simple assumption: if I can see and hear someone, I know it is them. Payments, approvals, instructions, decades of compliance — all of it rests on that. Synthetic media breaks the assumption, and not at some distant point on the horizon but in the incident reports being filed right now. The organisations that come through this are the ones that stop treating their own eyes and ears as proof, and build the means to verify in their place”. 

The post Q&A: Solving Synthetic Media Challenges Before All Trust is Lost appeared first on IT Security Guru.

❌
❌