Threat intelligence stories
The recognition comes as firms scramble to secure software pipelines, open-source code and AI assets against rising supply chain attacks.
Security teams could get faster threat triage and richer alert context as Proofpoint folds GPT-5.5 into managed workflows, not customer access.
ESET says the gang's operator-backed toolkit could help affiliates bypass defences faster, widening the threat to businesses worldwide.
Victims risk losing the newest and most active data first as a Go-based encryptor targets recently modified files before older ones.
More than half of countries surveyed now say cybercrime makes up 30 per cent of recorded offences, as phishing and ransomware spread fast.
Healthcare providers face a new malware route as Varist's engine scans DICOM, HL7 and FHIR files for hidden threats in imaging systems.
The acquisitions deepen Accenture's push into industrial cyber defence as it targets power grids, pipelines and data centres.
A near-decade of undetected access raises fresh concern after investigators found the group had hidden in a disconnected network since 2016.
Public release of the Mini Shai-Hulud code means copycat attacks can now hit developers, CI/CD systems and open-source supply chains.
The new system aims to curb fraud as AI-driven traffic surges and online security teams struggle to tell legitimate agents from attackers.
Security teams could cut wasted remediation work as the update helps separate blocked exposures from those attackers can still exploit.
A single phishing email can now compromise identities, bypass multifactor authentication and hit endpoints within five minutes, Barracuda said.
BlueVoyant says a ClickFix malware campaign using fake browser updates is linked to the Rapid Brigantine ransomware ecosystem.
AWS customers will gain broader visibility into AI and cloud risks as CrowdStrike adds new monitoring, trials and private connectivity.
The free check could help security teams uncover overlooked Java runtimes before AI-driven attackers exploit known flaws and outdated versions.
The new server lets security teams feed Claude and Codex with case history and triage logic, reducing manual alert handling.
The strain's self-checking code and file-wiping routine could make recovery harder for victims while giving investigators a rare attribution clue.
Only two of 13 vendors reached comprehensive maturity as browser security becomes central to Australian organisations' cyber defences.
Security teams face a heavier patching burden next year, with disclosure volumes now tracking far above FIRST's earlier estimate.
It aims to help critical infrastructure operators keep sensitive security data and AI models inside UK-controlled systems during cyber incidents.