Topic: attack automation

  • ShutterGap: 3.7M AWS Resources Exposed Outside CSPM/CNAPP View

    ShutterGap: 3.7M AWS Resources Exposed Outside CSPM/CNAPP View

    Over 3.7 million short-lived AWS resources with sensitive data are publicly exposed each year, often lasting only minutes or hours,too brief for traditional cloud security tools (CSPM and CNAPP) to detect but long enough for attackers to exploit. This security gap is worsening due to AI-driven at...

    Read More »
  • Five Eyes warns frontier AI cyber threats loom within months

    Five Eyes warns frontier AI cyber threats loom within months

    The Five Eyes intelligence alliance warns that frontier AI models will dramatically escalate offensive cyber capabilities within months, not years, requiring immediate defensive action. The warning emphasizes that AI will industrialize the exploitation of common vulnerabilities like legacy system...

    Read More »
  • Keepnet adds voice and SMS phishing data to 2026 Verizon DBIR

    Keepnet adds voice and SMS phishing data to 2026 Verizon DBIR

    Keepnet's voice and SMS phishing data was included in the 2026 Verizon DBIR for the first time, revealing a 40% higher median click rate for phone-based phishing (2%) compared to email-based simulations (1.4%). Attackers have shifted to synchronous voice and SMS attacks using AI voice cloning and...

    Read More »
  • Burp Suite Professional 2023: Key Updates & Features

    Burp Suite Professional 2023: Key Updates & Features

    Burp Suite Professional 2023 features an improved scanning engine that delivers faster, more reliable detection of complex vulnerabilities while reducing false positives. The update enhances session handling and authentication support for testing applications with intricate login flows, and boost...

    Read More »
  • GhostLock Tool Exploits Windows API to Block File Access

    GhostLock Tool Exploits Windows API to Block File Access

    A security researcher released GhostLock, a proof-of-concept tool that exploits the Windows CreateFileW API by setting `dwShareMode = 0` to gain exclusive file access, blocking other users and applications from opening files stored locally or on SMB network shares. The attack, which can be run by...

    Read More »
  • Beyond Document Fraud: The Rising Threat of Signal Manipulation

    Beyond Document Fraud: The Rising Threat of Signal Manipulation

    Identity verification is shifting from physical document checks to automated systems that assess a stream of digital behavioral and contextual signals, like biometrics and device data, to build a confidence score rather than provide absolute proof. This automated, signal-based approach creates ne...

    Read More »
  • AI Slashes Attacker Breakout Time to 4 Minutes

    AI Slashes Attacker Breakout Time to 4 Minutes

    AI is dramatically accelerating cyberattacks, with threat actors using automation to reduce the average breakout time to just 34 minutes, enabling lateral movement in as little as four minutes. Attackers are using AI to enhance reconnaissance and social engineering, while defenders struggle due t...

    Read More »
  • AI Browsers: The Looming Cybersecurity Threat

    AI Browsers: The Looming Cybersecurity Threat

    The rapid integration of AI into web browsers introduces serious cybersecurity vulnerabilities, including data breaches and privacy invasions, as these tools collect and retain more personal data than traditional browsers. Security researchers have identified flaws in early AI browsers, such as p...

    Read More »
  • DigiCert Unveils First RADAR Threat Intelligence Brief

    DigiCert Unveils First RADAR Threat Intelligence Brief

    DigiCert's inaugural RADAR Threat Intelligence Brief reveals an unprecedented escalation in DDoS attacks, with two incidents reaching peaks of 2.4 and 3.7 terabits per second, signaling a shift where internet infrastructure becomes both weapon and battleground. The report identifies key trends in...

    Read More »