Topic: threat landscape

  • Defenders Must Adapt Faster as Agentic AI Evolves

    Defenders Must Adapt Faster as Agentic AI Evolves

    The cybersecurity landscape is accelerating, forcing defense teams to adapt rapidly as attackers use automated methods and AI, shrinking the window for effective response. Despite increased security budgets, organizations face heavy financial losses and must address compounded damage from financi...

    Read More »
  • NCSC Urges Immediate Action to Build Cyber Resilience Amid Uncertainty

    NCSC Urges Immediate Action to Build Cyber Resilience Amid Uncertainty

    Paul Chichester, NCSC director, warns that unprecedented uncertainty from rapid technological change, geopolitical instability, and a shifting threat landscape makes cybersecurity "harder than they've ever been," urging stronger collaboration and cyber resilience. He highlights key challenges inc...

    Read More »
  • CISOs in Survival Mode: Navigating Risk Under Pressure

    CISOs in Survival Mode: Navigating Risk Under Pressure

    CISOs face an overwhelming threat environment where most believe a successful breach is inevitable, leading to a focus on rapid response amid frequent, high-impact attacks and low confidence in employee threat detection. Generative AI is a top priority as both a major security risk and a tool for...

    Read More »
  • Industrial Threat Actors Outpace OT Security Teams

    Industrial Threat Actors Outpace OT Security Teams

    Adversaries are increasingly focusing on "control-loop mapping" to understand and manipulate physical industrial processes, moving beyond simple network intrusion to enable real-world disruption. The threat landscape shows greater specialization, with distinct groups acting as initial access brok...

    Read More »
  • Insights from Top Leaders on Cybersecurity Awareness Month 2025

    Insights from Top Leaders on Cybersecurity Awareness Month 2025

    The 2025 Cybersecurity Awareness Month in Australia saw unprecedented engagement, highlighting the urgent need for action due to recent high-profile breaches and a rapidly changing threat landscape. Industry experts emphasized that cloud identity vulnerabilities and immediate attack execution req...

    Read More »
  • Cybersecurity Crisis: 2 in 3 Companies Face Staff Shortages

    Cybersecurity Crisis: 2 in 3 Companies Face Staff Shortages

    Nearly two-thirds of companies face unfilled cybersecurity positions, creating critical vulnerabilities due to slow hiring and sophisticated threats, while 55% still operate with insufficient staff. A disconnect exists between security teams and leadership, with only 56% of professionals believin...

    Read More »
  • Ivanti Neurons AI Automates IT to Cut Manual Work, Security Risks

    Ivanti Neurons AI Automates IT to Cut Manual Work, Security Risks

    Ivanti is enhancing its Neurons platform to enable autonomous IT operations, shifting from manual, reactive management to intelligent automation to handle growing security threats and workloads. A key innovation is Autonomous Patch Compliance, which automatically ensures endpoints meet regulatory...

    Read More »
  • AI Adversaries Accelerate Cyberattack Timelines

    AI Adversaries Accelerate Cyberattack Timelines

    AI and automation have dramatically accelerated cyberattack timelines, compressing the window for organizations to patch vulnerabilities from weeks to days or even minutes. Threat actors are leveraging AI to industrialize attacks, scaling reconnaissance, automating decisions, and generating convi...

    Read More »
  • Ransomware Payouts Hit Record $3.6M as Attacks Evolve

    Ransomware Payouts Hit Record $3.6M as Attacks Evolve

    The average ransom payment surged 44% to a record $3.6 million, even as the number of ransomware incidents decreased, indicating a shift toward more targeted attacks. Despite fewer attacks, 70% of victimized organizations paid ransoms, with critical sectors like healthcare and government facing a...

    Read More »
  • Why We Can't Quit Bad Authentication Habits

    Why We Can't Quit Bad Authentication Habits

    Companies rely on outdated authentication methods and face vulnerabilities from employees' poor security habits, despite better solutions being available. A significant training gap exists, with 40% of employees lacking cybersecurity training and outdated protocols leading to insecure practices. ...

    Read More »
  • Comcast SecurityEdge Preferred boosts protection for small businesses

    Comcast SecurityEdge Preferred boosts protection for small businesses

    Comcast Business launched SecurityEdge Preferred, a network-native cybersecurity solution for small businesses that activates in minutes without extra hardware, intercepting threats at the network edge. The solution addresses a severe threat landscape, with Comcast’s 2025 report showing record ac...

    Read More »
  • Cybersecurity's Triple Threat: AI, Quantum, Geopolitics

    Cybersecurity's Triple Threat: AI, Quantum, Geopolitics

    Geopolitical tensions and emerging threats are elevating cybersecurity to a top strategic priority, prompting organizations to reassess infrastructure and partnerships. Despite increased budgets and AI investments, low confidence in resilience persists due to legacy systems, reactive spending, an...

    Read More »
  • EU Cyberattacks Increasingly Target Critical Infrastructure

    EU Cyberattacks Increasingly Target Critical Infrastructure

    The ENISA Threat Landscape 2025 report reveals a significant increase in cyberattacks targeting operational technology systems, which now account for 18.2% of all documented threats, driven by their growing interconnectedness and deliberate targeting by malicious actors. Pro-Russian hacker groups...

    Read More »
  • Tycoon 2FA Phishing Platform Exposes Legacy MFA Flaws

    Tycoon 2FA Phishing Platform Exposes Legacy MFA Flaws

    The Tycoon 2FA phishing kit enables attackers to easily bypass multi-factor authentication by using automated tools and fake login portals, primarily targeting Microsoft 365 and Gmail credentials. It intercepts user credentials and session cookies in real-time while mimicking legitimate login exp...

    Read More »
  • Insider Threats: Australia's Top Cybersecurity Risk

    Insider Threats: Australia's Top Cybersecurity Risk

    Australian organisations are shifting their cybersecurity focus to insider threats, with 84% expecting an increase and 58% ranking them as a greater risk than external attackers. Many businesses are unprepared for insider threats, as only 34% use advanced detection tools like user behaviour analy...

    Read More »
  • Amazon Deploys AI Agents to Hunt Software Bugs

    Amazon Deploys AI Agents to Hunt Software Bugs

    Amazon has launched its Autonomous Threat Analysis (ATA) system to proactively identify software vulnerabilities and implement defenses before cybercriminals can exploit them, addressing security challenges in complex codebases. The system uses multiple specialized AI agents that simulate attack ...

    Read More »
  • AI malware detectors fail on unfamiliar data

    AI malware detectors fail on unfamiliar data

    A new study reveals that static AI malware detectors perform well on familiar data but struggle significantly when tested on diverse, real-world external datasets, including obfuscated and red-team threats. The research highlights a key trade-off: training models specifically on obfuscated malwar...

    Read More »
  • TA585 Hackers Unleash Advanced New Attack Tools

    TA585 Hackers Unleash Advanced New Attack Tools

    TA585 is a sophisticated cybercriminal group known for its fully autonomous infrastructure, managing its own phishing campaigns, malware deployment, and hosting platforms without relying on external services. The group primarily distributes MonsterV2, a versatile malware suite that acts as a remo...

    Read More »
  • 60,000 Redis Servers Exposed by Critical Security Flaw

    60,000 Redis Servers Exposed by Critical Security Flaw

    A critical vulnerability (CVE-2025-49844) in Redis, rated 10.0 in severity, allows attackers to gain full control over servers by exploiting a flaw in the Lua scripting engine that has existed for 13 years. Approximately 60,000 publicly accessible Redis servers with no authentication are at direc...

    Read More »
  • BarracudaONE platform updates boost cyber resilience

    BarracudaONE platform updates boost cyber resilience

    Barracuda Networks has upgraded its BarracudaONE cybersecurity platform to enhance defenses against sophisticated email, network, and generative AI threats, including extending email protection to Google Workspace and integrating AI risk controls. The company has also revamped its Partner Success...

    Read More »