#incident-response
46 stories taggedincident-response · page 2 of 4.

Your Incident Response Playbook Almost Certainly Does Not Cover AI Failures. That Is a Problem.
Seven in ten organisations have AI plugged into their core systems, yet most security teams are trying to handle AI breakdowns with tools built for a completely different kind of threat.

AI Agents Are Now Running Entire Cyberattacks, Start to Finish
Two separate investigations show that criminals are handing whole attack campaigns to artificial intelligence, cutting the time it takes to ransack a company from weeks to hours.

Japan's biggest taxi firm Nihon Kotsu hit by malware, dispatch system still down
The Tokyo-based operator pulled systems offline over the weekend after detecting unauthorized access. Bookings, phone dispatch and a service for expectant mothers remain suspended.

Your AI risk register is a list, not a plan. Here is what organisations are missing.
Documenting AI risks is the easy part. Knowing who can actually shut the system down when something goes wrong is where most programmes fall apart.

Progress tells ShareFile customers to pull the plug amid 'credible' threat
The maker of a widely used file-sharing tool is emailing on-premises customers to shut down their servers now, while it investigates what it calls a credible external threat.

When Attacks Take Minutes, Not Days: The AI Speed Problem Defenders Now Face
Criminals using AI models can now write phishing bait, pick targets and hop between machines faster than most security teams can read the first alert.

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise
Security firm Sygnia says a single attacker used artificial intelligence to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

Accenture Confirms Data Breach After Hacker Claims Source Code Was Stolen
The consulting giant says the incident is contained and caused no disruption, but a hacker has publicly claimed to have taken internal source code.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins all share the same quiet flaw: the copy most people read is rarely the full story.

The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You
A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

Chris Inglis on the Snowden Era: What NSA Got Wrong, and What CISOs Should Still Be Asking
The former NSA Deputy Director reflects on institutional failures, insider threat detection, and why 'enculturation' may matter more than access controls.

Twenty Years of Getting It Wrong: The Breaches and Blunders That Defined Modern Cybersecurity
From MGM's identity disaster to MOVEit's patch pile-up, the same failure modes keep appearing in postmortems. That's the problem.

The 2026 Vendor Survey Nobody Asked For, Except The Findings Actually Track
A survey of 1,200 practitioners says awareness is up and resilience is flat. Anyone running production already knew that.

Why SOCs Still Can't Answer 'What Happened?' — The Case for Network Detection
Alert-driven triage keeps missing context. NDR proponents argue packet truth is the only ground truth left.

Double Trouble: Two Unrelated Attacks Thrive on Unpatched SharePoint
Microsoft DART uncovers dual intrusions on same server, complicating response efforts.