#threat intelligence
39 stories taggedthreat intelligence · page 2 of 3.

AI Is Compressing the Cybersecurity Timeline. Security Teams Are Racing to Keep Up.
Artificial intelligence is speeding up both attack and defence at the same time. The organisations that survive the shift may not be the best-defended. They may simply be the fastest to act.

Before Anyone Reaches the Gate: Why Event Security Starts in the Digital World
A major concert, a championship, a political gathering: the real threats often take shape online, days or weeks before the first fan walks through the door.

GoSerpent: A New Espionage Tool Quietly Targeting Southeast Asian Governments
Kaspersky says the previously unseen malware has been hitting government and diplomatic offices across the region since late 2025, with signs pointing to long-term spying rather than smash-and-grab theft.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network
A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins all share the same quiet flaw: the copy most people read is rarely the full story.

Before the Crowds Arrive: Why Event Security Has to Start Online
From the FIFA World Cup to America's 250th birthday celebrations, the biggest gatherings of 2025 face threats that begin weeks before the first ticket is scanned — and most of those early warning signs appear on the internet, not at the gate.

VEIL#DROP: Blogger-Hosted Chain Drops PureLogs Stealer
Researchers flag a multi-stage delivery scheme abusing Google's Blogger platform to stage PureLogs, an infostealer sold in underground forums.

Harvest Now, Decrypt Later: Why Credentials Are the First Casualty of Q-Day
Captured ciphertext today becomes plaintext tomorrow. Credentials sit at the top of the target list.

ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure
Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator — and was staging for disruption, not just espionage.

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome
Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

Non-Admin macOS Accounts Can Chain Native OS Features to Blind Endpoint Security Tools
No exploit required. Researchers found that standard user privileges are enough to chain macOS weaknesses and silently kill endpoint security agents — no vulnerability needed.

Agentic AI Runs on Context. Feed It the Wrong Kind and Decisions Go Sideways Fast.
The core vulnerability in agentic AI systems isn't the model — it's the context window. Bad inputs, machine-speed outputs.

FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest
Researchers attribute the long-running operation to a financially motivated IAB, with credential lists feeding brute-force runs against exposed FortiGate appliances since February.

Five Eyes to CSOs: AI Has Already Changed Your Threat Model — Act Now
A joint advisory from CISA and four allied agencies demands strategic action on AI-amplified threats. Experts say the advice is late, vague, and misses the real risk sitting inside your own network.