#threat intelligence
54 stories taggedthreat intelligence · page 3 of 4.

Dysphoria Botnet Rebuilds on Blockchain After March Takedown
Researchers at CNCERT and XLab say the IoT botnet now hides its control servers behind blockchain domains and routes traffic through infected devices, making shutdowns harder.

Weekly Threat Recap: A Rogue AI Agent, Old Bugs Back at Work, and Exposed Systems Nobody Fixed
OpenAI reports an AI agent that stepped outside its lane, while attackers keep finding shelter in tools defenders already trust.

Can You Still Patch Your Way to Safety? Why the Old Playbook Is Breaking Down
Artificial intelligence can now turn a published vulnerability description into a working attack faster than most IT teams run their patch cycles. That changes the math for every organisation still relying on traditional schedules.

Most AI Models Fail New Malware-Investigation Test Inspired by Nuclear Sabotage
A benchmark built around a real industrial-attack case shows that today's leading AI systems can't follow a malware investigation all the way to a conclusion.

AI-Written Apps Are Shipping With Hundreds of Security Holes, Study Finds
A new analysis counted 434 exploitable flaws across apps built with AI coding tools, raising hard questions about who checks the work when the developer is a machine.

AI Is Compressing the Cybersecurity Timeline. Security Teams Are Racing to Keep Up.
Artificial intelligence is speeding up both attack and defence at the same time. The organisations that survive the shift may not be the best-defended. They may simply be the fastest to act.

Before Anyone Reaches the Gate: Why Event Security Starts in the Digital World
The real threats to a major concert, championship or political gathering often take shape online, days or weeks before the first fan walks through the door.

GoSerpent: A New Espionage Tool Quietly Targeting Southeast Asian Governments
Kaspersky says the previously unseen malware has been hitting government and diplomatic offices across the region since late 2025, with signs pointing to long-term spying rather than smash-and-grab theft.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network
A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins share the same quiet flaw: the copy most people read is rarely the full story.

Before the Crowds Arrive: Why Event Security Has to Start Online
From the FIFA World Cup to America's 250th birthday celebrations, the biggest gatherings of 2025 face threats that begin weeks before the first ticket is scanned, and most of those early warning signs appear on the internet, not at the gate.

VEIL#DROP: Blogger-Hosted Chain Drops PureLogs Stealer
Securonix flags a multi-stage delivery scheme abusing Google's Blogger platform to stage PureLogs, a commodity infostealer sold in underground forums.

Harvest Now, Decrypt Later: Why Credentials Are the First Casualty of Q-Day
Captured ciphertext today becomes plaintext tomorrow. Credentials sit at the top of the target list.

ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure
Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator and was staging for disruption, not just espionage.