Security analysis about the systems, assumptions and control failures that make consequential attacks possible. The path matters as much as the payload. H...
In 1994, Congress passed a law requiring U.S. telecommunications carriers to build a door for court-authorized surveillance. Thirty years later, an APT called Salt Typhoon walked through it. Among the data Salt Typhoon extracted from major U.S. carrier networks was information associated with lawful intercept requests — information that could reveal the identities of individuals under…
Last week’s JadePuffer attack chain breakdown documented what happens when a sophisticated ransomware actor deploys an AI agent as a decision-making orchestrator across an end-to-end intrusion. bandcampro is at the opposite end of the spectrum: a solo operator using jailbroken Google Gemini CLI AI tools as a co-worker for building attacks. In July 2026, TrendAI Research published “Six Minutes to…
In late June 2026, an AI agent appears to have executed the active phases of a ransomware operation — from reconnaissance through data destruction — with human involvement limited to only a few steps after setup. The Sysdig Threat Research Team traced the intrusion under the name JadePuffer: initial access through an unpatched Langflow server, a pivot to a separate production database, a forged…
Before the ransom demand lands in a target's inbox, the attacker has read their cyber insurance policy and used it to calibrate the number listed in the note. They've pulled the company's annual revenue from a sales intelligence database to establish their ceiling. They're working from a negotiation script they've run before, possibly with legal counsel available on demand. By the time the target…
By mid-March, 2026, a campaign began that would eventually hit hundreds of organizations per day across the United States, Australia, Canada, France, and more than a dozen other countries. Targets received attachments — PDFs, HTML files, spreadsheets — that looked like things they had good reason to open: investment decks, cash flow analyses, DocuSign signing requests, and meeting invitations.…
In April 2026, a software consultancy in the U.K. disclosed a breach. The leadership's public statement was the standard genre of corporate-ese: only “typical business data,” they said. Contracts, NDAs, contact information, nothing that should keep a client up at night. Behind the scenes, however, a ransomware operator going by zeta88 was drafting a very different account of what he'd taken —…
Another AI coding tool has now patched an MCP configuration-to-execution flaw. A pattern is emerging, and it's getting harder to dismiss as isolated vendor mistakes. This week, Amazon patched a flaw in Amazon Q Developer that let a malicious workspace execute commands after a developer opened it and marked it trusted. Four months earlier, the same boundary problem surfaced in three other AI coding…
A single dormant credential at one mid-market software vendor exposed the CRM and customer engagement data of dozens of organizations. The door was opened via a competitive-intelligence platform all the victims used — that platform held OAuth tokens connecting it to each of their environments. The incident happened because of the standing, delegated access that every modern SaaS integration…
In late 2025, a DragonForce affiliate operated for one to two months inside a major U.S. services firm. During the intrusion, the attackers deployed Backdoor.Turn, a custom Go-based RAT that Symantec says routed command-and-control traffic through the relay servers Microsoft Teams uses to carry calls. Every outbound connection the defenders could see went to legitimate Microsoft infrastructure,…
Consider two vulnerabilities. The first scores 9.8 on the CVSS scale — technically critical, but sitting on an internal system, never touched by a public exploit, with no evidence of active use in the wild. The second scores 7.2 — medium-high, the kind of thing that might not make the top of your queue. Except it's being actively weaponized right now, on an internet-facing asset, by attackers who…