LIVE · cybersecurity feed
Live wire
Cisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
ai

Should you care about an “AI slowdown?”

In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

zeroday.news ·

Discussions surrounding a potential "AI slowdown" are unlikely to significantly impact cybersecurity, according to a recent analysis. While ethical, geopolitical, and safety concerns regarding AI are valid, current AI models are already highly effective for both offensive and defensive cybersecurity tasks, with newer models offering only incremental improvements. Many organizations are struggling to effectively utilize existing AI capabilities for defense, and attackers are already leveraging AI to uncover vulnerabilities and streamline operations.

The primary reason an AI slowdown would have limited cybersecurity impact is the advanced state of current models. These models are proficient enough to identify numerous vulnerabilities by analyzing decades of accumulated technical debt. Instead of focusing on further model improvements, the cybersecurity community could benefit more from developing better agentic harnesses and frameworks to enhance the utility of existing AI.

Furthermore, many organizations still neglect fundamental cybersecurity practices, often referred to as "cyber-vegetables." These foundational elements, such as comprehensive asset and role inventories, robust identity management, least privilege access, and segmented networks, are crucial for effective security. Without these basics, even sophisticated AI tools will struggle to prevent compromises and breaches. While AI offers significant potential, it should complement, not replace, these essential security measures.

Recent trends in ransomware highlight the sophisticated use of AI by attackers. In the first half of 2026, Japan saw a nearly 5 percent increase in ransomware incidents, driven by groups like "The Gentlemen" and "Qilin." The Gentlemen, a rapidly expanding ransomware-as-a-service operation, utilizes legitimate red-teaming frameworks such as AdaptixC2 to evade detection during lateral movement. Qilin, on the other hand, is leveraging generative AI to create destructive scripts, accelerating attack speed and lowering the barrier to entry for its double-extortion tactics, primarily targeting small and medium-sized enterprises.

To counter these evolving threats, organizations are advised to strictly manage internet-accessible devices and secure credentials. This includes auditing VPNs, disabling unused features, and enforcing multi-factor authentication (MFA) for all administrative and third-party accounts. Robust endpoint detection is also critical to monitor for suspicious remote access attempts or efforts to disable backups.

Beyond AI, other significant cybersecurity developments include a new Android banking malware campaign in Indonesia that exploits Google's Work Profile feature to bypass security controls. Apple recently addressed approximately 200 vulnerabilities with its iOS 27 and macOS Golden Gate 27 releases, with about half affecting both mobile and desktop platforms across over 90 components, including AppleKeyStore, WebKit, and Sandbox. Additionally, "ClickFix" attacks are tricking Mac and Windows users into self-hacking through compromised social media accounts, such as a fake HBO Max ad posted on Reddit. A new, previously undocumented Windows enterprise hacking platform called VectraRAT is also available for a monthly subscription, featuring a custom-built implant, command-and-control infrastructure, and operator panel.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page. The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Cre

security

[Virtual Event] Cybersecurity Outlook 2027

malware

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

Beware the SparroWocky, my son! The backdoor that bites…

patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UA

patch

Windows 11 24H2 Home and Pro reach end of support in October

Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]

malware

Chosen Brick, Iran’s Surveillance Malware

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]