threat actors news
6 stories
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Microsoft's Digital Defense Report 2026, released October 1, 2026, warns that artificial intelligence (AI) has dramatically accelerated portions of the cyber-attack lifecycle, compressing post-compromise activities from days to mere minutes. This rapid evolution, driven by threat actors' early adoption of AI, presents a significant challenge for cybersecurity defenders.

Malware Crypting Services Aid Threat Actors in Evading Detection
Cybersecurity researchers have identified a growing market for "crypting" services, which enable threat actors to modify malicious payloads to evade detection by antivirus (AV) and endpoint detection and response (EDR) tools. These services are becoming increasingly sophisticated, offering a range of features beyond basic encryption to complicate analysis and preserve malware usability.

Attackers Exploit Law Enforcement Coordination Gaps
A recent report indicates that cybercriminals are successfully exploiting existing coordination gaps among law enforcement agencies, allowing them to adapt their tactics and evade detection more effectively. This suggests a growing challenge for authorities in responding to the rapidly evolving landscape of cyber threats, as attackers leverage the lack of unified global or even regional responses.

Bypassing AI guardrails is so easy a script kiddie can do it
Researchers from Cisco Talos have found that bypassing the guardrails designed to prevent large language models (LLMs) from assisting with cyberattacks is often straightforward, requiring little more than specific phrasing in prompts. Their analysis of prompt logs and artifacts from threat actor endpoints using tools like Claude Code, Codex, Cursor, and Gemini indicates that current guardrails…

Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target
A threat actor utilized agentic artificial intelligence to compromise an Amazon Web Services (AWS) cloud environment within 72 hours, a task that would typically take weeks, according to a report by the security vendor Sygnia. The attack, aimed at extortion, leveraged familiar cloud infrastructure exploitation techniques but at an accelerated pace due to AI assistance.

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
A campaign dubbed "FortiBleed" has exposed administrative and VPN credentials for an estimated 73,932 FortiGate firewall systems globally. The compromised data, reportedly originating from a Russian-speaking threat group, has impacted organizations across critical sectors including government, telecommunications, financial services, healthcare, manufacturing, and multinational corporations.