top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Microsoft Says AI Will Drive More Windows Security Updates as Vulnerability Discovery Accelerates
Microsoft is warning Windows users to expect a growing number of security updates as artificial intelligence dramatically speeds up the company's ability to uncover software vulnerabilities before attackers can exploit them. In a new blog post, Microsoft said AI is fundamentally changing how software flaws are discovered by enabling security teams to analyze significantly more code in less time. Rather than waiting for vulnerabilities to surface through external researchers o
Jul 13


Underground Hacker Tutorials Are Becoming an Early Warning System for Defenders as AI Fuels a New Wave of Cybercrime
Threat intelligence teams have long monitored ransomware groups, malware marketplaces, and dark web chatter for signs of emerging cyber threats. A new report from Radware suggests security teams may be overlooking another valuable source of intelligence: the underground tutorials where cybercriminals teach one another how to attack organizations. After analyzing nearly 9,000 tutorial posts published across 24 deep and dark web forums over more than three years, Radware resear
Jul 13


KDDI Cyberattack Exposes 12 Million Email Addresses and 7.6 Million Passwords in Japan ISP Breach
A cyberattack on an email platform operated by Japanese telecom giant KDDI exposed more than 12.2 million customer email addresses and 7.6 million passwords, marking one of the larger recent credential exposure incidents tied to shared internet service provider infrastructure in Japan. KDDI said the breach affected an email system it runs for five Japanese internet service providers. The platform supports customer email account management, webmail access and email storage. Th
Jul 7


China-Linked Hackers Target University Physics Departments in Roundcube Espionage Campaign
A previously unknown espionage group believed to be operating on behalf of China is targeting physics and engineering departments at universities in the United States and Canada, with a particular focus on research tied to national security, astrophysics, and particle physics. Security researchers at Proofpoint are tracking the activity as UNK_MassTraction. The group is exploiting a chain of vulnerabilities in Roundcube, a widely used open-source webmail platform, to steal cr
Jul 7


CrySome RAT Campaign Turns a Fake Freight Document Into a Full Remote Access Breach
A logistics-themed phishing campaign recently pushed the CrySome remote access trojan through a multi-stage Windows infection chain, showing how attackers are blending believable business lures, native system tools, open-source security-disabling utilities, and modular malware to gain persistent control of victim machines. Researchers with LevelBlue’s SpiderLabs said the incident began with a targeted spear-phishing email disguised as a freight rate confirmation. The message
Jul 6


AI Agent Carries Out Ransomware Attack in Possible Cybercrime First
A ransomware operation tracked as JadePuffer may be one of the clearest signs yet that autonomous AI agents are moving from theory into real-world cybercrime. According to cloud security firm Sysdig, JadePuffer used a large language model agent to conduct much of the ransomware attack chain on its own, including reconnaissance, credential theft, lateral movement, persistence, privilege escalation, and data encryption. The most important part was not that the attack used new t
Jul 6
bottom of page