Threat intelligence stories
AI is speeding up attacks as well as defence, with high-risk prompts and unsupervised agents exposing firms to new security gaps.
Boards face rising pressure to control shadow AI as attackers automate faster and security teams shift to continuous verification.
Attackers can stay inside WhatsApp accounts after a single fake device approval, exposing messages, calls and contacts without alerts.
Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.
Boards must now treat cyber security and AI governance as core resilience issues, with Russian-linked threats exposing wider operational risks.
Rising AI workloads are forcing APAC firms to invest more in data centres, fibre and energy, while also reshaping customer service and cyber defence.
Windows fleets could be left blind to malware once attackers gain admin rights, as Bitdefender says bind links can fool endpoint security tools.
Broader coverage in Mexico and Milan aims to cut latency for mobile security checks as fake app traffic grows more sophisticated.
Nearly half of commerce traffic across Akamai's network came from AI bots by late 2025, raising fraud and DDoS risks for retailers.
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.
AI-enabled attacks are forcing Asian firms to contain breaches faster, as Singapore urges micro-segmentation and tighter lateral movement controls.
Hackers are exploiting vulnerabilities in hours or minutes, leaving many organisations compromised before defenders spot the breach.
Users relying on SMS or voice for sign-ins will be nudged to passkeys as Microsoft phases out weaker multifactor methods in Entra ID.
Security teams are being pressed to prove their defences work in live attacks, as spending scrutiny shifts from tools to real-world response.
Poor governance is leaving many AI agents stuck out of production, while those that run can expose firms to legal and security risks.
Public agencies risk ransomware within seconds as attackers exploit identities, cloud tools and virtualisation layers, Google warns.
F-Secure's Laura Kankaala explains how the Yahoo Boys scam culture has evolved from advance-fee emails into sextortion and romance fraud.
Online shoppers in New Zealand face a sharper risk of fraud as fake stores and remote access attacks exploit trusted digital services.
UK consumers and businesses could benefit as Cifas adds nearly 500 scam signals to a global network aimed at faster takedowns.
Banks are seeing attackers favour stealthy access over ransomware, with a UK-specific exploit hitting nearly half of monitored sensors.