#AIcyberattacks
AI-Assisted Hacking Campaign Exposes Security Risks Across 14 Companies #aiagents #AIcyberattacks #AIHacking
AI-Assisted Hacking Campaign Exposes Security Risks Across 14 Companies
Cyberattacks have been made more effective and more accessible due to artificial intelligence, but a recent investigation has demonstrated just how far that accessibility can extend. According to OALABS cybersecurity researchers, an attacker with limited technical expertise compromised at least 14 organizations using Anthropic's Claude Code and OpenAI's Codex to obtain sensitive information.  Upon obtaining the attacker’s entire working directory from a compromised third-party server, researchers began investigating. The directory contains more than 1,000 sessions involving the two AI coding agents, including prompts, tool activity, and other evidence of the attacker’s activities. As indicated by the logs, the attacker frequently drew short, vague, poorly written prompts, while the artificial intelligence agents handled the vast majority of the technical tasks.  The investigation of exposed services, identification of potential vulnerabilities, development and testing of exploit code, establishment of access, and data collection were conducted using Claude Code and Codex. According to OALABS, the case demonstrates a growing concern for cybersecurity teams: sophisticated technical knowledge is no longer necessary to complete each stage of an intrusion when autonomous artificial intelligence coding agents can fill crucial gaps in the capabilities of an inexperienced operator.  AI Guardrails Failed Under Simple Deception A number of requests were not accepted without resistance by the AI systems According to the logs, nine requests were flagged as policy violations by Claude Code, while a warning was raised by Codex. However, the attacker managed to circumvent the limitations by framing the requests as part of an authorized red-team exercise.  When malicious activity was presented as legitimate security testing, the attacker was able to persuade the models to complete tasks that would otherwise raise stronger safeguards. Once the attacker provided Claude with a list of target addresses, he instructed him to conduct reconnaissance. After conducting most of the work normally required by skilled security operators, the agent handled them. The AI enabled the organisation of the results by analysing exposed services, researching known vulnerabilities, developing exploit code, and retrieving files from compromised systems. The AI also provided an analysis of the results for a number of victims by providing reports describing the compromised systems and the information obtained. In another meeting, Claude was requested by the attacker to evaluate the victims based on their potential to pay a ransom. The model then presented possible methods of monetizing the stolen access.  Poor Operational Security Exposed the Attacker Even though the attacker successfully compromised several organizations, he failed to demonstrate sufficient sophistication in protecting his own identity. The infrastructure used for the operation was not owned by him, but rather, a compromised server provided the AI tools. This decision ultimately led to the discovery of the intrusion and the recovery of the working directory by the server's owner.  A second feature of the attacker's Claude installation was that he obtained it from another developer rather than setting it up himself. The recovered logs contained a conversation during which the attacker requested Claude to improve his own resume. The document reportedly contained his real name, educational background, and LinkedIn information. A preliminary investigation suggested that these details may have been deliberately planted; however, further examination indicated they were the property of the attacker.  Claude was also able to provide clues about his location by examining the logs. Claude was asked to identify connections to the attacker's staging server at one point, since he suspected it had been compromised. Information included residential internet addresses associated with Addis Ababa, Ethiopia.  Millions in Cryptocurrency Remained Out of Reach There was also an opportunity to get close to a potentially significant cryptocurrency target. One compromised system contained a Lightning Network node for Bitcoin payment routing, which researchers determined contained approximately 69.71 bitcoins worth approximately $4 million when the investigation was conducted.  A wallet key file containing the funds could not be accessed by the attacker, preventing access to the cryptocurrency. The investigation also shows no clear evidence that the stolen information from these other organizations was sold or used for extortion. As a result, it provides more evidence regarding the attacker's access and activity than any financial gain.  The Risk Extends Beyond One Attacker This incident is noteworthy not because the attacker displayed advanced hacking skills, but rather because artificial intelligence agents performed most of the technical work on his behalf. Additionally, the models involved were not among the newest versions available at the time.  OALABS examined activity involving Claude Opus 4.5 and GPT-5.2, demonstrating that the problem is not restricted to one type of cutting-edge technology. By strengthening security controls, AI systems may be less susceptible to assisting malicious activity. However, tighter controls will also present a challenge to legitimate security researchers who use similar tools to identify and test vulnerabilities. The results of OALABS indicate that AI developers are faced with a challenging balance between preventing malicious use and making AI coding agents ineffective for legitimate security purposes.  Additionally, the case illustrates the difficulty of maintaining that balance when an inexperienced operator turns simple instructions into largely automated intrusion procedures. In light of the increasing security challenges associated with autonomous AI coding agents, stronger safeguards are needed to distinguish legitimate security research from malicious activity, as illustrated by this incident.
dlvr.it
August 24, 2026 at 4:05 PM
AI-Driven Cyberattacks Surge Globally as Stolen Credentials Flood the Dark Web: Fortinet Report #AIcyberattacks #CyberAttacks #Fortinetthreatreport
AI-Driven Cyberattacks Surge Globally as Stolen Credentials Flood the Dark Web: Fortinet Report
  Artificial intelligence is accelerating the scale and sophistication of cyberattacks, according to Fortinet’s latest 2025 Global Threat Landscape Report. The cybersecurity firm observed a significant 16.7% rise in automated scanning activity compared to last year, with a staggering 36,000 scans occurring every second worldwide. The report emphasizes that attackers are increasingly "shifting left" — targeting vulnerable digital entry points such as Remote Desktop Protocol (RDP), Internet of Things (IoT) devices, and Session Initiation Protocols (SIP) earlier in the attack cycle. Infostealer malware remains a major concern, with a dramatic 500% increase in compromised system logs now available online. This translates to over 1.7 billion stolen credentials circulating on the dark web. The report warns, “this flood of stolen data has led to a sharp increase in targeted cyberattacks against businesses and individuals.” Cybercriminals are actively exploiting this data, leading to a 42% jump in credentials listed for sale on underground forums. Interestingly, zero-day vulnerabilities only make up a minor portion of the current threat landscape. Instead, attackers are leveraging “living off the land” tactics — exploiting built-in system tools and overlooked weaknesses — to stay hidden and avoid detection. The ransomware ecosystem is also evolving. New groups are emerging while established ones strengthen their presence. In 2024, Ransomhub led the charts, accounting for 13% of ransomware victims. It was followed closely by LockBit 3.0 (12%), Play (8%), and Medusa (4%). A majority of these ransomware incidents targeted U.S.-based entities, which experienced 61% of the reported cases. The United Kingdom and Canada followed with 6% and 5% respectively, suggesting a disproportionate focus on American organizations. “Our 2025 Global Threat Landscape Report makes it clear: cybercriminals are scaling faster than ever, using AI and automation to gain the upper hand,” stated Derek Manky, Chief Security Strategist and Global Vice President of Threat Intelligence at FortiGuard Labs. He added, “Defenders must abandon outdated security playbooks and transition to proactive, intelligence-driven strategies that incorporate AI, zero trust architectures, and continuous threat exposure management.”
dlvr.it
June 10, 2025 at 4:34 PM
>Create a secret word or phrase that is known to your family and contacts so that this can be used for identification purposes in the case of a true emergency call
>Never share sensitive information with people you have met only online or over the phone
#AIcyberattacks
www.forbes.com/sites/daveyw...
FBI Warns Smartphone Users—Hang Up And Create A Secret Word Now
The FBI has issued a public warning for smartphone users to hang up immediately and create a secret word as new AI cyber attacks hit—here’s what you need to know and do.
www.forbes.com
December 6, 2024 at 3:10 AM
📢 AI Ransomware Attacks 2026 — How Malware Hacks You Automatically

AI ransomware attacks 2026 are fully automated — from phishing to encryption.

https://securityelites.com/ai-ransomware-attacks-2026/

#adaptivemalware #aicyberattacks
April 23, 2026 at 4:18 AM
AI-Driven Cyberattacks and Global Cybersecurity Shortages Raise Fears of an AI Bugocalypse #AIcyberattacks #AIcybersecurity #AIRisks
AI-Driven Cyberattacks and Global Cybersecurity Shortages Raise Fears of an AI Bugocalypse
 Artificial intelligence is rapidly transforming cyber warfare, with experts warning the world may already be entering an “AI bugocalypse.” Modern AI systems can identify hidden software flaws and weaponize them within hours — sometimes before vulnerabilities are even publicly disclosed.  At the same time, a growing shortage of cybersecurity professionals is leaving governments, businesses, hospitals, and critical infrastructure increasingly exposed. Concerns intensified after Anthropic introduced Mythos Preview, an advanced AI model reportedly capable of finding thousands of vulnerabilities across major operating systems and web browsers.  While about 40 organizations received early access to strengthen their defenses, most governments and smaller institutions remain without similar protection. Security researchers warn this imbalance is becoming dangerous. Wealthier organizations can patch systems quickly using advanced AI tools, while smaller entities struggle to keep pace. Because global digital infrastructure is tightly connected, a single weak point can trigger disruptions across banks, utilities, supply chains, and government systems.  AI-powered attacks are accelerating worldwide. CrowdStrike reported an 89% rise in AI-enabled cyber incidents during 2025. Criminal groups now use AI to create phishing emails, deepfake audio, fake videos, malware, and automated attack programs. Even inexperienced attackers can launch complex cyber operations using publicly available AI platforms. Attack timelines have also collapsed dramatically.  In 2018, organizations often had years between a vulnerability becoming known and hackers exploiting it. By 2024, that window had fallen to only a few hours, with some attacks occurring before official disclosures were even released. Experts say AI tools can now reverse-engineer software patches almost instantly, identify what flaw developers fixed, and generate working exploit code within minutes.  Once created, those attacks can spread globally before many organizations even install the update. Critical infrastructure is increasingly at risk as well. Hospitals, schools, public agencies, power systems, and water networks have all become targets. Cyberattacks linked to Iran recently disrupted organizations across the Middle East, while fraud networks in Southeast Asia reportedly used AI tools to steal massive sums from victims in Europe and the United States.  Meanwhile, the global shortage of cybersecurity professionals continues to grow, especially across heavily targeted Asia-Pacific regions. Experts warn companies can no longer rely solely on patching vulnerabilities after attacks begin. Instead, organizations must prepare for breaches in advance through stronger defenses, backups, response plans, and resilient system design.  Even AI developers acknowledge no single company can solve the crisis alone. Researchers, governments, software firms, and cybersecurity teams worldwide will need deeper cooperation as AI-driven threats continue evolving. Specialists increasingly argue that cybersecurity must be treated as an essential global priority rather than a luxury available only to organizations with major resources.
dlvr.it
May 16, 2026 at 1:56 AM
Windows 11 Faces Rising Threats from AI Malware and Critical Security Flaws #AIcyberattacks #AIMalware #AItechnology
Windows 11 Faces Rising Threats from AI Malware and Critical Security Flaws
 Pressure on Windows 11 security grows - driven by emerging AI-powered malware alongside unpatched flaws threatening companies and everyday users alike. The pace of change in digital threats becomes clearer through recent incidents, especially within large organizational networks. DeepLoad sits at the heart of recent cybersecurity worries. This particular threat skips typical download tactics altogether.  Instead of dropping files, it operates without any - earning its "fileless" label. Users themselves become part of the breach process. By following deceptive prompts, they run benign-looking instructions in system utilities such as Command Prompt. Once executed, those inputs quietly trigger malicious activity behind the scenes. Since nothing gets written to disk, standard virus scanners often miss what's happening.  Detection becomes difficult when there’s no file footprint to flag. After running, the malware stays active by embedding itself into system processes while reaching out to remote servers through standard Windows tools. Because it targets confidential information like passwords, its presence poses serious risks inside business environments. What makes it harder to detect is how it blends malicious activity with normal operating routines. Security teams may overlook it during routine checks due to this camouflage technique.  Artificial intelligence makes existing threats more dangerous. Because AI-driven malware adjusts on the fly, it slips past standard detection systems. As a result, security tools struggle to keep up. With each change the malware makes, response times shrink. The gap between finding a flaw and facing an attack grows narrower by the hour. Meanwhile, security patches have been rolled out by Microsoft to fix numerous high-risk weaknesses.  Affected are various business-focused builds of Windows 11 - both recent iterations and extended support variants. One major concern involves defects within the Routing and Remote Access Service (RRAS), where exploitation might let threat actors run harmful software from a distance. Full administrative access to compromised machines becomes possible through these gaps. Not just isolated systems feel the impact.  That last Patch Tuesday, Microsoft fixed over eighty security gaps in its programs - problems hiding even inside tools such as Excel and Outlook. Opening an attachment wasn’t needed; sometimes, just looking at it could activate harmful code, showing how dangerous these weaknesses really are. Experts warn that even emerging AI tools, such as Microsoft Copilot, could introduce new risks if not properly secured, particularly when sensitive data is handled automatically.  Though companies face the most attacks, regular individuals can still be affected. When new patches arrive, it helps to apply them without delay - timing often matters more than assumed. Opening unknown scripts carries risk; many breaches begin there. Unexpected requests, especially those demanding immediate steps, deserve extra skepticism.  Change is shaping a new kind of digital danger - cleverer, slyer, built to exploit how people act just as much as system flaws. One moment it mimics trust; the next, it slips through unnoticed.
dlvr.it
April 11, 2026 at 2:41 PM
Network Detection and Response Defends Against AI Powered Cyber Attacks #AIcyberattacks #AIRisks #AItechnology
Network Detection and Response Defends Against AI Powered Cyber Attacks
 Cybersecurity teams are facing growing pressure as attackers increasingly adopt artificial intelligence to accelerate, scale, and conceal malicious activity. Modern threat actors are no longer limited to static malware or simple intrusion techniques. Instead, AI-powered campaigns are using adaptive methods that blend into legitimate system behavior, making detection significantly more difficult and forcing defenders to rethink traditional security strategies.  Threat intelligence research from major technology firms indicates that offensive uses of AI are expanding rapidly. Security teams have observed AI tools capable of bypassing established safeguards, automatically generating malicious scripts, and evading detection mechanisms with minimal human involvement. In some cases, AI-driven orchestration has been used to coordinate multiple malware components, allowing attackers to conduct reconnaissance, identify vulnerabilities, move laterally through networks, and extract sensitive data at machine speed. These automated operations can unfold faster than manual security workflows can reasonably respond.  What distinguishes these attacks from earlier generations is not the underlying techniques, but the scale and efficiency at which they can be executed. Credential abuse, for example, is not new, but AI enables attackers to harvest and exploit credentials across large environments with only minimal input. Research published in mid-2025 highlighted dozens of ways autonomous AI agents could be deployed against enterprise systems, effectively expanding the attack surface beyond conventional trust boundaries and security assumptions.  This evolving threat landscape has reinforced the relevance of zero trust principles, which assume no user, device, or connection should be trusted by default. However, zero trust alone is not sufficient. Security operations teams must also be able to detect abnormal behavior regardless of where it originates, especially as AI-driven attacks increasingly rely on legitimate tools and system processes to hide in plain sight.  As a result, organizations are placing renewed emphasis on network detection and response technologies. Unlike legacy defenses that depend heavily on known signatures or manual investigation, modern NDR platforms continuously analyze network traffic to identify suspicious patterns and anomalous behavior in real time. This visibility allows security teams to spot rapid reconnaissance activity, unusual data movement, or unexpected protocol usage that may signal AI-assisted attacks.  NDR systems also help security teams understand broader trends across enterprise and cloud environments. By comparing current activity against historical baselines, these tools can highlight deviations that would otherwise go unnoticed, such as sudden changes in encrypted traffic levels or new outbound connections from systems that rarely communicate externally. Capturing and storing this data enables deeper forensic analysis and supports long-term threat hunting.  Crucially, NDR platforms use automation and behavioral analysis to classify activity as benign, suspicious, or malicious, reducing alert fatigue for security analysts. Even when traffic is encrypted, network-level context can reveal patterns consistent with abuse. As attackers increasingly rely on AI to mask their movements, the ability to rapidly triage and respond becomes essential.   By delivering comprehensive network visibility and faster response capabilities, NDR solutions help organizations reduce risk, limit the impact of breaches, and prepare for a future where AI-driven threats continue to evolve.
dlvr.it
December 22, 2025 at 4:51 PM
AI Browsers Raise Privacy and Security Risks as Prompt Injection Attacks Grow #AIBrowserSecurity #AIBrowsers #AIcyberattacks
AI Browsers Raise Privacy and Security Risks as Prompt Injection Attacks Grow
 A new wave of competition is stirring in the browser market as companies like OpenAI, Perplexity, and The Browser Company aggressively push to redefine how humans interact with the web. Rather than merely displaying pages, these AI browsers will be engineered to reason, take action independently, and execute tasks on behalf of end users. At least four such products, including ChatGPT's Atlas, Perplexity's Comet, and The Browser Company's Dia, represent a transition reminiscent of the early browser wars, when Netscape and Internet Explorer battled to compete for a role in the shaping of the future of the Internet.  Whereas the other browsers rely on search results and manual navigation, an AI browser is designed to understand natural language instructions and perform multi-step actions. For instance, a user can ask an AI browser to find a restaurant nearby, compare options, and make a reservation without the user opening the booking page themselves. In this context, the browser has to process both user instructions and the content of each of the webpages it accesses, intertwining decision-making with automation.  But this capability also creates a serious security risk that's inherent in the way large language models work. AI systems cannot be sure whether a command comes from a trusted user or comes with general text on an untrusted web page. Malicious actors may now inject malicious instructions within webpages, which can include uses of invisible text, HTML comments, and image-based prompts. Unbeknownst to them, that might get processed by an AI browser along with the user's original request-a type of attack now called prompt injection.  The consequence of such attacks could be dire, since AI browsers are designed to gain access to sensitive data in order to function effectively. Many ask for permission to emails, calendars, contacts, payment information, and browsing histories. If compromised, those very integrations become conduits for data exfiltration. Security researchers have shown just how prompt injections can trick AI browsers into forwarding emails, extracting stored credentials, making unauthorized purchases, or downloading malware without explicit user interaction. One such neat proof-of-concept was that of Perplexity's Comet browser, wherein the researchers had embedded command instructions in a Reddit comment, hidden behind a spoiler tag. When the browser arrived and was asked to summarise the page, it obediently followed the buried commands and tried to scrape email data. The user did nothing more than request a summary; passive interactions indeed are enough to get someone compromised.  More recently, researchers detailed a method called HashJack, which abuses the way web browsers process URL fragments. Everything that appears after the “#” in a URL never actually makes it to the server of a given website and is only accessible to the browser. An attacker can embed nefarious commands in this fragment, and AI-powered browsers may read and act upon it without the hosting site detecting such commands. Researchers have already demonstrated that this method can make AI browsers show the wrong information, such as incorrect dosages of medication on well-known medical websites. Though vendors are experimenting with mitigations, such as reinforcement learning to detect suspicious prompts or restricting access during logged-out browsing sessions, these remain imperfect.  The flexibility that makes AI browsers useful also makes them vulnerable. As the technology is still in development, it shows great convenience, but the security risks raise questions of whether fully trustworthy AI browsing is an unsolved problem.
dlvr.it
December 13, 2025 at 3:33 PM
AI-Assisted Cyberattacks Signal a Shift in Modern Threat Strategies and Defense Models #AIcyberattacks #AIcybersecurity #AItechnology
AI-Assisted Cyberattacks Signal a Shift in Modern Threat Strategies and Defense Models
 A new wave of cyberattacks is using large language models as an offensive tool, according to recent reporting from Anthropic and Oligo Security. Both groups said hackers used jailbroken LLMs-some capable of writing code and conducting autonomous reasoning-to conduct real-world attack campaigns. While the development is alarming, cybersecurity researchers had already anticipated such advancements.  Earlier this year, a group at Cornell University published research predicting that cybercriminals would eventually use AI to automate hacking at scale. The evolution is consistent with a recurring theme in technology history: Tools designed for productivity or innovation inevitably become dual-use. Any number of examples-from drones to commercial aircraft to even Alfred Nobel's invention of dynamite-demonstrate how innovation often carries unintended consequences.  The biggest implication of it all in cybersecurity is that LLMs today finally allow attackers to scale and personalize their operations simultaneously. In the past, cybercriminals were mostly forced to choose between highly targeted efforts that required manual work or broad, indiscriminate attacks with limited sophistication.  Generative AI removes this trade-off, allowing attackers to run tailored campaigns against many targets at once, all with minimal input. In Anthropic's reported case, attackers initially provided instructions on ways to bypass its model safeguards, after which the LLM autonomously generated malicious output and conducted attacks against dozens of organizations. Similarly, Oligo Security's findings document a botnet powered by AI-generated code, first exploiting an AI infrastructure tool called Ray and then extending its activity by mining cryptocurrency and scanning for new targets.  Traditional defenses, including risk-based prioritization models, may become less effective within this new threat landscape. These models depend upon the assumption that attackers will strategically select targets based upon value and feasibility. Automation collapses the cost of producing custom attacks such that attackers are no longer forced to prioritize. That shift erases one of the few natural advantages defenders had.  Complicating matters further, defenders must weigh operational impact when making decisions about whether to implement a security fix. In many environments, a mitigation that disrupts legitimate activity poses its own risk and may be deferred, leaving exploitable weaknesses in place. Despite this shift, experts believe AI can also play a crucial role in defense. The future could be tied to automated mitigations capable of assessing risks and applying fixes dynamically, rather than relying on human intervention. In some cases, AI might decide that restrictions should narrowly apply to certain users; in other cases, it may recommend immediate enforcement across the board. While the attackers have momentum today, cybersecurity experts believe the same automation that today enables large-scale attacks could strengthen defenses if it is deployed strategically.
dlvr.it
December 7, 2025 at 3:07 PM
Cybercriminals Speed Up Tactics as AI-Driven Attacks, Ransomware Alliances, and Rapid Exploitation Reshape Threat Landscape #AIcyberattacks #CyberSecurity #CybersecurityThreats
Cybercriminals Speed Up Tactics as AI-Driven Attacks, Ransomware Alliances, and Rapid Exploitation Reshape Threat Landscape
  Cybercriminals are rapidly advancing their attack methods, strengthening partnerships, and harnessing artificial intelligence to gain an edge over defenders, according to new threat intelligence. Rapid7’s latest quarterly findings paint a picture of a threat environment that is evolving at high speed, with attackers leaning on fileless ransomware, instant exploitation of vulnerabilities, and AI-enabled phishing operations. While newly exploited vulnerabilities fell by 21% compared to the previous quarter, threat actors are increasingly turning to long-standing unpatched flaws—some over a decade old. These outdated weaknesses remain potent entry points, reflected in widespread attacks targeting Microsoft SharePoint and Cisco ASA/FTD devices via recently revealed critical bugs. The report also notes a shrinking window between public disclosure of vulnerabilities and active exploitation, leaving organisations with less time to respond. "The moment a vulnerability is disclosed, it becomes a bullet in the attacker's arsenal," said Christiaan Beek, Senior Director of Threat Intelligence and Analytics, Rapid7."Attackers are no longer waiting. Instead, they're weaponising vulnerabilities in real time and turning every disclosure into an opportunity for exploitation. Organisations must now assume that exploitation begins the moment a vulnerability is made public and act accordingly," said Beek. The number of active ransomware groups surged from 65 to 88 this quarter. Rapid7’s analysis shows increasing consolidation among these syndicates, with groups pooling infrastructure, blending tactics, and even coordinating public messaging to increase their reach. Prominent operators such as Qilin, SafePay, and WorldLeaks adopted fileless techniques, launched extensive data-leak operations, and introduced affiliate services such as ransom negotiation assistance. Sectors including business services, healthcare, and manufacturing were among the most frequently targeted. "Ransomware has evolved significantly beyond its early days to become a calculated strategy that destabilises industries," said Raj Samani, Chief Scientist, Rapid7."In addition, the groups themselves are operating like shadow corporations. They merge infrastructure, tactics, and PR strategies to project dominance and erode trust faster than ever," said Samani. Generative AI continues to lower the barrier for cybercriminals, enabling them to automate and scale phishing and malware development. The report points to malware families such as LAMEHUG, which now have advanced adaptive features, allowing them to issue new commands on the fly and evade standard detection tools. AI is making it easier for inexperienced attackers to craft realistic, large-volume phishing campaigns, creating new obstacles for security teams already struggling to keep pace with modern threats. State-linked actors from Russia, China, and Iran are also evolving, shifting from straightforward espionage to intricate hybrid operations that blend intelligence collection with disruptive actions. Many of these campaigns focus on infiltrating supply chains and compromising identity systems, employing stealthy tactics to maintain long-term access and avoid detection. Overall, Rapid7’s quarterly analysis emphasises the urgent need for organisations to modernise their security strategies to counter the speed, coordination, and technological sophistication of today’s attackers.
dlvr.it
November 24, 2025 at 4:14 PM
India Most Targeted by Malware as AI Drives Surge in Ransomware and Phishing Attacks #acronis #AIcyberattacks #AItechnology
India Most Targeted by Malware as AI Drives Surge in Ransomware and Phishing Attacks
 India has become the world’s most-targeted nation for malware, according to the latest report by cybersecurity firm Acronis, which highlights how artificial intelligence is fueling a sharp increase in ransomware and phishing activity. The findings come from the company’s biannual threat landscape analysis, compiled by the Acronis Threat Research Unit (TRU) and its global network of sensors tracking over one million Windows endpoints between January and June 2025.  The report indicates that India accounted for 12.4 percent of all monitored attacks, placing it ahead of every other nation. Analysts attribute this trend to the rising sophistication of AI-powered cyberattacks, particularly phishing campaigns and impersonation attempts that are increasingly difficult to detect. With Windows systems still dominating business environments compared to macOS or Linux, the operating system remained the primary target for threat actors.  Ransomware continues to be the most damaging threat to medium and large businesses worldwide, with newer criminal groups adopting AI to automate attacks and enhance efficiency. Phishing was found to be a leading driver of compromise, making up 25 percent of all detected threats and over 52 percent of those aimed at managed service providers, marking a 22 percent increase compared to the first half of 2024.  Commenting on the findings, Rajesh Chhabra, General Manager for India and South Asia at Acronis, noted that India’s rapidly expanding digital economy has widened its attack surface significantly. He emphasized that as attackers leverage AI to scale operations, Indian enterprises—especially those in manufacturing and infrastructure—must prioritize AI-ready cybersecurity frameworks. He further explained that organizations need to move away from reactive security approaches and embrace behavior-driven models that can anticipate and adapt to evolving threats.  The report also points to collaboration platforms as a growing entry point for attackers. Phishing attempts on services like Microsoft Teams and Slack spiked dramatically, rising from nine percent to 30.5 percent in the first half of 2025. Similarly, advanced email-based threats such as spoofed messages and payload-less attacks increased from nine percent to 24.5 percent, underscoring the urgent requirement for adaptive defenses.  Acronis recommends that businesses adopt a multi-layered protection strategy to counter these risks. This includes deploying behavior-based threat detection systems, conducting regular audits of third-party applications, enhancing cloud and email security solutions, and reinforcing employee awareness through continuous training on social engineering and phishing tactics.  The findings make clear that India’s digital growth is running parallel to escalating cyber risks. As artificial intelligence accelerates the capabilities of malicious actors, enterprises will need to proactively invest in advanced defenses to safeguard critical systems and sensitive data.
dlvr.it
August 31, 2025 at 4:40 PM
This is not a crypto episode. It is a conversation about where cyber risk is headed and what people who have already lived through its hardest version have learned along the way.

Full episode at these spots:

YouTube - youtu.be/wfIst7aUwvA?...

Spotify - open.spotify.com/episode/7GGa...
AI Cyber Attacks: Why Compliance Is Not Security #AICyberAttacks
YouTube video by Cyber Insurance News
youtu.be
June 11, 2026 at 3:46 PM
Microsoft warns that hackers are supercharging cyberattacks with AI, using it to scale phishing, malware, and fraud faster. jpmellojr.blogspot.com/2026/03/hack... #Microsoft #AI #AICyberattacks #AIsecurity
Hackers Use AI to Supercharge Cyberattacks, Microsoft Warns
New research from Microsoft warns organizations that threat actors have begun integrating artificial intelligence (AI) into their workflow...
jpmellojr.blogspot.com
March 11, 2026 at 3:23 PM