#CybersecurityResearch
New Class of AI-Powered Malware Discovered

University of Toronto researchers identified a novel type of cyberthreat that uses easily accessible AI models to increase hacking power and reach.

#Malware #AIHacking #CybersecurityResearch
June 6, 2026 at 2:55 AM
Our #cybersecurity research group TEN18 by Exabeam conducted controlled tests on AI agents. The agents went rogue, signaling that organizations shouldn't let employees use them unchecked. Learn what our #CISO had to say: ow.ly/aoFX50WPQKz #AgenticAI #CybersecurityResearch #SecurityTrends
September 2, 2025 at 7:33 PM
Big news in #CybersecurityResearch! 🛡️ #McGill Professors Benjamin Fung & Steven Ding are part of a team recently awarded with a $5.6M #NSERC Alliance-CSE grant, to propel Canada to the forefront of Cybersecurity Data Analytics research 🇨🇦 www.mcgill.ca/research/cha...
School of Information Studies Professors Awarded $5.6M Grant to Propel Canada to the Forefront of Cybersecurity Data Analytics Research
Professor Benjamin Fung, Canada Research Chair in Data Mining for Cybersecurity, and Professor Steven Ding, both of the School of Information Studies in the Faculty of Arts, are part of a team that ha...
www.mcgill.ca
July 9, 2025 at 8:35 PM
Your Company's Phishing Tests Are Measuring the Wrong Thing #CredentialTheft #cybersecurityresearch #financialservices
Your Company's Phishing Tests Are Measuring the Wrong Thing
  When a phishing simulation returns a low click rate, security teams tend to relax. Leadership checks a compliance box. The program gets renewed. But a major new study suggests that sense of relief may be completely misplaced. Oslo-based cybersecurity firm Pistachio released its Phishing Behaviour Report 2026 this week, built from 2.47 million simulated phishing attacks sent to more than 123,000 employees across 1,200-plus organizations between June 2025 and May 2026. The finding that runs through all of it: the click rate, which most phishing programs live and die by, is the wrong thing to measure. "A low click rate can create a false sense of security," said Joe Jones, CEO and co-founder of Pistachio. "What matters more is what happens next: does the employee hand over credentials, recognize the attack and stop, or report it so the wider business can act?" A click alone does nothing. Credentials do. Clicking a phishing link causes no damage on its own. The actual risk begins when an employee submits a password or other sensitive information into a fake login page after clicking. That is the moment a simulated test becomes a real-world breach scenario, and it is largely what most phishing programs do not track. On their very first simulated phishing exercise, more employees in the Pistachio study reported the suspicious email than clicked it. That sounds like good news. The problem is that 1.57% handed over their credentials anyway. In a company with 500 employees, that works out to roughly eight people who will submit login details to a convincing enough lure with zero prior exposure. Click rate metrics would not flag any of them. Tech workers are not the safe bet they are assumed to be One of the more uncomfortable findings in the report concerns employees who are expected to know better. Tech development workers clicked at least one simulated phishing attempt at a rate of 30.27%. IT workers were not far behind at 28.53%. The assumption that technical employees carry lower phishing risk because they understand how attacks work does not hold up against the data. Understanding how phishing operates and catching a convincing one under inbox pressure are two different things. Construction carries the most risk. Financial services carry the least. The gap between industries was wider than most organization-wide risk scores would suggest. Construction workers showed the highest click rate of any department at 41.31% and the highest credential leak rate at 16.47%. Design workers, by contrast, clicked at just 26.35%. Financial services employees topped every resilience category in the study, which carries some irony. Financial services accounted for 27.7% of all observed phishing attempts in 2025, making it one of the most targeted sectors on the internet. That sustained pressure, combined with strict regulatory requirements and mandatory security training, appears to have produced genuinely more vigilant employees at the individual level. Health workers showed the lowest reporting rate of any department at 13.17%, despite a relatively low click rate. Logistics workers combined an above-average click rate with a below-average reporting rate of 17.11%. In both cases, the click rate alone would present a more reassuring picture than the full data supports. Things get worse before they get better Organizations running 12-month programs saw click rates and credential submission rates both rise through the first six months before declining. That initial rise reflects harder and more frequent testing rather than employees regressing. At the six-month mark, employees were receiving an average of 3.5 simulations per person, with 50.4% classified as hard difficulty. From that six-month peak to the 12-month stage, clicks declined by 27% and credential leaks by 41%. The report-to-click ratio increased from 1.3 at three months to 1.8 at 12 months, indicating that suspicious messages were reported nearly twice as often as they were clicked by the end of the program.  Organizations that run a single phishing simulation and judge the program from that result are drawing conclusions from the noisiest and least reliable moment in the entire training cycle. What to track instead The report does not argue that click rates should be dropped entirely. It argues they should sit alongside credential submission rates and reporting rates, which together give a far more accurate picture of actual resilience. Making it easy for employees to report suspicious emails, through one-click tools and fast confirmation, converts the workforce into an active detection channel rather than a passive one. NIST research found that 72% of organizations use phishing simulation click rates to gauge training effectiveness. By that measure, nearly three quarters of corporate security awareness programs are optimizing for an incomplete signal, in a threat environment where AI-driven phishing has pushed click rates among untrained employees to a record high of 54% in 2026.  The click rate was never the whole story. At this point, relying on it alone is a liability.
dlvr.it
September 14, 2026 at 4:21 PM
DoppelCart Fake-Shop Network Found Operating Across 119,000 Domains #CyberSecurity #cybersecurityresearch #Domain
DoppelCart Fake-Shop Network Found Operating Across 119,000 Domains
 A newly published investigation has uncovered what may be the largest documented fake-shop network to date, spanning roughly 119,000 domains and dubbed "DoppelCart" by researchers at nebty. The cluster's .shop domains alone account for 2.72 percent of the entire .shop domain population captured in a September 2026 snapshot — roughly one in every 37 domains registered under that extension.  The investigation, led by Benedikt Scheungraber and published September 7, began not as a large-scale probe but as routine work handling individual customer complaints. Researchers found fake shops targeting several clients and arranged for their removal, but noticed the same infrastructure patterns recurring across unrelated takedowns and monitoring cases. Using publicly accessible website scans from urlscan, the team began connecting domains and quickly realized the scale far exceeded a handful of isolated scam sites — eventually tracing around 119,000 associated domains back to a single technical foundation dressed up as countless different brand identities.  To put the discovery in context, researchers compared it to other publicly documented fake-shop networks. BogusBazaar, reported by SRLabs in 2024, spanned more than 75,000 domains over several years, with about 22,500 active at any one time. FraudWear, documented by CTM360 in 2026, involved over 30,000 domains with roughly 8,000 simultaneously active. Malwarebytes identified a cluster of more than 20,000 domains in March 2026, while Netcraft's Fibergrid investigation found 16,700 active fake shops on connected hosting infrastructure in April 2026.  DoppelCart's scale surpasses all of these prior cases. What makes the fake shops convincing, according to the investigation, is their use of genuine material lifted from real businesses. Examined storefronts featured product descriptions copied word for word from legitimate online stores, including detailed explanations of product features and construction. In some cases, the fake sites even embedded images directly from the legitimate brand's own image servers, pairing authentic-looking product photos with advertised discounts of 65 percent to create a convincing illusion of a genuine sale.  The fallout lands squarely on the copied businesses. Because many fake shops list the legitimate store's real support address, customers who never receive their orders end up contacting the authentic company, forcing its support staff to untangle orders they never placed or received payment for — all while trust in the real brand suffers.  To help affected companies respond, the researchers are publishing the full investigation database, allowing businesses to search for their own brand name or domain and review classifications and evidence for each entry. Journalists and security researchers can request the underlying raw data, including archived HTML pages, by contacting the team directly. While takedowns pursued so far have kept removed stores offline, the majority of the DoppelCart cluster reportedly remains active.
dlvr.it
September 9, 2026 at 3:16 PM
AI and Human Collaboration Uncover New Cybersecurity Vulnerabilities

🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️

#aisecurity #cybersecurityresearch

View full AI summary:
AI and Human Collaboration Uncover New Cybersecurity Vulnerabilities
Security researcher James Kettle's research at the Black Hat conference reveals that while agentic AI has advanced cybersecurity capabilities, it remains limited in creating novel hacking methods autonomously. His experiments with AI models demonstrated that human guidance is critical for developing new attack strategies. Kettle discovered a previously unknown vulnerability called Shared-Parser Confusion, which exploits how web servers use shared code to process both requests and responses. This finding highlights the synergy between AI's analytical power and human expertise in identifying complex security flaws. Although AI generated numerous potential vulnerabilities, only human evaluation confirmed their validity. The research underscores that while AI can accelerate cybersecurity efforts, it cannot replace human insight entirely. Kettle's work emphasizes the importance of understanding AI's limitations and the necessity of human oversight in both defensive and offensive hacking strategies.
en.killbait.com
August 6, 2026 at 7:57 AM
Bitdefender Uncovers Windows Bind Link Technique That Evades EDR Detection #Bindfltsys #Bitdefender #cybersecurityresearch
Bitdefender Uncovers Windows Bind Link Technique That Evades EDR Detection
  Researchers at Bitdefender have discovered a new technique for hiding malware from Endpoint Detection and Response (EDR) solutions by utilizing bind links, a valid Windows feature. Despite Microsoft's classification of this issue as low severity due to the fact that administrator privileges are required, Bitdefender maintains that the attack technique poses a significant risk since attackers frequently obtain elevated access during actual intrusions.  The Bind Link feature is a valid kernel-level functionality that can be used by components such as Windows Sandboxes, Microsoft Store apps, and Windows containers to redirect virtual paths to actual system locations. As Bitdefender reports, attackers can manipulate these links so that trusted Windows paths point to malicious files instead of legitimate ones, enabling malware to execute while appearing harmless to security applications. The issue affects Windows 10 RS4 and later versions, including Windows 11, meaning that most modern enterprise Windows systems may be vulnerable if attackers gain local administrator privileges. As a result, Bitdefender reports that this technique is particularly relevant as ransomware groups often seek elevated permissions before deploying malicious software or disabling security controls, making it particularly effective.  Several attack methods were identified by researchers that abuse bind links. The first, file-binding, redirects trusted Dynamic Link Libraries (DLLs) paths to malicious DLLs, thus allowing attackers to bypass security mechanisms such as the Antimalware Scan Interface (AMSI). Second, process-binding tricks EDR solutions into inspecting trusted executables while a malicious file is actually being executed.  By using Windows silos to create isolated filesystem views, silo-binding is the most advanced technique. Using this technique, malware is permitted to run within the silo while external security tools will only view clean, legitimate files. By disguising Invoke-Mimikatz as a trusted Windows system process, Bitdefender successfully bypassed an EDR solution by demonstrating the technique in practice.  In addition to bypassing built-in Windows security measures such as AppLocker, Windows Firewall, and Sysmon, researchers observed that bind-link abuse was an effective post-compromise evasion technique. A legitimate Windows capability is exploited by bind-link abuse, unlike traditional "EDR killer" techniques which often rely upon vulnerable drivers.  Instead of creating a permanent file on disk, the malicious redirection occurs only in memory via the Windows' bindflt.sys minifilter driver. Although Microsoft acknowledged these findings, they rated the issue as low severity since it requires local administrator privileges to exploit it. A ransomware group and advanced threat actor routinely obtain elevated privileges after compromising a computer system, according to Bitdefender, who disagreed with that assessment.  Using bind-link abuse is similar to the increasingly common Bring Your Own Vulnerable Driver (BYOVD) approach, as attackers are able to evade endpoint protection similarly, but utilizing legitimate Windows functionality rather than vulnerable drivers for evasion. To detect path manipulation, endpoint security products should repeatedly verify the underlying file during execution to detect path manipulation.  In addition, Bitdefender recommended that security vendors refrain from solely using trusted file paths when validating processes. Moreover, the researchers noted that Windows 24H2 offers protection against certain bind-link scenarios, although they described the safeguard as only a partial one. The findings of Bitdefender have been shared with Microsoft and the company has recommended strengthening monitoring of administrator-level activity and kernel-level filesystem changes.  In spite of the low severity of the issue, researchers report that attackers are increasingly utilizing legitimate Windows features rather than exploiting software vulnerabilities, resulting in a new challenge to endpoint security. Bitdefender's findings illustrate the importance of stronger endpoint security beyond trustable file paths as attackers continue to exploit legitimate Windows features to evade detection. To protect against evolving post-compromise threats, organizations should closely monitor privileged activity and employ advanced detection techniques.
dlvr.it
July 17, 2026 at 4:02 PM
Ransomfeed is proud to be cited in a peer-reviewed study on ransomware attack patterns, published on Journal of Information Security and Applications.

Grateful to the authors for acknowledging our dataset. @melillopietro.bsky.social

#CyberSecurityResearch #Ransomware #MITREATTACK
February 1, 2026 at 5:52 PM
Global Supply Chains at Risk as Indian Third-Party Suppliers Face Rising Cybersecurity Breaches #CyberSecurity #CybersecurityPrecautions #cybersecurityresearch
Global Supply Chains at Risk as Indian Third-Party Suppliers Face Rising Cybersecurity Breaches
 Global supply chains face growing cybersecurity risks as research highlights vulnerabilities in Indian third-party suppliers. According to a recent report by risk management firm SecurityScorecard, more than half of surveyed suppliers in India experienced breaches last year, raising concerns about cascading effects on international businesses. The study examined security postures across multiple sectors, including manufacturing for aerospace and pharmaceuticals, as well as IT service providers.  The findings suggest that security weaknesses among Indian suppliers are both more widespread and severe than analysts initially anticipated. These vulnerabilities could create a domino effect, exposing global companies that rely on Indian vendors to significant cyber threats. Despite the generally strong security posture of Indian IT service providers, they recorded the highest number of breaches in the study, underscoring their position as prime targets for attackers.  SecurityScorecard noted that IT service providers worldwide face heightened cyber risks due to their central role in enabling third-party access, their expansive attack surfaces, and their value as high-profile targets. In India, IT companies were found to be particularly vulnerable to typosquatting domains, compromised credentials, and infected devices. The research further revealed that suppliers of outsourced IT operations and managed services were linked to 62.5% of all documented third-party breaches in the country—the highest proportion the company has ever recorded.  Given India’s dominant role in the global IT services market, the implications are profound. Multinational corporations across industries rely heavily on Indian IT vendors, making them critical nodes in the international digital economy. “India is a cornerstone of the global digital economy,” said Ryan Sherstobitoff, Field Chief Threat Intelligence Officer at SecurityScorecard. “Our findings highlight both strong performance and areas where resilience must improve. Supply chain security is now an operational requirement.”  The report also emphasized the risks of “fourth-party” vulnerabilities, where the suppliers of Indian companies themselves create additional points of weakness. A single ransomware attack or disruptive incident against an Indian vendor, the researchers warned, could halt manufacturing, delay service delivery, or disrupt logistics across multiple countries.  The risks are not limited to India. A separate SecurityScorecard study revealed that 96% of Europe’s largest financial institutions have been affected by a breach at a third-party supplier, while 97% reported breaches stemming from fourth-party partners, a sharp increase from 84% two years earlier.  As global supply chains become increasingly interconnected, these findings highlight the urgent need for businesses to strengthen third-party risk management and enforce stricter cybersecurity practices across their vendor ecosystems. Without stronger safeguards, both direct and indirect supplier vulnerabilities could leave multinational enterprises exposed to significant financial and operational disruptions.
dlvr.it
October 3, 2025 at 2:38 PM
Researchers Link Surge in Malicious Scanning to New Vulnerability Disclosures Weeks Ahead #CVEdisclosure #CyberSecurity #cybersecurityresearch
Researchers Link Surge in Malicious Scanning to New Vulnerability Disclosures Weeks Ahead
  A new study suggests that in nearly 80% of cases, unusual spikes in malicious online activity — such as network reconnaissance, targeted scanning, and brute-force attacks on edge networking devices — occur within six weeks before the public disclosure of new security vulnerabilities (CVEs). The finding comes from threat intelligence company GreyNoise, which says these incidents are not random, but instead follow consistent and statistically significant patterns. GreyNoise analyzed data from its Global Observation Grid (GOG) dating back to September 2024, applying objective statistical measures to filter out noise, ambiguity, and low-quality entries. This process identified 216 significant spike events linked to eight enterprise edge vendors. "Across all 216 spike events we studied, 50 percent were followed by a new CVE within three weeks, and 80 percent within six weeks," explain the researchers. The correlation was especially strong for products from Ivanti, SonicWall, Palo Alto Networks, and Fortinet, and weaker for MikroTik, Citrix, and Cisco. According to GreyNoise, state-sponsored actors have consistently targeted such systems for initial access and persistence, often probing for older, already-documented flaws. Researchers believe this scanning activity either aids in uncovering new vulnerabilities or in identifying exposed endpoints that could later be exploited with novel attacks. Traditionally, defenders act after a CVE is published. However, GreyNoise’s findings indicate that unusual attacker behavior can serve as an early warning system — giving security teams a valuable window to strengthen defenses before a vulnerability becomes public knowledge. These pre-disclosure spikes allow defenders to bolster monitoring, tighten security controls, and prepare for possible exploits, even if no patch is yet available or the targeted component remains unknown. GreyNoise recommends closely monitoring scanning activity and swiftly blocking source IPs to prevent reconnaissance from progressing to active attacks. The company also stresses that scans targeting older vulnerabilities shouldn’t be dismissed as harmless, since attackers often use them to catalog internet-facing systems that might be vulnerable to other exploits in the future. In a related move, Google’s Project Zero announced it will now notify the public within one week of discovering a new vulnerability. The disclosure will include the affected vendor or product, the discovery date, and the standard 90-day patch deadline. No technical details, proof-of-concept code, or exploit information will be released in this early notice, ensuring attackers cannot leverage the information while helping administrators reduce the “patch gap.”
dlvr.it
August 9, 2025 at 3:26 PM
🎧 Forschungsquartett
Side-Channel-Angriffe: Was Computer über uns verraten (20min)
Listen
Details
#SideChannelAttacks #CybersecurityResearch #Forschungsquartett
October 23, 2025 at 7:07 PM
🔗 6/6: For in-depth analysis and further actions, check out the full article here: https://s.mtrbio.com/ojvgidigkp . #CyberSecurityResearch @DaveyWinder @Forbes
Critical Google Chrome Warning For 2.6 Million As 2FA Hackers Attack
Hackers have targeted Google Chrome users in a frightening 2FA bypass attack with dozens of extensions compromised with malicious code—here’s what we know so far.
s.mtrbio.com
January 2, 2025 at 1:30 PM