Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsu...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
70 articles found
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsu...
Rockstar Games’ breach history illustrates how stolen identities, trusted integrations and exposed development assets can undermine enterprise defenses witho...
Transcend has launched Transcend Rails, a new category of agent management that goes beyond identity and access control to govern what an agent does. Every e...
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scan...
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript ...
Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at A...
A large-scale scraping cluster dubbed PaperPhone, exposing how one operator can manufacture the appearance of tens of thousands of legitimate mobile users ac...
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core comp...
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs to...
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the acti...
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 11...
An Integrated Security Operations Center (ISOC) in Microsoft Defender, unifying security information and event management (SIEM) and threat-protection capabi...
Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than ...
The boundary between conventional conflict and cyber sabotage is narrowing as adversaries adopt artificial intelligence to industrialize deception, reconnais...
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadb...
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system re...
The flaw could enable sensitive files to be read with just an HTTP request.
A new Windows remote-access trojan dubbed SloppyRAT, which appears to be positioned as an intrusion-enablement tool for ransomware operations. First observed...
Threat actors increasingly deploy AI agents as operational systems for cyberattacks, moving beyond simple chatbot assistants. These AI systems automate vario...
Cisco Talos has warned that threat actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These vulner...