Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts

  Ransomware groups claimed responsibility for 2,279 attacks worldwide during the second quarter of 2026, marking a 7% increase from the pre...

All the recent news you need to know

Splunk Report Finds One in Five CISOs Pressured to Hide Cybersecurity Incidents

 

The Splunk 2026 CISO report makes public the challenges that CISOs face when trying to meet the rising demand to mask security incidents while also complying with tightening disclosure laws. According to the report, which draws its conclusions from the responses of 650 CISOs, 20% of respondents had experienced pressure from their organization not to disclose a cybersecurity incident or breach, and 53% of those who were challenged had reported an incident or breach anyway. 

It is stated that business and regulatory priorities conflict, putting CISOs in the middle of a regulatory dilemma. In addition, there is a growing sense among CISOs that they could face disciplinary or legal repercussions if they fail to protect the company from cyber ​​security threats. The percentage of CISOs concerned about being held accountable for a cyber ​​incident increased from 56% in 2025 to 78% in 2026. 

The report also shows that 79% of CISOs believe their jobs have become increasingly complex over the last year, with 43% reporting having taken on new roles and responsibilities outside their primary function, such as preventing fraud and financial crime. Moreover, 96% of CISOs responded that they are now responsible for the governance and risk management of artificial intelligence. This is yet another factor contributing to the complexity of the CISO’s work, as they must ensure that companies adopt responsible AI practices. 

The increasing difficulty of the CISO position is reflected in the fact that 26% of CISOs stated they have considered quitting their jobs due to the burdensome nature of the role. It is therefore not surprising that the report’s findings coincide with new government regulations that further tighten cybersecurity disclosure laws. For example, according to the Cyber Security and Resilience (Network and Information Systems) Bill currently under consideration in the UK Parliament, organizations in the UK will be required to report on major cyber ​​security incidents and strengthen board-level oversight of cybersecurity. 

CISOs must therefore carefully weigh the risks and benefits of any response, as reporting an incident too soon could result in financial losses for the company, whereas reporting it later could incur severe regulatory penalties. The report recommends that CISOs focus on building and maintaining strong governance by providing detailed information on how and by whom incidents were uncovered, as well as which steps had been taken to investigate and remediate the damage. 

This will ensure that the CISO’s decisions regarding disclosure of an incident are based on verifiable facts and figures. By analyzing all relevant data across enterprise networks, cloud, endpoints, or servers, the security leader can build a comprehensive report outlining the exact course of action taken after the breach was discovered. This will help to both satisfy regulatory authorities during an audit and assist in determining if and when a report needs to be filed. 

The report therefore highlights the fact that the role of the CISO has changed dramatically and now entails a wide range of responsibilities, requiring them to make decisions that go beyond the realm of traditional cybersecurity.

EU Mandates Driver Distraction Warning Systems in All New Vehicles Amid Privacy and Safety Debate

 

The European Union has introduced stricter vehicle safety regulations, making Advanced Driver Distraction Warning (ADDW) systems mandatory in all newly registered vehicles across member states from this week. The move is part of the European Commission’s expanded General Safety Regulation, aimed at reducing road fatalities and improving overall traffic safety.

Although Europe is considered one of the safest regions for road travel, the European Commission noted in its announcement that "the number of deaths and injuries from road accidents is still too high." To address this, the updated rules introduce several advanced safety requirements for new vehicles.

In addition to ADDW systems, the new legislation requires advanced emergency braking systems capable of detecting pedestrians and cyclists, along with improved forward visibility features. Driver distraction monitoring technology, which uses cameras to observe a driver's attention levels, will now become a standard feature in all newly registered vehicles.

These camera-based systems continuously monitor a driver's eye movements and facial expressions using sensors positioned behind the steering wheel or above the vehicle’s infotainment display. If the system determines that the driver has looked away from the road for an extended period, it issues alerts encouraging them to refocus.

Depending on the manufacturer, these alerts may include audible warnings, dashboard notifications, or the temporary disabling of features such as adaptive cruise control and other automated driving functions.

However, the mandate has sparked criticism from some quarters. The European Conservative described the Commission’s decision as the "latest annoying piece of EU overregulation," raising concerns over the lack of transparency regarding how data collected by these systems will be managed.

Current ADDW systems are designed to function in a closed-loop environment, where all information is processed locally within the vehicle without being transmitted to external servers. Despite this, concerns persist over the future handling of driver data as vehicles become increasingly connected.

Since April 2018, all newly approved passenger cars and light vans sold in the European Union have been equipped with the eCall emergency system, which automatically contacts emergency services following a serious accident. Combined with forecasts from consulting firm McKinsey that 95% of vehicles worldwide will be internet-connected by 2030, experts believe driver-monitoring information could eventually be transmitted beyond the vehicle.

Privacy concerns have already been highlighted in previous research. In 2023, Mozilla reviewed the privacy practices of 25 automotive brands and found that none met the organization's own privacy and security expectations. The report described connected vehicles as "the worst product category we have ever reviewed for privacy."

The issue has also drawn regulatory attention outside Europe. In 2024, the Texas Attorney General launched an investigation into several automobile manufacturers following allegations that they were collecting extensive driver data and selling it to third parties.

Critics argue that the European Union has yet to clearly define how information gathered by ADDW systems will be governed. They warn that such data could potentially be used in areas such as insurance pricing or legal proceedings in the future.

Beyond privacy issues, some motorists have questioned the usability of driver monitoring technology, arguing that overly sensitive systems can themselves become a source of distraction by issuing unnecessary alerts during routine driving activities.

While Euro NCAP has indicated that it aims to reduce reliance on "annoying" in-car safety features, the European Union’s latest regulations place greater emphasis on driver monitoring technologies, highlighting the ongoing debate between improving road safety and protecting driver privacy.

Sri Lanka Treasury’s USD 2.5 Million Loss Ruled Cybercrime Fraud

 

Sri Lanka’s recent finding that a USD 2.5 million Treasury loss was the result of cybercrime highlights how vulnerable government financial systems have become in the age of digital debt repayments. The case underlines that cybersecurity failures are no longer just technical glitches; they now directly translate into sovereign-level financial and reputational risks. 

In this incident, hackers infiltrated official communication channels linked to Sri Lanka’s Finance Ministry and Treasury during a foreign debt repayment to Australia. By compromising email systems in the Public Debt Management or related units, the attackers were able to alter payment instructions so that funds intended for a legitimate creditor were instead wired to accounts controlled by cybercriminals. The money formed part of a larger bilateral repayment package, but the redirected USD 2.5 million simply never reached the intended recipient, exposing serious weaknesses in verification and authorization workflows inside the ministry. 

A parliamentary oversight body, the Committee on Public Finance (COPF), was tasked with investigating the diversion and has now formally ruled it a cybercrime-driven fraud, not a technical debt default or routine accounting error. The panel’s report points to operational lapses within the ministry rather than a single rogue actor, suggesting that controls around email, payment approvals, and cross-checking beneficiary details were either inadequate or poorly enforced. Questions around possible internal collusion were raised in political debate, but COPF stressed that its mandate was limited to financial and procedural review, leaving any deeper criminal probe to law enforcement and cybersecurity agencies. 

For Sri Lanka, the stakes go beyond the immediate financial loss. The episode has unfolded in parallel with ongoing debt restructuring and negotiations with international creditors, making any hint of default or mismanagement politically sensitive. Officials have emphasized that creditors are likely to treat the incident as cyber fraud rather than a failure to honor obligations, yet the breach still damages confidence in the state’s ability to protect critical financial infrastructure. It also illustrates how attacks on public finance systems can ripple out into diplomatic relations, market perceptions, and domestic political narratives. 

The COPF report calls for stronger cybersecurity, a special audit of foreign debt repayment processes, and upgrades to public debt management systems so similar attacks can be detected and blocked early. For governments worldwide, the Sri Lankan case is a warning that protecting payment systems, official email, and inter-agency workflows is now a front-line national security issue, not a back-office IT concern. As cybercriminals increasingly target high-value sovereign transactions, robust multi-layer verification, staff training, and real-time threat monitoring must become standard practice in every finance ministry.

Unpatched Backdoor Identified in Firmware of Multiple Wi-Fi Routers


Research has discovered that several Tenda Wi-Fi routers are at risk of being compromised as a result of an undocumented authentication backdoor embedded in their firmware. An attacker can bypass the normal login process and gain administrator-level access to affected devices through this flaw, and no official security patch has been released yet. 

A US-based cybersecurity authority, CERT/CC (CERT/CC), identified the vulnerability and released it as a security advisory. According to the advisory, the backdoor is present in five firmware versions of older Tenda router models. A CVE-2026-11405 vulnerability has been assigned to this vulnerability. 

It is reported that the vulnerability is associated with the web server's login function, where a failed authentication attempt triggers a secondary verification process for passwords. Instead of validating both the username and password, firmware only checks the password value stored within the device configuration, which enables authentication to be successful regardless of the username used. 

In the case of Tenda devices, access is normally limited to administrator credentials via the web-based management interface. It has been discovered that the firmware contains an undocumented authentication mechanism that is activated upon failure of a standard login attempt. The firmware compares only a password stored in the device configuration, rather than validating both the username and password. Regardless of the username entered, administrative access is granted if the supplied password matches. 

Interestingly, researchers noted that the alternative password appears to be "rzadmin", which has previously been discovered in previous security research involving Tenda devices. However, since the authentication process does not validate the username, any username can successfully login when paired with the appropriate backdoor password. Despite the device's administrative interface, hidden functionality is not documented or disclosed. 

Upon matching the alternate password with the device configuration value, the firmware grants full administrator privileges and creates a valid management session. Because of its undocumented nature and inaccessibility through the standard administrative interface, it has been classified as an authentication backdoor by researchers. 

During previous security research involving Tenda devices, the alternate password was identified as "rzadmin", a credential that has previously surfaced. Despite the lack of clear explanations for its presence, experts believe it may have been accidentally left behind as part of a debugging or development tool. 

One of the biggest concerns is the lack of a vendor response. According to CERT/CC, they were unable to reach Tenda to coordinate a fix, resulting in the non-availability of official firmware updates for affected users. As a result, this vulnerability remains unpatched. Successful exploitation could result in router configuration changes, network settings changes, security settings being disabled, and potentially compromise other local networks. 

A security expert considers this vulnerability to be a significant risk for exposed devices due to its ability to grant administrator-level privileges without standard authentication. This firmware is affecting a variety of Tenda networking products, including routers, wireless hotspots, and other networking equipment. 
The following models have been confirmed as affected: 

  • FH1201 High Power AC1200 Dual-Band Wireless Router 
  • W15E v2.0 AC1200 Wireless Hotspot Router 
  • AC10 v1.0 AC1200 Smart Dual-Band Gigabit Router 
  • AC5 v1.0 AC1200 Smart Dual-Band Router 
  • AC6 v2.0 AC1200 Router 

There is a possibility that some of these products are older models and may already have reached end-of-life, resulting in uncertainty about future security updates. The CERT recommends that, until an official patch is available, remote web management be disabled and the router's default LAN IP address be changed to reduce exposure to automated internet scanning. 

If users have not received firmware updates for their affected devices and are unable to secure them, it may be prudent to replace the router with a supported model. Undocumented functionality embedded in networking firmware poses a number of security risks, particularly when vendors fail to provide timely security updates. 

Since there is no official patch available currently, users are advised to take immediate action to mitigate the vulnerability or to upgrade their hardware in order to reduce the risk of unauthorized access.

AI-Powered Attacker Breaches AWS Environment in 72 Hours, Highlights New Era of Rapid Cloud Extortion

 

A single threat actor leveraged artificial intelligence to execute a sophisticated cyberattack against a large Amazon Web Services (AWS) environment, completing the operation in just 72 hours before successfully extorting the targeted organization, according to new findings from cybersecurity and incident response firm Sygnia.

The research reveals that the financially motivated attacker relied on agentic AI workflows to significantly speed up multiple stages of the attack, including reconnaissance, tool creation, command generation, and adapting techniques to the victim's cloud environment.

While cybercriminals have increasingly used large language models (LLMs) to craft phishing emails, generate malware, and automate various stages of cyberattacks, Sygnia's investigation highlights a more advanced use case where AI enabled a single operator to carry out a large-scale cloud compromise typically associated with well-resourced threat groups.

The attack targeted an unnamed global enterprise operating within AWS and unfolded over approximately three days. According to Sygnia, the intrusion did not rely on a single security flaw but instead combined weaknesses across several components of the victim's cloud infrastructure.

"Conducted within an AWS environment, the intrusion did not exploit a single misconfiguration," Sygnia said. "Instead, it chained together weaknesses across application services, AWS resources, source code repositories, CI/CD pipelines, runtime components, and data stores. Simultaneously, the threat actor rapidly performed credential discovery, secrets harvesting, cloud enumeration, deployment pipeline abuse, runtime modification, database access, and operational disruption."

Researchers noted that although credential theft, cloud exploitation, and data exfiltration are common tactics in cloud-focused attacks, the speed and scale of this incident stood out. Activities that would normally take weeks were completed within just 72 hours, suggesting extensive use of AI-assisted automation.

Sygnia based its assessment on evidence including attacker-developed scripts, reporting artifacts, simultaneous activities, and the rapid execution of numerous cloud attack techniques. The company concluded that AI-assisted workflows enabled the attacker to accelerate reconnaissance, develop attack tools, structure commands, and continuously adapt to the target environment.

The attack reportedly began after the threat actor obtained an AWS access key through a vulnerability in an internet-facing application. Using that initial access, the attacker repeatedly executed multiple automated workflows to expand privileges, collect credentials, harvest secrets, and gain broader access across the cloud environment.

The campaign also involved systematic theft of sensitive information, creation of backdoors, and large-scale data exfiltration to strengthen the attacker's leverage during the extortion attempt.

"To increase pressure on the client, the threat actor performed mostly reversible impact actions as a demonstration of capability. These included denying access to S3 buckets, limiting ECS services or containers to a maximum capacity of zero, creating ACL rules to block network access, and purging SQS queues," the research stated. "While many of these actions were reversible, they served as a clear showcase of force: the actor was demonstrating that they had the ability to disrupt critical cloud services and could escalate to more destructive actions if needed."

Speaking to Dark Reading, Avi Dayan, Vice President of Incident Response at Sygnia, emphasized that while AI-generated commands may not significantly alter tactical defense strategies, they fundamentally change the pace at which defenders must respond.

"The mean time to detect (MTTD) and mean time to remediate (MTTR) must contract significantly [in cases where LLMs are involved in the attack execution process]. If an AI tool can execute a breakout or exfiltrate data in under a minute, a security team relying on human-in-the-loop triaging of SIEM alerts will always lose," he said. "Security operations must pivot toward automated, high-fidelity response playbooks [security orchestration, automation, and response, or SOAR] and AI-driven defense mechanisms just to match the adversary's tempo."

To counter increasingly automated threats, Sygnia recommends that organizations strengthen identity security, improve visibility across cloud assets, secure development environments, deploy layered security controls, and automate detection and incident response wherever possible.

The company also stressed the importance of having predefined containment procedures that can be executed immediately to prevent attackers from rapidly expanding access across interconnected cloud systems.

"Equally important is the establishment of predefined containment procedures that can be executed immediately when malicious activity is identified," the research stated. "In an environment where attackers can rapidly discover credentials, identify additional attack paths, and expand access across interconnected systems, delays in containment can have a disproportionate impact on the outcome of an incident. Organizations must therefore focus on reducing response friction and enabling rapid execution of containment actions at scale."

Helix Data Extortion Group Targets Microsoft SharePoint Using Vishing and MFA Abuse

 

Cybersecurity researchers have discovered a new data extortion group called Helix that has been targeting companies by using user credentials rather than software vulnerabilities. Helix has been employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to target Microsoft 365 and steal data from the company’s SharePoint service. 

According to the researchers at ReliaQuest, Helix has been attacking the company by first calling an employee and posing as their manager or another executive and tricking them into approving device code authentication and granting access to their Microsoft accounts. In some cases, the attackers used the manager’s name or changed the caller ID to disguise their location as the manager’s office. The attackers then register their own MFA Authenticator application on the victim’s account to ensure continued access to the Microsoft 365 platform even if the user changes their password. 

The intruders then proceed to conduct reconnaissance on the SharePoint servers, enumerating and downloading all the available data, including documents, before the company detects the breach. The data is then used to demand ransom from the victim organization by threatening to publish the information if the company does not pay a certain amount of cryptocurrency. In some instances, the attackers sell the data to other bad-actor groups. 

Researchers have noted that Helix’s automated SharePoint discovery has been one of the group’s most identifiable features. In one of the attacks, the attackers used automated search queries to find the SharePoint content before launching a large-scale data exfiltration campaign from the same IP address using a Python Requests user agent. ReliaQuest researchers suspect that Helix may be linked to the ShinyHunters and BlackFile data extortion groups due to the similarity in attack techniques. 

Although there is no conclusive evidence that the groups are connected, researchers have discovered similar infrastructure and tactics used by Helix and ShinyHunters. Some of the organizations that have fallen victim to Helix include Medtronic, Nissan, the National Association of Insurance Commissioners (NAIC), Kodak, Infinite Campus, and the University of Nottingham. These companies were previously targeted by the ShinyHunters group and confirmed the breach on their websites. 

In addition, ReliaQuest researchers discovered that one of the Helix’s exfiltration servers was hosted on an autonomous system previously used by the BlackFile infrastructure. Since BlackFile’s servers were shut down earlier this year, researchers suspect that Helix may have links to the BlackFile group or be an offshoot of the former group. However, other data extortion groups such as Pink and Redact may also be linked to BlackFile. 

The campaign that targets Microsoft 365 is similar to the ShinyHunters ransomware attack in several ways, including impersonating employees, targeting the Microsoft 365 platform, stealing data from SharePoint servers, and using social engineering to trick employees into giving access to the company’s network. Researchers have also discovered that Helix uses the NICENIC domain registrar, which has been used in some of the ShinyHunters attacks. 

Experts recommend that organizations disable device code authentication if possible and only allow managed devices to access the Microsoft SharePoint service. In addition, the company should monitor Microsoft 365 authentication activities and restrict all communications except those from trusted domains to protect their data from being exfiltrated by Helix or other cybercriminal groups. 

The discovery of the Helix campaign shows how cybercriminals are increasingly targeting user credentials to access sensitive information rather than exploiting software vulnerabilities.

Featured