The ransomware attack dubbed “JADEPUFFER”, one of the first documented cases of a threat actor using large language model (LLM) to conduct an end-to-end attack, offers a glimpse into how AI could shape future ransomware campaigns. https://t.co/FX87ickKFt
While the attack relied on familiar techniques, it demonstrated how AI can rapidly iterate, adapt to failures, and continue progressing toward an objective.
In this episode of the Microsoft Threat Intelligence Podcast, Elliot Volkman speaks with Michael Clark and Crystal Morin of Sysdig about the AI-driven activity, including its ability to generate and modify code, reason through errors, and work through technical obstacles that might slow a human operator.
Despite its use of AI, JADEPUFFER relied on familiar weaknesses, including exposed services, unpatched vulnerabilities, and poor credential hygiene, highlighting the continued importance of exposure management and foundational security practices.
🔥 FBI shuts down Chinese hacking platforms tied to intrusions at NASA, the Fed, and U.S. Senate.
QScan exploited vulnerable IoT devices, while QTRouter hid attack traffic behind compromised devices, commercial proxies, and VPSs.
How it worked: https://t.co/MDk69PGdnw
Microsoft is observing threat actors increasingly target AI infrastructure concentrating credentials, data access, model connectivity, and execution privileges, creating new opportunities to gain access, establish persistence, and monetize environments. https://t.co/IXojEBrc5X
Across multiple AI workload intrusions, attackers used different access paths but consistently sought provider credentials, database access, workflow execution, container visibility, and other resources that could support follow-on activity beyond the initially compromised system.
AI infrastructure is increasingly functioning as a control plane where credential theft, host compromise, and downstream data access can converge, making these platforms attractive targets for threat actors. Read the Microsoft Security Research blog for additional analysis and guidance.
Frontier AI is outpacing traditional vulnerability management.
CVSS, EPSS, and KEV are no longer enough. Teams need exploitability, reachability, misconfigurations, and business impact, plus faster, more automated patching.
See what needs to change - https://t.co/c8JhmMwRJi
🌍 National Cyber Exposure: 195 Countries Ranked
A new country-level cybersecurity ranking from ARP Syndicate’s Kenzer National Threat Intelligence Database assesses the exposed attack surface of 195 countries using continuous passive reconnaissance of government public-facing infrastructure.
Unlike traditional cybersecurity indexes based heavily on questionnaires or self-reported maturity, this dataset focuses on externally observable exposure.
According to the current snapshot:
* 🇮🇸 Iceland ranks #1 — 3.9/100 (A)
* 🇳🇱 Netherlands ranks #2 — 7.1/100 (A-)
* 🇬🇧 United Kingdom ranks #3 — 7.1/100 (A-)
* 🇯🇴 Jordan ranks #4 — 8.9/100 (A-)
* 🇵🇱 Poland ranks #5 — 8.9/100 (A-)
* 🇰🇵 North Korea is a surprising #8 — 10.1/100 (B+)
* 🇷🇺 Russia ranks #148 — 57/100
* 🇺🇸 United States ranks #164 — 66.8/100
* 🇨🇳 China ranks #171 — 70.6/100
* Five countries reach the maximum exposure score of 100/100
⚠️ Analyst Note:
This ranking should not be interpreted as a definitive measurement of which countries have the "best cybersecurity."
A lower score represents a smaller externally observable government attack surface according to Kenzer's methodology. Countries with highly centralized, restricted, isolated, or less publicly exposed infrastructure may therefore perform surprisingly well even if other measures of cyber capability or resilience would produce very different rankings.
That makes the dataset particularly interesting as an exposure-intelligence benchmark rather than a conventional cybersecurity maturity index.
Source: ARP Syndicate — Kenzer National Threat Intelligence Database
https://t.co/Ut6DyKLafR
#DDW #CyberSecurity #ThreatIntelligence #OSINT #AttackSurface #CyberExposure
Defenders can now test exploitability and validate attack paths before attackers act.
Through an expanded agreement with @AnthropicAI, @Unit42_Intel Exposure Analysis is integrating Claude Mythos 5. Guided by Unit 42 experts, this model helps defenders find hidden exposures and prioritize fixes.
See how this integration empowers defenders. https://t.co/JwA8r9WF9G
⚡ UPDATE: Microsoft says the CVSS 10.0 Entra ID flaw was not exploited in the wild.
Its original bulletin marked the vulnerability as exploited. On August 21, after @TheHackersNews contacted Microsoft, the company corrected the status to “No.”
We’ve updated the headline to reflect the correction: https://t.co/31qY0Pj5W2
‼️ Attackers can weaponize Defender’s own signed driver to delete security software at boot.
BTR.sys runs from Ring 0 before Defender’s user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.
See how it works: https://t.co/yGscUq6xQH
⚠️ A CVSS 10.0 Entra ID flaw was exploited in the wild.
CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.
Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.
Read more: https://t.co/31qY0Piy6u
🚨 Top 10 APT Groups to Watch in 2026
Nation-state cyber operations continue to evolve across espionage, critical infrastructure targeting, credential theft, disruption, and long-term persistence.
Our 2026 snapshot highlights 10 of the most significant APT groups based on publicly reported activity and government threat reporting:
* Salt Typhoon — China
* Volt Typhoon — China
* Lazarus Group — North Korea
* APT29 / Midnight Blizzard — Russia
* APT28 / Fancy Bear — Russia
* Sandworm — Russia
* Kimsuky — North Korea
* APT40 / Leviathan — China
* Pioneer Kitten / Lemon Sandstorm — Iran
* MuddyWater — Iran
Key trends we continue to see:
* Critical infrastructure targeting
* Telecom and cloud espionage
* Credential theft and phishing
* Living-off-the-land techniques
* Long-term persistence
* Disruptive and financially motivated operations
⚠️ Analyst Note: This is an editorial snapshot, not a permanent ranking. APT activity, aliases, targeting priorities, and attribution assessments can change as new campaigns are uncovered.
#DDW #APT #ThreatIntelligence #CyberSecurity #NationState #CyberEspionage
🚨 Four Critical Flaws Under Active Exploitation:
• macOS CVE-2026-65400
• SharePoint CVE-2026-55040
• vCenter CVE-2026-59310
• Microsoft IKE CVE-2026-33824
Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware.
Read: https://t.co/O6WRpXB4Di