For most of 2025, I was skeptical that AI was already playing a major operational role in real intrusions. Most public examples seemed limited to phishing and supporting tasks.
This report by my friend Eyal Eyal lines up with what I have been hearing elsewhere, too - in recent publications and in private conversations with people seeing this stuff up close.
I think that phase is over.
AI is moving into the operational core of attacks. With stronger models, open models, and jailbroken variants circulating, the economics have changed. Tailored tooling, exploit adaptation, and large-scale analysis get cheaper and faster.
I expect AI to play a major role in future campaigns, and that means more variation, more fresh tooling, and less reliance by attackers on recycled code.
All the more reason to focus on controls and detections that do not depend only on known samples.
Worth reading.
One of our very smart Active Directory experts has been putting together a series of blog posts about hardening AD. Already into its 7th installment, it covers SMB hardening, disabling NTLMv1, least privilege and more. Check the series out - https://t.co/KkKfarAX9a
CISA releases a Secure Software Development Attestation Form that will help ensure the software producers who partner with the US federal government leverage minimum secure development techniques and toolsets:
https://t.co/tyUp0tlU31
#Android: At BlackHat Europe researchers demonstrated that most #password managers for Android (1Password, LastPass, Dashlane, Keepass etc) are vulnerable to #AutoSpill attack allowing to steal account credentials on Android during the autofill operation:
https://t.co/dmUfu45JHU
The long-awaited Microsoft Cybersecurity Reference Architectures (MCRA) update is now live!
https://t.co/ZUd4ne90yD
In addition to the latest products & names, this is the first MCRA version integrated into the Microsoft Security Adoption Framework (SAF).
Share and Enjoy!
NEW: Conti affiliates use ProxyShell Exchange exploit in ransomware attacks ⚠️
In one of the ProxyShell-based attacks observed by Sophos, the Conti affiliates managed to gain access to the target’s network and set up a remote web shell in under a minute...
1/14
Wanted to do a quick blog on o365 audit logging and its quirks for a while now. Finally finished it. TLDR: enable it even if you dont monitor any of it. Atleast your incident responder will thank you.
https://t.co/azQ4Qb6oTY
Syncing your phone to the car or having a built in GPS are privacy risks. Cars don’t have the data protection of a modern phone. https://t.co/yjep5pyPqA
Just to add to this, look at ParkMobile’s password requirements then look at the cracked passwords and ask yourself: do those requirements help people make good passwords? No, of course not, that’s why we ditched that craziness years ago: https://t.co/BYuK0brgg5
If you are using #F5@F5Networks kit - be aware of 4 CRITICAL CVEs just announced minutes ago with almost all versions of BIG-IP and BIG-IQ 7.x vulnerable.
Unauthenticated #RCE. Patches released - do check out the knowledgebase article:
https://t.co/RqUtD9vZ6I
@F5Security