If the first part of our expert predictions series showed us how fast the threat landscape is shifting, part two shows us what happens when that shift becomes structural. Across this next set of expert insights, a pattern can be seen: the attack surface is no longer something organizations “manage”, it’s something that is growing on its own. Agentic AI is scaling identities at lightning speed, leaving governance once set by people in the dust. Meanwhile, connectors and integrations are turning into silent backdoors, Zero Trust is buckling under the weight of non-human identities, and AI-driven malefactors are operating in ways that our conventional policy models do…
Kirsten Doyle
An unprotected MongoDB database exposing over 4 billion records, revealing 16 terabytes of professional and corporate intelligence data, has been discovered by researchers at the Cybernews research team and SecurityDiscovery.com. The database exposed detailed LinkedIn-derived profiles, contact information, corporate relationships, and employment histories, alongside other personal information. There were nine collections within the dataset, with each file name indicating the type of information contained within: The researchers said all records within a specific collection are unique and details exposed included full names, dmails and phone numbers, linkedIn URLs and profile handles, employment histories, degrees, certifications, location data, social media accounts and more. The database was discovered on 23 November 2025, with the instance’s owners securing it two…
US President Donald Trump says he will sign an executive order this week meant to create a single national rulebook for AI in the country, replacing a patchwork of different state laws. “There must be only One Rulebook if we are going to continue to lead in AI. We are beating ALL COUNTRIES at this point in the race, but that won’t last long if we are going to have 50 States, many of them bad actors, involved in RULES and the APPROVAL PROCESS. THERE CAN BE NO DOUBT ABOUT THIS!” he wrote on TRUTH Social. “AI WILL BE DESTROYED IN ITS INFANCY! I will be…
If there’s one common threat in every expert prediction for 2026, it’s this: the ground is shifting faster than most organizations realize. AI has moved from a “trend” sitting neatly on a roadmap, to a technology embedded in every part of the threat landscape. It is reshaping attacker behavior, stretching defensive playbooks, and exposing gaps we’ve been slow to confront. At the same time, people remain the constant: still the primary targets, and point of failure or resilience. Across all the expert perspectives, there’s a shared recognition that security is entering a paradoxical era: one where automation accelerates everything, but our ability to pause, validate, and think critically becomes more important than ever. This 2026…
Barts Health, the UK’s largest NHS trust, which runs five major hospitals across London, has confirmed that patient and staff data was stolen in ransomware gang Cl0p’s mass-exploitation of Oracle’s EBS. “We are taking urgent action and seeking a High Court order to ban the publication, use or sharing of this data by anyone,” Barts Health said in an update on its website. Cl0p posted several stolen files on the dark web, including names and addresses of people who were liable to pay for treatment or services at a Barts Health hospital over several years. Several former employees are also listed because…
A Gartner report is recommending companies to block AI-powered “agentic browsers” due to severe security risks, including data leaks to cloud systems, prompt injection vulnerabilities, and potential for malicious manipulation. The analyst giant’s advisory said organizations should block AI browsers for now due to significant security risks, mostly because their default settings prioritize user experience and automation over security controls. It said agentic browsers can be hijacked to transfer sensitive data to attackers. Gartner analysts, including Dennis Xu, Evgeny Mirolyubov, and John Watts, issued an advisory titled “Cybersecurity Must Block AI Browsers for Now”. The key points from their analysis include: Enterprises Aren’t Fully Prepared …
ISC2 has released its 2025 Cybersecurity Workforce Study, and while the economic headwinds that battered security teams last year appear to be stabilizing, the industry’s skills gap is getting worse. The report, based on responses from more than 16,000 cybersecurity professionals, indicates that layoffs and budget cuts have ceased to accelerate. Reports of budget cuts (36%) and layoffs (24%) dipped slightly year over year. However, that modicum of relief isn’t translating into stronger teams. A third of respondents claimed their firms still can’t afford to staff security properly, and nearly as many reported they can’t hire the expertise they need. Unsurprisingly, 72% agreed that shrinking headcount directly increases the risk of breach. …
Cyber extortion is on the rise. New data from the Orange Cyberdefense Security Navigator 2026, highlighted how Cy-X victims rose 44.5% year-over-year, reaching 6,142 cases between October 2024 and September 2025. The ecosystem fueling these attacks has also expanded, with 91 distinct Cy-X brands now active, up from 76 the previous year. That growth, combined with an 18% jump in victims per actor, reveals how shared infrastructure and affiliate models are driving industrial-scale efficiency. While criminal groups mature, state-sponsored operations are becoming more methodical. Campaigns such as Salt Typhoon relied on known, unpatched vulnerabilities rather than zero-days to compromise routers, VPNs, and firewalls across 80 countries. …
Microsoft said it experienced a widespread outage that affected its Microsoft Defender portal, preventing many customers from accessing security alerts, device inventories, and threat-hunting dashboards. “We’re investigating an issue where users may experience issues when trying to access the Microsoft Defender portal. Additional information will be provided in the admin center under DZ1191468,” the company said on X. It all started when a sudden spike in traffic caused high CPU use on the backend components that are responsible for powering the Defender portal’s core functions. During the outage, users were met with missing devices, blank alert pages, and a portal that simply wouldn’t load, basically everything you don’t want from a security dashboard when you’re trying to keep an eye on risk. Microsoft rolled out mitigations, boosting…
The Cleafy Threat Intelligence team has discovered a new Android malware family, called Albiriox, that is making its way across the cybercrime ecosystem. It is offered as a full-fledged Malware-as-a-Service (MaaS) and already shows the hallmarks of modern mobile banking threats. First noticed in September this year during a quiet recruitment phase on underground forums, the operation went fully public a month later. Early signals, including forum chatter and infrastructure footprints, point to Russian-speaking threat actors behind the scourge. Albiriox is built for On-Device Fraud. Instead of spoofing activity from outside the device, the malware lets attackers operate inside legitimate banking and crypto apps in…
