New research from browser security firm Menlo Security reveals an alarming rise in unsanctioned generative AI (GenAI) use across enterprises, with growing concerns over data leakage, phishing, and regulatory compliance. According to The 2025 Report: How AI is Shaping the Modern Workspace, web traffic to GenAI sites spiked by 50% in under a year, culminating in 10.53 billion visits in January 2025 alone. At the heart of the findings is a sharp increase in what Menlo terms Shadow AI, or the use of unsanctioned GenAI tools by employees, often without their organization’s knowledge or oversight. AI Adoption Accelerates, Security Gaps…
Kirsten Doyle
A new name surfaced in Microsoft’s analysis of the ToolShell exploitation campaign earlier this year. Storm-2603. There was no history or track record. Just a cluster of activity, loosely linked to ransomware. Now, Check Point Research has filled in some of the blanks. Storm-2603, it turns out, was not born with ToolShell. It had been busy long before, targeting entities in Latin America and APAC. Its methods are like the hybrid DNA of advanced persistent threats and criminal ransomware crews. It moves with precision, using open-source tools and custom malware. It doesn’t bluff. An Unknown Name, Familiar Footsteps ToolShell is…
The UK has seen a steep rise in VPN usage following the enforcement of the Online Safety Act. On 25 July, Ofcom began implementing new age-verification rules designed to keep children away from adult content. In response, many users started using VPNs. Traffic spiked. So did downloads. Researchers at vpnMentor tracked a whopping 6,430% increase in VPN demand in the hours after the law came into effect. “It remained as such for almost two hours before it started dropping at the end of the day, but with spikes of 900% up to 4000% the following days,” researchers said. Several VPN…
Ransomware groups are ramping up pressure on the public sector. In the first half of 2025, 208 attacks were recorded against government entities worldwide. That’s a 65% increase over the same period in 2024, and a 25 percent rise from the second half of last year. These were some of the findings from Comparitech’s Map of worldwide ransomware attacks that is updated daily. Half of the incidents were confirmed by the targeted agencies. The rest remain unresolved or unacknowledged. This level of transparency is rare outside the public sector. In education, only 31% of incidents were confirmed. Healthcare: 32%. In…
A new draft from NIST, developed in collaboration with 14 industry partners, outlines how to build software with security baked in, not bolted on. This is part of a broader push to protect the software supply chain, and it’s open for public comment until 12 September 2025. The guidelines are a response to Executive Order 14306, issued in June, which called for sustained action to strengthen national cybersecurity. NIST’s National Cybersecurity Center of Excellence (NCCoE) is leading the work through a newly formed Software Supply Chain and DevOps Security Practices Consortium. The goal is simple, if ambitious: help organizations build,…
An investigation from Sonatype has exposed a cyber-espionage campaign by North Korea’s infamous Lazarus Group, this time targeting the tools developers rely on every day. Between January and July 2025, Sonatype blocked 234 unique malware-laden packages across the npm and PyPI ecosystems; a calculated assault on the trust that underpins open-source software. Disguised as popular developer utilities, these poisoned packages carried espionage implants designed to exfiltrate credentials, profile systems, and establish long-term backdoors. At last count, the campaign may have reached over 36,000 victims, and it’s still ongoing. “Open source has become the new attack surface,” Sonatype warns. “It’s not…
It starts with an ad. The branding looks familiar; Coinbase, Binance, OKX. The ad promises fast trading, high returns, or access to a new crypto platform. Click it, and you’re sent through a maze of redirects. At the end is a download: a Windows installer in .msi format. Behind this is JSCEAL, a malware campaign that’s been quietly active since March last year. It doesn’t use zero-days because it doesn’t need to. It hides in plain sight, behind sponsored ads and familiar logos. Check Point Research uncovered the campaign after tracking a spike in crypto-related malware infections across Europe. Their…
A newly documented attack on a US-based chemicals company is raising fresh concerns in the cybersecurity community, after researchers observed the first-known use of the evasive Auto-Color backdoor malware in conjunction with a critical SAP NetWeaver vulnerability, CVE-2025-31324. Discovered and contained by Darktrace, the incident involved a multi-stage attack where threat actors used the SAP vulnerability as an entry point to deploy the Auto-Color malware on Linux systems. The backdoor then attempted to persist by hijacking system processes, but was thwarted by AI-driven detection and autonomous response. “This is a wake-up call for every organization running SAP,” said Jonathan Stross,…
Amazon has quietly disclosed a near-catastrophic AI security incident that, while not making headlines, should send chills through every cybersecurity professional. No outages or data stolen, but the risk was real, and it came from within. In its latest Security Bulletin AWS-2025-015, Amazon revealed an “unapproved code modification” buried inside the Amazon Q plugin for Visual Studio Code. At first glance, it appeared to be a routine code oversight. Dig deeper, alas, and there is something far more alarming. Security researchers at PointGuard AI uncovered the actual commit on GitHub; a hardcoded AI prompt designed to erase everything. Not just…
A newly discovered vulnerability in Google’s Gemini CLI, an AI-powered tool designed to help developers explore and write code from the command line, has exposed users to silent execution of malicious commands without their knowledge. The security research team at Tracebit uncovered how a clever mix of prompt injection, weak validation, and deceptive user experience could allow attackers to run harmful code on anyone’s machine simply by inspecting a compromised codebase with Gemini CLI. What Happened? Google released Gemini CLI on 25 June 2025, aiming to streamline coding workflows by enabling developers to interact with code through natural language commands…
