Visualização normal

Antes de ontemRecorded Future
  • ✇Recorded Future
  • Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization
    Today, Recorded Future is announcing Automated Signature Creation, a new capability in Attack Surface Intelligence (ASI) to combat the speed of AI-generated exploits. ASI continuously maps an organization’s external exposure, correlates newly surfaced vulnerabilities with real-world threat intelligence, and prioritizes response to enable defenders to remediate before adversaries can act. This new function within ASI automatically creates signatures, pieces of detection logic that
     

Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization

3 de Setembro de 2026, 21:00

Today, Recorded Future is announcing Automated Signature Creation, a new capability in Attack Surface Intelligence (ASI) to combat the speed of AI-generated exploits.

ASI continuously maps an organization’s external exposure, correlates newly surfaced vulnerabilities with real-world threat intelligence, and prioritizes response to enable defenders to remediate before adversaries can act.

This new function within ASI automatically creates signatures, pieces of detection logic that empowers the Recorded Future Platform to recognize a specific vulnerable or exposed condition across organization’s assets in real time.

With Automated Signature Creation now available, Recorded Future is helping to close the gap between AI-enabled threat discovery and enterprise defense.

Tackling the machine speed of exploitable vulnerabilities

It seems everything is moving quicker these days and the time to exploit a vulnerability is no different. A new generation of AI models is accelerating this challenge, demonstrating that they can automatically find zero-day vulnerabilities in major operating systems and web browsers — a skill that was previously exclusive to the most advanced government cyber units and research labs.

Back in 2020, we cited how Gartner confirmed that the time from discovery to exploitation dropped from 45 days to 15 days, between 2010 to 2020.

In our 2025 Malware and Vulnerability Trends report, we reported that weaponization occurred “within days of disclosure." Today, that window is measured in hours.

As a result, the status quo of traditional defenses and manual processes are no longer sufficient. Let’s look back at how we got here, from pre-existing detection methods to Recorded Future’s latest ASI enhancement to better defend against AI-accelerated vulnerabilities.

How we got here

In the past year, Recorded Future’s traditional approach of expert-authored signatures from the Insikt Group® was effective; they were high quality but moved at a human pace.

For example, in February 2025 we reported on the Trimble Cityworks: CVE-2025-0994, showcasing how manual signature creation worked. The Insikt Group built a Nuclei template (shared as a downloadable YAML file) specifically for CVE-2025-0994. This enabled defenders to test potentially vulnerable Trimble Cityworks instances prior to the patched version, serving as a detection and prioritization aid for helping teams figure out where to focus patching efforts first. This worked in conjunction with one of ASI’s core functions, scanning web infrastructure to identify internet-facing assets vulnerable to CVE-2025-0994.

Since that vulnerability disclosure a little over a year ago, we have ample evidence that the speed at which vulnerabilities are exploited has increased exponentially. Just recently, it was reported that OpenAI’s own agents went rogue and exploited a zero-day vulnerability in Artifactory, now infamously tied to the Hugging Face incident.

Incidents like this one, and the underlying vulnerabilities that facilitate them, are exactly why Recorded Future automated signature creation.

Now, in the face of an attack moving at machine speed, agentic processing generates production-ready detection signatures autonomously by turning a newly surfaced vulnerability into a deployable signature in as little as 31 minutes. As a result, the number of in-platform signatures produced has increased tenfold. Let’s take a closer look at how it works.

How automated signature creation works

So what does a signature in this context actually mean? Think of it like this: the signature is a piece of detection logic that says "go ask this asset this exact question; if the answer looks like this, it's vulnerable." It's the difference between "we found your assets" and "we found the ones a threat actor can potentially break into."

Automated signature creation works like a three-step early warning system. (See Figure 1)

  1. The platform keeps a constant view of what your organization exposes to the internet such as domain records, certificates, and ownership data.
  2. When a new vulnerability is flagged and matched against your scanned assets, it's checked against live threat activity rather than just a generic severity score. The system looks for evidence that threat actors are actually exploiting it, tying it to malware, ransomware or threat actor intent.
  3. When Recorded Future Intelligence determines a CVE is relevant for detection, the system automatically processes it to generate a detection signature or product fingerprint in as little as 31 minutes.
Flowchart: Recorded Future Intelligence Platform processes CVE disclosures and external assets. It auto-populates environments, prioritizes threats, and automates operations to update threat hunts, add detections, and apply preventions in 31 minutes.
Figure 1: CVE disclosures mapped to external assets kick off automated processes

  • ✇Recorded Future
  • H1 2026 Malware Vulnerability Trends
    Executive Summary H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetize intrusions while blending into expected activity. This emphasis on evasion through normalcy rather tha
     

H1 2026 Malware Vulnerability Trends

2 de Setembro de 2026, 21:00

Executive Summary

H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetize intrusions while blending into expected activity. This emphasis on evasion through normalcy rather than technical novelty increases the risk that malicious activity will progress through approved tools and trusted services before defenders recognize it, reinforcing the need for stronger exposure management, identity and credential governance, behavioral detection, developer-environment security, backup resilience, mobile fraud monitoring, and third-party oversight.

AI-enabled cyberattacks became more visible in H1 2026, but remained mostly additive to established intrusion tradecraft. In the vulnerability ecosystem, AI-assisted research increased the volume of vulnerability reports, which, moving forward, could further compress remediation timelines by accelerating exploit-path analysis and lowering exploit-development costs for skilled operators. In malware activity, observed AI-enabled capabilities largely aligned with lower-to-mid-level stages of Recorded Future’s AI Malware Maturity Model (AIM3), where AI supported discrete functions such as persistence, user interface (UI) interaction, malware development, and delivery rather than fully autonomous operations.

Vulnerability exploitation broadened across enterprise operating systems, application frameworks, and network and security management products. Insikt Group identified 215 actively exploited common vulnerabilities and exposures (CVEs), and the most consequential cases combined network reachability, few access prerequisites, and code execution. Campaign reporting also showed that threat actors reused established post-exploitation playbooks across both newly disclosed and long-standing vulnerabilities, making exposure and impact more informative indicators of operational risk than vendor ranking or severity score alone. Across phishing and malware-delivery operations, threat actors repeatedly relied on familiar execution, obfuscation, discovery, and payload-transfer techniques rather than novel capabilities. Supply-chain compromises targeted package managers and developer environments, including AI-enabled tooling, where compromised credentials, trusted integrations, and software distribution channels enabled propagation into downstream cloud and software ecosystems. Other prominent activities included mobile malware enabling payment fraud through Near Field Communication (NFC) abuse and early AI-assisted workflows, as well as Magecart campaigns leveraging trusted third-party services and checkout manipulation.

The common risk across these threats is that malicious activity can progress through legitimate tools, trusted services, and routine workflows before defenders recognize it as part of a broader intrusion. Defenders should therefore prioritize vulnerabilities that can be exploited remotely or enable code execution, focus detection on suspicious sequences of behavior rather than isolated events, and strengthen controls protecting developer credentials, backup infrastructure, company-owned mobile devices, and payment environments.

Key Findings

  • Insikt Group identified 215 actively exploited CVEs in H1 2026, up 34% from 161 in H1 2025. 142 of the 146 vulnerabilities that could be exploited without prior authentication were also network-accessible, and 60 of the 82 remote code execution (RCE) vulnerabilities combined network access with no authentication requirement.
  • Similar to H1 2025, Recorded Future Malware Intelligence data showed the continued prominence of remote access trojans (RATs) throughout H1 2026. RATs led Insikt Group malware reporting, and Recorded Future Malware Intelligence submissions identified AsyncRAT as the top submitted malware family by total unique hashes and command-and-control (C2) configurations. AsyncRAT, Cobalt Strike, XWorm, Stealc, and REMCOS RAT remained in the top ten across H1 2025 and H1 2026.
  • H1 2026 AI-enabled malware activity was concentrated in AIM3 Levels 1 to 3, with threat actors using AI to augment existing malware and intrusion workflows rather than conduct fully autonomous attacks.
  • Ransomware operators continued to refine payload capabilities while relying on established intrusion methods, including ClickFix-style social engineering; exploitation of public-facing applications; abuse of legitimate tools such as s5cmd, PsExec, and AnyDesk; and techniques intended to reduce victims’ recovery options.
  • Android NFC malware was the most notable mobile malware trend in H1 2026, with families such as NFCShare and NGate abusing device NFC functionality to steal payment card data, relay contactless transactions, and facilitate ATM cash-outs.

AI-Enabled Cyberattacks

AI-enabled cyber threats became more visible in H1 2026, but the available evidence indicates that most observed activity still augmented existing tradecraft rather than replacing it with fully autonomous operations.

In the vulnerability ecosystem, the release of Anthropic’s Claude Mythos Preview reinforced the growing relevance of frontier models to offensive and defensive security research. Broader vulnerability reporting also increased following the model’s release under Project Glasswing: June National Vulnerability Database (NVD) disclosures were 43% above the previous six-month average, while Mozilla reported that Mythos Preview identified 271 vulnerabilities that it fixed in Firefox 150, compared with 22 security flaws fixed following its earlier testing with Claude Opus 4.6. Vendors, AI developers, and bug-bounty platforms like Microsoft, Anthropic, and HackerOne have also reported rising vulnerability discovery or submission volumes alongside broader adoption of AI-assisted research, adding pressure to validation, disclosure, and remediation workflows.

Despite the increase in vulnerability reports, AI has not changed the fundamentals of vulnerability management: Attackers still need to identify, validate, weaponize, and operationalize vulnerabilities that offer reach, reliability, and return on investment. This means that only a small proportion of newly discovered vulnerabilities are likely to be a threat.

Nonetheless, AI-enabled vulnerability research can still increase defender workload in three ways: It can produce more credible vulnerability reports that require triage; reduce the time available to mitigate exploitable vulnerabilities by accelerating exploit-path analysis and weaponization; and lower the cost of exploit development by helping skilled operators produce proof-of-concept (PoC) code, test attack paths, and iterate toward weaponizable exploits more quickly. For defenders, the near-term issue is therefore not a sudden flood of fully autonomous exploitation, but a narrower window to determine which vulnerabilities matter most and remediate them before threat actors operationalize them. Additionally, early H2 2026 reporting on the July 2026 Hugging Face incident demonstrated that autonomous agents can perform discovery, validation, weaponization, and operationalization with limited human intervention. Defenders should prepare by automating vulnerability enrichment, prioritization, and mitigation to reduce the gap between machine-speed attack development and defensive response.

The Vulnerability Equation infographic outlines the impact of automated capabilities on three areas: Vulnerability Reporting, Useable Exploit, and Impact on Target System. It shows that AI is making the vulnerability landscape noisier and more difficult to triage, making skilled threat actors more effective at writing exploits, and causing an early increase in actionable OS dependency vulnerabilities.
Figure 1: How automated capabilities will likely impact reporting, exploit development, and impact (Source: Recorded Future)

Malware reporting in H1 2026 showed more direct experimentation with AI-enabled capabilities compared to H1 2025. ESET identified PromptSpy as the first known Android malware to use generative AI (GenAI), using Google’s Gemini to interpret on-screen UI elements and generate step-by-step instructions to improve persistence across device layouts. Reporting on CANFAIL also showed threat actors using LLM-generated decoy logic or AI-assisted development artifacts to complicate analysis and facilitate malware delivery against Ukrainian organizations. These examples suggest that threat actors are testing AI in ways that can solve narrow operational problems: adapting to user interfaces, generating code or decoy logic, improving obfuscation, and supporting analyst confusion.

Threat actors also used AI-related products and ecosystems as delivery mechanisms. In February 2026, VirusTotal reported malicious OpenClaw skills disguised as useful automation for a local AI agent ecosystem, while Malwarebytes reported fake OpenClaw installers hosted on GitHub and surfaced through search results to deliver infostealers and proxy malware. This activity shows that attackers are exploiting user interest in AI tools in the same way they have historically abused popular software brands, distributing trojanized installers, malicious extensions, fake repositories, and dependency-based payloads through otherwise familiar channels.

As of H1 2026, Insikt Group assesses that most observed AI-enabled malware activity aligns with the low-to-mid-level stages of Recorded Future’s AI Malware Maturity Model (AIM3), specifically experimentation, adoption, and optimization, rather than fully autonomous AI-driven malware operations. Per the Recorded Future’s AIM3 framework, most publicly observed “AI malware” remains concentrated in Levels 1 to 3, where AI supports discrete operational tasks such as UI interpretation, persistence guidance, transaction timing, or operator guidance. Therefore, the near-term risk is not primarily self-directed malware operating independently, but rather the use of AI to make existing intrusion workflows faster, more convincing, more adaptive, and harder to analyze. Defenders should not expect a single control, model, or endpoint detection layer to reliably identify all AI-enabled malware activity. Instead, organizations should use defense-in-depth controls that can detect or disrupt different parts of the attack chain, including endpoint detection for script or installer activity tied to suspicious AI-themed downloads, extensions, repositories, or packages, mobile device management for accessibility service abuse and automated UI interaction, and restrictions on unapproved AI tools and installers.

Vulnerability Exploitation Trends

Key Takeaways

  • Network reachability and low access requirements compounded risk, as 142 of the 215 exploited CVEs were network-accessible and could be exploited without prior authentication; 60 of those also enabled RCE, while public exploits were available for 66 (31%).
  • Defenders faced both newly exploited flaws and persistent patch backlogs, as 162 CVEs were disclosed in 2025 or 2026, 53 predated 2025, and seventeen were dated from 2020 or earlier.
  • Threat actors reused post-exploitation playbooks across different initial vulnerabilities; StrikeShark applied the same six-tool stack across thirteen CVEs, while Storm-1175 linked credential theft, remote execution, data transfer, and ransomware tooling across ten. More broadly, stealware was the most common malware category, followed by offensive security tools, backdoors, remote access trojans, and ransomware.

Microsoft Remains the Leading Vendor for Exploited Vulnerabilities

In H1 2026, Insikt Group identified 215 actively exploited vulnerabilities, up 34% from 161 in H1 2025. From January to June, the number of exploited vulnerabilities increased by an average of seven vulnerabilities per month. Microsoft remained the vendor most frequently associated with exploited vulnerabilities, accounting for 40 unique CVEs, up from 28 in H1 2025, a 43% year-over-year increase. Red Hat ranked second with fifteen CVEs, Cisco third with thirteen, Vercel fourth with eleven, and Fortinet fifth with nine. By comparison, H1 2025’s top affected vendors after Microsoft were Apple with eight CVEs, Ivanti with seven, Linux with six, and SonicWall, Google, Fortinet, and Craft CMS with four each.

The exploited vulnerabilities affected products from 98 vendors, 67 of which were associated with only one CVE. This indicates that exploitation was not confined to the most frequently affected vendors. For defenders, this supports maintaining risk-based remediation across the full software inventory, including less common products that may receive less monitoring or slower patching than widely deployed enterprise platforms.

At the product-family level, Windows and Windows Server accounted for the largest H1 2026 concentration, with twenty unique CVEs, followed by Red Hat Enterprise Linux with thirteen, Vercel Next.js with eleven, Cisco Catalyst SD-WAN Manager with eight, and Apple iOS and iPadOS with seven. While Microsoft exploitation remained prominent, H1 2026 activity also increasingly involved enterprise Linux, application frameworks, and network management products. Several vendors’ vulnerabilities were also driven by concentrated exploitation of one product family rather than uniform interest across the vendor’s portfolio: all eleven Vercel CVEs centered on Next.js, eight of Cisco’s thirteen affected Catalyst SD-WAN, and thirteen of Red Hat’s fifteen affected Red Hat Enterprise Linux.

A treemap chart titled 'Top 10 Most Affected Vendors' displaying the number of actively exploited vulnerabilities in H1 2026. Microsoft leads with 40, followed by Red Hat (15), Vercel (11), Fortinet (9), Apple and Google (7 each), Ivanti (5), and Apache Software Foundation, Siemens, SolarWinds, and Synacor (4 each).
Figure 2: Most affected vendors (top ten, including ties) by number of actively exploited vulnerabilities in H1 2026 (Source: Recorded Future)

  • ✇Recorded Future
  • The Agentic SOC – From AI Theater to Real Defense
    Moving beyond "AI theater" with measurable KPIs: Security teams must distinguish between genuine value and "productivity theater." Success requires defining concrete KPIs—such as cost improvement, risk reduction, and speed—to measure true ROI, rather than deploying AI tools without a clear strategic purpose. Mitigate new autonomous risks: The shift to an agentic SOC introduces distinct threats, such as indirect prompt inject
     

The Agentic SOC – From AI Theater to Real Defense

31 de Agosto de 2026, 21:00
  • Moving beyond "AI theater" with measurable KPIs: Security teams must distinguish between genuine value and "productivity theater." Success requires defining concrete KPIs—such as cost improvement, risk reduction, and speed—to measure true ROI, rather than deploying AI tools without a clear strategic purpose.
  • Mitigate new autonomous risks: The shift to an agentic SOC introduces distinct threats, such as indirect prompt injection, and creates visibility gaps that traditional SIEM platforms are not built to handle. Organizations should shift from post-event observability to proactive control mechanisms, such as placing strict constraints on agent compute and communication.
  • Redefine the analyst’s role for speed at scale: As defensive timelines compress from days to seconds, the fundamental unit of work will evolve from alert handling to agent management. The human role is shifting from a manual processor to an architect, responsible for setting objectives, defining operational constraints, and overseeing the behavior of AI agents.

For security teams, AI has generated both more excitement and more confusion than any technology in the last decade. As threat actors experiment with AI to hone their attacks, defenders are trying to determine which AI investments will help them measurably reduce risk.

Matthew Farmer, Accenture’s Managing Director of Security Operations in EMEA, joined Recorded Future’s co-founder Christopher Ahlberg and CTO and co-founder Staffan Truvé in a recent discussion to discuss the agentic SOC and what it takes to move from “AI theater” to real defense. Read on to see the key highlights from the discussion.

Avoiding the "productivity theater" trap

While AI is demonstrably transforming investigation and decision-making layers in SecOps, there’s a significant risk that organizations are falling into what Farmer calls "AI productivity theater."

"We can all agree that there's great production value around a lot of AI capabilities and AI products," he said. "But there are also organizations that are really struggling to achieve any kind of return on investment on their AI.”

The panel noted that the difference between success and failure doesn’t necessarily have anything to do with being in a regulated or non-regulated industry. It’s more about the ability to move past the theater by defining concrete KPIs.

“A lot of what people want to achieve with AI, we can already achieve with existing machine learning or SOAR automation capabilities,” Farmer said. So rather than simply deploying an AI solution for the sake of being AI-enabled, organizations need to ask whether they’re solving for cost improvement, risk reduction, or speed. They need to understand their KPIs so they can measure their true ROI.

Navigating technical and operational challenges

When it comes to bringing new AI solutions online, the panel noted that SOCs often face administrative, legal, and compliance limitations that eclipse any technical hurdles.

They also agreed that data quality and lack of context — “two sides of the same coin” according to Truvé — remain fundamental challenges.

Farmer noted that, “In the new world of tokenomics, it costs just as much money to troll through poor quality data as high-quality data.” It’s essential that security organizations feed only the best intelligence into their AI tools.

Assessing new risks, from democratization to agentic threats

Farmer said that security organizations used to ask a key question: “Do those [threat actors] with the capability have the motive, and do those with the motive have the capability?” We’re now in a world where non-capable threat actors can use AI to capably launch highly sophisticated attacks.

Threats are also becoming more structural. The panel highlighted "indirect prompt injection"—where agents are manipulated by the very instructions they read—as a new, distinct threat vector.

As companies deploy a digital workforce of AI agents, they should consider applying the same security principles of permissions, monitoring, and accountability to agents that they do to humans. But that may not be sufficient. "One big difference [between an agent and a human] is that an agent can spawn off a thousand clones of itself," Truvé said.

A critical challenge facing security teams is that the current observability space of SIEMs and traditional monitoring platforms isn’t built to track the internal state of an LLM.

"You can observe what ports they talk on, you can write that to a SIEM,” Ahlberg said. “But you’re not observing what’s happening inside the LLM.”

The panelists suggested that rather than relying solely on post-event observability, security teams should rethink how they control agents. Instead of setting up easily bypassed guardrails, security teams need to be better at constraining what each agent can do and ask for.

“You could imagine giving them a budget in terms of compute, communication, and delegation,” said Truvé. “These things run too fast. When you’re observing it, it’s already going to be too late.”

Preparing for the move to autonomous defense

According to the panelists, the shift toward autonomous defense is inevitable. "We can choose to go early, or we can choose to go late,” Farmer said. “But I think the decision is made for us."

However, it doesn’t need to take years to begin realizing big benefits from AI. To do so, security organizations should consider:

  • Target high-friction areas, using AI to solve specific bottlenecks where addressable cost is low and ROI is immediate.
  • Use outcome-based metrics, measuring success through model accuracy, escalation precision, and scan turnarounds rather than simple activity tracking.
  • Assume breach, building defensive resilience that will pay dividends in the future.

On that last point, Farmer said he thinks that as teams grow more resilient, they develop a better appetite for deploying automated solutions — and that in turn strengthens their overall security posture.

The future of defense: Intelligence and speed at scale

According to the panel, the most profound change moving forward won’t just be the technology—it’ll be the velocity coupled with intelligence required for defense. "In three years, the main difference will be speed," Truvé predicted. "Defensive timelines will compress from days to minutes or seconds."

Ensuring security will require organizations to move past traditional constraints as they simply won't have time to manually ingest, analyze, and move intelligence. Taking detection engineering as an example, Farmer noted, “If we have to deliver more detection rules faster, we have to break that linear model between volume, speed, and headcount.” Consequently, SOCs will rely increasingly on high-quality, timely intelligence to enable rapid, automated decision-making.

As this shift occurs, the fundamental unit of work for a security analyst will evolve from handling individual alerts to managing and overseeing the agents that process them. In this new era, the human will remain essential—not as a manual processor of alerts, but as the architect who sets objectives, defines constraints, and monitors the behavior of the agents defending the enterprise.

Watch the full webinar here.

To see how your organization can use the Recorded Future Platform to better defend at machine speed, take our quick interactive tour.

  • ✇Recorded Future
  • BlueDelta Targets Defense and Diplomacy with HOOKEDGE
    Executive Summary Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The campaigns delivered a lightweight Windows batch-script backdoor, dubbed "HOOKEDGE," via macro-enabled Microsoft Word documents using diplomatic-themed lures, including material impersonating Spain's Ministry of the Presidency, Justice and Relations with
     

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

26 de Agosto de 2026, 21:00

Executive Summary

Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The campaigns delivered a lightweight Windows batch-script backdoor, dubbed "HOOKEDGE," via macro-enabled Microsoft Word documents using diplomatic-themed lures, including material impersonating Spain's Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 2025 meeting between Spanish and Moldovan officials.

Insikt Group assesses with moderate confidence that this activity was conducted by BlueDelta (which overlaps with APT28, Fancy Bear, and Forest Blizzard), a Russian state-sponsored threat group attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). This assessment is based on significant code and tradecraft overlap between HOOKEDGE and the HEADLACE backdoor used in prior BlueDelta campaigns, consistent infrastructure patterns, and targeting consistent with known Russian intelligence collection priorities.

HOOKEDGE shares HEADLACE's core architecture, abusing legitimate webhook services for command-and-control (C2), payload staging, and data exfiltration, enabling malicious activity to blend with legitimate network traffic while reducing the operational overhead of dedicated infrastructure. The implant has undergone continuous refinement between September 2025 and April 2026, likely to evade automated sandbox environments and adapt to reduced free-tier API limits on webhook[.]site.

BlueDelta continues to invest in lightweight, easily adaptable initial-access tooling to support intelligence collection against European government and diplomatic targets. Rather than introducing new capabilities, the group has steadily refined its existing tradecraft, emphasizing operational resilience by adapting established tooling to evolving defensive measures and infrastructure constraints.

Organizations should prioritize blocking macro execution from internet-originated documents and implementing detection coverage for scheduled task abuse, headless Microsoft Edge execution, and outbound connections to webhook services.

Key Findings

  • Between late September 2025 and early April 2026, BlueDelta conducted a series of initial access campaigns against defense manufacturing and diplomatic organizations in Romania, Spain, and Türkiye. BlueDelta used macro-enabled Word documents to deploy HOOKEDGE, a lightweight batch-script backdoor that shares significant code and tradecraft overlap with BlueDelta’s earlier implant, HEADLACE.
  • The campaigns employed both diplomatic-themed and generic lures. Early activity impersonated Spanish government material, while later campaigns adopted generic macro-enablement lures. One diplomatic lure was created shortly after a meeting between Spanish and Moldovan officials, potentially reflecting an effort to collect intelligence relevant to Russia ahead of Moldova’s September 2025 parliamentary elections.
  • BlueDelta continued to refine HOOKEDGE between September 2025 and April 2026, introducing changes to lure documents, execution methods, and beaconing intervals while maintaining the malware's core functionality and infrastructure model.
  • For targets assessed as having higher intelligence value, BlueDelta deployed a second-stage HOOKEDGE payload with a much shorter beaconing interval. This gave operators more responsive tasking and follow-on activity, while keeping the webhook endpoints used for initial access from being exhausted.
  • BlueDelta has historically demonstrated a preference for legitimate internet services (LIS) to facilitate C2, payload staging, and data exfiltration, with webhook[.]site’s free tier serving as the group’s exclusive choice across these campaigns.

Background

BlueDelta is a Russian state-sponsored threat group attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), and overlaps with activity publicly tracked as APT28, Fancy Bear, and Forest Blizzard. The group has conducted espionage-focused cyber operations for more than a decade, consistently targeting government, diplomatic, defense, and policy-related organizations in support of Russian intelligence requirements.

BlueDelta has a well-documented history of obtaining initial access through spearphishing, credential theft, and lightweight custom tooling. Previous campaigns have employed malicious documents, Windows batch scripts, and living-off-the-land techniques (LotL), frequently abusing LIS and free web infrastructure for C2, payload staging, and data exfiltration. Insikt Group documented BlueDelta's 2023 use of the HEADLACE malware family, a lightweight, batch-based backdoor used during the early stages of intrusions to execute follow-on payloads and commands in initial access campaigns targeting organizations across Europe.

The activity detailed in this report represents a direct continuation of those operations. The HOOKEDGE backdoor shares significant code and tradecraft overlap with HEADLACE, demonstrating BlueDelta's continued preference for lightweight, easily modified malware that can be rapidly adapted to operational requirements. Similar activity has also been reported publicly by Lab52 under the name Operation MacroMaze.

Threat Analysis

Lure Documents and Targeting

BlueDelta's choice of lure documents across these campaigns reflects deliberate targeting of European diplomatic audiences and reveals collection priorities consistent with known Russian intelligence requirements. Between late September 2025 and early April 2026, Insikt Group identified several malicious macro-enabled Word documents likely used by BlueDelta in initial access campaigns targeting government or diplomatic personnel in multiple European countries.

The earliest identified lure, first seen on September 26, 2025, purported to be a September 15, 2025, meeting agenda from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, as shown in Figures 1 and 2. Although the document’s authenticity could not be verified, BlueDelta has historically used authentic government documents, including publicly available material, as phishing lures.

Screenshot of a Microsoft Word document containing a Spanish government meeting agenda from the Ministry of the Presidency, Justice, and Relations with the Cortes, dated September 18, 2025."
Figure 1: Screenshot of Spain’s Ministry of the Presidency, Justice, and Relations with the Cortes document (Source: Recorded Future)

  • ✇Recorded Future
  • Recorded Future Launches AI Alert Filtering
    AI Alert Filtering is now available. Powered by Recorded Future AI, it automates the first pass of filtering Alerts by relevance so analysts prioritize faster while keeping control. Starting today, Recorded Future is launching AI Alert Filtering, an AI agent that automatically filters every Alert by relevance before an analyst opens it. At scale, Alerts surface a lot of intelligence to work through, and the volume is only accelerating a
     

Recorded Future Launches AI Alert Filtering

25 de Agosto de 2026, 21:00
AI Alert Filtering is now available. Powered by Recorded Future AI, it automates the first pass of filtering Alerts by relevance so analysts prioritize faster while keeping control.

Starting today, Recorded Future is launching AI Alert Filtering, an AI agent that automatically filters every Alert by relevance before an analyst opens it.

At scale, Alerts surface a lot of intelligence to work through, and the volume is only accelerating as threat actors are using AI to find vulnerabilities, spin up phishing infrastructure, and harvest credentials at a speed and scale that wasn't possible before. AI Alert Filtering turns that same AI advantage back on the problem, automating the first pass of Alert relevance so analysts spend their time on what actually warrants attention.

This gives analysts the benefit of seeing the highly relevant Alerts without giving up control. Customers with early access saw an average reduction in alert volume of around 63%, though results may vary based on rule configuration and use case.

Prioritizing intelligence at scale

Powered by Recorded Future AI, AI Alert Filtering takes on the first pass of prioritization, drawing on the Intelligence Graph® to classify references with the full context of Recorded Future's threat intelligence behind every call, not just the text of the reference itself. It sorts references by relevance, summarizes what came through, and explains its reasoning.

What we built

  • High and Low Relevance sorting: Every reference inside a fired Alert is classified against the rule's intent. The High Relevance section loads first. Low Relevance items are still there if you need them; you're just not wading through them by default.
  • AI summary at the top of every alert: Each Alert is delivered with a summary covering what came through, so analysts may quickly determine whether it demands immediate attention.
  • Custom intent per rule: You can define exactly what the AI should prioritize, beyond the default intent Recorded Future ships with the rule. For example, "this is for ACME Bank, not ACME Center" sharpens results without rebuilding the rule from scratch.
  • Optional auto-dismiss for empty alerts: When no references meet the relevance threshold, the Alert may be automatically dismissed instead of landing in your queue. Less to filter out, with the full details retained if you need to review it later.
  • No data loss: AI Alert Filtering changes what gets surfaced, not what gets stored. The original, unfiltered Alert details are always available in the Portal.
Figure 1: Relevance sorting

  • ✇Recorded Future
  • Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
    Mexico faces an increasingly complex cyber threat landscape, including ransomware, state-sponsored espionage, financial malware, data breaches, hacktivism, and cyber-enabled organized crime. Its 2025–2030 National Cybersecurity Plan seeks to address these challenges through stronger governance, new legislation, a national operations center, integrated incident-response teams, cyber exercises, AI-enabled defenses, and expanded regional cooperation. Insikt Group assesses ra
     

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

24 de Agosto de 2026, 21:00
Mexico faces an increasingly complex cyber threat landscape, including ransomware, state-sponsored espionage, financial malware, data breaches, hacktivism, and cyber-enabled organized crime. Its 2025–2030 National Cybersecurity Plan seeks to address these challenges through stronger governance, new legislation, a national operations center, integrated incident-response teams, cyber exercises, AI-enabled defenses, and expanded regional cooperation. Insikt Group assesses ransomware as the leading threat while highlighting growing risks from foreign threat actors and credential theft. We recommend leveraging threat intelligence, applying international security frameworks, and fostering cyber education. Ultimately, Mexico’s progress will depend on turning an ambitious roadmap into durable institutions, effective regulation, and sustained international cooperation.

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Mexico has no shortage of cyber threats. Ransomware attacks are rising, criminal groups are exploiting stolen credentials and financial malware, and state-linked threat actors increasingly view the country’s government agencies, universities, and critical infrastructure as attractive targets. Mexico’s new National Cybersecurity Plan (hereinafter referred to as “Plan”), introduced in December 2025, recognizes many of these risks. However, it remains uncertain as to whether the government can build the institutions needed to address them proactively.

Mexico is ranked as a "Tier 2" nation in the ITU's 2024 Global Cybersecurity Index, placing it alongside Canada, Ecuador, and Uruguay in the upper ranks, trailing the United States (US) and Brazil, which have reached Tier 1 in the Americas. Despite that standing, Mexico is generally perceived by cyber experts as lagging behind international standards in institutional capacity-building, with international cooperation identified as an area requiring growth.

The question of whether the government can build the proper institutions has become more urgent in the aftermath of the FIFA World Cup 2026, which provided a high-profile stress test for Mexico’s digital defenses. With the tournament over and implementation of the government’s 2025-2030 cybersecurity plan beginning in earnest, Mexico faces a major opportunity to improve its cyber posture.

For this reason, the Plan represents a major opportunity for Mexican authorities to bring the country’s cyber readiness to the next level. Although there have been attempts to advance national cybersecurity policy, they have failed to gain traction. With this new Plan, President Claudia Sheinbaum's administration has committed to full implementation over the course of her term, aided by her party's majority control of Congress.

The Plan lays out a six-phase roadmap designed to gradually build Mexico’s cybersecurity capabilities through 2030, with later phases intended to deepen and institutionalize them.

  • The 2025 Foundation Phase established a general framework for governance, risk management, incident reporting, and coordination, as well as initial steps to deepen international cooperation, including Mexico’s formal membership in the Latin America and Caribbean Cyber Competence Centre (LAC4) and a cybersecurity Memorandum of Understanding (MOU) with Brazil.
  • The 2026 Expansion Phase, now underway, focuses on translating that framework into institutions through the passage of a new General Cybersecurity Law in Mexico, creation of a National Cybersecurity Operations Center, and integration of federal computer security incident response teams (CSIRTs).
  • The 2027 Consolidation Phase would establish a National Cyber Range for red team and blue team exercises.
  • The 2028 Maturation Phase would incorporate AI into cyber defense and develop a regional response center.
  • The 2029 Leadership Phase aims to position Mexico as a cybersecurity services exporter across Latin America and the Caribbean.
  • The 2030 Transformation Phase culminates in the establishment of a permanent Cybersecurity Observatory to track incidents, threats, and emerging technologies.

Threat Landscape

In a recent report, Insikt Group assessed Mexico's threat landscape across six persistent categories:

Ransomware is identified as the dominant threat. From January 2020 through April 2026, Insikt Group documented 223 ransomware incidents involving 64 groups and over 100 victims in Mexico. The top ransomware groups were LockBit, Qilin, CL0P, Kazu, and ALPHV (BlackCat), with government, manufacturing, information technology (IT), and food and beverage as the sectors most heavily impacted.

op Five Ransomware Groups Impacting Mexico in 2025,' displaying the number of attacks over time from May 2020 to April 2026. The chart tracks activity for five ransomware groups: ALPHV (BlackCat), CL0P (FANCYCAT), Kazu, LockBit, and Qilin.

Top Five Industries Impacted by Ransomware Groups in Mexico in 2025,' showing the number of attacks across five key industries from May 2020 to April 2026. The industries tracked are Food and Beverage, Government, Government - Non-US, Information Technology, and Manufacturing, with colored lines plotting the volume of attacks against each sector over time.

Figure 1: Top five ransomware groups and top five industries impacted by ransomware groups in Mexico, 2025 (Source: Insikt Group)

  • ✇Recorded Future
  • PurpleDelta's Fraudulent Employment Operations
    Executive Summary Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. PurpleDelta operators maintained at least 22 fabricated personas across multiple clust
     

PurpleDelta's Fraudulent Employment Operations

17 de Agosto de 2026, 21:00

Executive Summary

Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. PurpleDelta operators maintained at least 22 fabricated personas across multiple clusters, some of which were supported by AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents sourced from an illicit ID-generation service, and were highly likely to be actively employed by at least ten organizations.

PurpleDelta operators demonstrate a high operational tempo to this day. In some cases, the operators have applied to at least 60 positions per day across multiple job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas simultaneously, and maintained detailed tracking spreadsheets to coordinate applications across identities. During job interviews, they used screen recording software alongside AI transcription and chatbot tools to generate real-time answers, often repeating ChatGPT responses verbatim. Once employed, operators recorded internal meetings at victim organizations and used Google Translate to draft pre-written excuses to justify using personal devices and bank accounts for work. Evidence from recorded sessions also indicates that PurpleDelta operators coordinated via Telegram and Slack, and at least two individuals were identified as facilitators who maintained company-issued hardware for the PurpleDelta operators.

Insikt Group assesses that this cluster of activity is consistent with the broader North Korean IT worker threat and presents material risk to organizations hiring for remote technical roles. Companies that have observed indicators listed in Appendix A should treat this as a potential active compromise and review the employment history and access privileges of matching individuals.

Key Findings

  • Insikt Group has identified at least 22 fabricated personas linked to multiple PurpleDelta clusters that submitted applications to over 1,100 companies across the software, staffing, healthcare, and financial sectors, with operators submitting as many as 60 or more applications per day across at least 8 job platforms.
  • These clusters of PurpleDelta operators are highly likely to have been actively employed at ten or more organizations, with confirmed or probable placements at companies that pose an ongoing and material insider threat.
  • PurpleDelta demonstrated a high degree of operational sophistication, using multi-account management browsers, multiple Chrome profiles, AI-generated profile photos, custom ChatGPT assistants, and real-time AI transcription tools to deceive hiring managers during interviews, sometimes repeating AI-generated responses verbatim.
  • Once employed, PurpleDelta operators recorded internal meetings at victim organizations, used screen recording software during work sessions, and drafted pre-written Google Translate excuses to justify the use of personal devices and personal bank accounts.
  • Video evidence indicates that PurpleDelta operators use identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, and coordinate via Telegram and Slack, with support from facilitators who procure and maintain company-issued hardware on the operators' behalf.

Background

PurpleDelta is Recorded Future's designation for the cluster of activity associated with North Korean IT workers, a state-directed network of covert technology laborers operating across global freelancing platforms and corporate hiring pipelines. The group overlaps with threat actor designations used by other vendors, including Jasper Sleet, UNC5267, Wagemole, and Famous Chollima. PurpleDelta operators pose as independent contractors and job-seeking developers to secure remote employment at organizations worldwide, with earnings systematically funneled through layers of individual facilitators, shell companies, and money-laundering front companies, ultimately financing the North Korean regime's sanctioned military and nuclear programs.

PurpleDelta operators employ extensive persona management tradecraft to obscure their nationality and true affiliation. Each operator maintains multiple fabricated identities across platforms, including GitHub, LinkedIn, Medium, Upwork, and a range of smaller freelancing sites, with personas deliberately constructed to project credibility through aged accounts, curated technology stacks, and cross-platform social proof. These identities are reinforced through the use of AI tools, temporary phone number services, anti-detect browsers, and resume-building platforms. In addition to generating illicit revenue, Insikt Group has observed signs of overlap with several North Korean state-sponsored groups, including PurpleBravo, a related cluster of activity that deploys malware through fraudulent recruitment campaigns targeting software developers primarily in the cryptocurrency space, indicating the broader potential for intelligence collection, downstream compromise, and supply-chain risk.

Threat Analysis

As part of Recorded Future’s ongoing tracking of PurpleDelta, Insikt Group has documented multiple clusters of North Korean IT workers since 2025 that are likely based in China. Operators in one of these clusters applied to jobs at over 1,100 companies. Almost half of the companies (~41%) to which the operators applied were in the IT and software services space, followed by staffing and consulting (~26%), and healthcare and biotechnology (~10%). Roughly 80% of the companies are based in North America, but the operators applied to companies in every region of the world. Many of the operators have a nexus in Shenyang, China, as indicated by their professional profiles, social media presence, and artifacts observed on their systems.

A pie chart titled 'Industry Breakdown of Companies PurpleDelta Operators Applied To' shows the distribution of industries targeted by fraudulent operators: Software/SaaS accounts for 41%, Staffing/Consulting 26%, Healthcare/Biotech 10%, Fintech/Insurance 7%, AI/Data/Security 6%, Consumer/Media 4%, Industrial/Public Sector 3%, and Other 2%
Figure 1: Breakdown of industries of the companies applied to by PurpleDelta operators (Source: Recorded Future)

  • ✇Recorded Future
  • CopyCop Targets AI Investment in Armenia
    The Russian influence network CopyCop (Storm-1516) very likely targeted the joint United States (US) and Armenian-backed Firebird AI data center in Hrazdan, Armenia, as part of a broader campaign to undermine Armenia's westward geopolitical and economic realignment. Between June 24 and July 13, 2026, Insikt Group documented three separate CopyCop media impersonations targeting the facility ahead of its July 2026 opening. These impersonations fabricated an i
     

CopyCop Targets AI Investment in Armenia

17 de Agosto de 2026, 21:00

The Russian influence network CopyCop (Storm-1516) very likely targeted the joint United States (US) and Armenian-backed Firebird AI data center in Hrazdan, Armenia, as part of a broader campaign to undermine Armenia's westward geopolitical and economic realignment. Between June 24 and July 13, 2026, Insikt Group documented three separate CopyCop media impersonations targeting the facility ahead of its July 2026 opening. These impersonations fabricated an imminent earthquake risk, cast doubt as to the facility's economic and infrastructure viability, and, most recently, impersonated an official Iranian military communications that justified treating the data center as a legitimate military target. Reach expanded substantially across the three instances, growing from limited initial engagement to over 1.6 million combined views by the third, indicating growing audience viewership as the campaign progressed.


CopyCop will likely continue targeting Western investment in Armenia, given the influence operation’s demonstrated reuse of the same social media amplifier network against other Armenia-linked Western investment projects. The network’s targeting of a major AI project likely seeks to capitalize on heightened media attention to booming AI investments and megaprojects to amplify pro-Russian narratives.

  • ✇Recorded Future
  • Malware Crypting Services and the Threat Actors Who Sell Them
    Executive Summary Crypting services and products modify malicious payloads to help threat actors bypass detection, complicate analysis, and preserve malware usability after exposure. Although basic crypting consists of encrypting or obfuscating a customer-supplied payload, mature providers increasingly operate as broader malware-enablement services. Their offerings often combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery
     

Malware Crypting Services and the Threat Actors Who Sell Them

12 de Agosto de 2026, 21:00

Executive Summary

Crypting services and products modify malicious payloads to help threat actors bypass detection, complicate analysis, and preserve malware usability after exposure. Although basic crypting consists of encrypting or obfuscating a customer-supplied payload, mature providers increasingly operate as broader malware-enablement services. Their offerings often combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery packaging, and post-detection “cleaning” or re-crypting services.

Insikt Group analyzed 24 threat actors advertising crypting services and products within the past year and identified a market that is competitive, reputation-driven, and heavily focused on Windows payloads. Providers advertise through underground forums, restricted communities, chat platforms, clearnet sites, and social media accounts. They compete through tiered pricing, antivirus (AV) detection scores of crypted samples, discounts, malware-developer partnerships, private or shared stubs, and promised turnaround times for re-crypting detected payloads.

Advertised crypter capabilities vary by provider, but the underlying objectives are consistent: reduce detection, delay or prevent analysis, and support stealthier payload execution. Because crypted payloads are designed to defeat both static and dynamic analysis, defenders should prioritize behavioral detection over static indicators. See the Outlook and Mitigations section for details.

Key Findings

  • AV and endpoint detection and response (EDR) tools should not be treated as sufficient standalone protection against crypted payloads. Defenders should pair endpoint controls with behavioral detection, telemetry correlation, upstream hunting, suspicious process monitoring, and rapid triage of suspicious samples.
  • Popular crypting service providers primarily advertise support for Windows payloads, with no identified advertising for macOS or Linux crypting services. However, although Windows environments were most frequently targeted by the services reviewed in this report, they are not inherently more susceptible to the execution of crypted payloads.
  • Crypted payloads increase the likelihood of successful malware execution and delayed detection, but they do not independently provide end-to-end intrusion capability. Downstream activities, such as lateral movement, data theft, ransomware deployment, and follow-on compromise, depend on the embedded malware and the operator's objectives.
  • Crypter risk varies significantly with provider maturity and technical capability: advanced crypters offer portability, anti-analysis, process injection, persistence, and security product bypass capabilities, whereas less-advanced crypters generally provide basic payload obfuscation techniques.
  • Crypter capabilities are generally not novel individually, but their commercial packaging makes established defense-evasion tradecraft easier to access, reuse, and operationalize. The significance of crypters lies less in technical innovation than in making mature evasion methods available as paid services.

The Crypter Landscape

What Is a “Crypter”?

“Crypting” is what threat researchers generally refer to as a service or product wherein a file, almost exclusively a malicious executable of some kind, is encrypted to bypass malware detection technologies. The result of a crypting service is a malicious payload that modifies the supplied executable in ways that deter defenders and endpoint security solutions (namely, AV and EDR products) from detecting and analyzing it.

How Does Crypting Work?

While the core functionality of a crypting service or product is to encrypt a payload, services vary in the capabilities they provide. These capabilities can range from the encryption algorithms used, which are often proprietary, to behavioral adjustments for how the resultant payload will execute in a victim environment. For instance, many crypting services include execution guardrails or methods for indicator suppression, such as ensuring execution fails in virtual environments or performing environmental scanning before execution to determine whether the payload is running in an analysis or sandbox environment.

By using crypting services, threat actors can evade detection and prevent their malicious code from being easily exposed to researchers, an important consideration for those who wish to reuse payloads for extended periods without detection.

Who Is Selling Crypting Services?

The crypter landscape comprises a community of criminal threat actors that often operate on restricted or closed networks, including the dark web and underground forums, to market and sell their crypting services. Threat actors may also opt to market their services on clearnet websites they own and operate. In some instances, threat actors may be accessible only via messaging platforms, such as Telegram or TOX, which likely mask their exposure and reduce the likelihood of sensitive data leaking through forum chats. Finally, some threat actors have created social media accounts where they post updates on their services, partnerships, pricing, and links through which interested buyers can inquire about purchases.

Additionally, partnerships between malware developers and crypting service providers are not uncommon. For instance, a well-established crypting service provider on underground forums, “GoldenCrypt”, is reportedly affiliated (1, 2, 3) with multiple malware families, including FvncBot, Albiriox, and Mirax. The level of affiliation between a crypting service provider and a malware developer can range widely, from providers with loose reputational ties to developers who are mainly affiliated with one hacking group and will opportunistically provide services to third parties. However, these partnerships are often a marketing strategy that crypting service providers use to secure kickbacks and boost positive reputational sentiment.

All of these services come at widely varying costs, typically based on core factors. For instance, crypting service fees are often tied to the volume and types of files to be encrypted, as well as the duration of service, with almost all crypting service providers offering tiered payment options along these lines. The actual prices of these tiers are pegged to additional factors related to the provider and their product, including the reputation of the threat actor, the capabilities of their encryption service, the promise that a crypted payload is fully undetectable (FUD), and additional features provided to the buyer. Threat actors will support the assertion that their payloads are FUD by using multi-AV platforms, the most common of which is KleenScan, a service that allows threat actors to scan samples without storing and potentially exposing the samples to researchers. As with other legitimate services, service providers also advertise discounts and similar deals to remain competitive with their peers.

Who Is Using Crypting Services?

Many threat actors have been observed in the wild using crypting services due to their stealth capabilities. All malware types can be crypted, and the key factors determining whether a threat actor can use a crypting service are the targeted device’s operating system and the payload’s programming language. For instance, the most common crypting services are geared toward Windows .exe and .dll payloads. Still, considerations such as whether a payload is coded in .NET, C, or C++ can provide additional capabilities for crypted payloads or, in other instances, prevent certain payloads from being crypted.

While the use of crypting services is common among threat actors, it is by no means ubiquitous. Due to sometimes prohibitive pricing strategies and an environment that often relies on reputational checks before purchase, crypting services are often used only by well-established criminal threat actors or larger threat actor groups that have their own specialist or custom tooling for crypting payloads. Furthermore, as discussed previously in this report, not all crypting services support all types of payloads. While this does not expressly ensure that a payload cannot be crypted, threat actors seeking to crypt more unique types of executables may find their options limited or even nonexistent.

Nevertheless, crypting services are commonly marketed by threat actors and are commonly implemented by professional threat actor groups. Multiple open-source reports on high-impact cyberattack campaigns have supported this. For instance, in July 2025, eSentire reported an association between PureRAT, a remote access trojan (RAT) first advertised in January 2023, and GhostCrypt, a crypting service sold by an underground forum member of the same moniker, in an attack that impacted a public US accounting firm in May 2025.

Crypting Service Characteristics

Insikt Group investigated 24 crypting service or product providers active within the past year and identified the various capabilities advertised by each. This information helped determine the capabilities most commonly displayed by crypting services, products, and the payloads they create, and provided insight into the capabilities most desirable to customers buying these services and products. A heat map of the techniques advertised by these threat actors is shown in Figure 1, below. (The list of MITRE ATT&CK techniques shown in Figure 1 can also be found in Appendix B.)

A MITRE ATT&CK heat map showing the specific tactics and techniques observed in crypting advertisements. The chart is organized into nine categories: Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Discovery, and Command and Control, with the number of observed techniques listed under each category.
Figure 1: MITRE ATT&CK Enterprise tactics and techniques described in crypting advertisements (Source: Recorded Future)

Recorded FutureがGartner® サイバー脅威インテリジェンス・テクノロジー部門のMagic Quadrant™のリーダーの1社に位置づけられました。

1 de Julho de 2026, 21:00

Recorded FutureがGartner® サイバー脅威インテリジェンス・テクノロジー分野のMagic Quadrant™のリーダーの1社に位置づけられました。

17のベンダーを対象に業界全体の動向や各ベンダーの位置付けを抱括的に分析しています。

[レポートの全文をダウンロードする(英語版のみ)]

  • ✇Recorded Future
  • Mines, Minds, and Machines: The Journey of AI
    Minerals become chips. Chips supply data centers. Data centers power the training of models, and models are acquiring arms and legs. Mines, Minds, and Machines traces the supply chain of the fourth industrial revolution, and shows how geopolitical rivalry and cyber operations now run along every link.
     

Mines, Minds, and Machines: The Journey of AI

10 de Agosto de 2026, 21:00
Minerals become chips. Chips supply data centers. Data centers power the training of models, and models are acquiring arms and legs. Mines, Minds, and Machines traces the supply chain of the fourth industrial revolution, and shows how geopolitical rivalry and cyber operations now run along every link.

  • ✇Recorded Future
  • The Hugging Face Hack Was Cheap Persistence at Work
    The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow. The agent discovered and exploited previously unknown vulnerabilities. The more consequential development came afterward. Over a four-and-a-half-day campaign, it carried out roughly 17,600 actions against Hugging Face’s infrastructure. Most of those actions failed. The operation advanced because each failure imposed little cost, and the next attempt could begin immediately. The
     

The Hugging Face Hack Was Cheap Persistence at Work

9 de Agosto de 2026, 21:00

The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow.

The agent discovered and exploited previously unknown vulnerabilities. The more consequential development came afterward. Over a four-and-a-half-day campaign, it carried out roughly 17,600 actions against Hugging Face’s infrastructure. Most of those actions failed. The operation advanced because each failure imposed little cost, and the next attempt could begin immediately. The system could keep exploring, reconstruct its tools, revisit abandoned paths, and test another hypothesis without fatigue or meaningful opportunity cost.

That changes both the economics and the tempo of cyber offense.

For most of cybersecurity history, sustained intrusion activity has been constrained by human attention. Skilled operators have limited time, and every unproductive hour spent on one target is unavailable for other work. AI erodes that constraint. The significance of 17,600 actions lies as much in their concentration as in their cost. They occurred within four and a half days.

AI enables concentration of effort in time. A motivated attacker has always been able to spend more on a valuable target, but money alone could not make human operators sustain this tempo. The new advantage is the ability to concentrate thousands of attempts on a single environment before a defender’s traditional processes can assemble the evidence.

The future threat is therefore unlikely to resemble a single, infallible artificial hacker. It is more likely to resemble a flood of low-confidence activity probing the accumulated technical debt of modern enterprises.

Large organizations are especially fertile terrain. Their environments have developed over decades, layering legacy systems with cloud services and inherited trust relationships that no one designed as a whole. An autonomous system need not outperform the best human attacker. It only needs to search for that complexity cheaply and quickly enough to find the few combinations that work before defenders can assemble the pattern.

The OpenAI incident occurred under highly unusual conditions. The models were being evaluated for advanced cyber capabilities with reduced refusals, substantial inference resources, and an objective that encouraged persistent exploration. OpenAI has also said that the most capable research prototype involved was never intended for public release. Its complete technical investigation remains unfinished.

Those caveats should temper sensationalism. They do not invalidate the warning.

Frontier capabilities diffuse. Models become smaller, cheaper, and easier to operate. Techniques developed in advanced laboratories eventually migrate into commercial tools, open-source projects, state programs, and criminal services. Recorded Future’s research had previously found that complex autonomous cyber operations remained beyond the practical capabilities of generally available models at the time, while the broader trajectory pointed toward more complex agentic operations. The Hugging Face incident suggests that this transition is occurring faster than many defenders expected.

The question is no longer whether AI can execute a multistage intrusion under the right conditions. It is how quickly those conditions will become cheaper to reproduce.

Layered defense for the agentic era.

Prevention remains essential, yet this incident also exposes its limits.

The first breakthrough did not occur within Hugging Face’s perimeter but stemmed from a previously unknown vulnerability in an Artifactory component (CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018) in OpenAI’s evaluation environment. Before the campaign reached Hugging Face, neither Hugging Face nor an external intelligence provider had a factual basis to know that this specific path existed or that Hugging Face would become the target.

If agentic systems increase the frequency with which unknown vulnerabilities are discovered and exploited, organizations must assume that some first lines of defense will fail without warning. The stronger defensive question is how many independent opportunities remain for detecting and constraining what follows.

The more useful objective is to prevent one success from becoming twenty.

The Hugging Face compromise advanced because the agent could convert access in one environment into authority elsewhere. A compromised workload exposed additional secrets. Those secrets opened new trust relationships. Each successful transition gave the agent more information and more privilege with which to attempt the next one. Consequently, Hugging Face’s remediation focused on reducing that trust inheritance by narrowing credential scopes, strengthening workload identities, increasing isolation, and implementing more restrictive access controls.

Layered defense is not simply a matter of adding more controls. Each boundary should limit the authority inherited from the previous step and produce evidence when that boundary is crossed.

A resilient environment forces the attacker to solve a genuinely new problem at every stage. A fragile environment allows one credential or trusted connection to collapse several boundaries at once. AI makes that distinction more consequential because an autonomous system can exhaust permissive paths faster than a human team can understand their cumulative significance.

Least privilege remains essential, but architecture alone will not settle the contest. Large enterprises cannot eliminate complexity. Their environments continue evolving across legacy and cloud systems, accumulating exceptions and trust relationships that appear reasonable in isolation.

Layered defense must therefore combine structural separation with the ability to recognize when an attacker is assembling those isolated exceptions into a route through the enterprise.

A mature environment makes every additional move more expensive for the attacker and more legible to the defender.

The critical metric is time to conviction.

Hugging Face’s most important disclosure concerns the period after its controls began producing evidence.

The company reported that multiple security systems observed anomalous activity. Its AI security stack correlated those events into a coherent signal, yet the finding was not judged sufficiently critical to wake the response team in time.

Hugging Face collected much of the evidence it needed. The breakdown occurred in assessment and escalation. Available signals were not converted into a judgment urgent enough to trigger action.

Most mature organizations already produce more alerts than their teams can investigate. Their scarcer resource is certainty. An unusual authentication or an unfamiliar public service may be benign when viewed in isolation. The campaign advances while the defender tries to determine whether the observations are connected.

When offensive effort is compressed into a few days, the defender cannot afford for context to arrive one console at a time. A delay of hours can be enough for the attacker to cross the next trust boundary.

Traditional security operations evaluate discrete alerts after they occur. Each tool asks whether its own event appears malicious, and analysts later reconstruct the wider campaign. That model is static and retrospective. Time disappears as evidence moves between systems, is repeatedly interpreted, and is reassembled by people who may see only one portion of the environment.

The defensive system of the future must instead maintain a living hypothesis. Every new observation should update the probability that a campaign is underway. Yesterday’s suspicious use of the token may initially carry little weight. When today’s unfamiliar network destination appears, the system should reconsider both events as part of the same investigation.

The unit of defensive work becomes the evolving campaign rather than the isolated alert.

This is where intelligence has to become operational.

For years, threat intelligence was treated largely as external knowledge delivered into a security program. That model remains useful, but it can be incomplete against an adversary that can generate new infrastructure faster than defenders can assign reputation to it.

Attackers have long abused legitimate public services and disposable infrastructure. Agentic AI did not create that tactic, but it increases the speed and volume at which the tactic can be used. A static list of malicious infrastructure ages faster when a system can discard one endpoint and establish another without human delay.

The meaning lies in the relationship between those services and the behavior occurring within the victim’s environment.

Intelligence in the agentic era must provide that connective tissue. It must combine what the outside world knows with what the organization itself is observing, then preserve and revise that assessment as the operation changes.

That is the underlying premise of the Intelligence Graph® at Recorded Future. Its value comes from preserving relationships across time, not simply from containing a large volume of information. Autonomous Threat Operations applies that context to continuous investigations across the controls a customer already has. It does not replace those controls or the analysts operating them. It can help prevent an investigation from losing its accumulated context whenever the attacker changes technique or the evidence moves into another system.

No counterfactual can guarantee that this would have prevented the Hugging Face incident. The defensible claim is narrower.

Once observable activity began, a customer with the relevant telemetry and integrations could have defended differently. Persistent hunts might have linked unusual credential behavior to the compromised workload without waiting for analysts to manually reconstruct the context. External intelligence could have helped distinguish ordinary use of public infrastructure from a rapidly changing command channel. New evidence could have revised an existing investigation rather than creating another isolated queue of alerts.

Intelligence could not have predicted the first private zero-day. It could have created more opportunities to interrupt the operation before the agent accumulated durable privilege.

Defensive autonomy requires different constraints.

The natural response to autonomous attack systems is to demand equally autonomous defenders. Defensive autonomy, however, operates under a different set of constraints.

An offensive system can test thousands of unsuccessful paths without harming its own operation. Defensive action has consequences for the business it is intended to protect. Indiscriminate blocking can disrupt legitimate activity and create an operational incident in its own right.

Automated systems are best suited to work where delay is expensive, and the consequences of error are limited or reversible. They can maintain investigations continuously, correlate new evidence, and take bounded actions under predefined conditions. Human judgment should remain concentrated on decisions that could materially disrupt the business.

Organizations should gradually expand the scope of automated defensive actions. The progression should begin with observation and explanation, then move toward low-risk and reversible actions as performance becomes measurable. More consequential authority should remain governed by explicit technical and organizational guardrails. Those guardrails cannot be static. Human oversight must remain in the loop to test whether defensive agents are focused on the right threats and behaving as expected. The human role is not limited to approving a consequential action; it includes governing the system as its assumptions and behavior change over time.

Recorded Future has taken this approach with Autonomous Threat Operations, which supports continuous hunting and multi-source correlation while allowing customers to govern how intelligence is operationalized.

The distinction between automation and autonomy also matters. An automated rule repeats a predetermined response. An autonomous system revises its investigation as the evidence changes. The Hugging Face agent altered its methods when previous paths failed. A defense based entirely on fixed workflows will struggle to maintain pace with that adaptation.

Defensive systems do not need to mirror every attacker's action in real time. They need to preserve continuity of understanding while the attacker moves.

Human analysts remain essential. Their future value will lie less in moving indicators between products than in challenging the system’s conclusions and owning decisions that cannot be easily reversed.

They should govern the defense both at the moment of action and over the loop that produces it. Moving context manually between tools is work the system should absorb.

Connected intelligence becomes more valuable as models commoditize.

The models available to attackers and defenders will continue improving. Over time, access to competent cyber agents will become less distinctive. A model advantage that appears significant today may disappear with the next release or open-source replication.

Individual data sources may also be commoditized. Agents will make collection cheaper, and more companies will possess useful but partial views of risk. The durable advantage lies in quickly assembling those fragments into a coherent picture that can change a decision.

An attacker can begin each operation with a new model instance, fresh infrastructure, and no durable identity. That can make attribution more difficult. The defender’s advantage lies in continuity: years of knowledge about its own environment, joined with external intelligence and signals from the wider economy.

That advantage is often wasted because the evidence is partitioned by domain. One system can see the cyber compromise while another sees downstream abuse, yet no layer assembles them quickly enough to maintain the whole argument.

The strategic role of intelligence is to make that accumulated knowledge usable at the moment of decision.

This is where the combination of Recorded Future and Mastercard becomes distinctive. Recorded Future helps connect weak cyber signals across the Intelligence Graph and sustain the investigation as those signals change. Mastercard adds fraud expertise and payment-risk signals that can reveal how compromise is beginning to manifest beyond the victim’s network. The advantage lies in assembling those perspectives early enough to interrupt the operation.

Vulnerability Prioritization becomes relevant when a private flaw begins to produce public evidence, allowing defenders to understand whether the issue is moving from theoretical exposure to operational exploitation. Attack Surface Intelligence determines where the vulnerable technology intersects with the organization. Digital Risk Protection can warn when credentials have been exposed externally. Third-Party Risk helps determine whether a supplier’s incident changes the customer’s own exposure.

These capabilities matter most when they inform one another. Their purpose is to produce one defensible judgment about what the organization should do next.

This is where defenders can build a genuine asymmetry.

Offensive systems can be disposable. Connected defensive intelligence can compound. Each investigation adds context to the next, and each new source can strengthen or challenge the current assessment. An organization that can assemble those perspectives in time forces the attacker to overcome both today’s controls and the accumulated lessons of previous attempts.

The decisive advantage will be temporal.

The Hugging Face incident does not prove that autonomous cybercrime has arrived at scale.

As capable models become cheaper, attackers will be able to sustain more simultaneous attempts. The first effect may be volume rather than brilliance. That alone changes the equation.

Organizations cannot answer this shift simply by producing more alerts or placing a human analyst in the middle of every decision. Prevention will remain essential, but some first controls will inevitably fail.

They will need layered architectures that limit how far one success can travel. They will need intelligence that preserves context while the attacker changes shape. They will need an autonomous investigation whose authority remains bound by the consequences of getting a decision wrong.

Two opposing curves will determine the future of cyber defense.

For the attacker, the cost of another attempt is falling, while the number of attempts that can be concentrated within a single operational window is rising.

For the defender, the time required to assemble weak signals into a coherent judgment must fall faster.

Recorded Future’s role in that future is practical: connecting weak signals across a broad Intelligence Graph and sustaining the investigation as those signals change, so decision-makers gain conviction before temporary access becomes enduring control.

Foreknowledge of every private zero-day is impossible. Continuity after the first observable signal is achievable.

AI is making persistence cheap. The defenders who prevail will make progress expensive.

  • ✇Recorded Future
  • July 2026 CVE Landscape
    In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data. The 85 vulnerabilities
     

July 2026 CVE Landscape

6 de Agosto de 2026, 21:00

In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data.

The 85 vulnerabilities in this report affected products from 61 vendors, with Microsoft accounting for approximately 12% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.

Insikt Group previously created a Nuclei template to detect the Langflow vulnerability (CVE-2025-3248) featured in this report. These are available to Recorded Future customers via the Recorded Future Intelligence Platform.

Quick reference: July 2026 Vulnerability Table

All 81 vulnerabilities below were actively exploited or operationally weaponized in July 2026. This table does not include the four CVEs that were primarily surfaced through our honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.

#
Vulnerability
Risk
Score
Vendor/Product
KEV
Analysis
RCE
PoC
1
CVE-2008-4128
99
Cisco IOS
2
CVE-2017-17215
99
Huawei HG532
3
CVE-2018-0802
99
Microsoft Office Equation Editor
4
CVE-2021-4034
99
Polkit
5
CVE-2021-27137
99
DD-WRT
6
CVE-2023-4346
99
KNX Association KNX Protocol Connection Authorization Option 1
7
CVE-2025-55182
99
Meta React Server Components
8
CVE-2025-68686
99
Fortinet FortiOS
9
CVE-2026-0770
99
Langflow
10
CVE-2026-15409
99
SonicWall SMA1000 Appliances
11
CVE-2026-15410
99
SonicWall SMA1000 Appliances
12
CVE-2026-16232
99
Check Point SmartConsole
13
CVE-2026-16812
99
Arista VeloCloud Orchestrator
14
CVE-2026-20316
99
Cisco Secure Firewall Management Center (FMC)
15
CVE-2026-25089
99
Fortinet FortiSandbox
16
CVE-2026-34486
99
Apache Tomcat
17
CVE-2026-39808
99
Fortinet FortiSandbox
18
CVE-2026-39987
99
Marimo
19
CVE-2026-46817
99
Oracle E-Business Suite
20
CVE-2026-48282
99
Adobe ColdFusion
21
CVE-2026-48907
99
JoomlaContentEditor.net Joomla Content Editor (JCE)
22
CVE-2026-48908
99
JoomShaper SP Page Builder
23
CVE-2026-48939
99
iCagenda
24
CVE-2026-50522
99
Microsoft SharePoint
25
CVE-2026-55255
99
Langflow
26
CVE-2026-56155
99
Microsoft Active Directory Federation Services
27
CVE-2026-56164
99
Microsoft SharePoint Server
28
CVE-2026-56290
99
Joomlack Page Builder
29
CVE-2026-56291
99
Balbooa Forms
30
CVE-2026-58644
99
Microsoft SharePoint
31
CVE-2026-60137
99
WordPress Core
32
CVE-2026-63030
99
WordPress Core
33
CVE-2021-3156
89
Sudo
34
CVE-2021-29441
89
Alibaba Nacos
35
CVE-2025-6389
89
Sneeit Framework
36
CVE-2025-9491
89
Microsoft Windows
37
CVE-2025-32432
89
Craft CMS
38
CVE-2025-3248
89
Langflow
39
CVE-2025-34152
89
Shenzhen Aitemi M300 Wi-Fi Repeater
40
CVE-2025-49113
89
Roundcube Webmail
41
CVE-2025-66376
89
Zimbra Collaboration
42
CVE-2026-0257
89
Palo Alto Networks PAN-OS and Prisma Access
43
CVE-2026-0740
89
SaturdayDrive Ninja Forms - File Uploads
44
CVE-2026-3055
89
NetScaler ADC and Gateway
45
CVE-2026-6875
89
ServiceNow AI Platform
46
CVE-2026-12569
89
PTC Windchill PDMLink and FlexPLM
47
CVE-2026-29014
89
MetInfo CMS
48
CVE-2026-42897
89
Microsoft Exchange Server 2016 CU23 and Subscription Edition RTM
49
CVE-2026-45659
89
Microsoft SharePoint Server
50
CVE-2026-31843
87
goodoneuz pay-uz
51
CVE-2013-3307
79
Linksys E1000, E1200, and E3200
52
CVE-2016-20016
79
MVPower TV-7104HE and TV-7108HE DVRs
53
CVE-2017-5259
79
Cambium Networks cnPilot
54
CVE-2017-7269
79
Microsoft IIS
55
CVE-2018-11511
79
ASUSTOR ADM Photo Gallery
56
CVE-2018-14558
79
Tenda AC9, AC10, and AC7 firmware
57
CVE-2020-8515
79
DrayTek Vigor2960, Vigor300B, and Vigor3900 firmware
58
CVE-2020-22653
79
Ruckus APs, SmartZone, and ZoneDirector
59
CVE-2020-22658
79
Ruckus APs, SmartZone, and ZoneDirector
60
CVE-2020-25499
79
TOTOLINK A3002RU firmware
61
CVE-2020-36847
79
Eemitch Simple File List
62
CVE-2021-31755
79
Tenda AC11 firmware
63
CVE-2021-32305
79
WebSVN
64
CVE-2022-35733
79
UNIMO Technology UDR-JA1004, UDR-JA1008, and UDR-JA1016 digital video recorders
65
CVE-2023-25717
79
Ruckus Wireless Admin
66
CVE-2024-42009
79
RoundCube Webmail
67
CVE-2025-9528
79
Linksys E1700
68
CVE-2025-12057
79
WavePlayer
69
CVE-2025-12352
79
Gravity Forms
70
CVE-2025-13486
79
Hwk-Fr Advanced Custom Fields: Extended
71
CVE-2025-28137
79
TOTOLINK A810R firmware
72
CVE-2026-1357
79
WPvivid Backup, Migration & Staging
73
CVE-2026-3395
79
MaxSite CMS
74
CVE-2026-3844
79
Cloudways Breeze Cache
75
CVE-2026-16723
79
Alibaba Fastjson
76
CVE-2026-29059
79
Windmill
77
CVE-2026-33824
79
Microsoft Windows IKE Extension
78
CVE-2021-24139
78
Photo Gallery by 10Web
79
CVE-2025-7852
78
Iqonic Design WPBookit
80
CVE-2026-1969
72
ThemeREX Addons WordPress plugin
81
CVE-2025-7443
71
BerqWP Automated Page Speed Optimization

Table 1: List of vulnerabilities that were actively exploited in July, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).

Key trends: July 2026

  • In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure; Cloud Atlas abused Microsoft Equation Editor to deliver CloudAtlasGo; Armored Likho used a malicious Windows shortcut to deploy BusySnake Stealer; and JADEPUFFER and Cl0p targeted exposed AI and product-lifecycle platforms for encryption, data theft, and extortion.
  • 57 of the 85 vulnerabilities enabled remote code execution (RCE), including flaws affecting Microsoft, Fortinet, Langflow, ServiceNow, WordPress, and Joomla ecosystems, internet-facing security appliances, and embedded network devices.
  • We identified public proof-of-concept (PoC) exploits and scanners for 60 of the 85 vulnerabilities in this report.
  • The most commonly observed weakness classes were CWE-78 (OS Command Injection), CWE-434 (Unrestricted Upload of File with Dangerous Type), CWE-94 (Code Injection), and CWE-502 (Deserialization of Untrusted Data).
  • 14 of the 85 vulnerabilities in this month’s table are at least 5 years old, with the oldest approximately 18 years old, reinforcing how threat actors continue to exploit long-known weaknesses in environments where patching has lagged. Additionally, the fastest observed time from a vulnerability’s public disclosure to reported exploitation was less than one day.

Trend analysis: Malware-Linked Exploitation Spans IoT, Email, and Enterprise Applications

An Insikt Group® TTP Instance on the Dysphoria botnet linked CVE-2013-3307, CVE-2016-20016, CVE-2017-17215, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-35733, CVE-2025-28137, CVE-2025-34152, CVE-2025-55182, CVE-2025-9528 to the exploitation of routers, gateways, cameras, repeaters, and other embedded Linux devices. Dysphoria combined known RCE flaws with weak Telnet and Secure Shell credentials to enroll compromised systems into DDoS and relay infrastructure.

Figure 1: Vulnerability Intelligence Card® for CVE-2017-17215 in Recorded Future (Source: Recorded Future)

  • ✇Recorded Future
  • Emerging Threats to Neurotechnology
    Summary Neurotechnology is rapidly moving beyond clinical use cases, expanding the attack surface for sensitive neurological and biometric data: As adoption grows, larger volumes of brain activity, biometric, and behavioral data will be collected by commercial platforms, creating new opportunities for data theft, misuse, and exploitation. China and the United States (US) are engaged in strategic competition in neurotechnology development: The US leads in the number of neurotechno
     

Emerging Threats to Neurotechnology

5 de Agosto de 2026, 21:00

Summary

Neurotechnology is rapidly moving beyond clinical use cases, expanding the attack surface for sensitive neurological and biometric data: As adoption grows, larger volumes of brain activity, biometric, and behavioral data will be collected by commercial platforms, creating new opportunities for data theft, misuse, and exploitation.

China and the United States (US) are engaged in strategic competition in neurotechnology development: The US leads in the number of neurotechnology firms, and brain-computer interface (BCI) research has been a long-term research priority for the US military. At the same time, China’s five-year guidance for BCI development, subsidies for major wearable technology firms, and military research into human-machine integration suggest that neurotechnology is a strategic priority.

Leading neurotechnology companies are likely to face increased targeting for intellectual property (IP) theft: Because neurotechnology is costly to develop and strategically valuable, companies in this sector are likely to become attractive targets for state-sponsored espionage, insider threats, and cyber-enabled theft. Successful IP theft could erode the competitive advantage of companies that invest heavily in research and development (R&D). Military and higher education research laboratories are also likely to be targeted for access to R&D and related data.

Neurological and biometric data will become an increasingly valuable target for cybercriminals and state-linked actors: Attackers may seek to exfiltrate these datasets for extortion, surveillance, strategic intelligence, or model development. The sensitivity of this data could make breaches particularly damaging for affected individuals and companies, making it an attractive target for extortion-focused cybercriminals.

Regulatory and national security scrutiny of neurological data will likely intensify: Existing privacy frameworks in the European Union (EU) and several US states already provide heightened protections for neurological or biometric data, but rapid advances in neurotechnology may outpace consumer protection laws.

Infographic showing neurotech threats: IP theft, disruption, data extortion, and legal risks, alongside five future risk outlooks for the industry.
Figure 1: Key threats in neurotechnology and how they will evolve (Source: Recorded Future)

  • ✇Recorded Future
  • 8 Ways AI is Changing Threat Intelligence
    The fundamentals haven't changed — the clock speed has. Defending everything is still the job, but adversaries can now move at machine-speed, which means the intelligence behind every decision has to move just as fast. AI cuts both ways. The same automation that lets defenders orchestrate faster is available to attackers too, and whoever uses it more creatively will often hold the advantage at any given moment.
     

8 Ways AI is Changing Threat Intelligence

2 de Agosto de 2026, 21:00
  • The fundamentals haven't changed — the clock speed has. Defending everything is still the job, but adversaries can now move at machine-speed, which means the intelligence behind every decision has to move just as fast.
  • AI cuts both ways. The same automation that lets defenders orchestrate faster is available to attackers too, and whoever uses it more creatively will often hold the advantage at any given moment.
  • Trust in automation is being built one decision at a time. Human-in-the-loop approval is today's norm, but most security leaders expect that to shift toward human oversight of largely autonomous systems within the next few years.

AI is changing the threat landscape faster than most security organizations can keep up. Recorded Future co-founder Christopher Ahlberg, CTO and co-founder Staffan Truvé, and Head of Threat Intelligence Levi Gundert unpack what’s actually happening in a recent conversation — and what it means for your defenses. Read on for their 8 takeaways.

1. The threat landscape now moves at machine speed.

AI has made exposure discovery instant. Your unknown exposures are now part of your attack surface, and threats are multiplying faster than most teams can triage. While most security organizations are responding by trying to move faster, speed without accuracy isn’t an advantage. Staying ahead means having intelligence that makes machine-speed defense more effective, not just fast.

As Truvé put it, intelligence has always been the way to stay proactive instead of reactive, and as "clock speed" increases across the industry, staying even a little ahead requires acting on intelligence faster than ever.

“External attack surface, security operations, vulnerability management, prioritizing — so many of these use cases and workflows take on a new level of urgency because of the speed component,” Gundert said.

2. "Defend the right things" is now a multi-bear problem.

The team agreed that the old security adage — you don't have to outrun the bear, just the person next to you — no longer holds.

AI removes that comfort almost entirely. Attackers only need one way in. Defenders have to cover just about everything. That asymmetry has always been the challenge and AI is making it structurally worse. It’s no longer one bear chasing the herd anymore — it's one bear chasing each member of the herd, since attackers can automate at scale even more efficiently.

3. Attacks are already becoming more clever, not just faster.

The panel discussed a real-world software supply chain compromise where attackers used compromised credentials to push a malicious package update, then had an LLM already present on infected developer machines search out AWS keys, SSH keys, and other credentials locally. The stolen data was encrypted and exfiltrated through a public GitHub repository — activity that never tripped EDR because it looked like ordinary LLM usage.

It was a preview of a much bigger wave of clever attacks that will likely quietly repurpose and weaponize the AI tools already installed on a target's machine.

4. Locking down devices isn't the only answer — context-aware access might be.

Locking down every endpoint isn't realistic, and it probably is not the answer. Situational permissions, such as access that flexes by location, time, and context are zero trust logic applied to the AI era.

5. Whether AI favors attackers or defenders depends on execution.

Everyone is talking about what AI can do. Fewer are asking who AI will ultimately benefit. Will the advantage belong to attackers or defenders?

It’s a question of how well organizations manage the trade-off between innovation and guardrails. Teams that articulate boundaries tend to build stronger solutions.

Truvé broadened the definition of "AI" beyond LLMs to include things like anomaly detection, and predicted an ongoing arms race. “At any given point in time, depending on who's more creative in using the new technology,” he said, “one side or the other will have the upper hand.”

6. Human-in-the-loop is a bridge, not a destination.

Expect humans to stay involved in approving high-stakes actions.

“Hopefully that just becomes very minimal decision points on all of the articulation that has been built around an incident,” Gundert said. “All the telemetry has been gathered, everything's been enriched. The agent wants to take an action. Maybe they want to isolate a machine on the network, maybe they want to revoke credentials, and it comes to you over Signal or Slack or whatever it is to hit Approve.” But he compared it to the first few rides in a self-driving car: Comfort builds with repeated exposure.

In five years, requiring a human in the loop for every decision may look as outdated as manual patch management does today — replaced by an expectation of an agent in the loop with lighter human oversight.

7. Intelligence will be critical for more than effective resource allocation.

With AI expected to surface a flood of newly discovered vulnerabilities, prioritization will become a major challenge. While work is being done to identify which vulnerabilities are likely to be weaponized and which are likely to target a given organization, the explosion of AI-generated "dark code" is predicted to expand the attack surface by as much as tenfold.

Intelligence should become the mechanism for deciding where limited security resources and token budgets get allocated first. This is why intelligence accuracy is paramount — organizations need to be able to prioritize the right things to defend.

8. Real-time data beats built-in model knowledge.

The team emphasized that relying on a model's internal knowledge risks working from information that's months old — precisely when speed matters most.

LLMs with search still only reach the open web and surface-level open-source intelligence. They don't have access to the technical detail or restricted spaces needed to understand what adversaries are actually doing.

And there are plenty of reasons an LLM won't deploy agents into the internet's bad neighborhoods — which is exactly why the underlying data feeding an intelligence program can matter as much as the model interpreting it.

Stay ahead of AI-enabled attacks.

AI is raising the stakes in terms of speed, prioritization, and trust in automation. The organizations that will weather what follows are building two things now: intelligence they can trust, and comfort with autonomous action.

They need to be able to:

  • Prioritize with intelligence they can trust.
  • Act pre-attack, at the first sign of threat.
  • Defend at scale, autonomously.

Teams that invest now in high-quality, real-time intelligence — and start building comfort with agentic decision-making in lower-stakes workflows — will be better positioned when fully autonomous attacks eventually arrive.
Take Recorded Future’s interactive tour to see what defending at machine speed looks like in practice. Learn more and launch the interactive tour.

Watch the full conversation with Recorded Future leaders as they discuss how AI is reshaping threat intelligence, the evolving threat landscape, and what it means for defenders.

  • ✇Recorded Future
  • The Hugging Face Incident Was a Governance Failure
    AI is reshaping the threat landscape, but inflated claims around the latest security events can obscure how. This post is part of Insikt Group’s ongoing “AI Hype vs. Reality” series, which cuts through the noise around AI developments to examine what the evidence actually shows and what defenders should prioritize as a result. Agentic defense will be essential to countering agentic offense. However, defend
     

The Hugging Face Incident Was a Governance Failure

4 de Agosto de 2026, 21:00
AI is reshaping the threat landscape, but inflated claims around the latest security events can obscure how. This post is part of Insikt Group’s ongoing “AI Hype vs. Reality” series, which cuts through the noise around AI developments to examine what the evidence actually shows and what defenders should prioritize as a result.

Agentic defense will be essential to countering agentic offense. However, defenders must actively mitigate the risk of autonomous systems operating outside of their expected parameters.

In July 2026, OpenAI disclosed that models undergoing an internal cybersecurity evaluation had escaped their testing environment and compromised part of Hugging Face’s production infrastructure. OpenAI characterized the event as an “unprecedented cyber incident.”

The incident should put security leaders on alert, but not for the reasons OpenAI suggests.

One concern is that OpenAI’s agents demonstrated the ability to autonomously carry out an end-to-end cyberattack, placing the models at the highest level of autonomy within Recorded Future’s AIM3 framework. However, the greater concern is that the model operators did not sufficiently monitor for or prepare to mitigate unauthorized agentic activity. Enterprises using agents for security and other purposes should see the Hugging Face incident as a warning about what happens when agents are set loose without safeguards against adverse outcomes.

What Happened

The incident began during an OpenAI evaluation designed to measure advanced cyber capabilities. The evaluation involved GPT-5.6 Sol and an even more capable internal research prototype that OpenAI says was not intended for public release. Because the objective was to test their maximum offensive potential, the models were operated with reduced security guardrails (normally used to prevent high-risk activity).

According to OpenAI, the models spent substantial computing resources searching for a path to the internet. They exploited a zero-day vulnerability in Artifactory, the package-registry cache proxy available in the evaluation environment, and then performed privilege escalation and lateral movement within OpenAI’s research environment until they reached a node with internet access.

Once online, the models inferred that Hugging Face might contain models, datasets, or solutions associated with ExploitGym, the benchmark they had been instructed to solve. OpenAI says the agents then chained stolen credentials, zero-day vulnerabilities, and remote code execution paths to obtain test solutions from a Hugging Face production database.

Hugging Face’s technical reconstruction covers roughly 17,600 recovered agent actions, grouped into approximately 6,280 clusters, between July 9 and July 13, 2026. Although most attempts failed, the agent still gained administrative access to internal and production systems, accessed some source-code repositories, and used a stolen credential to connect external systems to the company network. Hugging Face found no evidence that its public models, datasets, services, packages, or published software supply chain were altered. It says the only customer content accessed comprised five datasets, apparently related to ExploitGym or CyberGym.

A Capability Breakthrough and a Control Failure

Most coverage of this incident has framed it as a breakthrough in model capabilities, since it is the first known instance of a model apparently independently conducting an end-to-end cyberattack. The underlying techniques were largely familiar to those used in human-led cyberattacks: vulnerability exploitation, credential theft, staging, remote code execution, lateral movement, and abuse of privileged or trusted access. What was notable was the agents’ ability to select and chain those steps autonomously across a long-running operation. This represents a significant shift in the speed and scale of future incidents.

An autonomous agent can execute thousands of actions, test multiple paths, and continue working without the fatigue, coordination costs, or time constraints that limit human operators. In this case, most of the roughly 17,600 recovered actions were associated with failed paths. The operation was noisy and failure-prone, but it needed only a small number of successful chains to create a material impact.

This compresses what could be called time to everything:

  • Time from vulnerability discovery to exploitation
  • Time from initial access to privilege escalation
  • Time from data theft to analysis and extortion
  • Time from defensive signal to attacker adaptation

What this means for defenders is that any exposed flaw may now have disastrous consequences in the era of agentic attackers. The agents exploited multiple errors across the Hugging Face environment to carry out the attack, finding these weak points and exploiting them much faster than a human operator. The new pace of operations makes continuous vulnerability management, threat visibility, and risk mitigation essential to limiting the impact of an agentic attack.

The Greater Risk May Be Your Own Agents

While the capability breakthroughs are noteworthy, the incident is also a failure of AI safety. Removing behavioral safeguards may have been necessary to measure the models’ maximum capabilities, but doing so should have increased reliance on compensating controls: strict network isolation, credential separation, resource limits, real-time telemetry, and automatic termination when predefined boundaries were crossed.

Instead, an evaluation intended to simulate advanced cyber activity became a real security incident affecting an external organization. This should be a warning to any organization deploying AI agents: without strict AI governance, agents can act outside their authorized scope while still pursuing the objective they were given.

An enterprise agent does not need malicious intent to cause harm. A poorly scoped objective, excessive permissions, and inadequate operational boundaries may be enough.

An agent instructed to “resolve a customer issue,” “complete the research,” or “fix the vulnerability” may decide that the most efficient path involves accessing restricted information, interacting with an external system, accepting contractual terms, modifying production code, or using credentials in a manner its operator never anticipated. Any of these could potentially result in a major security incident.

The fact that an agent selected an action does not transfer accountability away from the organization that deployed it. Depending on the facts and applicable law, an organization may face legal, contractual, or regulatory exposure based not only on how information is used, but on how the agent obtained it.

The Executive Agenda

The Hugging Face incident shows that using agents for defense will be essential to counter agentic offense, but must be approached with a thorough understanding of the risks.

Govern authority and ensure checks on higher privileges. Every agent should have a clearly defined identity, narrowly scoped permissions, and explicit limits on activity. In cases where agents need higher levels of permissions, mitigating controls such as approval gates or additional monitoring (detailed below) should be applied.

Design containment on the assumption that behavioral safeguards may fail or be reduced. Prompts, refusals, and policy controls should be treated as one layer of protection — not as the security boundary. Network segmentation, egress controls, credential isolation, and execution limits must remain effective even when a model behaves unexpectedly.

Create approval gates for consequential actions. Transactions, production changes, external communications, credential use, and access to sensitive systems should require deterministic policy checks or human authorization.

Monitor behavior, not just outputs. Organizations need visibility into the tools an agent invokes, the systems it contacts, the credentials it uses, the resources it consumes, and the sequence of decisions leading to an action. Unusual compute consumption or repeated attempts to bypass a boundary should trigger intervention.

Prepare for machine-speed defense. Security programs will need automated enrichment and prioritization to determine which of a rapidly expanding set of vulnerabilities and attack signals create genuine exposure. In addition, automated response and mitigation are necessary to successfully defend against automated attackers.

Two Possible Futures

The long-term impact of agentic AI will depend largely on two variables: how capable the systems become and how broadly access to those capabilities is distributed.

Scenario One: Capabilities Proliferate

In this future, highly capable agents remain broadly available through commercial services, open-weight releases, and illicitly modified models.

Attackers use these agents to automate reconnaissance, vulnerability discovery, social engineering, and lateral movement. Defenders will need to apply these capabilities to automated response and mitigation, producing an accelerated contest between machine-speed offense and machine-speed defense.

The advantage is unlikely to be distributed equally. Large technology and security companies will be better positioned to deploy sophisticated defensive agents, operate extensive telemetry networks, and rapidly isolate compromised systems.

Smaller organizations may increasingly depend on managed platforms and tightly controlled technology ecosystems. The result could be an internet composed of more walled gardens, as organizations gravitate toward providers capable of operating security at machine speed.

Scenario Two: Frontier Access Narrows

In the second future, governments and model providers restrict access to the most capable systems through trusted-partner programs, identity requirements, geographic limitations, or export controls.

In June 2026, a White House executive order directed federal agencies to design a voluntary framework for evaluating “covered frontier models.” The same month, the Commerce Department temporarily applied export controls to Anthropic’s Mythos and Fable models, requiring restrictions on access by foreign nationals — an unprecedented move to regulate access to AI models themselves rather than only to advanced chips or model weights.

Chinese authorities have reportedly considered similar restrictions on foreign access to the country’s most advanced models, although no final policy had been announced at the time of reporting.

This future would concentrate frontier capabilities among governments, critical infrastructure operators, and large, approved organizations. Other businesses would rely on older commercial models, open-weight alternatives, or systems that can be modified to bypass safeguards.

Restrictions could reduce broad access to the most dangerous capabilities, but they would not eliminate malicious use of AI. Criminal groups would continue to jailbreak available systems, steal model access, and use open-weight alternatives. Enterprises could also face sudden operational disruption if a model embedded in a critical workflow becomes unavailable due to regulatory changes, vendor policies, or geopolitical tensions.

The Most Likely Future Is a Mix of Both

These scenarios are not mutually exclusive.

The more probable future is a fragmented ecosystem in which the most advanced models are increasingly gated, while slightly less capable open-weight systems remain widely available. Criminals, states, major technology companies, and ordinary enterprises will operate at different levels of capability and under different constraints.

This means organizations cannot base their security strategy on the assumption that governments will successfully contain dangerous models — or that unrestricted access will continue indefinitely.

They must be prepared for both capability proliferation and access disruption.

The Hugging Face incident does not show that AI systems developed human-like intent or an independent, malicious objective. Nor was it merely a harmless laboratory accident.

It is evidence that autonomous systems can turn narrow instructions into consequential external actions outside their operators’ intended scope, using familiar weaknesses at a speed and scale that existing controls may not withstand.

The central question for executives now is how to manage the authority those agents should receive and how to mitigate the likelihood and consequences of their pursuing objectives outside authorized boundaries.

Don't Let the Next Incident Catch You Unprepared.

The OpenAI/Hugging Face incident raises questions that don't have easy answers about agentic autonomy, organizational accountability, and how fast the threat landscape is shifting. Hear our panel unpack what actually happened, what it reveals about agentic AI risk, and what security and governance teams need to know and do now.

Watch the Webinar

Read more in the “AI Hype vs. Reality” series:

About Insikt Group®

Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Its mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.

  • ✇Recorded Future
  • Iran War’s Secondary Effects Shape 2026 US Violent Extremism
    Executive Summary The United States (US) will almost certainly remain at heightened threat from physical threat activities conducted by homegrown and domestic violent extremists (HVEs and DVEs, respectively) during the next twelve months. Since the last installation of this report in July 2025, there has been a substantial increase in mass-casualty attacks and attack plots by Islamic State (IS) supporters, assassinations and attempted assassinations of US government officials and high-pr
     

Iran War’s Secondary Effects Shape 2026 US Violent Extremism

29 de Julho de 2026, 21:00

Executive Summary

The United States (US) will almost certainly remain at heightened threat from physical threat activities conducted by homegrown and domestic violent extremists (HVEs and DVEs, respectively) during the next twelve months. Since the last installation of this report in July 2025, there has been a substantial increase in mass-casualty attacks and attack plots by Islamic State (IS) supporters, assassinations and attempted assassinations of US government officials and high-profile public figures by anti-government and anti-authority violent extremists (AGAAVEs), and multiple plots by anarchist violent extremists (AVEs) to cause substantial damage to facilities using destructive devices.

Coinciding with these trends, the Iran War will almost certainly have significant ramifications for the violent extremism threat landscape in the US over the next twelve months, even if the war has concluded. Based on Insikt Group’s observations to date, Iranian external operations are less likely to be a significant cause of violent extremist threat activity in the US than HVEs and DVEs motivated by the second-order sociopolitical and economic effects of the war. Iran almost certainly intends to guide or inspire HVEs to conduct physical threats in the US on its behalf. However, Iran-nexus physical threat activities in the US during the war have been largely aspirational, reliant on low-sophistication, financially motivated threat actors, and disrupted by law enforcement in the early planning stages of attacks. This likely suggests Iran lacks the capabilities necessary to guide large-scale HVE attacks in the US at present.

In contrast, the second-order effects of the Iran War will almost certainly add to the list of grievances and causes for mobilization popular among a wide swath of US violent extremists, likely increasing the risk of violent extremist physical threat activities during the next twelve months. Specifically, the war surfaced salient domestic and international political issues that have historically mobilized US violent extremists. These controversies include US military involvement in the Middle East; the relationships among the US, Israel, and other Middle Eastern countries; the state of the US economy; and the involvement of specific US private-sector entities in US foreign policy planning and military operations. In addition to motivating violent extremists, these issues will almost certainly influence US political discourse during the 2026 midterm elections in the US; the election cycle itself will very likely drive additional US violent extremist threats in late 2026 and early 2027.

Public- and private-sector organizations face differing levels of violent extremist threats due to their sector, industry, role, associations, and attack surfaces. While different categories of violent extremists employ various TTPs depending on their ideology and objectives, Insikt Group continues to assess that targeted attacks against facilities and high-profile personnel constitute the predominant violent extremist risks to most organizations. Overall, entities associated with US foreign policy decision-making, immigration enforcement, the Israeli government and military, or the provision of critical infrastructure services very likely face heightened risks from violent extremists. Threat intelligence — including features within the Recorded Future Intelligence Operations Platform — can support organizations’ efforts to identify, analyze, and mitigate threats posed by US-based violent extremists.

Key Findings

During the next twelve months:

  • Iran-nexus physical threat actors will very likely attempt to target facilities and personnel in the US that they associate with the US or Israeli government and military, although the sophistication, impact, and frequency of these plots will likely be limited by Iran’s capability gaps.
  • HVE IS supporters will be the most likely violent extremist threat actors to conduct mass-casualty attacks in the US, particularly during the period between October 2026 and January 2027.
  • Instructional and ideological material produced by the neo-Nazi accelerationist movement will very likely continue to drive mass-casualty attack plots and sabotage against critical infrastructure, despite the fragmentation of neo-Nazi accelerationist organizations and online networks.
  • AGAAVEs motivated by partisan animus will almost certainly pursue targeted physical attacks against high-profile public officials; secondary effects of the Iran War and the 2026 US midterm election cycle will very likely exacerbate these risks.
  • AVEs will likely employ increasingly sophisticated and destructive means of conducting attacks targeting facilities and property, particularly targets they associate with US immigration enforcement policies

Background

Insikt Group’s forecast is predicated on its assessments of open-source information on the activities of HVEs and DVEs in the US, including Recorded Future’s extensive index of HVE and DVE communications on various online platforms. During the past twelve months, Insikt Group researchers curated several hundred HVE and DVE sources, adding them to an extensive index of preexisting sources of this type.

This report defines “homegrown violent extremist,” “domestic violent extremist,” and several categories of HVEs and DVEs based on the US Intelligence Community’s definitions and categorizations of threat actors. Periodically, this report uses definitions adopted by Insikt Group subject-matter experts for analytic utility, or in instances where the US government has not officially defined a particular phenomenon or movement. A full list of terms and definitions used in this report is available in Appendix A.

Homegrown Violent Extremists

The HVE threat to the US is very likely at its most severe level since the mid-2010s, during the period following the Islamic State’s rise to power and 2014 offensive to seize territory in Syria and Iraq. Jihadist Salafi HVEs, specifically IS supporters, very likely remain the most likely HVE threat actors to conduct mass-casualty attacks, despite a very likely resurgent threat from HVEs tied to Iran and its “axis of resistance” groups. While both jihadist Salafi HVEs and Iran-nexus HVEs almost certainly have the intent to conduct attacks in the US, we judge Iran-nexus HVEs have more limited capability to do so, due to a very likely smaller number of HVEs who support Iran or its “axis of resistance.”

Despite the June 17, 2026, memorandum of understanding (MoU) that established a ceasefire between the US and Iran, Iran’s military and intelligence agencies, proxy groups, and sympathizers in the US will very likely continue their efforts to guide physical threat activities on US soil, albeit with a greater focus on maintaining plausible deniability. The Iran War and the deaths of several notable members of Iran’s clerical and military leadership almost certainly removed most of the limits to Iran’s intent to target the US by proxy. However, Iran has not yet publicly demonstrated that it possesses sophisticated capacities to engage in physical threat activities on US soil. Observed plots during the Iran War involving Iran-nexus US-based physical threat actors have been largely aspirational, unsuccessful, and reliant on financially motivated (as opposed to ideologically motivated) threat actors.

While not direct participants in the conflict, IS, al-Qaeda, and other foreign terrorist organizations are likely to leverage second-order developments in the Iran War to further recruitment and radicalization of US HVEs. During the past three years, these groups have almost certainly positioned previous shifts in the Middle East’s geopolitical environment — notably Israeli military activity in Gaza and Lebanon following Hamas’s October 7, 2023, attack in Israel, the 2024 fall of the Bashar al-Assad regime in Syria, and diplomatic normalization of relationships between Israel and Muslim countries — to support influence narratives, generate propaganda, and reach a new generation of potential supporters. IS, which almost certainly remains at the forefront of the global jihadist Salafi movement, influenced a significant uptick in HVE threat activity in the US during the past twelve months, a dynamic that is very likely to continue in 2026 and early 2027.

HVEs of all varieties are very likely to target entities they associate with the US or Israeli government or military, private sector entities they associate with the US or Israeli government, Jewish communities, and large public gathering places. Most observed plots continue to use low-cost means, such as firearms, knives, incendiary devices, and vehicular attacks. Nevertheless, Insikt Group has monitored efforts by HVEs to share information on improvised explosive device (IED) manufacturing in online forums; there are additionally several known cases during the past year of HVEs successfully manufacturing IEDs for use in attacks. In addition, HVEs almost certainly will continue to experiment with novel tactics, techniques, and procedures (TTPs), including the use of 3D-printed weapons, unmanned aerial vehicle (UAV)-borne IEDs, and generative artificial intelligence (AI) for attack planning.

Iran and Axis of Resistance

The Iran War almost certainly increased Iran-nexus physical threat actors’ motivation to conduct attacks, sabotage, arson, and defacement in the US, as a form of Iran’s asymmetric retaliation against the US. The cessation of direct hostilities between Iran and the US is very unlikely to deter Iran-nexus threat actors from carrying out physical threat activities, although, post-MoU, these threat actors are very likely to pursue more covert and less destructive TTPs. In rank order, the most likely targets of these activities are:

  • Targets perceived to be associated with Israeli or Jewish communities
  • High-profile US, Israeli, and Western foreign policy and military officials
  • Iranian dissidents residing abroad
  • Private-sector organizations affiliated with the US or Israeli military, particularly defense contractors, insurance companies, banks and financial institutions, and critical infrastructure service providers

There are almost certainly few remaining strategic or ideological barriers to Iran’s aspirations to guide attacks on US soil, even after the June 2026 ceasefire agreement with the US. While the June 2026 MoU stipulates that Iran must “refrain from interfering in [the US’s] affairs,” it is unclear whether Iran would interpret non-interference to include Iran-nexus physical threat activities. Additionally, Iranian security agencies may choose not to abide by the clause, especially given how the conflict empowered hardliner elements within Iran’s security apparatus and granted them significant autonomy in operational decision-making. Tehran also very likely would not interpret the clause as applying to Iran’s “axis of resistance” groups. Regardless, Iran has attempted to solicit HVEs to conduct attacks in the US for decades, even during periods without direct military confrontation with the US. During the Iran War, the US killed several senior religious and military figures within Iran (including Ayatollah Ali Khamenei); the deaths of senior Iranian leaders have historically been harbingers of Iran-nexus physical threat activity in the US. Since the beginning of the Iran War, senior Shi’a Muslim clerics in Iran have issued rulings encouraging Muslims around the world to avenge Khamenei’s death by targeting the US and Israel. Iran has also leveraged online influence operations networks to recruit individuals to carry out attacks in the US, and has very likely inspired attack plots in the US. Iran will very likely attempt to ensure any post-MoU external operations in the US are deniable and avoid mass-casualty attacks or assassinations of high-profile public figures — to avoid provoking the US — but there almost certainly remain no significant ideological or strategic deterrents to Iranian external operations as a whole.

Regardless of its intent, however, Iran likely lacks access to a significant number of US-based, ideologically sympathetic HVEs, limiting its external operations capabilities in the US. During the last decade, Iranian operators predominantly tied to the Islamic Revolutionary Guard Corps (IRGC) attempted to pay members of transnational criminal organizations (TCOs), petty criminals, and other financially motivated threat actors to conduct attacks in the US. Insikt Group’s observations of Iran-nexus physical threat activity post-February 2026 indicate this threat model did not change due to the Iran War. For instance, in April 2026, a commander of the IRGC’s Iraq-based proxy Kataib Hezbollah (KH) and its external operations-focused persona Islamic Movement of the Companions of the Right (IMCR, also known as Ashab al-Yamin and HAYI) allegedly attempted to recruit a Federal Bureau of Investigation (FBI) undercover officer — whom he believed to be a US-based Mexican TCO member — to conduct attacks on several synagogues in the US, offering the undercover officer $10,000 in cryptocurrency.

A screenshot of a digital statement from the Islamic Movement of the Companions of the Right (IMCR), featuring text and imagery that conveys a direct threat against U.S. President Donald Trump and his family.
Figure 1: April 20, 2026, IMCR statement threatening US President Donald Trump and his family. (Source: Recorded Future)

  • ✇Recorded Future
  • Dealing with AI-Generated Extortion
    Proving a Negative How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files weren’t stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors?
     

Dealing with AI-Generated Extortion

29 de Julho de 2026, 21:00

Proving a Negative

How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files weren’t stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors?

This is a surprisingly challenging question to answer. Finding the answer is also more difficult because data governance has not been the traditional purview of security teams. Data governance has long been thought of as a compliance problem, unfortunately that is no longer the case. Security teams are now, whether they want to be or not, need to consider data governance. This means they have to be able to confidently say whether leaked data is real or not.

How do you do that?

History of Ransomware

What we call ransomware has evolved over the years. Ransomware has gone from largely focused on encryption to a combination of encryption and data theft to today’s reality where data theft alone is the most common version of a “ransomware” attack.

Threat actors have figured out that managing encryption keys is challenging, stealing data and holding it hostage is significantly easier. They’ve also figured out that stealing the right data can be just as profitable as encryption and, as we’ve seen from ransomware trends, switching to data theft only allows groups to accelerate the number of attacks. Compare the number of victims from 2024 to 2025 in the Recorded Future® Ransomware dashboard with a noticeable rise in ransomware trends.

alt=""

Line graph of ransomware trends

Figure 1: Rise in ransomware trends increasing from 2024 to 2025 (Source: Recorded Future)

  • ✇Recorded Future
  • Ransomware is the Scoreboard
    13,000. That’s the number of ransomware victims Recorded Future has observed over the past two years. Watching the near-real-time ransomware attacks on businesses, non-profits, and government agencies has left me, like many security professionals and board directors, pondering how and why cyber defense keeps losing this particular fight. Adversaries like Interlock a
     

Ransomware is the Scoreboard

23 de Julho de 2026, 21:00
Ransomware scoreboard by industry. 12,394 total victims, 218 Industries hit, 13.99% Manufacturing share

13,000.

That’s the number of ransomware victims Recorded Future has observed over the past two years.

Watching the near-real-time ransomware attacks on businesses, non-profits, and government agencies has left me, like many security professionals and board directors, pondering how and why cyber defense keeps losing this particular fight. Adversaries like Interlock and RansomHub have continued their successful march to riches over the past 18 months. The multi-billion-ruble question is, “How?”

RansomHub Ransomware Group Malicious Traffic Analysis defensive graph

BloodHound and the defensive graph concept debuted over a decade ago and still maintain a vibrant open-source community. Continuous Threat Exposure Management (CTEM) (and attack path management) is an established cyber vendor category, yet ransomware crews are demonstrably eating many organizations’ lunch.

Let’s explore the problems (which are relatively easy to enumerate) and a solution (harder): modeling defense as the graph attackers actually traverse, at the speed they traverse it, which, of course, involves intelligence.

The Barometer

Ransomware is a solid barometer of operational defensive success, specifically because, unlike espionage, it’s noisy, financially motivated, and opportunistic. Certainly, ransomware also benefits from an optimal ecosystem, including payment economics, cyber insurance playbooks, and jurisdictional safe havens, which help incentivize ransomware gangs to find the cheapest attack paths. Relatively inexperienced actors can pick up commodity tools and reach the crown jewels. That highly repeated Ransomware-as-a-Service (RaaS) dynamic is a verdict on the availability of attack paths, regardless of payment incentives.

❌
❌