Fortinet confirmed a 9.8-rated, unauthenticated file-write zero-day in FortiMail that attackers are using to drop a reboot-surviving ld.so.preload rootkit. Patching closes the hole but leaves any implant already on the appliance in place.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Detection at the first hop forced CISA's red team onto donated access at Organization B. It did not stop the team reaching the same sensitive systems it reached at Organization A.
Perspective Coverage
5 publishers
- Builder
- Builder 39%
- Operator
- Operator 53%
- Investor
- Investor 8%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+12
- Incentives35
- Confidence72
Five US agencies report attackers scanning for exposed S7 PLCs and using a public library to read and write data blocks. The mitigation list reads like a commissioning checklist.
Publishers:sans.org · scworld.com Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+40
- Incentives
- Insufficient
- Confidence60
Unit 42 worked a ransomware intrusion where the operator handed tactical execution to frontier AI agents, and the chain from a public API endpoint to stolen cloud AI keys closed inside a single working day with no zero-day.
Reality
- Evidence50
- Adoption20
- Hype gap+25
- Incentives60
- Confidence55
The federal cyber agency now recommends planting fake records, credentials and files across critical infrastructure networks, and its pitch to understaffed teams is that an alert on a decoy needs no analyst to interpret it.
Perspective Coverage
5 publishers
- Builder
- Builder 46%
- Operator
- Operator 47%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence75
Conifers assessed 14,652 customer detections and found 47% at the average organization need attention while still showing as deployed. Against the ATT&CK techniques relevant to each customer, average protection stood at 64%, leaving one in three without a reliable detection.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+30
- Incentives68
- Confidence40
SANS's 2026 hunting survey found 72.7% of hunters who caught nation-state actors saw them living off the land, against 63.4% for ransomware crews. Hunters rank data quality as their top barrier, so detecting misused admin tools starts with the telemetry those hunts depend on.
Reality
- Evidence50
- Adoption45
- Hype gap+10
- Incentives60
- Confidence50
Island says the adversary-in-the-middle service runs on at least 755 domains against hundreds of organizations. The session it steals arrives after an authentication the identity provider records as entirely normal.
Reality
- Evidence45
- Adoption58
- Hype gap+18
- Incentives65
- Confidence55
Microsoft and Omdia put the average security operations centre at close to 3,000 alerts a day with 42% never investigated, while a 2026 benchmark scored the best frontier model at 3.8% on finding malicious events in raw Windows logs.
Reality
- Evidence38
- Adoption45
- Hype gap+30
- Incentives80
- Confidence40
Kaspersky's responders found no encrypted files and no malware on disk across the Windows estate of a Middle East manufacturer in April 2026. The impact arrived through one Group Policy Object linked at the domain root.
Reality
- Evidence62
- Adoption35
- Hype gap+12
- Incentives72
- Confidence58
The demo uploads a model file as base64 chunks over GET, then starts an inference server on it. It shows why egress and WAF rules keyed on the HTTP verb miss what the URL is doing.
Reality
- Evidence64
- Adoption9
- Hype gap+14
- Incentives30
- Confidence56
Palo Alto's Unit 42 says a human directing AI agents went from a public API endpoint to cloud keys in under 10 hours in summer 2026. The control that blocked the backdoor attempt was a repository setting.
Reality
- Evidence52
- Adoption22
- Hype gap+18
- Incentives75
- Confidence55
The PIVOT program was announced on September 15 with Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos signed up, and the first comparative results are due in January 2027. MITRE's rival test drew 11 vendors in 2025.
Reality
- Evidence42
- Adoption35
- Hype gap+40
- Incentives72
- Confidence45
The Enterprise matrix now runs 15 tactics, and the two that replaced Defense Evasion leave different forensic evidence, so detection content mapped to the old tactic has to be reassigned technique by technique.
Reality
- Evidence48
- Adoption20
- Hype gap+18
- Incentives82
- Confidence55
Jon Baker of AttackIQ treats the subscription-gated report as evidence that AI hands any attacker fast access to a technique catalog that has not grown, and builds a spending case for chokepoint detection on it.
Reality
- Evidence32
- Adoption30
- Hype gap+32
- Incentives78
- Confidence52
Huntress and BleepingComputer describe sponsored ads that land on a real Claude Artifact page. The download link and the pasted curl command both reach elsewhere, so the trusted hostname never serves the payload.
Reality
- Evidence45
- Adoption35
- Hype gap+15
- Incentives55
- Confidence45
The malware asks for accessibility, then has a second component build a work profile and copy the bank app into it. Group-IB says the clone registers with the bank as a new device while a black screen hides the transfer.
Reality
- Evidence42
- Adoption38
- Hype gap+12
- Incentives34
- Confidence48
Rubrik's Threat Monitoring and Threat Hunting now match backup snapshots against ReversingLabs' ransomware feed, aimed at catching a dormant payload before an operator restores it and at dating the last clean snapshot.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+38
- Incentives88
- Confidence60
The new cloud web applications threat matrix sorts eleven ATT&CK tactics for managed runtimes and serverless code, starting with assets an app team rarely owns, such as dead DNS records and linked source repositories.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+6
- Incentives58
- Confidence67
Earlier coverage
- Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours
Science · September 5, 2026 · 2 publishers
- Unit 42's ten-hour intrusion forces a choice about who may disable an account without asking
Leadership · September 5, 2026 · 1 publisher
- Deception.Pro logged an operator pairing hands-on ScreenConnect with XLoader in one 54-hour chain
Security · August 31, 2026 · 1 publisher
- Zabbix's Windows agent installer loads DLLs from a directory low-privileged users can write
Build · August 28, 2026 · 1 publisher
- The 2026 LLM Top 10 lands: prompt injection still first, hidden context now its own line item
Security · August 26, 2026 · 1 publisher
- AWS says GuardDuty catches the universal attacks. The rest is your detection engineering.
Build · August 26, 2026 · 1 publisher
- AWS detection gets a shortlist: seven ATT&CK tactics, and only what has been seen in the wild
Build · August 24, 2026 · 1 publisher
- Talos tells the story instead of the matrix, and BEC's new economics fall out
Security · August 20, 2026 · 1 publisher
- The AI security line item to fund first is log coverage, not another agent
Security · August 18, 2026 · 2 publishers
- Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now
Security · August 18, 2026 · 1 publisher
- Storm-0501's first move is deleting your resource locks, not encrypting your disks
Security · August 18, 2026 · 1 publisher
- Microsoft is generating its detection test logs, and admitting what they do not prove
Build · August 17, 2026 · 1 publisher
- CrowdStrike's own triage numbers make AI auto-close a calibration contract, not a headcount cut
Build · August 17, 2026 · 1 publisher
- Seven agentic AI incidents, one front door: the identity metadata you publish on purpose
Security · August 14, 2026 · 2 publishers
- Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel
Security · August 15, 2026 · 2 publishers