ZeroHour

Search: “Recorded Future AI”

26 stories

Recorded Future Launches AI Alert Filtering

Recorded Future launched AI Alert Filtering to automatically triage threat intelligence alerts by relevance, letting analysts prioritize faster while retaining control.

Recorded Future announced general availability of AI Alert Filtering, powered by Recorded Future AI. The feature automates the first pass of filtering alerts by relevance so analysts can prioritize faster while keeping human control. It applies LLM-based automation to threat intelligence alert triage workflows.

Recorded Future · 22d agoTools

Recorded Future Launches Impact and Metrics Dashboard

Recorded Future releases an Impact and Metrics Dashboard aggregating risk-reduction, detection, and analyst-efficiency metrics for customer leadership reporting.

The dashboard pulls data from a customer's environment, alerts, integrations, threat detections, and analyst activity into six metric areas: platform-wide security value, threat prioritization, threat detection, digital risk protection, account and credential monitoring, and Recorded Future AI and Insikt Group research usage. It is available now to all Recorded Future customers, who are advised to configure Priority Intelligence Requirements in Settings so reporting maps to their intelligence program. The vendor cites its 2025 ROI Report across nearly 300 customers reporting 351.3% annual ROI and says customers aligning alerting to PIRs identified new threats 65% faster.

Recorded Future · 24d agoTools

The AI Malware Maturity Gap

Recorded Future introduces AIM3, a five-level maturity model for AI malware, showing current attacker AI use is mostly AI-assisted rather than autonomous.

Recorded Future proposes AIM3, a five-level model defining AI malware from LLM-translated to LLM-embedded, spanning experimentation to fully autonomous agentic campaigns. Public examples remain early-stage: PROMPTFLUX uses Google Gemini to rewrite its VBScript dropper (Level 1), while Lamehug/PROMPTSTEAL, attributed to APT28, invokes the HuggingFace API to generate reconnaissance commands (Level 3). The authors argue most current AI malware augments existing tradecraft rather than enabling one-click autonomous attacks.

Recorded Future · 22d agoResearch

The Agentic SOC – From AI Theater to Real Defense

Recorded Future and Accenture experts outline how security teams can move beyond 'AI theater' toward agentic SOC operations guided by measurable KPIs.

Recorded Future published a blog featuring perspectives from its own and Accenture experts on building an agentic security operations center. The piece argues organizations should prioritize measurable KPIs and proactively mitigate risks from autonomous agents. It also discusses evolving the analyst role from managing alerts to managing agents.

Recorded Future · 16d agoIndustry

Why The Vulnerability Backlog Is About To Get Worse

Recorded Future analysis says AI-driven vulnerability discovery and faster weaponization will grow the triage backlog while shrinking defenders' response windows.

Disclosed vulnerabilities rose from roughly 21,000 in 2021 to nearly 50,000 in 2025, while Recorded Future assessed only 446 as actively exploited in 2025. VulnCheck found nearly 29% of 2025 KEV entries were exploited on or before CVE publication. The authors argue AI-assisted discovery and automated exploit development will multiply credible reports, cut disclosure-to-exploit time toward minutes, and force re-evaluation of medium-severity flaws as exploit-chain components.

Recorded Future · 22d agoResearch

Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization

Recorded Future launched Automated Signature Creation in ASI, turning new CVEs into deployable detection signatures in as little as 31 minutes.

Recorded Future announced Automated Signature Creation within its Attack Surface Intelligence product, autonomously generating production-ready detection signatures for newly surfaced vulnerabilities in as little as 31 minutes. The platform correlates an organization's internet-facing assets, live threat activity (malware, ransomware, actor intent), and vulnerability intelligence to prioritize which CVEs warrant detection. The company reports a tenfold increase in in-platform signatures and maps the capability to the four prioritization criteria in CISA's June 2026 directive on risk-based vulnerability mitigation.

Recorded Future · 13d agoToolsCVE-2025-09941

Threat Intelligence Alone Won't Close the Exploitation Gap

Pentera argues threat intelligence alone leaves a validation gap, promoting threat-led penetration testing that auto-tests leaked credentials against real attack surfaces.

A contributed Pentera piece argues that threat intelligence signals such as leaked credentials and vulnerability advisories often sit unactioned in queues because teams lack the offensive capacity to validate them against live environments. It promotes threat-led penetration testing (TLPT) and highlights Pentera's integration with Recorded Future, which triggers automated validation of leaked credentials against an organization's external attack surface. Wyndham Hotels & Resorts cybersecurity VP Joseph Gothelf is quoted supporting the convergence of threat intelligence and security validation.

The Hacker News · 1d agoIndustry

Recorded Future Launches Digital Risk Protection, Unifying Brand and Identity Monitoring

Recorded Future launched Digital Risk Protection, unifying brand and identity monitoring across five external threat surfaces in one workflow.

Recorded Future announced Digital Risk Protection, combining brand threat monitoring and identity exposure monitoring across five use cases: malicious site, impersonation, code repository, dark web brand, and identity exposure monitoring. The platform includes an AI Triage Agent that automates alert evaluation with explicit verdicts and context, expanding social media analysis, OCR, full Telegram coverage, and infostealer log ingestion. Gartner's 2026 Magic Quadrant folded digital risk protection into cyber threat intelligence technologies, and the launch cites $15.9 billion in 2025 US fraud/scam losses, up 28% year over year.

Recorded Future · 8d agoTools

Citrix adds AI-powered browser activity analysis to SecurAccess

Citrix launched Session Insights for SecurAccess with Chrome Enterprise, using AI to record and analyze browser activity from users and autonomous agents.

Citrix Session Insights adds automatic session recording and AI-powered risk detection for browser activity by human users and autonomous AI agents within Citrix SecurAccess with Chrome Enterprise. The capability creates visual forensic records, highlights risky behavior for faster investigations, and recommends policy adjustments or changes to agent authority levels. It is designed to support audits and governance as enterprise AI agent workflows expand.

Help Net Security · 1d agoTools

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

NSA is reorganizing into five mission centers covering China, cybersecurity, AI, combat support and global intelligence, with full capability targeted by January.

NSA Director Gen. Joshua Rudd announced a sweeping reorganization replacing existing directorates with five mission centers focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence. A 30-day implementation clock has started, and the centers are expected to reach full operational capability by January. Officials acknowledge the rapid realignment will 'break things' in the agency's bureaucracy; this is the largest restructuring since the NSA21 effort roughly a decade ago, which was widely viewed as a failure.

The Record · 3d agoPolicy & legal

CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro

CIA deputy director credits the Cyber Mission Center's cyber operations for the intelligence picture behind Nicolás Maduro's capture.

CIA Deputy Director Michael Ellis said at the Billington Cybersecurity Summit that cyber operations built the 'flawless intelligence picture' enabling US special forces to locate Nicolás Maduro in his Caracas bunker and apprehend him within four minutes of landing during January's Operation Absolute Resolve. Director John Ratcliffe elevated the Center for Cyber Intelligence to a standalone mission center, which Ellis said smooths reporting chains and aligns resources. Ellis also said AI will 'permeate' every aspect of intelligence work, with human-in-the-loop safeguards and multi-vendor approaches to avoid model lock-in. The US has unsealed narcoterrorism charges against Maduro and his wife, who are seeking dismissal under immunity claims.

The Record · 8d agoPolicy & legal 2 sources

Lawmakers call for investigation into impact of CISA staffing cuts

Democratic lawmakers asked the GAO to investigate how CISA's roughly one-third workforce reduction affects its mission and critical-infrastructure protection.

Democratic lawmakers led by House Homeland Security ranking member Bennie Thompson asked the Government Accountability Office to examine how recent staffing cuts at CISA affect its ability to protect critical infrastructure and respond to cyber and physical threats. Nearly 1,000 CISA employees have been fired or quit since the Trump administration began, and acting director Nick Andersen plans to hire 300. The letter also flags the FY2027 budget proposal to eliminate nearly 900 additional positions and cut more than $700 million from the agency. CISA has had no confirmed director since Jen Easterly departed, and GAO confirmed it received the request.

The Record · 26d agoPolicy & legal

What the 3M ChatGPT case reveals about AI governance

3M litigation shows ChatGPT prompts can become discoverable evidence, forcing enterprises to govern AI conversation records.

In the Watson Grinding explosion litigation, an engineering expert retained by 3M had used ChatGPT, and a surfaced prompt asked the system to 'show how 3M is 0% at fault'; after an off-record deposition demand, more than 350 pages of previously unproduced ChatGPT material were provided. The author argues AI interaction histories are becoming part of decision records and discovery material, a trend the American Bar Association has already examined. Enterprises are urged to manage retention, ownership, sharing, and deletion of AI conversation logs across tools like ChatGPT, Copilot, Claude, and Gemini.

CSO Online · 3d agoPolicy & legal

The Money Mule Solution: What Every Scam Has in Common

CYBERA's money mule intelligence, now in Recorded Future's Payment Fraud Intelligence, targets the shared exit point of $450B-$1T annual scam losses.

Scams, especially authorized push payment fraud, do not require a breach; Global Anti-Scam Alliance estimated ~$450B in 2025 losses while CYBERA co-founder Claudio Staub puts the real figure near $1 trillion when underreporting is counted. Every scam needs a mule account to receive funds, so CYBERA uses agentic personas to engage active scammers and extract verified mule account details before payments occur, now available as an add-on to Recorded Future's Payment Fraud Intelligence. CYBERA collected over 16,000 confirmed mule accounts across 72 countries in H2 2025, finding 28% remained active 30 days or more after identification, including one account in 25 engagements. In Europe 51% of mule accounts sat at neobanks and fintechs, while outside Europe 69% were at major banks; regulatory pressure like the UK's APP reimbursement mandate is raising the stakes for institutions.

Recorded Future · 18d agoPhishing & fraud

Hottest cybersecurity open-source tools of the month: August 2026

August's open-source security roundup highlights NVIDIA SkillSpector for AI agent skill scanning, Future AGI, Chainloop, PentestGPT, and Hazmat agent containment.

Help Net Security's August 2026 roundup covers five open-source tools: NVIDIA's SkillSpector, a scanner that assesses AI agent skills from directories, zips, SKILL.md files, or Git URLs and returns findings and risk scores; Future AGI, an Apache 2.0 platform for tracing, evaluating, simulating, and guardrailing LLM agents; Chainloop, a software supply chain evidence store that produces signed in-toto attestations in CI pipelines; PentestGPT, an agentic penetration testing framework running recon, exploit, and reporting stages; and Hazmat, which runs AI coding agents like Claude Code and Codex inside a separate machine account for containment.

Help Net Security · 22d agoTools

White House bans foreign-made equipment for power generation over cyber backdoor concerns

Trump executive order bans acquisition of foreign-made bulk-power system equipment over cyber backdoor and supply-chain concerns for US electricity infrastructure.

The White House issued an executive order declaring foreign-made bulk-power system electric equipment an "unusual and extraordinary threat," banning its acquisition or installation in the US. The order covers technology managing transmission lines rated at 69,000 volts or higher, substations, control rooms, power generating stations, reactors, and associated remotely accessible software and firmware. It follows recent cyberattacks on water utilities in at least 12 states, malicious activity targeting over 100 internet-exposed water and wastewater systems, and an NSA/FBI advisory on an AI-powered threat to operational technology. The Defense, Commerce, and Energy Departments have 120 days to create rules, identify countries warranting scrutiny, and inventory at-risk equipment.

The Record · 20d agoPolicy & legal

Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit

NSA will host a reunion of former Tailored Access Operations hackers as it moves to rebuild and rebrand the elite unit.

The invitation-only event at Fort Meade, spearheaded by Deputy Director Tim Kosiba, a former TAO technical director, will tour the new TAO building and pitch alumni to return. TAO, credited with contributions to Stuxnet and once grown to over 2,000 personnel, was renamed Computer Network Operations about a decade ago, and the recent reshuffle undid some of those changes after NSA lost roughly 2,100 staff (8% of its workforce) last year.

The Record · 21d agoIndustry

Hunting Vulnerabilities Using Frontier Models

Okta used frontier AI models GPT-5.5 Cyber and Mythos via OpenAI and Anthropic programs to scan millions of code lines for vulnerabilities.

Okta describes using frontier AI models, including GPT-5.5 Cyber Preview (TAC) and Mythos Preview, through OpenAI's Daybreak Cyber Partner Program and Anthropic's Project Glasswing to hunt vulnerabilities across its product codebase. The team built a custom Python orchestrator with strong isolation, vendor-agnostic model support, and four distinct scanning pipelines executed as isolated Codex or Claude Code sessions with progressive context loading to reduce context bloat. Human experts and AI agents worked both autonomously and in paired hunts, and Okta reports the best results when humans and agents taught each other.

Okta Security · 9d agoResearch

How MSSPs Can Prove Their Value When “Nothing Happened”

ANY.RUN outlines how MSSPs can demonstrate SOC value by reporting investigation outcomes, threat patterns, and response metrics using its sandbox products.

ANY.RUN's blog argues MSSPs should report investigation outcomes, decision speed, and recurring threat patterns rather than raw alert counts. It cites company 2026 data: email accounts for 30.3% of MSSP sandbox submissions, and customers report 20% less Tier 1 investigation time and 30% fewer Tier 1 to Tier 2 escalations. Frequently analyzed threat families include ClickFix, Sneaky2FA, EvilTokens, EtherHiding, and Kali365.

ANY.RUN · 4h agoIndustry 3 sources

How AI and cybersecurity are reshaping ServiceNow

Analysis argues ServiceNow's $7.75B Armis acquisition and AI-driven consumption pricing are reshaping its ITSM platform amid SaaS market anxiety.

CSO Online examines how AI agents, vibe-coding fears, and a reported 30% share price drop are pressuring ITSM leader ServiceNow, and how the company is pivoting toward consumption-based revenue and cybersecurity. The piece highlights ServiceNow's $7.75 billion cash acquisition of Armis, priced at roughly 23 times the vendor's $340 million annual revenue, as a strategic move to supercharge ITSM workflows with accurate device inventory and orchestration rather than to sell a standalone security product. Experts note this ends Armis's vendor-neutral position, introduces the CISO as a new buyer, and will likely lead to aggressive Armis bundling at contract renewals.

CSO Online · 6d agoIndustry

Germany moves to give spy agencies hacking and sabotage powers

Germany's cabinet approved a 732-page bill granting BND and BfV intelligence agencies new hacking, sabotage, and disinformation powers pending parliamentary approval.

Germany's cabinet approved draft legislation that would give the foreign intelligence service BND and domestic agency BfV active operational powers, including hacking foreign systems, sabotaging supply chains with faulty components, disabling servers of hostile state-sponsored hackers, and feeding false information to extremists inside Germany. The 732-page bill, the largest overhaul of postwar German spy laws, requires telecom carriers and digital providers to assist the agencies, bars measures endangering life, and imposes new statutory controls on how agencies use AI analysis, including judge-supervised spot checks of machine-generated outputs. The reforms stem from a Federal Constitutional Court ruling on surveillance proportionality and are expected to pass parliament, with the government aiming for the law to take effect next year; civil liberties groups plan to challenge it.

The Record · Aug 13, 2026Policy & legal

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Academics linked Chinese vendor Geedge Networks' Tiangou Secure Gateway source code to one of the Great Firewall's three traffic filtering capabilities.

US researchers presenting at USENIX Security reconstructed Geedge Networks' Tiangou Secure Gateway firmware from over 100,000 leaked files, including Git repositories with commit history, and matched its filtering behavior to sections of China's Great Firewall. They found only 1 of 3 characterized DNS injectors matched Geedge code, noted the system relies on memory-unsafe C components and copied third-party code, and said its bugs could aid future circumvention tools. Geedge also exports censorship tools to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The newsletter additionally rounds up multiple breaches.

Risky Business News · 27d agoResearch2

Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws

Automox launched an AI-speed Mitigation Worklet Pipeline that drafts and publishes mitigations for unpatchable vulnerabilities within hours of disclosure.

Automox announced its Mitigation Worklet Pipeline, which uses AI to draft mitigations for unpatchable vulnerabilities and publishes human-reviewed Worklets to its catalog within hours of disclosure. The company cites rising vulnerability volume, including a record Patch Tuesday with 973 CVEs, as motivation. Customers can search Worklets by CVE, control deployment targets, and verify execution through Activity Logs and Policy Results.

Help Net Security · 6d agoTools

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

A weekly bulletin aggregating short security updates, including the City-Forum data-theft campaign, a ShipMonk breach, a Cursor CLI flaw, and GhostJacking AI attacks.

The Hacker News ThreatsDay Bulletin bundles roughly 20 short updates across cloud services, AI tools, malware, breaches, and scams. Highlights include the City-Forum campaign pulling data from unauthenticated guest access in Salesforce Experience Cloud and ServiceNow Service Portals since March 2025, and a ShipMonk breach exposing Trezor customer order data for orders in seven countries between May 10 and August 8, 2026. Other items cover a patched Cursor CLI flaw that let cloned repositories run commands before the workspace-trust prompt, Okta's analysis of the Work Panel vishing console used by actors like UNC6671, and GhostJacking AI agent hijacking via a patched Claude Desktop sandbox escape. Meta also launched an on-device WhatsApp Scam Alert machine learning model that keeps message content on the device.

The Hacker News · 29d agoIndustry1

1Password's AI patching benchmark is misleading

Trail of Bits reanalysis says 1Password's 26% AI clean-fix rate is misleading; 86% of eligible patches blocked exploits.

Trail of Bits critiques 1Password's FLAWED AI patching benchmark, arguing its 26% clean-fix headline mixes trials where agents were instructed to apply wrong fixes (22% of data) with trials that prohibited compiling or testing (36%). Restricting to reasonable conditions, 2,634 of 3,067 patches (86%) blocked the supplied exploit. Trail of Bits also reports 12.5% of 2,265 developer first fixes failed in its own 2024-2026 assessments, and released post-patch-validation and review-walkthrough agent skills.

Lobsters · security · 1d agoResearch1

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Hacker News ThreatsDay digest: malicious browser extensions, AI-agent intrusions, NCSC shadow AI warning, M&A wire fraud, and 119,000-domain fake shops.

Socket found four malicious Chrome and Firefox extensions (J7Tracker, VREO, Orbit Tracker) stealing session tokens and wallet data from Axiom Trade and Padre users via attacker-controlled Vercel deployments. Hunt.io reported a Chinese-speaking operator using Claude Code, Alibaba Qwen, and DeepSeek with the SecFlow orchestration framework to automate intrusions against government and financial targets in Afghanistan, Thailand, Taiwan, and the US. The UK NCSC warned shadow AI use risks breaches and regulatory failure, Microsoft announced privacy-preserving Windows Age APIs, and Gen Digital described fake M&A wire-fraud scams. A 119,000-domain fake-shop operation called DoppelCart was also highlighted.

The Hacker News · 6d agoIndustry in the wild