ZeroHour

Source: Infosecurity Magazine

9 stories in the last 7d

Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program

SE Labs launched PIVOT, a six-month vendor detection testing program backed by CrowdStrike, Fortinet, Palo Alto Networks and Sophos, as major vendors exit MITRE evaluations.

SE Labs unveiled PIVOT on September 15, a six-month testing program in which its ethical hackers replicate nation-state and criminal attack chains against participating vendor products, with results due January 2027. Broadcom (Symantec/Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos have confirmed participation, and Gartner and Forrester analysts will verify the underlying evidence before publication. The launch follows declining participation in MITRE Engenuity ATT&CK Evaluations: Enterprise, which fell from 30 vendors in 2023 to 11 in 2025 after public withdrawals by Microsoft, SentinelOne and Palo Alto Networks.

Infosecurity Magazineupdated · 3h agofirst · 1d agoIndustry 12 sources

CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

CISA and NIST published Interagency Report 8587 with voluntary guidance to harden cloud identity tokens against theft, forgery, and lateral movement.

CISA and NIST released NIST Interagency Report 8587 on September 15 with final voluntary guidance for federal agencies, cloud providers, and their customers on protecting SSO, federation, and API tokens. Requirements include one-hour maximum token lifetimes, 90-day signing key rotation for high-impact systems, hardware-backed key storage, explicit audience fields, and keeping tokens out of logs. The guidance was motivated by the 2020 ADFS compromise where forged SAML assertions bypassed MFA, and an incident where a leaked consumer signing key enabled token forgery and theft of 60,000+ emails from one agency. Nearly 250 public comments shaped the text, with input from Google, Microsoft, Okta, AWS, Oracle, IBM, HashiCorp, Wiz, and the OpenID Foundation via the Joint Cyber Defense Collaborative.

Infosecurity Magazine · 22h agoAdvisory

Cyber-Attacks Cost Organizations $52,000 on Average

Hiscox's 2026 survey of 6,800 security leaders found 29% of organizations hit by successful attacks averaging $52,000 in costs and 32.8 hours of downtime.

The Hiscox Cyber Readiness Report 2026, based on a survey of 6,800 security decision-makers across the UK, Europe, and US, found 29% of organizations suffered at least one successful cyber-attack in the past 12 months, averaging four incidents per victim. UK firms were most attacked at 38% while US firms were least at 20%; average incident cost was $52,000 globally, peaking at $134,138 in Italy, with 32.8 hours of average downtime. Impacts included growth delays (32%), financial penalties (28%), and burnout or toxic culture (69%). Businesses invest about $51,000 annually in resilience, and 32% now tie executive compensation to cybersecurity outcomes.

Infosecurity Magazine · 1d agoIndustry

Most Firms Unable to Recover Quickly from Ransomware

Fenix24's first State of Recoverability report finds only 0.5% of 800+ ransomware clients neared 24-48 hour recovery targets, with identity failures central.

Drawing on 500+ ransomware recoveries, Fenix24 found only four of 800+ clients (0.5%) came close to their own 24-48 hour recovery targets, and none reached full operations for weeks. 99.2% lacked a documented identity recovery plan, Active Directory typically fell first, and 94% tied backup systems to the compromised directory. In 38% of engagements backups survived but could not carry recovery; storage ran short in 82% of cases and 95% lacked meaningful MFA on critical infrastructure consoles.

Infosecurity Magazine · 1d agoResearch

Black Axe Members Extradited to US Over Internet Fraud Claims

Five alleged Black Axe leaders were extradited from South Africa to the US over romance scam and money laundering charges.

Five Nigerian nationals who allegedly led Black Axe's Cape Town zone were extradited to the US on September 11 and appeared in federal court in Trenton, New Jersey on September 14. The superseding indictment alleges romance scams, advance-fee fraud, BEC, and money laundering via US bank accounts between 2011 and 2021, using social media, dating sites, and VoIP, with coercion via threats to distribute victims' intimate photos. Charges include wire fraud and money laundering conspiracy carrying up to 20 years each, plus aggravated identity theft for three defendants.

Infosecurity Magazine · 1d agoPolicy & legal

AI the Top Priority for New Spend as Cyber Budgets Flatline

IANS survey of 500 US CISOs finds AI is the top priority for net-new security budget even as overall cybersecurity budgets stay flat.

IANS's 2026 Security Budget Benchmark Report, based on interviews with 500 US security executives, found AI was the most popular focus for incremental budget, cited by 69% of respondents. Software now accounts for 35% of the security budget in 2026, up from 29% last year, nearly matching staff and compensation. Overall median budget growth remained flat, with 55% keeping budgets flat or making cuts, while 71% of VC-backed companies increased security budgets versus 52% of public companies. Most CISOs (69%) do not expect AI to cut headcount, and 81% anticipate it creating demand for new roles and skills.

Infosecurity Magazine · 1d agoIndustry

Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

MarketsandMarkets projects the cyber warfare market to nearly double from $14.99bn in 2026 to $28.75bn by 2031, driven by attacks on military systems.

A MarketsandMarkets report projects the global cyber warfare market will grow from $14.99bn in 2026 to $28.75bn by 2031. Growth is driven by rising attacks on military networks, reliance on connected platforms and cloud command-and-control systems, and Western investment in offensive cyber capabilities. Europe is projected to hold the largest market share, supported by NATO's shared cyber capabilities and joint exercises. Cloud-based security is expected to be the fastest-growing market segment.

Infosecurity Magazine · 2d agoIndustry

Most Organizations Skip Permissions Reviews Before Deploying AI Tools

Syskit survey of 327 US/UK IT leaders finds 76% deployed M365 AI tools but only 43% reviewed permissions and oversharing risk first.

Syskit's State of Microsoft 365 Governance Report 2026, based on a survey of 327 IT and security decision-makers at US and UK organizations with 500+ employees, shows most enterprises deploy AI tools like Copilot without thorough permissions reviews. Only 22% have a formal policy defining what AI agents may access, and 9% let agents inherit the deployer's full permissions. 90% report experiencing or suspecting a security incident tied to M365 misconfigurations or over-permissioned access in the past two years.

Infosecurity Magazine · 6d agoAI safety & security2· 1 read

CISA Updates Insider Threat Guide With New Mitigation Advice

CISA updated its Insider Threat Mitigation Guide on September 9 with new case studies and guidance on hybrid work, AI and employee separations.

CISA published a revision of its Insider Threat Mitigation Guide, first issued in 2020, adding case studies, statistics and guidance for security, HR and leadership audiences. New material covers hybrid and remote work changes to physical and digital access, AI used to manipulate or deceive, access control, visitor screening and adverse employee separations. The agency framed the update around growing insider threat impact on critical infrastructure and pointed to preparedness resources for organizations without existing programs.

Infosecurity Magazine · 6d agoAdvisory