🔶 Incident response guide for AWS CloudTrail investigations
AWS's Security Incident Response Team (SIRT) walks through two real-world CloudTrail investigation scenarios, cross-account S3 data deletion with ransomware implications and cryptocurrency mining via stolen console credentials, teaching investigators how to read key log fields, recognize attacker patterns, and apply practical response checklists. You can also check out Part 2.
https://aws.amazon.com/ru/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1
#aws
AWS's Security Incident Response Team (SIRT) walks through two real-world CloudTrail investigation scenarios, cross-account S3 data deletion with ransomware implications and cryptocurrency mining via stolen console credentials, teaching investigators how to read key log fields, recognize attacker patterns, and apply practical response checklists. You can also check out Part 2.
https://aws.amazon.com/ru/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1
#aws
❤1👍1🔥1
🔶 Agentic SOC alert triage: 60% to 92% AI accuracy
Elastic's InfoSec team describes how enriching a three-agent SOC triage pipeline with per-rule investigation guides, user risk data, and 30 days of historical case verdicts lifted AI alert accuracy from 60% to 92%, enabling analysts to close most alerts with a single Slack button click.
https://www.elastic.co/security-labs/blog/alert-triage-agentic-soc-self-correcting-agents
#aws
Elastic's InfoSec team describes how enriching a three-agent SOC triage pipeline with per-rule investigation guides, user risk data, and 30 days of historical case verdicts lifted AI alert accuracy from 60% to 92%, enabling analysts to close most alerts with a single Slack button click.
https://www.elastic.co/security-labs/blog/alert-triage-agentic-soc-self-correcting-agents
#aws
❤2👍1🔥1
This AI threat update provides GTIG's findings on adversarial misuse of AI including Gemini and other non-Google tools.
https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
Microsoft researchers discovered a high-volume phishing campaign that repurposed ASCII smuggling to split financial keywords like "funding" and evade email filters, generating over 2.3 million messages daily at its February 2026 peak.
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3🔥1👏1
Anthropic's September 2026 threat report covers disrupted misuse of Claude (Dec 2025-Aug 2026) across seven harm areas: AI-augmented cyber ops by state and criminal actors, influence operations across six continents, surveillance platforms targeting dissidents, conventional weapons software development, dual-use biological research, fraud/scams, and illicit distillation by PRC AI labs including Alibaba, DeepSeek, Moonshot, and Zhipu.
https://www.anthropic.com/threat-intelligence-report-september-2026
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
OpenAI's Defense Factory is a continuous, agent-first vulnerability detection and remediation pipeline using Codex and specialized cyber models (Daybreak Blue/Red). It automates inventory, triage, dynamic validation, ownership assignment, and verified patching, achieving 0.81% false-positive rate and 0.53% fix rollback rate.
https://openai.com/ru-RU/the-defense-factory
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
Techniques for attacking AI customer service agents: email spoofing to hijack agent actions, MFA bypass via email normalization and IVR channel-switching, email address smuggling via RFC comments for IDOR, OTP exfiltration via inbox-monitoring agents, asymmetric MIME content, conversation forgery, and RAG knowledge base poisoning.
https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
CVE-2026-82533 (CVSS 9.4) in DeepSeek Harness lets a sandboxed AI agent escape confinement via a single curl call to the unauthenticated local API, spoofing the Host header to elevate its session to danger-full-access.
https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape
#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
🔶 Introducing Amazon EBS Volume Clones across AWS account
AWS introduces Amazon EBS Volume Clones with cross-account copy, so you can create copies of your EBS volumes into other AWS accounts and optionally re-encrypt them with an AWS Key Management Service (AWS KMS) key in the target account.
https://aws.amazon.com/ru/blogs/aws/introducing-amazon-ebs-volume-clones-across-aws-accounts
#aws
AWS introduces Amazon EBS Volume Clones with cross-account copy, so you can create copies of your EBS volumes into other AWS accounts and optionally re-encrypt them with an AWS Key Management Service (AWS KMS) key in the target account.
https://aws.amazon.com/ru/blogs/aws/introducing-amazon-ebs-volume-clones-across-aws-accounts
#aws
❤1👍1🔥1