Cybersecurity Daily: News & Threats
(00:00:00) Extortion Without Encryption, Third-Party Breach Surge & Q-Day Risk (00:00:45) Spain's Pure Extortion Alert (00:01:24) Third-Party Breach Epidemic (00:02:11) AI Poisoning Supply Chains (00:02:41) Q-Day Amplifies Stolen Data Risk (00:03:01) What Defenders Should Watch Ransomware's economic model has collapsed — and attackers have already moved on. In today's briefing, we unpack the most significant shift in threat actor behaviour in years: gangs abandoning file encryption entirely in favour of silent exfiltration and pure extortion. When only 28% of victims now pay ransoms — down from 76% in 2019 — the incentive to encrypt evaporated. What replaced it is stealthier, leaves almost no forensic artifact, and renders traditional EDR tooling blind. Kaspersky has confirmed an active pure-extortion campaign targeting Spanish enterprises right now. Infiltrate, exfiltrate, disappear, extort. No encrypted files. No ransom note dropped to disk. The signal most defenders are watching for never fires. Running parallel to that story: third-party and supply chain breaches have doubled in a single year, from 15% to 30% of material incidents. SecurityScorecard puts the broader figure at 35.5% of all breaches — up 6.5 points year over year. Vendors and supply chain partners are now a more reliable attack pathway than direct compromise, and a single weak vendor can cascade into dozens of customers simultaneously. Layered on top: adversaries are deploying machine learning against vendor logistics and manufacturing systems — model poisoning, prompt injection, adversarial inputs — at a scale and cost defenders haven't matched yet. Finally, the harvest-now, decrypt-later threat ties it all together. Data silently stolen today in extortion campaigns could be decrypted after a future quantum breakthrough, making Q-Day a compounding risk for every organisation that isn't already migrating to post-quantum cryptography. Detection priorities, SBOM mandates, zero-trust baselines, and DLP reconfiguration — all covered in today's episode. This episode includes AI-generated content.
32 episoder
Kommentarer
0Vær den første til at kommentere
Tilmeld dig nu og bliv en del af Cybersecurity Daily: News & Threats-fællesskabet!