Darktrace detected a blockchain-hosted infostealer campaign targeting Windows and macOS devices across multiple customer environments. The campaign combined ClickFix social engineering with trusted ...
New research reveals how agentic AI harnesses can be hijacked, turning a workstation into an autonomous attacker. Using conversation history poisoning, researchers convinced a frontier model it was an ...
The company faced a challenge familiar to many organizations moving quickly with AI: demand for new tools was growing faster than the organization's ability to see and govern how they were being used.
Darktrace’s analysis of the first half of 2026 shows attackers increasingly exploiting trust rather than bypassing security controls. Identity compromise, supply-chain attacks, SaaS abuse, AI-enabled ...
As AI agents become more autonomous, understanding behavior is becoming even more important. The OpenAI and Hugging Face incident highlights why behavioral security is foundational to securely ...
Darktrace researchers identified a Twill Typhoon–linked China‑nexus campaign targeting APJ customers. The activity observed includes CDN impersonation, legitimate binaries, and DLL sideloading to ...
Darktrace analysts observed attackers exploiting a Jenkins honeypot to deploy a new DDoS botnet targeting video game servers. Leveraging Jenkins scriptText abuse, the malware installs a multi-platform ...
Darktrace analysis reveals ZionSiphon, an OT‑focused malware targeting Israeli water treatment and desalination systems. The malware combines privilege escalation, persistence, USB propagation, and ...
As Model Context Protocol (MCP) becomes the control plane for autonomous AI agents, it creates a new and largely ungoverned security attack surface. This article outlines the key MCP risks CISOs must ...
Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices. Darktrace’s honeypot networks revealed evolving tactics and ...
NetSupport RAT is the malicious abuse of the legitimate NetSupport Manager remote administration tool. Originally designed for IT support, threat actors exploit it to gain unauthorized system access, ...
This blog explores a macOS phishing campaign that leverages social engineering, AppleScript loaders, and attempted abuse of the macOS’ TCC feature to gain privileged access. It highlights a broader ...