Spy Vs. Spy: How GenAI Is Powering Defenders and Attackers

Generative AI (GenAI) is transforming cybersecurity for both attackers and defenders. While adversaries use it for coding, phishing, and malware, defenders utilize it to analyze threats, enhance response, and detect vulnerabilities. The rapid evolution of GenAI complicates its quantification in the threat landscape. Adversaries leverage it for anti-analysis tactics, while defenders can use it to sift through vast data. Effective GenAI applications arise in vulnerability hunting and enterprise security, although its success relies on knowledgeable humans to guide its use.

https://blog.talosintelligence.com/spy-vs-spy-how-genai-is-powering-defenders-and-attackers/

Manufacturers Face Growing Supply Chain Exposure

Manufacturers face increasing cyber threats as attackers exploit digital forms transferring sensitive data across supply chains. A Kiteworks report reveals that 88% experienced web-form security incidents, with many collecting sensitive information. Legacy systems lack modern security, making them vulnerable to various attacks. Compliance expectations are rising, complicating security efforts.

https://www.sdcexec.com/safety-security/risk-compliance/news/22956060/kiteworks-manufacturers-face-growing-supply-chain-exposure

Superagency in the Workplace: Empowering People to Unlock AI’s Full Potential

AI's workplace potential is immense, akin to the steam engine's impact during the Industrial Revolution. Companies largely invest in AI but face challenges in achieving maturity, mainly due to hesitant leadership rather than employee readiness. Employees show eagerness for AI, often underestimating its integration into their roles. A McKinsey report indicates AI can boost productivity by $4.4 trillion, emphasizing the need for bold leadership to harness this technology effectively. As AI capabilities evolve, businesses must prioritize practical applications and support for employees, aligning technological adoption with strategic goals to remain competitive.

https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/superagency-in-the-workplace-empowering-people-to-unlock-ais-full-potential-at-work

Fun With Incident Data and Statistical Process Control

Incident response time (TTR) is inherently unpredictable and rarely under statistical control, as demonstrated by a control chart analysis of Cloudflare's incident data from 2025. Filtering out irrelevant data, the analysis showed significant TTR variations, particularly for complex incidents. The unpredictability of incidents makes metrics like MTTR ineffective, emphasizing the need for continuous improvement in incident response without expecting full control over the process.

https://surfingcomplexity.blog/2025/11/27/fun-with-incident-data-and-statistical-process-control/

The Browser Defense Playbook: Stopping the Attacks That Start on Your Screen

TLDR: Browsers have become central to work, increasing risks from attacks like phishing and malware. Common security lapses include trust in browser vendors, insecure extensions, session hijacking, and lack of policies. To combat these threats, organizations should utilize secure browsers, enforce zero trust principles, conduct behavior monitoring, and continuously assess risks associated with users and their devices.

https://unit42.paloaltonetworks.com/browser-defense-playbook/

New Joint Guide Advances Secure Integration of Artificial Intelligence in Operational Technology

CISA & ASD released a guide for secure AI integration in Operational Technology (OT), highlighting risks and principles to ensure safety in critical infrastructure. Key steps include: educate on AI, assess risks, establish governance, and embed security.

https://www.cisa.gov/news-events/news/new-joint-guide-advances-secure-integration-artificial-intelligence-operational-technology

CISOs Are Questioning What a Crisis Framework Should Look Like

CISOs expect future breaches and struggle with crisis frameworks. A Binalyze report reveals 84% believe breaches are inevitable, leading to rushed budgets and investigation delays, costing $114,000 per hour. Only half of CISOs can effectively answer key questions during incidents. Limited visibility into IT environments complicates investigations, which can cost over $1 million due to unclear information. Investigators are in short supply and face burnout, slowing down response efforts. Improved investigation readiness and clarity can reduce damage and enhance recovery from attacks.

https://www.helpnetsecurity.com/2025/12/03/binalyze-crisis-management-framework-report/

How Amazon Finds Its Cybersecurity Weak Spots

Amazon avoids typical cybersecurity benchmarks and instead monitors the introduction of new and old devices in its network in real time, believing these are key to spotting risks. The company leads with meticulously detailed metrics instead of using averages or simple dashboards and shares its findings with a specialized security board committee. This approach, guided by Chief Security Officer Stephen Schmidt, emphasizes outlier risks and continuous oversight, setting Amazon apart from peers.

https://www.wsj.com/articles/how-amazon-finds-its-cybersecurity-weak-spots-f932e836

Cloudflare’s 2025 Q3 DDoS Threat Report — Including Aisuru, the Apex of Botnets

Cloudflare's 2025 Q3 DDoS Threat Report reveals a significant rise in DDoS attacks, particularly from the Aisuru botnet, reaching peaks of 29.7 Tbps. Total DDoS attacks increased by 15% QoQ, with a notable 347% surge against AI companies in September. Network-layer attacks dominate at 71%, while HTTP attacks have decreased. Major attack sources include Indonesia and key industries like Automotive and Mining, attributed to geopolitical tensions. Regions like the Maldives and France experienced spikes in attacks due to protests. Cloudflare blocked over 8.3 million attacks in Q3 alone, highlighting an urgent need for robust anti-DDoS measures.

https://blog.cloudflare.com/ddos-threat-report-2025-q3/

Scroll to Top