Cloudflare’s 2025 Q3 DDoS Threat Report — Including Aisuru, the Apex of Botnets

Cloudflare's 2025 Q3 DDoS Threat Report reveals a significant rise in DDoS attacks, particularly from the Aisuru botnet, reaching peaks of 29.7 Tbps. Total DDoS attacks increased by 15% QoQ, with a notable 347% surge against AI companies in September. Network-layer attacks dominate at 71%, while HTTP attacks have decreased. Major attack sources include Indonesia and key industries like Automotive and Mining, attributed to geopolitical tensions. Regions like the Maldives and France experienced spikes in attacks due to protests. Cloudflare blocked over 8.3 million attacks in Q3 alone, highlighting an urgent need for robust anti-DDoS measures.

https://blog.cloudflare.com/ddos-threat-report-2025-q3/

The Cybersecurity And Resilience Bill Is Coming. Here’s What It Means

UK's Cyber Security and Resilience Bill introduced in November aims to enhance cyber defenses for essential services amid rising cyberattacks. It updates 2018 NIS regulations and imposes new reporting duties with stricter penalties. Broader scope includes managed service providers and critical suppliers. Implementation phases are planned post-approval, mandating organizations to assess compliance and strengthen cyber risk management before laws take effect.

https://insight.scmagazineuk.com/the-cybersecurity-and-resilience-bill-is-coming-heres-what-it-means

Turning AI From a Cost Into a Catalyst: Rethinking The CIO’s Role In The AI Era

CIOs are largely focused on AI governance and safe use, but struggle to show clear financial returns from AI. The traditional cost-based IT budget model limits the ability to use technology as a strategic driver of business transformation. True value from AI requires rethinking operating models across the whole organization, not just adding AI to old processes. CIOs need to shift from cost managers to value creators, measuring ROI with new approaches and working with business leaders to treat technology as a long-term investment and growth driver.

https://www.forbes.com/sites/peterbendorsamuel/2025/12/03/turning-ai-from-a-cost-into-a-catalyst-rethinking-the-cios-role-in-the-ai-era/

North Korea Lures Engineers to Rent Identities in Fake IT Worker Scheme

North Korea's Famous Chollima, linked to the Lazarus group, exploits developers by recruiting them to rent their identities for illicit purposes. This scheme involves deceiving engineers into acting as fronts for North Korean agents in high-profile companies, often using AI for interviews. Engineers provide sensitive personal information and use their computers as proxies, risking legal consequences. Recent findings include spamming job listings on GitHub to attract candidates. Researchers monitored these tactics using sandbox environments, discovering tools like AI for job applications and communication methods that help agents maintain anonymity.

https://www.bleepingcomputer.com/news/security/north-korea-lures-engineers-to-rent-identities-in-fake-it-worker-scheme/

You Can’t Fall Behind in AI if You Never Start

CISO Series discusses AI integration in organizations, highlighting the challenge of securing it and the need for AI expertise due to a scarcity of trained professionals. Host David Spark and CISO Mike Johnson emphasize building internal talent for AI roles rather than hiring externally. Guest John Barrow shares the importance of internal context and trust in cybersecurity roles, advocating for proactive communication and strategic GRC positioning within the boardroom to align security with business goals while managing budget constraints.

https://cisoseries.com/you-cant-fall-behind-in-ai-if-you-never-start/

Key Questions CISOs Must Ask Before Adopting AI-enabled Cyber Solutions

The article outlines crucial steps and questions for CISOs considering AI-powered security tools. Threats involving AI, like deepfakes and data leaks, are growing, making AI-driven defenses necessary. Organizations benefit from faster breach recovery and cost savings with AI, but also face risks from unmanaged shadow AI. Key uses of AI in security include threat detection, automated reporting, and alert management. CISOs should evaluate the organization’s risk tolerance, specific security needs, and regulatory environment, and consider whether to adopt platform-based or point solutions. When assessing vendors, focus on areas such as shadow AI identification, data protection, effectiveness metrics, workforce impact, tool integration, regulatory compliance, trust in AI decisions, scalability, vendor reliability, ongoing support, and total cost.

https://www.csoonline.com/article/4094763/key-questions-cisos-must-ask-before-adopting-ai-enabled-cyber-solutions.html

How to Build Forward-thinking Cybersecurity Teams for Tomorrow

Microsoft emphasizes adapting cybersecurity talent strategies in response to AI advancements, highlighting the need for critical thinkers alongside technical skills. Future cybersecurity teams should consist of diverse backgrounds to understand AI vulnerabilities better and promote innovative problem-solving. The recruitment process must focus on adaptability, interdisciplinary collaboration, and a proactive learning culture. Effective onboarding and retention of talent are critical, emphasizing continuous training to keep pace with evolving threats. Microsoft advocates for a shift in hiring practices to build resilient cybersecurity defenses against AI-powered adversaries.

https://www.microsoft.com/en-us/security/blog/2025/12/02/how-to-build-forward-thinking-cybersecurity-teams-for-tomorrow/

AI Takes Center Stage as the Major Threat to Cybersecurity in 2026

Experian’s 2026 forecast warns that AI is transforming cyberattacks, making them more advanced and personal, with threats like synthetic identities and AI-powered malware. Data breaches are at record levels, and many consumers—especially millennials—report rising identity theft and phishing. Most people are worried that companies aren’t ready for AI-based attacks. In Australia, CPA’s report highlights that as more businesses adopt AI, cyber risks rise, especially for small firms, with many still lacking solid protections. Both organizations recommend stronger cybersecurity strategies, frequent updates, and more training as reliance on AI grows.

https://finance.yahoo.com/news/ai-takes-center-stage-major-110000818.html

NIS2: Much Needed, but Also More Work Pressure

NIS2 Directive increases cybersecurity resilience in the Netherlands, requiring organizations to manage supplier risks. While essential, it imposes administrative burdens on clients and suppliers, potentially exceeding their readiness by the 2026 deadline. Preparing involves suppliers standardizing security documentation and clients assessing supplier risks.

https://ioplus.nl/en/posts/nis2-much-needed-but-also-more-work-pressure

Scroll to Top