<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Recorded Future</title>
        <link>https://www.recordedfuture.com/jp</link>
        <description>Strengthen Your Defenses with Threat Intelligence</description>
        <lastBuildDate>Thu, 30 Jul 2026 13:57:34 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>Recorded Future, Inc.</generator>
        <language>en</language>
        <copyright>Copyright © 2026 Recorded Future, Inc.</copyright>
        <atom:link href="https://www.recordedfuture.com/jp/feed" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[Iran War’s Secondary Effects Shape 2026 US Violent Extremism]]></title>
            <link>https://www.recordedfuture.com/jp/research/iran-violent-extremism-landscape</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/iran-violent-extremism-landscape</guid>
            <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Explore the 2026 US violent extremism threat landscape. This report analyzes rising risks from HVEs, DVEs, and Iran-nexus actors to public and private sector entities.]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>The United States (US) will almost certainly remain at heightened threat from physical threat activities conducted by homegrown and domestic violent extremists (HVEs and DVEs, respectively) during the next twelve months. Since the last installation of this report in July 2025, there has been a substantial increase in mass-casualty attacks and attack plots by Islamic State (IS) supporters, assassinations and attempted assassinations of US government officials and high-profile public figures by anti-government and anti-authority violent extremists (AGAAVEs), and multiple plots by anarchist violent extremists (AVEs) to cause substantial damage to facilities using destructive devices.</p>
        <p>Coinciding with these trends, the Iran War will almost certainly have significant ramifications for the violent extremism threat landscape in the US over the next twelve months, even if the war has concluded. Based on Insikt Group’s observations to date, Iranian external operations are less likely to be a significant cause of violent extremist threat activity in the US than HVEs and DVEs motivated by the second-order sociopolitical and economic effects of the war. Iran almost certainly intends to guide or inspire HVEs to conduct physical threats in the US on its behalf. However, Iran-nexus physical threat activities in the US during the war have been largely aspirational, reliant on low-sophistication, financially motivated threat actors, and disrupted by law enforcement in the early planning stages of attacks. This likely suggests Iran lacks the capabilities necessary to guide large-scale HVE attacks in the US at present.</p>
        <p>In contrast, the second-order effects of the Iran War will almost certainly add to the list of grievances and causes for mobilization popular among a wide swath of US violent extremists, likely increasing the risk of violent extremist physical threat activities during the next twelve months. Specifically, the war surfaced salient domestic and international political issues that have historically mobilized US violent extremists. These controversies include US military involvement in the Middle East; the relationships among the US, Israel, and other Middle Eastern countries; the state of the US economy; and the involvement of specific US private-sector entities in US foreign policy planning and military operations. In addition to motivating violent extremists, these issues will almost certainly influence US political discourse during the 2026 midterm elections in the US; the election cycle itself will very likely drive additional US violent extremist threats in late 2026 and early 2027.</p>
        <p>Public- and private-sector organizations face differing levels of violent extremist threats due to their sector, industry, role, associations, and attack surfaces. While different categories of violent extremists employ various TTPs depending on their ideology and objectives, Insikt Group continues to assess that targeted attacks against facilities and high-profile personnel constitute the predominant violent extremist risks to most organizations. Overall, entities associated with US foreign policy decision-making, immigration enforcement, the Israeli government and military, or the provision of critical infrastructure services very likely face heightened risks from violent extremists. Threat intelligence — including features within the Recorded Future Intelligence Operations Platform — can support organizations’ efforts to identify, analyze, and mitigate threats posed by US-based violent extremists.</p>
        <h2>Key Findings</h2>
        <p>During the next twelve months:</p>
        <ul>
          <li>Iran-nexus physical threat actors will very likely attempt to target facilities and personnel in the US that they associate with the US or Israeli government and military, although the sophistication, impact, and frequency of these plots will likely be limited by Iran’s capability gaps.</li>
          <li>HVE IS supporters will be the most likely violent extremist threat actors to conduct mass-casualty attacks in the US, particularly during the period between October 2026 and January 2027.</li>
          <li>Instructional and ideological material produced by the neo-Nazi accelerationist movement will very likely continue to drive mass-casualty attack plots and sabotage against critical infrastructure, despite the fragmentation of neo-Nazi accelerationist organizations and online networks.</li>
          <li>AGAAVEs motivated by partisan animus will almost certainly pursue targeted physical attacks against high-profile public officials; secondary effects of the Iran War and the 2026 US midterm election cycle will very likely exacerbate these risks.</li>
          <li>AVEs will likely employ increasingly sophisticated and destructive means of conducting attacks targeting facilities and property, particularly targets they associate with US immigration enforcement policies</li>
        </ul>
        <h2>Background</h2>
        <p>Insikt Group’s forecast is predicated on its assessments of open-source information on the activities of HVEs and DVEs in the US, including Recorded Future’s extensive index of HVE and DVE communications on various online platforms. During the past twelve months, Insikt Group researchers curated several hundred HVE and DVE sources, adding them to an extensive index of preexisting sources of this type.</p>
        <p>This report defines “homegrown violent extremist,” “domestic violent extremist,” and several categories of HVEs and DVEs based on the US Intelligence Community’s <a href="https://www.dni.gov/files/ODNI/documents/assessments/UnclassSummaryofDVEAssessment-17MAR21.pdf">definitions and categorizations</a> of threat actors. Periodically, this report uses definitions adopted by Insikt Group subject-matter experts for analytic utility, or in instances where the US government has not officially defined a particular phenomenon or movement. A full list of terms and definitions used in this report is available in <strong>Appendix A</strong>.</p>
        <h2>Homegrown Violent Extremists</h2>
        <p>The HVE threat to the US is very likely at its most severe level since the mid-2010s, during the period following the Islamic State’s rise to power and 2014 offensive to seize territory in Syria and Iraq. Jihadist Salafi HVEs, specifically IS supporters, very likely remain the most likely HVE threat actors to conduct mass-casualty attacks, despite a very likely resurgent threat from HVEs tied to Iran and its “axis of resistance” groups. While both jihadist Salafi HVEs and Iran-nexus HVEs almost certainly have the intent to conduct attacks in the US, we judge Iran-nexus HVEs have more limited capability to do so, due to a very likely smaller number of HVEs who support Iran or its “axis of resistance.”</p>
        <p>Despite the June 17, 2026, memorandum of understanding (MoU) that <a href="https://www.bbc.com/news/articles/c4gy700j0eko">established</a> a ceasefire between the US and Iran, Iran’s military and intelligence agencies, proxy groups, and sympathizers in the US will very likely continue their efforts to guide physical threat activities on US soil, albeit with a greater focus on maintaining plausible deniability. The Iran War and the deaths of several notable members of Iran’s clerical and military leadership almost certainly removed most of the limits to Iran’s intent to target the US by proxy. However, Iran has not yet publicly demonstrated that it possesses sophisticated capacities to engage in physical threat activities on US soil. Observed plots during the Iran War involving Iran-nexus US-based physical threat actors have been largely aspirational, unsuccessful, and reliant on financially motivated (as opposed to ideologically motivated) threat actors.</p>
        <p>While not direct participants in the conflict, IS, al-Qaeda, and other foreign terrorist organizations are likely to leverage second-order developments in the Iran War to further recruitment and radicalization of US HVEs. During the past three years, these groups have almost certainly positioned previous shifts in the Middle East’s geopolitical environment — notably Israeli military activity in Gaza and Lebanon following Hamas’s October 7, 2023, attack in Israel, the 2024 fall of the Bashar al-Assad regime in Syria, and diplomatic normalization of relationships between Israel and Muslim countries — to support influence narratives, generate propaganda, and reach a new generation of potential supporters. IS, which almost certainly remains at the forefront of the global jihadist Salafi movement, influenced a significant uptick in HVE threat activity in the US during the past twelve months, a dynamic that is very likely to continue in 2026 and early 2027.</p>
        <p>HVEs of all varieties are very likely to target entities they associate with the US or Israeli government or military, private sector entities they associate with the US or Israeli government, Jewish communities, and large public gathering places. Most observed plots continue to use low-cost means, such as firearms, knives, incendiary devices, and vehicular attacks. Nevertheless, Insikt Group has monitored efforts by HVEs to share information on improvised explosive device (IED) manufacturing in online forums; there are additionally several known cases during the past year of HVEs successfully manufacturing IEDs for use in attacks. In addition, HVEs almost certainly will continue to experiment with novel tactics, techniques, and procedures (TTPs), including the use of 3D-printed weapons, unmanned aerial vehicle (UAV)-borne IEDs, and generative artificial intelligence (AI) for attack planning.</p>
        <h2>Iran and Axis of Resistance</h2>
        <p>The Iran War almost certainly increased Iran-nexus physical threat actors’ motivation to conduct attacks, sabotage, arson, and defacement in the US, as a form of Iran’s asymmetric retaliation against the US. The cessation of direct hostilities between Iran and the US is very unlikely to deter Iran-nexus threat actors from carrying out physical threat activities, although, post-MoU, these threat actors are very likely to pursue more covert and less destructive TTPs. In rank order, the most likely targets of these activities are:</p>
        <ul>
          <li>Targets perceived to be associated with Israeli or Jewish communities</li>
          <li>High-profile US, Israeli, and Western foreign policy and military officials</li>
          <li>Iranian dissidents residing abroad</li>
          <li>Private-sector organizations affiliated with the US or Israeli military, particularly defense contractors, insurance companies, banks and financial institutions, and critical infrastructure service providers</li>
        </ul>
        <p>There are almost certainly few remaining strategic or ideological <a href="https://www.foreignaffairs.com/iran/will-iran-turn-terrorism">barriers</a> to Iran’s aspirations to guide attacks on US soil, even after the June 2026 ceasefire agreement with the US. While the June 2026 MoU stipulates that Iran must “refrain from interfering in [the US’s] affairs,” it is unclear whether Iran would interpret non-interference to include Iran-nexus physical threat activities. Additionally, Iranian security agencies may choose not to abide by the clause, especially given how the conflict empowered hardliner elements within Iran’s security apparatus and granted them significant autonomy in operational decision-making. Tehran also very likely would not interpret the clause as applying to Iran’s “axis of resistance” groups. Regardless, Iran has <a href="https://extremism.gwu.edu/propaganda-procurement-and-lethal-operations-irans-activities-inside-america">attempted</a> to solicit HVEs to conduct attacks in the US for decades, even during periods without direct military confrontation with the US. During the Iran War, the US <a href="https://www.reuters.com/world/middle-east/which-key-iranian-figures-have-been-killed-us-israeli-strikes-2026-04-06/">killed</a> several senior religious and military figures within Iran (including Ayatollah Ali Khamenei); the deaths of senior Iranian leaders have historically been <a href="https://www.politico.com/news/2024/10/11/iran-trump-assassination-plans-00183488">harbingers</a> of Iran-nexus physical threat activity in the US. Since the beginning of the Iran War, senior Shi’a Muslim clerics in Iran have issued <a href="https://www.iranintl.com/en/202603010955">rulings</a> encouraging Muslims around the world to avenge Khamenei’s death by targeting the US and Israel. Iran has also leveraged online influence operations networks to <a href="https://www.recordedfuture.com/jp/research/iran-handala-physical-threats">recruit</a> individuals to carry out attacks in the US, and has very likely <a href="https://www.nytimes.com/2026/05/07/us/austin-bar-shooting-gunman-iran-fbi-investigation.html">inspired</a> attack plots in the US. Iran will very likely attempt to ensure any post-MoU external operations in the US are deniable and avoid mass-casualty attacks or assassinations of high-profile public figures — to avoid provoking the US — but there almost certainly remain no significant ideological or strategic deterrents to Iranian external operations as a whole.</p>
        <p>Regardless of its intent, however, Iran likely <a href="https://warontherocks.com/between-intent-and-capability-assessing-the-lack-of-iranian-attacks-on-the-u-s-homeland/">lacks</a> access to a significant number of US-based, ideologically sympathetic HVEs, limiting its external operations capabilities in the US. During the last decade, Iranian operators predominantly tied to the Islamic Revolutionary Guard Corps (IRGC) attempted to <a href="https://ctc.westpoint.edu/wp-content/uploads/2025/08/CTC-SENTINEL-082025.pdf">pay</a> members of transnational criminal organizations (TCOs), petty criminals, and other financially motivated threat actors to conduct attacks in the US. Insikt Group’s observations of Iran-nexus physical threat activity post-February 2026 indicate this threat model did not change due to the Iran War. For instance, in April 2026, a commander of the IRGC’s Iraq-based proxy Kataib Hezbollah (KH) and its external operations-focused persona Islamic Movement of the Companions of the Right (IMCR, also known as Ashab al-Yamin and HAYI) allegedly attempted to <a href="https://www.justice.gov/usao-sdny/media/1440956/dl">recruit</a> a Federal Bureau of Investigation (FBI) undercover officer — whom he believed to be a US-based Mexican TCO member — to conduct attacks on several synagogues in the US, offering the undercover officer $10,000 in cryptocurrency.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="A screenshot of a digital statement from the Islamic Movement of the Companions of the Right (IMCR), featuring text and imagery that conveys a direct threat against U.S. President Donald Trump and his family." src="https://www.recordedfuture.com/jp/media_1536d002a2d1606d7a852982e4a430418459b0d40.png?width=750&amp;format=png&amp;optimize=medium" width="852" height="1200" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1</strong>:</em> April 20, 2026, IMCR statement threatening US President Donald Trump and his family. (Source: Recorded Future)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_1dcf334a3456dbd8cac9e92251d42bca36328dc3e.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Dealing with AI-Generated Extortion]]></title>
            <link>https://www.recordedfuture.com/jp/blog/ai-generated-extortion</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/ai-generated-extortion</guid>
            <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Combat AI-generated extortion and fake ransomware leaks. Learn how organizations can verify data authenticity using robust governance and threat intelligence.]]></description>
            <content:encoded><![CDATA[
        <h2>Proving a Negative</h2>
        <p>How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files <em>weren’t</em> stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors?</p>
        <p>This is a surprisingly challenging question to answer. Finding the answer is also more difficult because data governance has not been the traditional purview of security teams. Data governance has long been thought of as a compliance problem, unfortunately that is no longer the case. Security teams are now, whether they want to be or not, need to consider data governance. This means they have to be able to confidently say whether leaked data is real or not.</p>
        <p>How do you do that?</p>
        <h2>History of Ransomware</h2>
        <p>What we call ransomware has evolved over the years. Ransomware has gone from largely focused on encryption to a combination of encryption and data theft to today’s reality where data theft alone is the most common version of a “ransomware” attack.</p>
        <p>Threat actors have figured out that managing encryption keys is challenging, stealing data and holding it hostage is significantly easier. They’ve also figured out that stealing the right data can be just as profitable as encryption and, as we’ve seen from ransomware trends, switching to data theft only allows groups to accelerate the number of attacks. Compare the number of victims from 2024 to 2025 in the Recorded Future® Ransomware dashboard with a noticeable rise in ransomware trends.</p>
        <div>
          <div>
            <div>
              <p>
                <img loading="lazy" alt="alt=&quot;&quot;" src="https://www.recordedfuture.com/jp/media_1cf6f3fa1bbe54bb343fa9ee64be498043e466f4c.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="677" />
              </p>
              <p>
                <img loading="lazy" alt="Line graph of ransomware trends" src="https://www.recordedfuture.com/jp/media_1aad701459ecedfed8d10167de523fdac9b266228.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="675" />
              </p>
            </div>
          </div>
          <div>
            <div>Figure 1: Rise in ransomware trends increasing from 2024 to 2025 (Source: Recorded Future)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1f83d492f8a28ff468374797c5d4f99d8f59b3a2a.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Ransomware is the Scoreboard]]></title>
            <link>https://www.recordedfuture.com/jp/blog/ransomware-is-the-scoreboard</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/ransomware-is-the-scoreboard</guid>
            <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Ransomware is the scoreboard for defensive architecture. Learn why traditional security methods fail and how to use AI and threat intelligence to identify and remediate critical attack paths.]]></description>
            <content:encoded><![CDATA[
        <p>
          <img loading="lazy" alt="Ransomware scoreboard by industry. 12,394 total victims, 218 Industries hit, 13.99% Manufacturing share" src="https://www.recordedfuture.com/jp/media_1697c1d1eb3d15c7e40d28242cfbdb093a5c628a6.png?width=750&amp;format=png&amp;optimize=medium" width="1898" height="1659" />
        </p>
        <p>13,000.</p>
        <p>That’s the number of ransomware victims Recorded Future has observed over the past two years.</p>
        <p>Watching the near-real-time ransomware attacks on businesses, non-profits, and government agencies has left me, like many security professionals and board directors, pondering how and why cyber defense keeps losing this particular fight. Adversaries like <a href="https://www.picussecurity.com/resource/blog/cisa-alert-aa25-203a-interlock-ransomware-analysis">Interlock</a> and <a href="https://www.recordedfuture.com/jp/research/ransomhub-draws-in-affiliates-with-multi-os-capability-and-high-commission-rates">RansomHub</a> have continued their successful march to riches over the past 18 months. The <a href="https://cybersecurityventures.com/ransomware-damage-to-cost-the-world-74b-in-2026/">multi-billion-ruble</a> question is, “How?”</p>
        <p>
          <img loading="lazy" alt="RansomHub Ransomware Group Malicious Traffic Analysis defensive graph" src="https://www.recordedfuture.com/jp/media_1b2d467fe96c9ced4acb37c491ab206b225b0caf4.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="1456" height="668" />
        </p>
        <p><a href="https://github.com/specterops/bloodhound">BloodHound</a> and the defensive graph concept debuted over a decade ago and still maintain a vibrant open-source community. <a href="https://www.attackiq.com/ctem">Continuous Threat Exposure Management (CTEM)</a> (and attack path management) is an established cyber vendor category, yet ransomware crews are demonstrably eating many organizations’ lunch.<br /><br />Let’s explore the problems (which are relatively easy to enumerate) and a solution (harder): <strong>modeling defense as the graph attackers actually traverse, at the speed they traverse it, which, of course, involves intelligence.</strong></p>
        <h2>The Barometer</h2>
        <p>Ransomware is a solid barometer of operational defensive success, specifically because, unlike espionage, it’s noisy, financially motivated, and opportunistic. Certainly, ransomware also benefits from an optimal ecosystem, including payment economics, cyber insurance playbooks, and jurisdictional safe havens, which help incentivize ransomware gangs to find the cheapest attack paths. Relatively inexperienced actors can pick up commodity tools and reach the crown jewels. That highly repeated <a href="https://www.recordedfuture.com/jp/research/ransomware-as-a-service">Ransomware-as-a-Service (RaaS)</a> dynamic is a verdict on the availability of attack paths, regardless of payment incentives.</p>
        <div>
          <div>
            <div>tkhlbp1eyn</div>
          </div>
        </div>
        <p><br /><br />The prior two years of Recorded Future data revealed 834 unique ransomware families (or brands). The ransomware playbook is only becoming more effective over time, particularly as regional and industry-specific data privacy compliance regulations proliferate. The <a href="https://intelligence2risk.substack.com/p/five-risk-categories">risk impact</a> is now less about operational disruption, as offline backup resilience has increased, and more squarely focused on the legal or compliance failure of losing legislatively protected information.</p>
        <h2>What’s in a Graph?</h2>
        <p>It’s helpful to visualize an organization as an interconnected graph of nodes and edges, comprising hosts, configurations, credentials, and more. Adversaries attempt to traverse the graph and identify any available weaknesses that, when combined (via attack paths), lead to risk impacts.</p>
        <p>If operational defense shifts focus from compliance-driven lists and categories, and we model the environment as a graph, will we better understand and remediate attack paths to prevent ransomware? Only if we can match adversarial velocity.</p>
        <div>
          <div>
            <div>hiccbodazp</div>
          </div>
        </div>
        <p><br /><br />For an enterprise, the graph is combinatorially large, changes hourly, and humans can’t maintain or query it at the tempo at which attackers traverse it. <strong>Graphs provide the structure. Threat intelligence supplies the edge weights, and AI agents deliver the speed.</strong> In practice, that means agents recompute attack paths whenever the graph changes, test whether a newly reported adversary technique actually traverses your environment, and push the choke point to the top of the remediation queue, continuously, without waiting on an analyst.<br /><br />Interlock ransomware is a good example of an attack path. Interlock uses multiple tactics to acquire unauthorized access. One of their favorites is <a href="https://www.recordedfuture.com/jp/research/clickfix-campaigns-targeting-windows-and-macos">ClickFix-style social engineering</a>: a <a href="https://www.recordedfuture.com/jp/blog/massive-hidden-infrastructure-enabling-big-game-hunting-at-scale">fake CAPTCHA</a> convinces a user to paste a command into the Windows Run dialog or PowerShell, which executes malware that harvests credentials, and the group moves laterally from there. That initial access is CVE-free at the point of entry, and it doesn’t appear on any vulnerability list. The entire path is identity and configuration edges. A defender with a perfect, fully patched vuln list has zero visibility into the path Interlock actually takes.</p>
        <p>That’s one example of an attack path. Interlock employs numerous attack paths, and the group’s techniques and procedures constantly change to ensure continued success against defensive adaptations.</p>
        <p>Now multiply those already numerous attack paths across ~800 ransomware groups. The permutations quickly cause a <a href="https://intelligence2risk.substack.com/p/the-resilience-dilemma">complexity issue</a> for defenders. Lists and categories can’t keep pace with the offensive tempo, which is what exposure management has to solve.</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1661e838ac93d892da39efdf36158130aef1ae42f.png?width=750&amp;format=png&amp;optimize=medium" width="1797" height="1508" />
        </p>
        <h2>The Solution</h2>
        <p>Effective CTEM means discovering and remediating attack paths before the adversary. The Breach and Attack Simulation (BAS) piece requires constant updates to traverse the graph and perform control validation. A snapshot of adversary behavior might be useful for a week, but tactics and procedures drift, so the snapshot decays quickly. Emulating adversary attack paths with clean fidelity and timeliness requires broad and timely intelligence collection.<br /><br />MITRE ATT&amp;CK codes, for example, may help analysts understand patterns, but automating attack path chains requires specific adversary procedures and details.</p>
        <div>
          <div>
            <div>cojq4wjb46</div>
          </div>
        </div>
        <h2><br />So What? Now What?</h2>
        <p>To avoid ransomware risk impacts, there are three timely questions for business executives.</p>
        <ul>
          <li>Are we scrutinizing the quality of CTEM solutions? How does a new edge type enter the graph, and how long does it take? If the answer is “quarterly content updates”, the graph is a museum and a beautiful record of what transpired during a breach.</li>
          <li>How are we investing in agentic R&amp;D now to build trust and confidence in production deployments and ensure integrity with compliance obligations?</li>
          <li>When can we deploy continuous attack path recomputation, intelligence-weighted graph edge scoring, and agentic validation of new paths with choke-point remediation queues?</li>
        </ul>
        <p>The scoreboard updates in real time, and the verdicts are public. The only open question is whether cyber defense recalibrates before the score changes again.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1648c3c891b5eac193658d669c60d10d147394b38.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[TAG-195 Upgrades MaaS Ecosystem with Modular Tools]]></title>
            <link>https://www.recordedfuture.com/jp/research/tag-195-evolves-maas-ecosystem</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/tag-195-evolves-maas-ecosystem</guid>
            <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families through ongoing tracking of the TAG-195 MaaS ecosystem. We named two of the families "TinyEgg" and “ChonkyChicken"; the third is a modularized variant of ChonkyChicken. The fourth family, which includes a modified browser credential theft helper, we named “ChromEggscalator". TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling Insikt Group has previously linked to TAG-127 as an operator and customer. (Insikt Group has directly observed TAG-127 deploying TinyEgg via “ClickFix”-style campaigns that use fake security verification pages to trick victims into manually executing malicious commands that download and install malware payloads via a legitimate Windows system utility.)</p>
        <p>The four new families indicate an architectural transition and evolution in the TAG-195 MaaS ecosystem. TinyEgg is a lightweight initial-access backdoor providing host profiling, interactive shell access, and persistence management. ChonkyChicken substantially expands that capability with browser credential theft, browser session automation, credential-backed remote execution, network reconnaissance, and sustained surveillance. The modularized ChonkyChicken extends this design by introducing a controller-and-plugin architecture in which a base controller implant requests and loads discrete capability modules from attacker-controlled infrastructure on demand rather than embedding all functionality in the implant itself. TAG-195 also modified a publicly available Chrome encryption-bypass tool into a custom helper within the malware family that Insikt Group named ChromEggscalator. All four families share a common set of architectural traits: consistent command-and-control mechanisms, a shared persistence approach, string obfuscation, and execution via the same delivery model.</p>
        <p>Insikt Group assesses that TAG-195’s transition to a modular architecture almost certainly reduces the base implant's static detection exposure, and likely also reflects commercial incentives inherent to the MaaS model, including the ability to provision capabilities selectively to operators, limit exposure if a customer is compromised, and serve a broader range of operational requirements. Defenders should prioritize detection of ClickFix-style clipboard execution chains, misuse of legitimate system utilities to load payloads from user-writable directories, suspicious startup persistence mechanisms, browser processes launched with remote debugging enabled, and unusual outbound communications to attacker-controlled infrastructure.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>Insikt Group identified four new TAG-195 malware families through its continued tracking of the TAG-195 MaaS ecosystem: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator. Their identification indicates sustained active development and a deliberate architectural transition toward modular, operator-driven tooling.</li>
          <li>The modularized ChonkyChicken variant uses a controller-and-plugin architecture in which a base controller implant requests and loads at least fourteen capability modules on demand. Insikt Group assesses that this design almost certainly reduces the base implant's static detection footprint while enabling operators to deploy only what each intrusion requires.</li>
          <li>All four malware families share four recurring architectural traits that indicate their origin within the same TAG-195 development ecosystem: filename execution gating, Run key persistence under a consistent value name, string obfuscation, and execution via a legitimate Windows binary.</li>
        </ul>
        <h2>Background</h2>
        <p>TAG-195, also known as “Golden Chickens” or "Venom Spider", is a financially motivated MaaS developer with a long-standing history of providing credential theft and remote access tooling to criminal operators. Insikt Group assesses TAG-195 as a MaaS provider based on the availability of its malware to multiple distinct threat actors and its sustained operation across successive generations of tooling. Public reporting by <a href="https://www.esentire.com/web-native-pages/unmasking-venom-spider">eSentire</a> has previously linked TAG-195 tooling to FIN6, Cobalt Group, and Evilnum, three financially motivated criminal groups, suggesting the ecosystem serves a select customer base; however, details on sales models and access conditions remain unknown. Additionally, Insikt Group tracks TAG-127 as a threat group that uses the TAG-195 MaaS, with ClickFix or VenomLNK as delivery methods.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Diagram showing threat group associations for TAG-195, also known as Golden Chickens or Venom Spider, highlighting its links as a Malware-as-a-Service (MaaS) provider to threat actors including FIN6, Cobalt Group, Evilnum, and TAG-127." src="https://www.recordedfuture.com/jp/media_19fe004f7d3a6c47139b7be9d4a3f8bb0e7fc607d.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1036" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em>TAG-195 threat group associations (Source: Recorded Future)</em></div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_108cee2fcb0c1792cbb340558328d069bb0036624.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Modern Attack Vectors | Recorded Future]]></title>
            <link>https://www.recordedfuture.com/jp/blog/modern-attack-vectors</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/modern-attack-vectors</guid>
            <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[What is an attack vector, and how does it impact your business? Discover the top threat actor targets in 2026 and learn attack vector vs attack surface dynamics.]]></description>
            <content:encoded><![CDATA[
        <h2>Key Takeaways</h2>
        <ul>
          <li>Modern threat actors have <a href="http://fbi.gov/contact-us/field-offices/atlanta/news/cybercriminals-are-stealing-cookies-to-bypass-multifactor-authentication">shifted from brute-forcing firewalls to compromising digital identities</a> via stolen session cookies and credential stuffing to bypass MFA entirely</li>
          <li>Adversaries <a href="https://www.sygnia.co/threat-reports-and-advisories/defending-your-network-edge-against-the-next-zero-day-exploit/">increasingly target unpatched edge infrastructure</a> like VPNs for zero-day access while <a href="https://www.cybersecuritydive.com/news/cisa-security-software-supply-chain-compromises-GitHub/821487/">exploiting open-source repositories</a> to launch upstream supply chain attacks</li>
          <li>Traditional internal security telemetry may miss critical pre-attack signals, making real-time, outside-in threat intelligence essential to neutralizing modern vectors before a breach occurs</li>
        </ul>
        <p>For today’s Chief Information Security Officers (CISOs) and security team leaders, defending your business can feel like trying to hold back the ocean. As organizations rapidly scale cloud-native infrastructure, integrate sprawling third-party ecosystems, and adopt enterprise AI workflows, most organizations' digital footprints have exploded.</p>
        <p>But a massive digital footprint isn’t the core problem. The problem is that adversaries are changing how they navigate it.</p>
        <p>Advanced persistent threats (APTs) and sophisticated cybercriminal syndicates are no longer relying on blunt-force intrusions. <a href="https://www.sygnia.co/threat-reports-and-advisories/defending-your-network-edge-against-the-next-zero-day-exploit/">Instead, they are tracking organizational vulnerabilities from the outside in</a>, using targeted methods to slip past defenses unnoticed. To stay ahead, security leaders must look past traditional, inward-facing security telemetry and think more like the adversary. That begins with a precise, real-time understanding of modern attack vectors.</p>
        <h2>What is an Attack Vector?</h2>
        <p>In cybersecurity, an attack vector is the specific path, route, or method an adversary uses to gain unauthorized access to a network, system, or endpoint to deliver a malicious payload or extract data. If an exploit is the lockpick, the attack vector is the hallway the intruder walked down to reach the door.</p>
        <p>Historically, attack vectors were relatively straightforward. A decade ago, an enterprise might primarily worry about phishing emails containing malicious executable attachments or unpatched, internet-facing servers.</p>
        <p>In 2026, <a href="https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report">attack vectors have evolved</a> from isolated incidents into complex, multi-stage journeys. Modern adversaries rarely rely on a single open door. Instead, they link multiple vectors together to achieve their objectives.</p>
        <p>For example, a modern <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/threat-actors/threat-actor-types">threat actor</a> might initiate an intrusion using an automated multi-factor authentication (MFA) fatigue campaign to compromise a low-level employee identity, pivot through an exposed, undocumented API, and ultimately execute a <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/cyber-threats/ransomware">ransomware</a> payload via a trusted third-party software update.</p>
        <h2>Attack Vector vs. Attack Surface: What’s the Difference?</h2>
        <p>While they are frequently used interchangeably in security discussions, conflating your attack vectors with your <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/vulnerability-management-threat-hunting/attack-surface">attack surface</a> can create fundamental gaps in your defensive strategy.</p>
        <ul>
          <li><strong>An Attack Surface</strong> is the sum total of all potential vulnerabilities, exposure points, and digital assets across an organization’s entire footprint that an unauthorized user could try to enter or extract data from—including public cloud buckets, employee credentials, IoT devices, code repositories, and vendor networks.</li>
          <li><strong>An Attack Vector</strong> is the specific vehicle, mechanism, or strategy used to exploit a precise point on that surface. It is the active "weapon" or method of transit chosen by the hacker.</li>
        </ul>
        <p>Think of your organization as a <a href="https://www.recordedfuture.com/jp/resources/guides/the-castle-dilemma-cti-fraud-fusion">fortified castle</a>. The attack surface is the entirety of the castle's physical structure—every wall, window, gate, and underground passage. The attack vector is the specific ladder, battering ram, or sleeping guard the invading army uses to breach a specific point on that structure.</p>
        <p>Defending the attack surface requires comprehensive visibility into what you own. Neutralizing an attack vector requires <a href="https://www.recordedfuture.com/jp/threat-intelligence">real-time intelligence</a> on how adversaries are actively weaponizing their toolkits.</p>
        <h2>What Threat Actors Are Actively Targeting in 2026</h2>
        <p>Adversary tactics are driven by efficiency and return on investment (ROI). In 2026, threat actors largely abandoned brute-force attacks on hardened corporate firewalls. Instead, they target systemic structural weaknesses across three primary dimensions:</p>
        <h3>Identity as the New Perimeter</h3>
        <p><a href="https://www.recordedfuture.com/jp/threat-intelligence-101/glossary/what-is-identity-protection">Identity</a> has emerged as the definitive battleground for enterprise security. Rather than breaking in, modern threat actors simply log in. Defenses have been circumvented by the massive industrialization of the <a href="https://www.recordedfuture.com/jp/blog/leaked-credentials-candy-dark-web">cybercrime underground</a>, where initial access brokers (IABs) and infostealer malware supply millions of stolen session cookies and valid credentials daily.</p>
        <p>Adversaries can use credential stuffing to bypass traditional authentication, target cloud identity providers (IdPs) directly, and leverage session hijacking to step over MFA entirely—rendering standard boundary defenses obsolete.</p>
        <h3>Edge Infrastructure and Software Supply Chain Vulnerabilities</h3>
        <p>The perimeter has moved to the edge, and adversaries have followed. Over the past few years, we have seen a <a href="https://www.sygnia.co/threat-reports-and-advisories/defending-your-network-edge-against-the-next-zero-day-exploit/">significant surge</a> in threat actors <a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/edge-under-siege-how-state-sponsored-actors-exploit-your-perimeter">targeting unpatched edge devices</a>—such as VPN gateways, firewalls, and edge routers—to secure <a href="https://www.recordedfuture.com/jp/blog/toolshell-exploit-chain-thousands-sharepoint-servers-risk">zero-day footholds</a> directly into corporate networks. Simultaneously, the software supply chain has become a highly lucrative upstream vector. By poisoning open-source repositories or compromising trusted third-party dependencies, adversaries can affect thousands of downstream organizations in a single, silent stroke.</p>
        <h3>AI-Driven Exploitation and Prompt-Based Manipulation</h3>
        <p><a href="https://www.recordedfuture.com/jp/research/emerging-ai-threats-future-of-automated-operations">Generative AI</a> has fundamentally altered the velocity and scale of modern attack vectors. Threat actors now leverage automated LLM orchestrations to generate personalized <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/glossary/what-is-social-engineering">social engineering</a> campaigns and deepfake audio/video that can easily deceive even well-trained employees. Even as enterprises rush to integrate AI into internal workflows, new vectors like prompt injection and data poisoning have transitioned from theoretical concepts to active threat vectors, allowing adversaries to manipulate LLM outputs and extract proprietary enterprise data.</p>
        <h2>Why Traditional Security Frameworks Cannot Stop Modern Attack Vectors</h2>
        <p>Most enterprise security architectures were built for a static world that no longer exists. When confronted with the dynamic vectors of 2026, traditional frameworks break down in two distinct ways:</p>
        <h3>Static Vulnerability Management</h3>
        <p>Many <a href="https://www.recordedfuture.com/jp/blog/soc-alert-overload">security operations centers (SOCs)</a> remain tied to traditional vulnerability management models that prioritize patching based strictly on CVSS scores. This creates <a href="https://www.recordedfuture.com/jp/blog/nist-nvd-enrichment">a dangerous blindspot</a>. Advanced persistent threats intentionally chain together multiple "low-severity" or "medium-severity" vulnerabilities that, when combined, can grant full administrative access.</p>
        <p>Manual asset discovery tools also struggle to keep pace with ephemeral cloud environments, creating visibility gaps that turn unmapped assets into instant attack vectors.</p>
        <h3>The Outside-In Blindspot</h3>
        <p>Internal security teams are naturally focused on internal telemetry—pouring over logs inside their SIEM, EDR, and NDR tools. However, this creates a reactive stance. By the time an adversary triggers an EDR alert, the attack vector has already been successfully executed. Internal telemetry is often blind to pre-monetization signals: the registration of typosquatted domains targeting your brand, the sale of corporate credentials on dark web marketplaces, or the collaborative planning occurring in closed adversary forums.</p>
        <h2>Neutralizing Modern Attack Vectors with Recorded Future</h2>
        <p>To defeat adversaries who operate at the speed of automation, organizations must shift from a reactive posture to a proactive, intelligence-led defense. <a href="https://www.recordedfuture.com/jp/">Recorded Future</a> provides the external visibility and real-time intelligence required to map, prioritize, and dismantle modern attack vectors before they breach your perimeter.</p>
        <h3>Cyber Operations: Shifting from Reactive Response to Machine-Speed Defenses</h3>
        <p>Faced with overwhelming alert fatigue, SOC teams cannot afford to chase every theoretical vulnerability. <a href="https://www.recordedfuture.com/jp/products/cyber-operations">Recorded Future Cyber Operations</a> acts as the antidote to operational noise. Powered by the Intelligence Graph®, which continuously sifts through millions of global data points, it automatically <a href="https://www.recordedfuture.com/jp/blog/ai-vulnerability-playbook">prioritizes vulnerabilities based on live, real-world exploitation data</a> rather than static CVSS math.</p>
        <p>By enriching your existing internal tools (SIEM, EDR, SOAR) via <a href="https://www.recordedfuture.com/jp/platform/collective-insights">Collective Insights®</a>, Recorded Future injects real-time adversary Tactics, Techniques, and Procedures (TTPs) directly into your workflow, enabling defenders to triage alerts and block active attack vectors at speed.</p>
        <h3>Digital Risk Protection: Securing the External Attack Surface</h3>
        <p>You cannot defend against an attack vector you cannot see. <a href="https://www.recordedfuture.com/jp/use-case/digital-risk">Recorded Future Digital Risk Protection</a> provides an outside-in view of your organization, mapping your external attack surface, mirroring how an adversary scans it.</p>
        <p>By monitoring open, deep, and dark web sources, it identifies compromised corporate credentials, active typosquatted phishing domains, and source code exposures on public repositories. This visibility allows security teams to take down malicious infrastructure and revoke compromised access before threat actors can convert them into active entry points.</p>
        <h3>Third-Party Risk: Closing the Vendor Supply Chain Gap</h3>
        <p>Relying on annual, static security questionnaires to assess vendor risk is the equivalent of checking the weather once a year and assuming it will never rain. <a href="https://www.recordedfuture.com/jp/products/third-party-intelligence">Third-Party Risk</a> replaces outdated point-in-time assessments with continuous, automated risk monitoring.</p>
        <p>Providing real-time Risk Scores (ranging from 0-99) and mapping complex fourth-party ecosystem dependencies, it alerts your team the moment a vendor within your supply chain shows signs of compromise. This enables you to isolate vulnerable connections long before an upstream vendor breach turns into your downstream crisis.</p>
        <h3>Payment Fraud: Disrupting Fraud Lifecycles</h3>
        <p>For financial institutions and e-commerce enterprises, the attack vector of choice often targets transaction infrastructure. <a href="https://www.recordedfuture.com/jp/products/payment-fraud-intelligence">Recorded Future Payment Fraud</a> can disrupt the fraud lifecycle by monitoring pre-monetization signals.</p>
        <p>By identifying Magecart e-skimmers on digital storefronts, monitoring underground carding forums, and spotting tester merchant activities in real time, Recorded Future allows organizations to fraud-check and block compromised payment cards before fraudulent transactions hit the bottom line.</p>
        <h2>Proactive Mapping Leads to Resilient Defense</h2>
        <p>In 2026, understanding your attack vectors can no longer be treated as a check-the-box compliance exercise or a periodic audit. Adversaries are highly dynamic, highly automated, and constantly scouting for the path of least resistance across your digital footprint.</p>
        <p>True organizational resilience requires continuous, automated external intelligence. By seeing your enterprise exactly the way the adversary sees it, you can move from a state of constant reaction to one of strategic deterrence.</p>
        <p>Don't wait for an alert to tell you your perimeter has been breached. <a href="https://www.recordedfuture.com/jp/get-started">Book a demo</a> with Recorded Future today to gain real-time visibility into your external attack surface and neutralize modern threat vectors before they unfold.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_175f90febab938ca2898eb7c0fca57030e111fa1f.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Threat Hunting: A Guide | Recorded Future]]></title>
            <link>https://www.recordedfuture.com/jp/blog/cyber-threat-hunting</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/cyber-threat-hunting</guid>
            <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Master modern cyber threat hunting by embracing real-time threat intelligence. Discover the elite tools, steps, and frameworks to expose hidden adversaries.]]></description>
            <content:encoded><![CDATA[
        <p>Enterprise security architectures have never been more heavily funded, yet the <a href="https://techent.tv/2026/06/26/turning-security-on-its-head-why-the-perimeter-is-dead-in-the-age-of-ai/">perimeter is functionally obsolete</a>. Despite multi-million dollar investments in next-generation firewalls and complex defense stacks, sophisticated adversaries slip past automated boundaries every day. They don't break in; they log in, embedding themselves silently into the background noise of normal business operations.</p>
        <p>To survive in this environment, modern cyber defense teams must anchor their strategy to a single, non-negotiable rule: Assume you are already breached. Waiting for an automated alert to trigger is a losing strategy. Proactive cyber threat hunting shifts the power dynamic from reactive firefighting to active, aggressive detection. Human analysts alone cannot process the volume and velocity of data required to detect sophisticated adversaries at enterprise scale. To truly master modern threat hunting, security teams should consider enriching internal telemetry with real-time, external threat intelligence.</p>
        <h2>Understanding threat hunting</h2>
        <p>At its core, threat hunting is the practice of proactively and iteratively searching networks, endpoints, and cloud environments to detect and isolate advanced threats that evade existing security solutions. It is a human-led, hypothesis-driven discipline—not a purely automated feature of a software suite.</p>
        <p>Here is how it differs from other standard security functions:</p>
        <ul>
          <li><strong>Threat Hunting vs. Incident Response</strong><br />Incident response is fundamentally reactive; it is the act of extinguishing an active, visible fire after an alert has triggered. Threat hunting is proactive, searching the architecture for hidden threats before they erupt into a catastrophic breach.</li>
          <li><strong>Threat Hunting vs. Penetration Testing</strong><br />Penetration testing evaluates perimeter defenses from the outside in, evaluating whether a simulated adversary can breach the network. Threat hunting operates under the explicit assumption that the attacker is already firmly rooted inside, hunting them down from within.</li>
          <li><strong>Threat Hunting vs. Vulnerability Assessments</strong><br />Vulnerability management focuses on patching open windows and updating code to prevent future exploitation. Threat hunting assumes an attacker has already gained access and focuses on detecting their lateral movement before damage is done.</li>
        </ul>
        <h2>What teams need to begin threat hunting</h2>
        <p>An effective threat hunt cannot begin in a vacuum. Before analysts can root out sophisticated threat actors, organizations must establish a baseline foundation across three core pillars: visibility, integration, and external context.</p>
        <h3>1. Visibility</h3>
        <p>Threat hunting requires deep, centralized internal telemetry logs, including:</p>
        <ul>
          <li><strong>Endpoint Event Logs (EDR Data)</strong>: Process execution trees, registry modifications, and local network connections.</li>
          <li><strong>Network Traffic Analysis (NTA)</strong>: NetFlow data, DNS queries, and TLS handshake anomalies.</li>
          <li><strong>Identity &amp; Access Management (IAM) Logs</strong>: Cross-zone authentication spikes, anomalous MFA prompts, and privilege escalations.</li>
        </ul>
        <h3>2. Tool integration</h3>
        <p>Relying on isolated data silos paralyzes analysts. Security teams are recommended to leverage unified SIEM and SOAR integrations to aggregate disparate data sets, normalize log schemas, and eliminate the white noise of benign network activity.</p>
        <h3>3. External intelligence</h3>
        <p>Analyzing internal logs without external context is like looking at footprints in the mud without knowing what animal made them. Deep web, dark web, and technical intelligence should be required, providing the exact behavioral profiles, infrastructure layouts, and campaign contexts needed to guide the hunt.</p>
        <h2>The 3 Core threat hunting methodologies</h2>
        <h3>1. Hypothesis-Driven Hunting</h3>
        <p>This methodology relies on a baseline understanding of an organization's unique threat profile. Rather than chasing random anomalies, hunters form educated, structured theories based on environmental risk.</p>
        <p>For example: "If an advanced persistent threat (APT) targets our specific financial services vertical using a known cloud-storage exploit, do those specific forensic artifacts exist in our environment right now?" Analysts then construct targeted queries to validate or disprove the theory.</p>
        <h3>2. Intelligence-driven hunting (IOC &amp; TTP mapping)</h3>
        <p>Tactical and operational intelligence can serve as the blueprint for tracking down precise adversary patterns. By mapping observed threat intelligence—such as malicious IP addresses, command-and-control (C2) domains, newly announced CVEs, and adversary Tactics, Techniques, and Procedures (TTPs)—directly to the <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/tools-and-technologies/mitre-attack-framework">MITRE ATT&amp;CK® framework</a>, hunters can systematically search internal logs for identical behavioral signatures.</p>
        <h3>3. Advanced analytics &amp; AI hunting</h3>
        <p>This approach uses behavioral profiling and data stacking to isolate structural outliers from massive datasets. By evaluating thousands of similar data points, machine learning models highlight anomalous user or machine actions—such as a standard HR user account suddenly executing administrative command-line scripts or initiating mass data transfers at 3:00 AM.</p>
        <h2>The Lifecycle of a proactive cyber threat hunt</h2>
        <p>A successful <a href="https://www.recordedfuture.com/jp/resources/guides/threat-hunt-e-book-2026">threat hunt</a> follows a structured, iterative lifecycle. By injecting external threat intelligence into every phase, analysts can transform an ad-hoc search into an accelerated, scalable defensive program.</p>
        <h3>Step 1: Let intelligence drive your hunt</h3>
        <p>The hunt begins when an analyst defines a focused area of inquiry based on a structured hypothesis. This initial trigger is driven by real-time threat intelligence regarding an active campaign, an emerging zero-day vulnerability, or a newly discovered infrastructure cluster belonging to a relevant threat actor family.</p>
        <h3>Step 2: Architect your hunt at scale</h3>
        <p>Once the hypothesis is set, hunters deploy advanced threat hunting tools to translate technical indicators into sweeping enterprise queries. Analysts architect data-gathering parameters across disparate EDR databases, SIEM platforms, and network traffic monitors to ensure better visibility across the entire enterprise footprint without manual bottlenecking.</p>
        <h3>Step 3: Activate autonomous threat hunting</h3>
        <p>Rather than executing one-off, static searches that instantly age out, teams deploy continuous automated playbooks. By integrating real-time intelligence directly into detection engines, cyber threat hunting teams are able to shift from an ad-hoc manual task to a 24/7 autonomous monitoring process that tracks evolving adversary behavior in real time.</p>
        <h3>Step 4: Review correlated findings</h3>
        <p>When anomalous activity matches the hunt parameters, analysts evaluate the high-fidelity telemetry alongside external intelligence inputs. If malicious activity is verified, the hunt instantly pivots to incident response for isolation; if the anomaly is benign, the findings are fed back into the security ecosystem to update rules and eliminate future noise.</p>
        <h3>Step 5: See the impact with AI reporting</h3>
        <p>The final phase translates complex forensic data into strategic business metrics. By leveraging automated, intelligent reporting, security leaders instantly visualize the hunt’s operational impact—documenting exactly which assets were protected, how dwell time was mitigated, and how defensive postures were permanently hardened against future attack vectors.</p>
        <h2>Where modern threat hunting can fall short</h2>
        <p>Executing a continuous, high-yield threat hunting program presents severe operational friction points for modern CISOs and SOC managers:</p>
        <ul>
          <li><strong>The cybersecurity skills shortage</strong>: Seasoned threat hunters require a rare blend of data science, digital forensics, and adversary mindset analysis. These professionals are incredibly scarce, highly sought after, and financially burdensome to recruit and retain.</li>
          <li><strong>Alert fatigue and false positives</strong>: Analysts spend hours chasing benign data anomalies because legacy threat hunting tools lack external context. Without real-time enrichment, an unusual out-of-hours connection looks identical to a critical C2 beaconing event.</li>
          <li><strong>The time-to-exploit collapse</strong>: The window between a vulnerability being announced on the clear web and actively weaponized on the dark web has <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-collapsing-exploit-window-ai-speed-vulnerabil/">shrunk to mere hours</a>. Static, ad-hoc hunting schedules often cannot keep pace with this compressed timeline, leaving networks exposed between manual hunts.</li>
        </ul>
        <h2>Mastering the hunt with Recorded Future</h2>
        <p>Recorded Future reduces these operational bottlenecks, transforming threat hunting from a resource-draining manual grind into an accelerated, intelligence-led defense mechanism.</p>
        <h3>The Intelligence Graph®</h3>
        <p>Recorded Future’s <a href="https://www.recordedfuture.com/jp/platform/intelligence-graph">Intelligence Graph®</a> continuously monitors open sources, technical infrastructure, and illicit dark web forums. By analyzing billions of entities in real time, it delivers a live map of global threat actors, emerging malware families, and weaponized vulnerabilities. This gives threat hunters visibility into external shifts before they are able to impact internal networks.</p>
        <h3>Reducing manual triage</h3>
        <p>Instead of forcing tier-3 analysts to waste critical hours pivoting across dozens of open-source intelligence (OSINT) browser tabs, Recorded Future delivers instantly actionable context. Internal alerts within your SIEM and EDR are automatically enriched and tagged with real-time threat-actor details, Risk Scores, and mapped TTPs, allowing hunters to identify high-risk anomalies instantly.</p>
        <h3>Insikt Group® insights</h3>
        <p>Security teams no longer need to spend days writing complex detection logic from scratch. Recorded Future’s <a href="https://www.recordedfuture.com/jp/research/insikt-group">Insikt Group®</a>—an elite team of veteran threat researchers—delivers pre-written, expert-vetted YARA, Snort, and Sigma rules directly into your existing SIEM, SOAR, and EDR environments. This can turn global threat discoveries into immediate, internal defensive barriers.</p>
        <h3>Cyber Operations: unified intelligence for modern hunters</h3>
        <p>To truly scale a threat hunting program, security teams need to bridge the gap between external intelligence and internal workflows. Recorded Future <a href="https://www.recordedfuture.com/jp/products/cyber-operations">Cyber Operations</a> centralizes this process by mapping real-time adversary infrastructure, campaigns, and malware behaviors directly to the MITRE ATT&amp;CK® framework. By delivering instantly deployable hunting packages alongside curated operational context, Cyber Operations can reduce the time it takes for analysts to shift from an external intelligence trigger to an active, internal environment scan.</p>
        <h3>Autonomous Threat Operations</h3>
        <p>To solve the persistent challenge of understaffed security teams, Recorded Future delivers <a href="https://www.recordedfuture.com/jp/products/autonomous-threat-operations">Autonomous Threat Operations</a>. By executing continuous hunting, detection, and response workflows autonomously, the Platform constantly scours your environment for complex threats. This <a href="https://www.recordedfuture.com/jp/blog/autonomous-threat-operations-in-action">elevates your defensive posture</a> 24/7, freeing human analysts to focus on high-level strategic risk management.</p>
        <h2>The future of threat hunting</h2>
        <p>Modern threat hunting is no longer about working harder or writing longer queries; it is about hunting smarter. As adversaries exploit automation and compressed execution timelines, security teams should not rely on internal telemetry alone to defend the enterprise. Combining sharp human analyst logic with the most comprehensive threat intelligence platform available is how security teams can transition from reactive defense to proactive, intelligence-led threat hunting at enterprise scale.</p>
        <p>Don't let advanced adversaries dictate the timeline of your security operations. <a href="https://www.recordedfuture.com/jp/get-started">Book a demo</a> today to supercharge your threat hunting program and secure your environment from the inside out.</p>
        <h2>Threat hunting FAQs</h2>
        <p><strong>What is cyber threat hunting in simple terms?</strong></p>
        <p>Cyber threat hunting is the proactive, human-led practice of systematically searching through an organization's networks, endpoints, and data repositories to detect malicious actors or hidden threats that have already bypassed automated perimeter defenses.</p>
        <p><strong>What are the common methodologies or triggers for a threat hunt?</strong></p>
        <p>Threat hunts generally rely on three types of investigations: hypothesis-driven (triggered by new adversary tactics, techniques, and procedures or TTPs), intelligence-driven (triggered by specific indicators of compromise or IOCs), and analytics-driven (triggered by machine learning detecting structural anomalies in network traffic behavior).</p>
        <p><strong>How does threat hunting differ from digital forensics and incident response (DFIR)?</strong></p>
        <p>Incident response and digital forensics are inherently reactive—they kick off after a security control fires an alert or a breach is publicly known to contain damage. Threat hunting is aggressively proactive; it assumes a breach has already occurred silently and searches for active adversaries before they trigger an alert.</p>
        <p><strong>How does Recorded Future accelerate the threat hunting process?</strong></p>
        <p>Threat hunting traditionally requires manual data gathering across disjointed open-source platforms. <a href="https://www.recordedfuture.com/jp/products/cyber-operations">Recorded Future Cyber Operations</a> can collapse this timeline by automatically mapping external adversary infrastructure, campaigns, and malware behaviors directly to the MITRE ATT&amp;CK framework. It delivers instantly deployable hunting packages alongside pre-written YARA, Snort, and Sigma rules to enable a shift in a hunter’s workflow from manual intelligence gathering to immediate data interrogation.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_16545ae11d245b7ee01c1a5b8dd6ccbf1e0999131.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Tracking Advanced Persistent Threat Groups | Recorded Future]]></title>
            <link>https://www.recordedfuture.com/jp/blog/tracking-advanced-persistent-threats</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/tracking-advanced-persistent-threats</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Learn how real-time cyber intelligence powers advanced persistent threat detection, from exposing infrastructure to stopping attacks early.]]></description>
            <content:encoded><![CDATA[
        <h2>Key takeaways</h2>
        <ul>
          <li>Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conducted by well-funded human adversaries (often nation-states) who target specific organizations for espionage, data theft, or critical infrastructure disruption.</li>
          <li>Traditional security tools often fail because APT groups bypass signature-based defenses by using customized malware and Living-off-the-Land (LotL) tactics that mimic legitimate user activity inside the network.</li>
          <li>Effective advanced persistent threat detection requires minimizing breakout time, the window between initial access and lateral movement, by identifying threats before they establish deep persistence.</li>
          <li>To defeat modern APTs, organizations must move from reactive internal monitoring to proactive threat intelligence, tracking adversary infrastructure on the open, deep, and dark web before an attack is launched.</li>
        </ul>
        <p>Modern organizations face highly resourceful, patient, and deeply calculated adversaries. This shift has ushered in an era of coordinated operations where elite <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/threat-actors/threat-actor-types">threat actors</a> don't just compromise a system and leave, but may spend weeks or months quietly surveying networks, mapping architecture, and identifying high-value targets.</p>
        <p>These operations are the hallmark of an advanced persistent threat (APT). <a href="https://www.recordedfuture.com/jp/blog/cybersecurity-history">Traditional cybersecurity</a> frameworks have long relied on perimeter defenses designed to catch malicious activity at the gates. However, once an APT group breaches a network, they often intentionally manipulate native administrative tools and harvest legitimate credentials to blend into daily business traffic.</p>
        <p>To better confront an adversary that behaves like an insider, organizations must shift their perspective outward, leveraging real-time, external threat intelligence to identify and intercept <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/cyber-threats">cyber threats</a> before they can establish a permanent foothold.</p>
        <h2>What is an Advanced Persistent Threat (APT)?</h2>
        <p>An APT is a sophisticated, prolonged cyber campaign executed by a highly organized group with specific, long-term objectives. Breaking down the acronym highlights the unique nature of these threats:</p>
        <ul>
          <li><strong>Advanced:</strong> APT actors do not rely on off-the-shelf exploits. They frequently utilize customized malware, discover and weaponize zero-day vulnerabilities, and practice meticulous operational security (OpSec) to deliberately evade modern security controls.</li>
          <li><strong>Persistent:</strong> Unlike cybercriminals who encrypt a server and immediately demand a ransom, APTs utilize a "low-and-slow" methodology. They prioritize stealth over speed, regularly remaining inside an environment for months to achieve strategic goals such as espionage, intellectual property theft, or the long-term disruption of critical infrastructure.</li>
          <li><strong>Threat:</strong> Behind every APT is a well-funded organizational structure. These are not lone hackers; they are highly structured syndicates and state-sponsored units—such as the <a href="https://www.recordedfuture.com/jp/research/north-koreas-cyber-strategy">Lazarus Group or APT41</a>—backed by massive financial and geopolitical resources.</li>
        </ul>
        <h2>The multi-stage APT attack lifecycle</h2>
        <p>Generally, APT groups do not operate at random. They follow a rigorous, multi-stage lifecycle. For defenders, understanding this timeline is critical to shrinking “breakout time"—the vital window between the initial compromise and the moment the attacker begins moving through the network.</p>
        <h3>1. Reconnaissance and planning</h3>
        <p>Before a single line of malicious code is deployed, attackers gather <a href="https://www.recordedfuture.com/jp/blog/open-source-intelligence-definition">open-source intelligence (OSINT)</a>, scan exposed internet-facing infrastructure, and map out the target’s digital footprint to find weak points.</p>
        <h3>2. Initial infiltration</h3>
        <p>Attackers typically gain entry via hyper-targeted <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/glossary/what-is-social-engineering">spear-phishing or social engineering campaigns</a>, credential stuffing, or complex <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/risk-assessment-management/supply-chain-threats">supply chain compromises</a>, often bypassing standard authentication checks.</p>
        <h3>3. Establishing footholds</h3>
        <p>Once inside, actors deploy stealthy backdoors and obfuscated <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/what-is-malware">rootkits</a>. This ensures that even if security teams discover and close the primary entry vector, the attackers maintain alternative entry routes.</p>
        <h3>4. Lateral movement and escalation</h3>
        <p>Adversaries navigate from system to system, harvesting administrative credentials and mapping Active Directory trust boundaries to compromise the enterprise network.</p>
        <h3>5. Data exfiltration or disruption</h3>
        <p>The group gathers, stages, and quietly extracts sensitive data using encrypted command-and-control (C2) channels. In some cases, they may deploy ransomware or execute a DDoS attack as a distraction to cover their tracks.</p>
        <h2>Why traditional advanced persistent threat detection isn’t enough</h2>
        <p>For <a href="https://www.recordedfuture.com/jp/teams/cyber-threat-intelligence">Cyber Threat Intelligence (CTI) teams</a>, threat hunters, and <a href="https://www.recordedfuture.com/jp/teams/security-operations">SOC managers</a>, keeping pace with APTs using legacy tools is an uphill battle. Traditional detection tools and processes consistently fail against advanced actors for several reasons:</p>
        <ul>
          <li><strong>Signature-Based Defenses:</strong> Legacy firewalls and traditional antivirus rely on known file hashes. Because APT groups write custom code and heavily leverage Living-off-the-Land (LotL) tactics using native administrative tools, they can leave no traditional signatures behind.</li>
          <li><strong>Dwell Time:</strong> Internal log correlation through SIEM and EDR platforms is inherently reactive. If your team is only looking at alerts generated inside your perimeter, the attacker may have already achieved a foothold and begun their mission.</li>
          <li><strong>Alert Fatigue and Data Silos:</strong> SOC teams are often drowning in a sea of disconnected internal alerts. Without external context, it is nearly impossible to distinguish a routine network anomaly from an APT group spinning up a new unclassified C2 server.</li>
          <li><strong>Fragmented Vendor Taxonomies:</strong> Tracking adversaries across the industry is notoriously confusing. One threat group might be designated by a weather pattern by one vendor, an animal by another, or a random number by a third, complicating cross-team collaboration and intelligence sharing.</li>
        </ul>
        <h2>Shifting from reactive defense to real-time intelligence</h2>
        <p>To better counter advanced persistent threats, organizations must meet bad actors earlier in the attack lifecycle. This means disrupting the adversary during their reconnaissance and infrastructure-staging phases, long before they ever execute an exploit on an internal endpoint.<br />Real-time threat intelligence in the context of APTs means continuously harvesting, analyzing, and structuring data from across the open, deep, and dark web to monitor attackers as they build their technical infrastructure.</p>
        <p>By tracking newly registered domains, malicious IP allocations, and discussions on illicit forums, defenders can identify a threat actor's setup phase. Mapping these observations to the <a href="https://www.recordedfuture.com/jp/threat-intelligence-101/tools-and-technologies/mitre-attack-framework">MITRE ATT&amp;CK® framework</a> allows security teams to decode the specific Tactics, Techniques, and Procedures (TTPs) of an adversary, enabling them to anticipate and block the attacker's next move.</p>
        <h2>Mastering APT detection with Recorded Future</h2>
        <p><a href="https://www.recordedfuture.com/jp/">Recorded Future</a> equips threat hunters and CTI analysts with the visibility needed to track advanced persistent threats across every stage of the attack lifecycle. By centralizing automated collection and elite human analysis, Recorded Future converts massive volumes of public and dark web data into actionable, proactive defense.</p>
        <h3>The Intelligence Graph®</h3>
        <p>The <a href="https://www.recordedfuture.com/jp/platform/intelligence-graph">Recorded Future Intelligence Graph®</a> automatically maps, links, and updates relationships between billions of entities—including IPs, domains, malware strains, and threat groups—across massive global datasets in real time, giving defenders an unparalleled view of adversary infrastructure.</p>
        <h3>Third-Party Risk</h3>
        <p>Sophisticated threat actors frequently target weak links in an enterprise ecosystem. With <a href="https://www.recordedfuture.com/jp/products/third-party-intelligence">Third-Party Risk</a>, organizations gain real-time visibility into the security postures of their vendors, contractors, and partners, cutting off supply-chain entry vectors.</p>
        <h3>Insikt Group®</h3>
        <p>Recorded Future’s elite network of threat researchers, the Insikt Group, acts as an extension of your security team, providing the latest <a href="https://www.recordedfuture.com/jp/products/geopolitical-intelligence">geopolitical intelligence</a>. They deliver pre-vetted, highly contextual information and actionable hunting rules (including YARA, Sigma, and Snort) directly into the Platform, allowing security teams to rapidly deploy defenses against emerging state-sponsored campaigns.</p>
        <h3>Recorded Future AI</h3>
        <p><a href="https://www.recordedfuture.com/jp/platform/ai">Generative AI capabilities</a> reduce Mean Time to Respond (MTTR). Analysts can use natural language to query complex APT behaviors, instantly surface connection points, and generate comprehensive, shareable intelligence briefs in seconds, streamlining leadership communications during critical events.</p>
        <h2>Staying one step ahead of cyber threats</h2>
        <p>Advanced persistent threats win when they remain hidden in the noise of a network. True detection requires looking beyond internal firewalls and endpoints, demanding visibility into the external environments where adversaries plan, build, and launch their operations.</p>
        <p>In the face of highly organized, nation-state-backed syndicates, speed and visibility are the ultimate metrics of success. By shifting from a reactive internal posture to a proactive, real-time intelligence strategy, organizations can illuminate adversary infrastructure, disrupt the attack lifecycle, and secure their digital perimeter against even the most patient and well-resourced threat actors.</p>
        <p>Want to see how real-time intelligence can transform your threat hunting capabilities? <a href="https://www.recordedfuture.com/jp/get-started">Book a demo</a> with Recorded Future today.</p>
        <h2>FAQs</h2>
        <p><strong>What is the primary objective of an advanced persistent threat (APT) group?</strong></p>
        <p>Unlike typical cybercriminals who seek immediate financial payouts through rapid encryption or ransomware, the primary objective of an APT group is usually long-term cyber espionage. Backed by nation-states or heavily funded syndicates, these actors aim to establish an undetected, prolonged presence within a target network to quietly steal intellectual property, harvest state secrets, or maintain access to critical infrastructure for future geopolitical leverage.</p>
        <p><strong>Why is advanced persistent threat detection so difficult for traditional security tools?</strong></p>
        <p>Traditional security tools rely heavily on static signatures—meaning they look for known, previously identified file hashes or malicious code patterns. APT actors easily bypass these defenses by writing customized malware, exploiting zero-day vulnerabilities, and using "Living-off-the-Land" (LotL) tactics that abuse legitimate system administration tools already built into your network. Because their activity mimics normal administrative tasks, they go unnoticed by internal firewalls.</p>
        <p><strong>What is "breakout time," and why does it matter in tracking APTs?</strong></p>
        <p>Breakout time is the critical window between an adversary's initial compromise of a single machine and their ability to move laterally to other systems on the network. For elite APT groups, this window can be incredibly tight. Tracking threat actor infrastructure in real time allows security teams to recognize the initial entry vector immediately and stop the actor before they can escalate privileges or move beyond the original target endpoint.</p>
        <p><strong>How does generative AI improve advanced persistent threat detection?</strong></p>
        <p>When a sophisticated attack is underway, speed is everything. AI capabilities allow security teams to instantly analyze, synthesize, and summarize vast amounts of complex threat data. Instead of spending hours manually combing through forensic logs and disparate threat intel feeds, analysts can use natural language queries to instantly understand an APT group's current TTPs, lowering the Mean Time to Respond (MTTR) from hours to seconds.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1cfb025019e4285d3c6408ff3d381d07d78bcdbf6.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict]]></title>
            <link>https://www.recordedfuture.com/jp/research/iran-ai-asymmetric-playbook</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/iran-ai-asymmetric-playbook</guid>
            <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Explore how Iran has utilized AI to enhance its asymmetric playbook during the 2026 conflict. Learn how AI acts as a force multiplier for Iranian cyber operations, influence campaigns, and domestic surveillance.]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Between January and June 2026, Tehran survived unprecedented military, economic, and political pressure by relying on its longstanding hybrid warfare model: blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. Artificial intelligence (AI) enhanced these capabilities, acting as a force multiplier and almost certainly increasing the speed, scale, and effectiveness of Iranian operations. Ultimately, Iran demonstrated that its strategic resilience does not depend on possessing the most advanced AI capabilities; rather, the source of Iranian power remains the asymmetric playbook itself.</p>
        <p>During these crises, Iran <a href="https://www.washingtoninstitute.org/media/4505">compensated</a> for conventional military and economic disadvantages through scalable, low-cost, and deniable asymmetric capabilities. Iran’s use of AI almost certainly improved its cyber capabilities, accelerated the production of propaganda and influence narratives, and expanded the reach of information campaigns. AI’s impact on Iranian military operations is less clear, as Iran’s battlefield use of AI has not been independently confirmed. However, the support Russia provided to Iranian military operations increases the likelihood that AI-enabled tactics and capabilities, refined in Ukraine, contributed to Iranian drone attacks against Israel and Persian Gulf states. Domestically, AI-driven surveillance systems deployed during and after the 2022 “Woman, Life, Freedom” protests likely facilitated the Iranian regime’s violent suppression of unrest in January 2026.</p>
        <p>As low-level conflict persists and the risk of a return to war with the United States (US) and Israel remains heightened, Iran’s expanding use of AI-enabled cyber operations will likely pose an elevated threat to Western and regional critical infrastructure and vital industries. Iran’s rapid production and dissemination of AI-generated propaganda expose corporate and state entities to highly targeted influence operations (IOs), risking erosion of customer and citizen trust. As Iran rebuilds its military arsenal, its acquisition of Russian-backed drone capabilities will pose an ongoing risk to critical infrastructure and maritime logistics in the region. Across all sectors, Iran’s hybrid warfare capabilities will likely continue to pose a risk to digital and physical assets, requiring organizations to build resilience against AI-enhanced asymmetric threats that are more scalable and harder to attribute.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>In 2026, AI technologies very likely accelerated existing Iranian capabilities across cyber, influence, military, and domestic repression domains, rather than creating new ones.</li>
          <li>AI’s clearest strategic impact for Iran has been in its information warfare, as AI content generation enables Iran to shape perceptions of the conflict by rapidly producing widely resonant propaganda and influence content.</li>
          <li>Iran’s AI advances appear tied to foreign partnerships — Russian military AI and drone innovations, as well as Russian and Chinese surveillance technologies; Tehran will likely seek to incorporate these foreign AI innovations into its established playbook.</li>
          <li>Organizations and governments should strengthen defenses against AI-enhanced Iranian tradecraft — including AI-assisted phishing, cyber intrusions targeting operational technology, and IO campaigns — while ensuring resilience against combined cyber and physical disruption efforts.</li>
          <li>Post-conflict, Iran is likely to prioritize rebuilding the missile, drone, and maritime capabilities that underpin its asymmetric deterrence model while integrating AI, where possible, to improve efficiency and effectiveness.</li>
        </ul>
        <p>Following a directive issued by former Supreme Leader Ali Khamenei in 2021, Iran pursued a centralized national AI strategy intended to expand domestic research and development, reduce technological dependence on foreign actors, and position the country as a regional technological power. However, Tehran’s AI <a href="https://www.recordedfuture.com/jp/research/irans-ai-ambitions-balancing-economic-isolation-national-security-imperatives">ambitions</a> have faced severe economic constraints and technological limitations as a result of sanctions and isolation.</p>
        <h2>Background</h2>
        <p>Between the 2021 directive and the 2026 conflicts, Tehran <a href="https://www.recordedfuture.com/jp/research/irans-ai-ambitions-balancing-economic-isolation-national-security-imperatives">prioritized</a> developing AI for use in cyber operations, influence campaigns, intelligence and military systems, and domestic repression. Iranian threat actors incorporated generative AI and large language models (LLMs) into spearphishing, social engineering, and online IOs, while Iranian officials publicly emphasized AI-enabled drone, missile, and intelligence capabilities. More broadly, Iran appears to view AI not only as an economic and technological imperative, but also as a tool for preserving regime security and offsetting the strategic constraints imposed by its international isolation.</p>
        <h2>AI Enhancing Iran’s Asymmetric Capabilities</h2>
        <p>Insikt Group analyzed cybersecurity and AI threat reports, social media, Iranian state-run messaging and government/military statements, and activist investigations to illuminate Iran’s AI use, or lack thereof, during 2026. While Iran’s unprecedented internet blackouts create significant gaps in open-source understanding of Iran’s AI capabilities during domestic crises and wartime, one theme is clear: AI has almost certainly enhanced Iran’s asymmetric tactics and hybrid warfare doctrine, but has not fundamentally altered the strategic logic underpinning Iran’s approach to the conflict.</p>
        <h2>Cyber Operations</h2>
        <p>Iran’s use of AI to support the cyber dimension of its conflict with the US and Israel predates the January 2026 protest crackdown and the February 28, 2026, coordinated US-Israeli airstrikes, known as Operation Epic Fury / Roaring Lion. The 2026 crises likely prompted Iranian state-sponsored and state-aligned threat actors to leverage generative AI to gain productivity and tradecraft improvements across reconnaissance, code/malware development, social engineering, and translation. However, AI has not fundamentally shifted Iranian cyber capability. Iran's 2026 campaign has remained anchored in the same baseline TTPs — including spearphishing, wiper malware, credential theft, abuse of legitimate enterprise tooling, and hack-and-leak operations — that pre-date the AI era. The pattern is consistent with what Google, OpenAI, and other AI developers have documented since 2024: AI accelerates and scales what Iranian actors were already doing, rather than enabling new capabilities.</p>
        <h3>Reconnaissance and Operational Research</h3>
        <p>In October 2024, OpenAI <a href="https://cdn.openai.com/threat-intelligence-reports/influence-and-cyber-operations-an-update_October-2024.pdf">reported</a> that Iran-linked hacktivist persona “CyberAv3ngers” used ChatGPT to conduct reconnaissance on programmable logic controllers (PLCs), a use case that has continued to bolster Iranian capabilities against industrial control systems (ICS) during 2026. According to CloudSEK, AI is <a href="https://www.cloudsek.com/blog/ai-the-iran-us-conflict-and-the-threat-to-us-critical-infrastructure#ai-as-the-force-multiplier-lowering-the-barrier-to-ics-attacks">accelerating</a> the research phase in ICS attacks: “An actor can move from intent to a list of accessible US ICS devices with known default credentials in under five minutes.” CloudSEK researchers recreated CyberAv3ngers's research on vulnerable US-based ICS systems in an unspecified AI LLM agent and identified an additional exposed ICS portal, <a href="https://www.cloudsek.com/blog/ai-the-iran-us-conflict-and-the-threat-to-us-critical-infrastructure#ai-as-the-force-multiplier-lowering-the-barrier-to-ics-attacks">highlighting</a> a critical infrastructure “playbook that other groups can now replicate much more easily with the help of AI.” Using this research playbook, Iranian threat actors can not only identify vulnerable ICS systems but also understand the unique properties of the specific technologies they are targeting.</p>
        <p>In May 2026, an attack <a href="https://profero.io/blog/war-between-wars/">attributed</a> to “Cyber Isnaad Front” targeted an Israeli industrial refrigeration system, sabotaging the system by programming it to fail. While there is no direct evidence of AI use in this incident, the attack required expertise in both Windows internal coding and refrigerant physics to ensure maximum damage, suggesting in-depth research into the target system. The targeting selection demonstrates that Islamic Revolutionary Guard Corps (IRGC)-backed cyber personas are concentrated on identifying vulnerabilities in adversaries’ supply chains, logistics, industrial operations, and food production. By facilitating research, AI lowers the level of expertise required to target ICS systems across multiple critical industries.</p>
        <h3>Code Writing and Malware Development</h3>
        <p>Iranian-linked threat actor groups also use AI to accelerate their malware development capabilities. In February 2026, Google’s GTIG AI Threat Tracker reported that GreenBravo (also known as APT42, Charming Kitten, Mint Sandstorm) has been <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use">using</a> Gemini “as an engineering platform to accelerate the development of specialized malicious tools,” including for debugging, code generation, and researching exploitation techniques. Another example is Operation Olalampo, first observed on January 26, 2026, and attributed to GreenGolf (also known as MuddyWater, Mango Sandstorm) in a Group-IB <a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">report</a>. The campaign <a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">delivered</a> four novel malware families (CHAR, GhostFetch, GhostBackDoor, HTTP_VIP) against MENA targets via spearphishing. Group-IB’s analysis of the Rust-based CHAR backdoor identified debug strings <a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">containing</a> emojis — “a trait rarely seen in human-authored code” — across four separate instances. Group-IB assessed that the emojis indicate the operator used an AI model to generate code segments and failed to sanitize debug strings before compilation. Group-IB explicitly tied this to Google's earlier reporting that MuddyWater was already experimenting with Gemini for file transfer and remote execution code.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="screenshot of lines of code" src="https://www.recordedfuture.com/jp/media_131ba6ea40e70ff7a57372095f5201e6b109c772b.png?width=750&amp;format=png&amp;optimize=medium" width="1028" height="150" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1:</strong> Emojis used in CHAR malware suggest AI use (Source: <a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">Group-IB</a>)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_1541a712e2eff6d3bec5ee1570a181ea75e5b0449.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The Shift: A New Era of AI Regulation]]></title>
            <link>https://www.recordedfuture.com/jp/blog/the-shift-new-era-ai</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/the-shift-new-era-ai</guid>
            <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Explore how recent US export controls on frontier AI models like Anthropic's Fable signal a new era of regulatory uncertainty. Learn how security leaders can build resilient AI strategies by treating frontier models as volatile assets rather than stable technology]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>The export controls imposed on Anthropic’s Fable model mark a significant shift in United States (US) artificial intelligence (AI) policy. The controls set a precedent for treating frontier AI models as strategic assets rather than ordinary software products, creating uncertainty for enterprises adopting advanced AI. Security leaders should respond by investing in resilient, interoperable AI strategies rather than simply chasing the most powerful model available.</div>
          </div>
        </div>
        <h2>The Saga of the Fable Export Controls</h2>
        <p>Because the US is home to <a href="https://epoch.ai/benchmarks?view=graph&amp;tab=eci">most</a> of the companies building leading models, US AI policy has an outsized impact on global access. The Trump administration’s <a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">public posture</a> on AI has largely favored accelerating the frontier. Proponents of this approach argue that the US must stay ahead of other nations in AI development because whoever leads in AI will shape the next era of economic, military, and technological power.</p>
        <p>But when Anthropic released Fable on June 9, 2026, US AI policy suddenly became much more restrictive.</p>
        <p>Fable (technically known as Claude Fable 5) was presented as the <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">user-safe version</a> of Mythos Preview, a limited-release frontier model with advanced cybersecurity capabilities, including red teaming, vulnerability discovery, and offensive security reasoning. Anthropic argued that Fable’s guardrails made those capabilities safe for broader use. The White House disagreed, asserting that Fable contained a critical vulnerability that Anthropic refused to patch.</p>
        <p>The dispute ended with an extraordinary outcome: <a href="https://fortune.com/2026/06/13/anthropic-disables-fable-mythos-export-controls-national-security-threat/">export controls</a> prohibiting non-US citizens from using the model, including Anthropic employees. Unable to segment users by citizenship, Anthropic responded by pulling access entirely.</p>
        <p>Anthropic argued that the <a href="https://www.anthropic.com/news/fable-mythos-access">reported jailbreak</a> did not enable Fable to do anything <a href="https://x.com/k8em0/status/2065915072732635238">meaningfully</a> more dangerous than what less sophisticated models could already do. Nevertheless, it reported that it <a href="https://www.anthropic.com/news/redeploying-fable-5">blocked</a> the jailbreak, which it cautioned would block some benign requests. This apparently satisfied the safety concerns of the White House, which <a href="https://www.politico.com/news/2026/06/30/anthropic-wh-lifting-export-limits-00980865">lifted the export controls</a> on June 30, and Anthropic restored access to both Fable and Mythos the following day. Uncertainties remain, however, as to why the export controls were imposed in the first place and when access might be restricted next.</p>
        <p>The imposition of export controls on Fable sets a precedent for similar actions on future advanced models, such as <a href="https://www.axios.com/2026/06/25/trump-administration-openai-gpt-model-release">OpenAI’s GPT-5.6</a>. The lack of a clear message on what made the Fable jailbreak warrant export controls introduces significant regulatory uncertainty for both AI developers and organizations incorporating frontier AI models into their enterprise.</p>
        <h2>Possible Motives Behind US Policy</h2>
        <p>Given the lack of details, it’s worth considering two alternative explanations that may be driving the US government’s decision-making, beyond what’s been publicly stated.</p>
        <p>The first is political. The US government has had an <a href="https://www.npr.org/2026/02/24/nx-s1-5725327/pentagon-anthropic-hegseth-safety">uneasy</a> relationship with Anthropic’s leadership and safety-forward approach. Under this view, export controls are not the signal of a broader policy shift. Instead, they are intended to send a more immediate message to the AI industry: private-sector pushback on government priorities will not be tolerated (whatever those priorities happen to be at the moment).</p>
        <p>If the export controls are motivated by politics, it means AI regulations are likely to remain unpredictable — and can be reversed at any time.</p>
        <p>The second is strategic. Anthropic itself has <a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks">warned</a> that foreign actors may try to use frontier model outputs to reverse-engineer or distill advanced systems. Distillation threatens the US model advantage by allowing competitors to reproduce elements of frontier performance without bearing the full cost of large language model (LLM) training. According to <a href="https://www.semafor.com/article/06/13/2026/white-house-move-to-limit-anthropic-linked-to-concerns-about-chinese-access-to-mythos">one source</a>, the White House suspected that a “China-linked group” had already gained access to Mythos Preview, potentially enabling the group to replicate its capabilities. If this characterization is accurate, the export controls on the model itself are an extension of well-established export controls on advanced computing chips imposed to prevent adversaries from gaining the computing power necessary to build advanced models.</p>
        <p>The strategic explanation represents a fundamental shift in how AI is governed in the US. The model itself — not just the physical hardware behind it — is now being treated as controlled technology. However, not knowing why export control decisions are made makes the strategic motivation as unhelpful for predicting future actions as the political one.</p>
        <h2>The Definition of “Dangerous AI” Is Still Unclear</h2>
        <p>One element adding to the uncertainty is that the export controls on Fable were implemented outside of existing frameworks for assessing the risks posed by AI.</p>
        <p>This is not because a suitable framework doesn’t exist: <a href="https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence">governments</a>, <a href="https://airc.nist.gov/">standards bodies</a>, and think tanks have developed frameworks for characterizing AI risk. But in the Fable case, the US government did not publicly point to a clear threshold for what makes Fable riskier than other comparably available frontier LLMs.</p>
        <p>That matters because all LLMs can support malicious cyber operations in some form. Threat actors use continuously evolving jailbreaking techniques to <a href="https://huggingface.co/blog/mlabonne/abliteration">disable</a> or <a href="https://www.hiddenlayer.com/research/same-model-different-hat">bypass</a> safety controls to achieve a prohibited response. Google, OpenAI, and Anthropic regularly release reports documenting how threat actors have manipulated their models to carry out cyberattacks. Even less sophisticated, non-frontier models can be effective tools in the right environment and with enough computing power. Much like exploitable code vulnerabilities in traditional software, the <a href="https://medium.com/@kumon/when-ai-breaks-its-own-rules-the-state-of-llm-safety-research-16511be83d88">underlying mechanics</a> of LLMs make it very unlikely that defenders will ever find a permanent solution for jailbreaking.</p>
        <p>So what is it about Fable that requires the US government to restrict its use? What made the reported jailbreak so serious that it demanded regulatory action? Will the next generation of Gemini or ChatGPT require similar restrictions? What about open-weight models, like China’s recently released <a href="https://www.forbes.com/sites/craigsmith/2026/06/28/buckle-up-the-bad-guys-now-have-a-model-as-powerful-as-mythos/">GLM-5.2</a>, that can be run without centralized monitoring of how they’re used?</p>
        <p>Without a clear explanation of what separates acceptable from unacceptable risk for AI, regulation becomes reactive. For companies, that uncertainty makes it extremely difficult to adopt or integrate frontier AI models into critical systems.</p>
        <h2>Ad Hoc Regulation May Become the Norm</h2>
        <p>The most likely outcome for the US government, at least in the near-term, is that the voluntary model reviews described in the executive order will become de facto mandates. This has already happened with OpenAI’s latest model, which was initially <a href="https://www.cnbc.com/2026/06/26/openai-limits-new-ai-models-to-trusted-partners-request-us-government.html">voluntarily limited</a> at the White House's request. Anthropic, Google, and OpenAI are likely to continue coordinating closely with the government to avoid future surprise export-control announcements on their latest models.</p>
        <p>Even if these security reviews align with the strategic goal of preventing adversaries from accessing powerful US models, this still means AI regulation is developing on a case-by-case basis. This means that AI users won’t fully understand the trade-offs between speed and security. The security guardrails placed on Fable make the tool more difficult to use for legitimate security functions — a problem that security researchers <a href="https://www.graphistry.com/blog/fables-and-mythos-conceptions-the-defenders-perspective-with-receipts">complained</a> about prior to the jailbreak fix. How do users know if the safety benefits gained are worth the capabilities lost?</p>
        <p>Ad hoc regulations or classified benchmarks create uncertainty for enterprises. A company may integrate a frontier model into internal workflows only to discover later that access rules have changed, certain employees are restricted, or the model is no longer commercially available. The more powerful the model, the more exposed the organization may be to sudden policy intervention, making it difficult to adopt advanced AI reliably.</p>
        <p>At the same time that US frontier models are coming under more scrutiny, open-source Chinese AI models are becoming more <a href="https://www.cnbc.com/2026/07/07/chinese-ai-models-costs-us-openai-anthropic.html">widely used</a>. These models cost significantly less than the leading US models; however, they face the same access uncertainty as US models. First, the Chinese government is <a href="https://finance.yahoo.com/technology/ai/articles/exclusive-beijing-looking-curbing-overseas-101644780.html">reportedly</a> considering its own export controls to limit access to its most advanced models and protect proprietary technology. Second, the US government may choose to block access to Chinese tools under its own national security laws. Similar to the ban on <a href="https://www.bbc.com/news/world-us-canada-63764450">Huawei and ZTE telecommunications</a> technology or the <a href="https://www.bbc.com/news/articles/c3edd1l328lo">attempted ban</a> on TikTok, the US government may determine that using Chinese AI models poses an unacceptable national security threat. Regardless of where the ban originates, the risk of losing access remains the same.</p>
        <h2>How Security Leaders Should Respond</h2>
        <p>AI adoption now requires more than evaluating model performance. It requires evaluating regulatory durability, access risk, and operational dependency.</p>
        <p>Security leaders should respond across three areas.</p>
        <h2>1. Mindset Shift: Use Caution on the Frontier</h2>
        <p>Organizations should stop chasing the latest frontier model and start evaluating which model (or models) is most appropriate for specific workflows. The reality is that most projects do not need to rely on cutting-edge AI capabilities to function. Depending on the task, less sophisticated models may be fully capable of running the operation.</p>
        <p>This does not mean companies should avoid frontier models entirely. Rather, they should think strategically about where these models can provide the greatest advantage, while avoiding critical workflows that depend on uninterrupted access to a single frontier provider. This requires a mindset shift: companies must move from treating LLMs as a novelty to managing them as a mature component of the workflow.</p>
        <h2>2. Governance Shift: Treat Frontier AI as a Volatile Asset</h2>
        <p>Frontier AI should be treated as a volatile asset: powerful, useful, and potentially transformative, but exposed to sudden changes in regulation, vendor policy, geopolitical pressure, and safety restrictions. This is especially important for multinational companies. If model access becomes tied to citizenship, location, or corporate structure, AI governance becomes more complex than traditional software-as-a-service (SaaS) procurement. A tool may be approved for one team but restricted for another. A vendor may be viable in one jurisdiction but risky in another.</p>
        <p>Security teams should ask:</p>
        <ul>
          <li>What happens if access to this model is restricted?</li>
          <li>Which employees, regions, or business units could be affected?</li>
          <li>Can the workflow fall back to another model or internal process?</li>
          <li>Is the model being used for convenience, or has it become operationally critical?</li>
        </ul>
        <p>The organizations best positioned for this environment will be those that can benefit from frontier capabilities without becoming trapped by them.</p>
        <h2>3. Spending Shift: Invest in Resilience Over Novelty</h2>
        <p>Finally, companies should reassess whether AI budgets are weighted too heavily toward the newest and most capable models. As frontier AI becomes more expensive, restricted, or unpredictable, access to advanced capabilities will not be enough.</p>
        <p>The stronger investment may be in resilience: diversified vendors, fallback options, evaluation processes, and workflows that can continue if a preferred model changes or becomes unavailable.</p>
        <p>The key budget question should not be only, “Can we access the most powerful model?” but also, “Are we investing in the tools that will provide long-term effectiveness and resilience?”</p>
        <h2>Final Thoughts</h2>
        <p>The export controls on Fable may prove to be an isolated case. They may also be the first visible sign of a more restrictive AI era.</p>
        <p>This does not mean the era of AI innovation is ending. It means the era of frictionless access to frontier models may be ending. For security leaders, the lesson is not to avoid advanced AI models, but to treat them as volatile assets shaped by cybersecurity risk, geopolitics, export controls, and national security policy. The organizations best prepared for this shift will be those that can benefit from powerful AI capabilities without becoming dependent on access that may disappear overnight.</p>
        <h3>About Insikt Group<sup>®</sup></h3>
        <p><em>Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Its mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.</em></p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1e4012e24849950062073c7bea2d6df22a33dbb2b.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future]]></title>
            <link>https://www.recordedfuture.com/jp/blog/fbi-fake-permit-fees</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/fbi-fake-permit-fees</guid>
            <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A government impersonation scam is targeting property owners with fake planning and zoning permit invoices, and authorized wire transfers are clearing behavioral controls. Here's how the scheme works and why beneficiary account intelligence is the signal that catches it.]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>A fast-growing scam impersonates city and county planning departments, sending property owners real-looking invoices for fake permit fees and pressuring them to wire payment on a deadline. Because the victim authorizes the transfer, payments commonly clear the behavioral checks built to catch fraud, making beneficiary accounts one of the most reliable signals to track this campaign. Research from CYBERA, the partner behind Recorded Future® Money Mule Intelligence, maps a single active ring down to the verified accounts it used, and shows why direct, fraudster engagement and account-level intelligence catches what scoring misses.</div>
          </div>
        </div>
        <h2><br />The FBI sounded the alarm. Issuers still can't see it</h2>
        <p>On March 9, 2026, the FBI's Internet Crime Complaint Center <a href="https://www.ic3.gov/PSA/2026/PSA260309">issued a public alert</a> about criminals impersonating city and county officials to collect fraudulent planning and zoning permit fees. The criminals pull publicly available permit records, email property owners who have active applications, and demand payment by wire transfer, peer-to-peer transfer, or cryptocurrency.</p>
        <p>Government impersonation schemes like this one were among the fastest-growing categories in the FBI's <a href="https://www.fbi.gov/file-repository/2025_ic3report.pdf/view">2025 Internet Crime Report</a>, with reported losses nearly doubling year over year to roughly $798 million. While the alert raises public awareness, it does little to help issuers screen customers payments against the heightened risk these impersonation scams create.</p>
        <h2>Why an authorized payment defeats your controls</h2>
        <p>In this scheme the customer is real, the login is legitimate, and the wire is one the customer chooses to send. Behavioral analysis models are generally built to flag account takeover and out-of-pattern activity, so customer-authorized payments tend to score as low risk and the money moves.</p>
        <p>These fraud signals don’t live in the sender's behavior. They live in the destination: the beneficiary (or mule) account that the scammer will use to cash out the stolen funds. That makes this mule account <a href="https://www.recordedfuture.com/jp/blog/money-mule-solution">the one signal that often separates a legitimate payment from a scam payment</a>.</p>
        <p>Here is how the scheme runs, according to the FBI alert and <a href="https://www.cybera.io/">CYBERA's</a> research:</p>
        <ol>
          <li><strong>Target selection</strong>: the actors identify property owners with active planning or zoning applications using public records</li>
          <li><strong>Impersonation</strong>: they email those owners while posing as the municipal planning department, citing real permit and property details to establish credibility with the target</li>
          <li><strong>The invoice</strong>: they send an official-looking invoice for an approval or processing fee</li>
          <li><strong>The pressure</strong>: they demand a wire on a short deadline and warn that the application will fail if it is missed</li>
          <li><strong>The confirmation</strong>: they ask for the wire receipt to confirm the payment landed</li>
        </ol>
        <h2>What direct engagement reveals that scoring cannot</h2>
        <p>CYBERA's research on one active ring, which it has monitored since September 2025 under the internal name Diligent Planner, shows what that destination signal looks like in practice. Rather than estimating risk, CYBERA's analysts engage the scam operations directly and collect the exact accounts the criminals ask victims to wire money to.</p>
        <p>Across this single operation, that approach produced 53 verified mule accounts spanning 23 separate email campaigns, with roughly 55 percent of the accounts concentrated in just two beneficiary banks. These are confirmed accounts pulled from the criminals themselves, not probabilistic matches, which can be the difference between an account you can act on and a score you have to second-guess.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="A network mapping visualization showing a single money mule ring, featuring interconnected nodes that represent beneficiary bank accounts, email campaigns, and impersonated government bodies." src="https://www.recordedfuture.com/jp/media_1f0ae6960051a4823e36fd9ae5f3f673ec6ce3331.png?width=750&amp;format=png&amp;optimize=medium" width="1798" height="720" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1:</strong> CYBERA's mapping of a single money mule ring, expanded from one beneficiary bank into one connected cluster of accounts, emails, and impersonated government bodies (Source: CYBERA)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_197a3f79b01febb25dc8abd514c8f07d9d1d57ecd.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[June 2026 CVE Landscape]]></title>
            <link>https://www.recordedfuture.com/jp/blog/june-2026-cve-landscape</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/june-2026-cve-landscape</guid>
            <pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[In June 2026, Insikt Group® identified 59 high-impact vulnerabilities that should be prioritized for remediation, 30 of which had a Very Critical Recorded Future Risk Score. This represents a 47% increase from last month.]]></description>
            <content:encoded><![CDATA[
        <p>In June 2026, <a href="https://www.recordedfuture.com/jp/research/insikt-group">Insikt Group®</a> identified <strong>59 high-impact vulnerabilities that should be prioritized for remediation</strong>, 30 of which had a Very Critical Recorded Future Risk Score. This represents a 47% increase from last month. 23 of the 59 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 33 were reported by vendors, and three were primarily surfaced through honeypot data.</p>
        <p>The 59 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 17% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.</p>
        <p>Insikt Group created Nuclei templates to detect two of the vulnerabilities featured in this month’s report: CVE-2026-35616 affecting Fortinet FortiClient EMS and CVE-2026-25939 affecting Frangoteam FUXA. These are available to Recorded Future customers via the Recorded Future Intelligence Operations Platform.</p>
        <h2>Quick reference: June 2026 Vulnerability Table</h2>
        <p><em>All 56 vulnerabilities below were actively exploited in June 2026. This table does not include the three CVEs associated with honeypot activity, which are available to Recorded Future customers via the CVE Monthly report, in the platform. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.</em></p>
        <div>
          <div>
            <div><strong>#</strong></div>
            <div><strong>Vulnerability</strong></div>
            <div><strong>Risk</strong><br /><strong>Score</strong></div>
            <div><strong>Vendor/Product</strong></div>
            <div><strong>KEV</strong></div>
            <div><strong>Malware Analysis</strong></div>
            <div><strong>RCE</strong></div>
            <div><strong>PoC</strong></div>
          </div>
          <div>
            <div>1</div>
            <div>CVE-2020-17103</div>
            <div>99</div>
            <div>Microsoft Windows 10/11 and Windows Server 2019</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2020-17103&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>2</div>
            <div>CVE-2022-0492</div>
            <div>99</div>
            <div>Linux Kernel</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2022-0492&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>3</div>
            <div>CVE-2025-55182</div>
            <div>99</div>
            <div>Meta React Server Components packages</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2025-55182&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>4</div>
            <div>CVE-2025-67038</div>
            <div>99</div>
            <div>Lantronix EDS5000</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>5</div>
            <div>CVE-2025-8088</div>
            <div>99</div>
            <div>WinRAR</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2025-8088&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>6</div>
            <div>CVE-2026-10520</div>
            <div>99</div>
            <div>Ivanti Sentry</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-10520&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>7</div>
            <div>CVE-2026-11645</div>
            <div>99</div>
            <div>Google Chromium V8 and Chrome</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-11645&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>8</div>
            <div>CVE-2026-12569</div>
            <div>99</div>
            <div>PTC Windchill, Windchill PDMLink, and FlexPLM</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>9</div>
            <div>CVE-2026-20230</div>
            <div>99</div>
            <div>Cisco Unified Communications Manager</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/">✓ Link</a></div>
          </div>
          <div>
            <div>10</div>
            <div>CVE-2026-20245</div>
            <div>99</div>
            <div>Cisco Catalyst SD-WAN Manager and Controller</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-20245&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>11</div>
            <div>CVE-2026-20253</div>
            <div>99</div>
            <div>Splunk Enterprise</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/">✓ Link</a></div>
          </div>
          <div>
            <div>12</div>
            <div>CVE-2026-20262</div>
            <div>99</div>
            <div>Cisco Catalyst SD-WAN Manager</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-20262&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>13</div>
            <div>CVE-2026-21509</div>
            <div>99</div>
            <div>Microsoft 365 Apps for Enterprise and Office 2016</div>
            <div></div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-21509&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>14</div>
            <div>CVE-2026-28318</div>
            <div>99</div>
            <div>SolarWinds Serv-U</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-28318&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>15</div>
            <div>CVE-2026-33825</div>
            <div>99</div>
            <div>Microsoft Defender Antimalware Platform</div>
            <div></div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-33825&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>16</div>
            <div>CVE-2026-34908</div>
            <div>99</div>
            <div>Ubiquiti UniFi OS, UniFi OS Server, UDM, and UDM-Pro</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/">✓ Link</a></div>
          </div>
          <div>
            <div>17</div>
            <div>CVE-2026-34909</div>
            <div>99</div>
            <div>Ubiquiti UniFi OS, UniFi OS Server, Express 7, and UDM</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/">✓ Link</a></div>
          </div>
          <div>
            <div>18</div>
            <div>CVE-2026-34910</div>
            <div>99</div>
            <div>Ubiquiti UniFi OS, UniFi OS Server, UDM, and UDM-Pro</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/">✓ Link</a></div>
          </div>
          <div>
            <div>19</div>
            <div>CVE-2026-35273</div>
            <div>99</div>
            <div>Oracle PeopleSoft Enterprise PeopleTools</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-35273&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>20</div>
            <div>CVE-2026-39808</div>
            <div>99</div>
            <div>FortiSandbox PaaS</div>
            <div></div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-39808&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>21</div>
            <div>CVE-2026-41089</div>
            <div>99</div>
            <div>Microsoft Windows Server 2012</div>
            <div></div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-41089&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>22</div>
            <div>CVE-2026-42271</div>
            <div>99</div>
            <div>BerriAI LiteLLM</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-42271&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>23</div>
            <div>CVE-2026-48558</div>
            <div>99</div>
            <div>SimpleHelp</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/J4ck3LSyN-Gen2/CVE-2026-48558">✓ Link</a></div>
          </div>
          <div>
            <div>24</div>
            <div>CVE-2026-48907</div>
            <div>99</div>
            <div>Joomla Content Editor (JCE) extension for Joomla</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-48907&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>25</div>
            <div>CVE-2026-50751</div>
            <div>99</div>
            <div>Check Point Security Gateway, Quantum Security Gateway, and Spark Firewalls</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-50751&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>26</div>
            <div>CVE-2026-54420</div>
            <div>99</div>
            <div>LiteSpeed cPanel Plugin</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-54420&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>27</div>
            <div>CVE-2026-7473</div>
            <div>99</div>
            <div>Arista EOS</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/fevar54/CVE-2026-7473---Arista-EOS-Tunnel-Decapsulation-Bypass">✓ Link</a></div>
          </div>
          <div>
            <div>28</div>
            <div>CVE-2021-26855</div>
            <div>89</div>
            <div>Microsoft Exchange Server 2016 and 2019</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2021-26855&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>29</div>
            <div>CVE-2021-36260</div>
            <div>89</div>
            <div>Hikvision Firmware</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2021-36260&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>30</div>
            <div>CVE-2022-40684</div>
            <div>89</div>
            <div>Fortinet FortiOS, FortiProxy, and FortiSwitchManager</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2022-40684&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>31</div>
            <div>CVE-2023-20198</div>
            <div>89</div>
            <div>Cisco IOS XE Software</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2023-20198&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>32</div>
            <div>CVE-2024-21182</div>
            <div>89</div>
            <div>Oracle WebLogic Server</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2024-21182&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>33</div>
            <div>CVE-2024-21762</div>
            <div>89</div>
            <div>Fortinet FortiProxy and FortiOS</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2024-21762&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>34</div>
            <div>CVE-2025-48595</div>
            <div>89</div>
            <div>Android Framework</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2025-48595&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>35</div>
            <div>CVE-2025-6218</div>
            <div>89</div>
            <div>WinRAR</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2025-6218&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>36</div>
            <div>CVE-2026-21513</div>
            <div>89</div>
            <div>Microsoft Windows 10 and Windows Server 2012</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>37</div>
            <div>CVE-2026-3300</div>
            <div>89</div>
            <div>WPEverest Everest Forms Pro</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/HORKimhab/CVE-2026-3300">✓ Link</a></div>
          </div>
          <div>
            <div>38</div>
            <div>CVE-2026-35616</div>
            <div>89</div>
            <div>Fortinet FortiClientEMS</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-35616&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>39</div>
            <div>CVE-2026-41091</div>
            <div>89</div>
            <div>Microsoft Malware Protection Engine</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-41091&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>40</div>
            <div>CVE-2026-44963</div>
            <div>89</div>
            <div>Veeam Backup and Replication</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>41</div>
            <div>CVE-2026-45247</div>
            <div>89</div>
            <div>Mirasvit Full Page Cache Warmer for Magento 2</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-45247&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>42</div>
            <div>CVE-2016-4437</div>
            <div>79</div>
            <div>Apache Shiro</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2016-4437&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>43</div>
            <div>CVE-2021-27076</div>
            <div>79</div>
            <div>Microsoft SharePoint and Business Productivity Servers</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>44</div>
            <div>CVE-2021-27137</div>
            <div>79</div>
            <div>DD-WRT Firmware</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>45</div>
            <div>CVE-2022-27925</div>
            <div>79</div>
            <div>Zimbra</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2022-27925&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>46</div>
            <div>CVE-2022-41082</div>
            <div>79</div>
            <div>Microsoft Exchange Server 2013</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2022-41082&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>47</div>
            <div>CVE-2023-32315</div>
            <div>79</div>
            <div>Openfire</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2023-32315&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>48</div>
            <div>CVE-2023-46747</div>
            <div>79</div>
            <div>F5 BIG-IP</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2023-46747&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>49</div>
            <div>CVE-2024-36401</div>
            <div>79</div>
            <div>Geoserver</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2024-36401&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>50</div>
            <div>CVE-2026-25089</div>
            <div>79</div>
            <div>Fortinet FortiSandbox PaaS and Cloud</div>
            <div></div>
            <div>✓</div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-25089&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>51</div>
            <div>CVE-2026-39813</div>
            <div>79</div>
            <div>Fortinet FortiSandbox and Cloud</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-39813&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>52</div>
            <div>CVE-2026-4020</div>
            <div>79</div>
            <div>Gravity SMTP</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-4020&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>53</div>
            <div>CVE-2026-46817</div>
            <div>79</div>
            <div>Oracle Payments</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-46817&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>54</div>
            <div>CVE-2026-5027</div>
            <div>79</div>
            <div>Langflow</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-5027&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>55</div>
            <div>CVE-2026-8206</div>
            <div>79</div>
            <div>Kirki – Freeform Page Builder, Website Builder &amp; Customizer</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-8206&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>56</div>
            <div>CVE-2026-25939</div>
            <div>72</div>
            <div>Frangoteam FUXA</div>
            <div></div>
            <div>✓</div>
            <div></div>
            <div><a href="https://github.com/mbanyamer/CVE-2026-25939-SCADA-FUXA-Unauthenticated-Remote-Arbitrary">✓ Link</a></div>
          </div>
        </div>
        <p><em><strong>Table 1:</strong></em> <em>List of vulnerabilities that were actively exploited in June, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).</em></p>
        <h2>Key trends: June 2026</h2>
        <ul>
          <li>In June 2026, StrikeShark exploited public-facing applications to deploy SharkLoader and deliver Cobalt Strike; Lazarus exploited CVE-2025-55182 to deploy COPPERHEDGE; APT36 exploited Microsoft vulnerabilities in operations targeting India; a C0XMO botnet propagated through DD-WRT routers; EKZ information-stealing malware was delivered through FortiClient EMS exploitation; and Qilin ransomware was associated with a vulnerability affecting Check Point gateways.</li>
          <li>25 of the 59 vulnerabilities enabled remote code execution (RCE), affecting products from 18 vendors: Meta, WinRAR, Ivanti, Google, PTC, Cisco, Ubiquiti, Fortinet, Microsoft, BerriAI, Android, WPEverest, Veeam, Mirasvit, Apache, Hikvision, F5, and GeoServer.</li>
          <li>Insikt Group identified public proof-of-concept (PoC) exploits for 53 of the 59 vulnerabilities identified this month.</li>
          <li>The most commonly observed flaws this month were CWE-22 (Path Traversal), followed by CWE-502 (Deserialization of Untrusted Data), CWE-78 (OS Command Injection), CWE-306 (Missing Authentication for Critical Function), and CWE-287 (Improper Authentication).</li>
          <li>4 of the 59 vulnerabilities in this month’s prominent vulnerability disclosures table are at least five years old, with the oldest approximately ten years old, reinforcing how attackers continue to exploit long-known weaknesses in environments where patching has lagged. Additionally, the fastest observed time from a vulnerability’s public disclosure to exploitation was less than one day.</li>
        </ul>
        <h2>Trend analysis: Malware-linked exploitation and intrusion activity</h2>
        <p>June's strongest campaign-linked theme was the exploitation of externally reachable enterprise applications and appliances. Insikt Group published a TTP Instance on the StrikeShark campaign which described activity spanning CVE-2025-55182 affecting React Server Components, CVE-2021-26855 and CVE-2022-41082 affecting Microsoft Exchange, CVE-2021-36260 affecting Hikvision firmware, CVE-2022-40684 and CVE-2024-21762 affecting Fortinet FortiOS, CVE-2023-20198 affecting Cisco IOS XE Web UI, CVE-2016-4437 affecting Apache Shiro, CVE-2021-27076 affecting Microsoft SharePoint, CVE-2022-27925 affecting Zimbra, CVE-2023-32315 affecting Openfire, CVE-2023-46747 affecting F5 BIG-IP, and CVE-2024-36401 affecting GeoServer. The exploitation of these vulnerabilities resulted in the deployment of SharkLoader, which then delivered Cobalt Strike.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Screenshot detailing risk assessment metrics and exploit status for the React2Shell vulnerability." src="https://www.recordedfuture.com/jp/media_1019592f9a7666c73f4e8cbcd9b9d132604d812c0.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1014" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em><a href="https://www.recordedfuture.com/jp/use-case/vulnerability-prioritization">Vulnerability Intelligence Card®</a></em> <em>for CVE-2025-55128 (React2Shell) in Recorded Future (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p>React Server Components was also linked to targeted malware delivery outside the broader StrikeShark set: Lazarus Group exploited CVE-2025-55182 to deploy COPPERHEDGE against financial and blockchain-related organizations. Microsoft-related exploitation appeared in both endpoint and document-processing contexts: APT36 exploited CVE-2026-21509 (affecting Microsoft 365 Apps for Enterprise and Office 2016) and CVE-2026-21513 (affecting Windows client and server versions) in operations targeting India. This activity was linked to backdoor deployment and SHEETCREEP. CVE-2021-27137, affecting DD-WRT firmware, was linked to a C0XMO botnet campaign across Linux architectures, while Qilin Ransomware was associated with CVE-2026-50751 affecting Checkpoint Security Gateway and Spark Firewalls.</p>
        <p>PoC exploit trends and analyses associated with this month's high-impact vulnerabilities are available to Recorded Future customers.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1239191713c0e7359a6e3e0dd047fe76e065dcc92.jpg?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney]]></title>
            <link>https://www.recordedfuture.com/jp/blog/riskx-interview-payment-fraud</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/riskx-interview-payment-fraud</guid>
            <pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Recorded Future CEO Colin Mahony and Mastercard’s Aditi Sawhney discuss the convergence of cyber and financial crime. Explore how Payment Fraud helps teams move from reactive fraud models to proactive, pre-monetization disruption.]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>At RiskX Singapore 2026, Recorded Future CEO Colin Mahony and Mastercard's Aditi Sawhney discussed why payment fraud has become an ecosystem problem that spans cyber and financial crime. The fraudulent transaction is the visible end of a chain that began weeks or months earlier, with harvested credentials, registered lookalike domains, and infected merchant sites. This post looks at how connecting cyber and fraud signals lets defenders intervene before monetization, and how Recorded Future’s Payment Fraud solution maps to each stage of that chain.</div>
          </div>
        </div>
        <div>
          <div>
            <div>https://www.youtube.com/watch?v=NTqcdZrx0ic</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1eabc07284f36be59d8dd93065d301c2b62a762a2.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The Threat Isn’t the Frontier Model]]></title>
            <link>https://www.recordedfuture.com/jp/blog/build-defensive-ai-agents</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/build-defensive-ai-agents</guid>
            <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The real AI threat isn't frontier models. It's cheap local models getting easier to run. Here's why CISOs should build defensive agents now, before attackers scale.]]></description>
            <content:encoded><![CDATA[
        <p>Summer ‘26 vibes: international flights, Riyadh heat, and plentiful CISO conversations. Every conversation (regardless of geographic location or industry vertical) currently begins and ends with AI strategy. Let’s unpack the nuance.<br /><br />Every executive should be <strong>contemplating two questions</strong> <strong>at this moment</strong>:</p>
        <ol>
          <li>Are we building, testing, and scaling agents for the coming onslaught of AI-enabled adversary activity?</li>
          <li>Do we have the breadth of intelligence necessary to move at machine speed?</li>
        </ol>
        <h2><br />Why Agents and Why Now?</h2>
        <p>Timing is everything in life. So the question is: why invest in agents for defensive workflows now? Two premises need to be explained here.<br /><br />First, let’s focus on financially motivated adversaries that don’t receive a government paycheck (directly or indirectly). The state-sponsored adversaries have a different set of resources at their disposal.<br /><br />There are controlled cases where Frontier AI models enable autonomous adversarial activity in malware generation or holistic intrusion chains. Even the Five Eyes are <a href="https://www.cyber.gov.au/about-us/view-all-content/news/five-eyes-cyber-security-agencies-statement">officially warning</a> about adversarial use of frontier models. Yet the onslaught of offensive agents hasn’t materialized yet. Like the Uruk-hai attacking Helm’s Deep in <em>The Lord of the Rings</em>, we expect the wave is coming, but the automated army hasn’t arrived. Why not?<br /><br />Frontier models may be susceptible to context poisoning over time, but it’s difficult to use them at any scale for automated offensive operations. The guardrails are sufficient for the moment. Adversaries are also caught between the OPSEC tension of using third-party APIs (which increases attribution risk) and investing the resources to build local open-source models.<br /><br />While much has been made of open-source model capabilities, the reality is that time, effort, and financial resources are required to use them effectively for offensive campaigns. To get nerdy for a second (because the details are important), a recent experiment with <a href="https://www.librechat.ai/">LibreChat</a> and <a href="https://ollama.com/library/dolphin-llama3">Dolphin-llama3:14b</a> (uncensored LLM) on a $3K local server (containing a reasonable Nvidia GPU with <a href="https://www.reddit.com/r/ArtificialInteligence/comments/1irot4e/how_much_vram_do_you_really_need_to_run_local_ai/">16GB of VRAM</a>) revealed that simple tasks like coding a new web shell are still out of reach.</p>
        <p>The level of effort and hardware required to build a local resource capable of orchestrating effective autonomous attack agents will only decrease over time. <a href="https://developer.nvidia.com/blog/model-quantization-concepts-methods-and-why-it-matters/">Quantization</a> is the clock defenders should be watching. A reductive quantization explanation in this AI context is using less memory by rounding billions of numbers (weights) rather than maintaining precision, thereby shrinking an AI model’s size. Even though the model is slightly less capable, it’s still useful for most tasks. Quantization drives the hardware bar down, and the lower that bar falls, the sooner opportunistic actors can execute attacks at scale.</p>
        <p>
          <img loading="lazy" alt="A circular image with numbers 1 to 12 outlining advancement of AI models" src="https://www.recordedfuture.com/jp/media_197f2b8e196c160eb3df257c1a3b3c635b61018f3.png?width=750&amp;format=png&amp;optimize=medium" width="1859" height="1511" />
        </p>
        <p><strong>The danger for defenders isn’t the headline-grabbing frontier models; it’s the ease with which adversaries can deploy effective local models on modest hardware.</strong> Based on the <a href="https://docs.z.ai/release-notes/new-released">previous 18 months of advances</a>, the next 6-12 months will likely yield similar advances in open-source model capabilities with minimal hardware investment. That’s when opportunistic actors start staging at scale.</p>
        <p>Which brings us back to protecting the proverbial house with defensive AI agents. Now is the time <a href="https://intelligence2risk.substack.com/p/i-built-with-ai-for-three-months">to build</a>, not ponder. We don’t jump into self-driving cars until we have some confidence that the edge cases have been worked out. Similarly, the agentic workflow edge cases can’t be discovered and solved without iteration and testing.</p>
        <p>Smart CISOs are building an <a href="https://youtu.be/lfOraNjwZ7s?si=m1X_pOb8nYyLKEt2">AI control plane</a> (in collaboration with adjacent business units) to enable transparency into AI token consumption, project ROI visibility, and <a href="https://intelligence2risk.substack.com/p/digital-supply-chain-breach">code security</a>. Building and testing agents is part of a larger control-plane project and is particularly time-sensitive.<br /><br />Sandwiched between data availability and information security regulations, CISOs need to generate trust and confidence in agents. Humans may stay in the decision loop for the foreseeable future, but observing agents in a non-production environment is critical. From applying a patch to generating and applying a signature to quarantining a PC or revoking credentials, there is no substitute for iterating over time. Vendors are certainly useful for sharing domain knowledge and solutions, but given the implications of agents gone bad in production environments, teams should own and observe workflows for an extended period.</p>
        <p>Organizations that don’t begin building and iterating with agents now will find themselves at a significant disadvantage as financially motivated actors (specifically) increase their autonomous capabilities using open-source AI models.</p>
        <h2>Where Should Agents Go First?<br /></h2>
        <p>This is the second question in practice. Agents are only as good as the data available to them, and moving at machine speed requires intelligence that is both broad and traceable. There’s plenty of low-hanging fruit (brand protection, for example), but the following three categories are big value.<br /><br />1. <strong>CTEM (Continuous Threat Exposure Management).</strong> All five CTEM stages are suited for agents. Specifically, AI-led vulnerability <a href="https://savvypoc.com/">discovery is exploding</a>, but reliable patches aren’t always available. The name of the game is K-E-V. <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">KEVs (Known Exploited Vulnerabilities)</a> and agent-built detection signatures are the urgent priority in a sea of largely irrelevant <a href="https://nvd.nist.gov/vuln-metrics/cvss">CVSS scores</a>. When newly identified KEVs are combined with a comprehensive asset inventory and enumerated services, from both internal and external views, a powerful agentic workflow emerges. The breadth of KEV intelligence visibility is directly proportional to the quality of CTEM outcomes.</p>
        <p>2. <strong>BAS (Breach &amp; Attack Simulation).</strong> Think continuous Red Teaming. Controls rarely prevent or detect threats at the advertised efficacy rate. Adversary AI will map resources and dismantle controls in minutes. Validating coverage and exposing gaps before an adversary’s agents get in is well-advised. The intelligence necessary to power BAS starts with malware <a href="https://www.recordedfuture.com/jp/blog/threat-actor-ttp-sources">tools, tactics, and procedures (TTPs)</a>, but living-off-the-land tools and new procedure permutations are equally important. In the short term, agents will accelerate the orchestration between new TTPs and BAS platforms. Long-term agents will replace many of the BAS platform actions.<br /><br />3. <strong>Security Operations.</strong> This is where there’s currently <a href="https://www.reddit.com/r/cybersecurity/comments/1s42od3/ai_soc_vendors_are_selling_a_future_that/">substantial movement</a> in the AI start-up vendor space, as tactical SIEM alerts and potential incident response investigations are triaged faster. Deep intelligence from multiple source classes around indicators and artifacts enables an agentic decision advantage to escalate, remediate, or close a ticket. The discipline is in matching autonomy to consequence. Closing a benign ticket and revoking production credentials sit at opposite ends of the risk spectrum, and the governance model should let agents move fast on the former while keeping a human on the latter.</p>
        <h2>Agentic Early Adoption or Wait?</h2>
        <p>
          <img loading="lazy" alt="A visual representation of the concept that while production-grade AI agents are still developing, early research and development are essential to build organizational resilience before opportunistic attackers can easily deploy effective local AI models" src="https://www.recordedfuture.com/jp/media_18d5a14bda90e9ffc77823f65501e10f89b7f8b91.png?width=750&amp;format=png&amp;optimize=medium" width="1954" height="1145" />
        </p>
        <p>Production-grade security agents may still be a work in progress, but investing in research and development now will enable a deeper organizational resilience as models continue to improve and quantization accelerates. The defensive urgency is just beginning; the point is to prepare before opportunistic actors can easily deploy local AI models.<br /><br />Combining vendor services support with in-house AI and security domain expertise will accelerate the learning curve. Humans stay in the loop where judgment matters, while agents take on more of the repeatable work. Don’t wait. Start building today.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1c37540586fb839f07e7e6135ed156e263c96aa5a.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool]]></title>
            <link>https://www.recordedfuture.com/jp/research/nexus-tag182-disseminates-markirat</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/nexus-tag182-disseminates-markirat</guid>
            <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Insikt Group has identified new infrastructure associated with the TAG-182 threat cluster, used to disseminate MarkiRAT malware in support of Iranian government surveillance operations. It is highly likely that TAG-182 is targeting Iranians living inside and outside the country using different lures, including free download tools and fake VPN applications. The group’s operations are highly likely active across social media platforms like Instagram.</p>
        <p>As the kinetic conflict with the United States and Israel has subsided since April 2026, Iran's security apparatus is likely redirecting its focus toward intensified cyber surveillance and digital enforcement operations targeting perceived dissidents and alleged foreign collaborators. TAG-182’s operations are consistent with these security objectives and are likely to continue following the partial restoration of internet access in Iran on May 26, 2026. The indicators of compromise (IoCs) for this report are viewable in <strong>Appendix A</strong>, while defensive signatures are located in <strong>Appendix C</strong> and <strong>Appendix D</strong>.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>TAG-182 is highly likely a component of Iran’s broader surveillance ecosystem, using MarkiRAT malware distributed through fake Android applications masquerading as legitimate services such as VPNs and media tools to collect intelligence from Iranian targets.</li>
          <li>The MarkiRAT sample identified during this research shares notable tradecraft overlaps with historical variants, including the use of the Background Intelligent Transfer Service (BITS), suggesting a credible relationship between TAG-182 and activity previously attributed to Ferocious Kitten. However, while these similarities support an operational connection, additional evidence is necessary to confidently assess that the two clusters are organizationally linked.</li>
          <li>Since Iran’s reconnection to the global internet, Iranian surveillance operations are highly likely to increase as authorities seek to identify and monitor perceived dissidents amid concerns over internal unrest and potential uprisings. The majority of Iranian intelligence and security organizations are likely to prioritize enhanced digital surveillance and intelligence collection to support domestic security objectives.</li>
        </ul>
        <h2>Threat Analysis</h2>
        <p>In early 2026, open-source information surfaced malware <a href="https://x.com/malwrhunterteam/status/2016245674635923855">samples</a> linked to MarkiRAT, which has <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/">historically</a> been used by Ferocious Kitten for surveillance against anti-government networks, activists, and human rights advocates inside Iran. The IoCs, specifically the lures, suggest that threat actors custom-built a website that acts as a staging point for an application called “YESHICA” (<strong>Table 1</strong>). Other sample names also include “Pis2ray VPN”, which is not a legitimate application on either Google Play or Apple’s App Store (see <strong>Appendix A</strong> for additional IoCs).</p>
        <p>In March 2026, Insikt Group identified a new sample associated with TAG-182’s updated infrastructure that uses an almost identical media player theme name, “YESHICA YEPlayer” (<strong>Figure 1</strong>).</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 1: Example showing the evolving naming tradecraft of TAG-182, where the threat actor updated its fake media player app name from 'YESHICA' to 'YESHICA YEPlayer' to continue targeting users." src="https://www.recordedfuture.com/jp/media_165a3fe17dbb1574d7f78c45de4ffa1e5e8262c36.png?width=750&amp;format=png&amp;optimize=medium" width="1011" height="700" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em>TAG-182 continued to operate using similarly named applications despite open-source exposure of its tradecraft and infrastructure (Source: Recorded Future)</em></div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_11d60acbcd8901a8e5c5002f7f21ae6e799acee43.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge]]></title>
            <link>https://www.recordedfuture.com/jp/blog/expertise-meets-algorithm-intelligence-edge</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/expertise-meets-algorithm-intelligence-edge</guid>
            <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Discover how Recorded Future’s Insikt Group combines human expertise with automated analysis to turn raw data into actionable, industry-leading threat intelligence.]]></description>
            <content:encoded><![CDATA[
        <p>In the <a href="https://www.recordedfuture.com/jp/blog/recorded-future-proprietary-collection-engine">previous</a> article in our series on Recorded Future’s unique data sourcing model, we detailed the four types of data we analyze and how, together, they provide unprecedented visibility into each of our customers’ unique threat landscapes.</p>
        <p>In this final article, we’ll show how our Insikt Group research team turns our raw data into actionable intelligence.</p>
        <h2>The Insikt Group advantage</h2>
        <p>Made up of experts with backgrounds in government, military, law enforcement, and intelligence agencies, the Insikt Group research team brings decades of expertise to their work analyzing the always-evolving threat landscape. The combination of seasoned human judgment with automated data indexing and analysis embodies the “<a href="https://hdsr.mitpress.mit.edu/pub/3rvlzjtw/release/4">centaur model</a>” of intelligence, where human analysts and technology work together to produce insights neither could achieve alone.</p>
        <p>“Insikt” is Swedish for “insight”. By using their deep knowledge of specific adversary groups and TTPs to contextualize data within broader geopolitical and criminal dynamics, Insikt Group analysts are able to provide insights that automated systems might miss.</p>
        <p><strong>A research methodology that sets the standard</strong></p>
        <p>Insikt Group uses advanced technical analysis methodologies to uncover threat actor operations. They include:</p>
        <ul>
          <li><strong>Infrastructure detection and pivoting:</strong> By combining proprietary Recorded Future Network Traffic Analysis with large-scale automated network traffic analytics and expert analysis, the team can detect malicious infrastructure before it’s even activated. The team uses sophisticated methods to track changes in adversary server configurations, domain registrations, autonomous system numbers (ASNs), and multi-tiered infrastructure layers. These findings are the basis for many research streams, including the annual malicious infrastructure <a href="https://www.recordedfuture.com/jp/research/2025-year-in-review-malicious-infrastructure">report</a>.</li>
          <li><strong>Victim identification through analysis of adversary infrastructure:</strong> Using Network Traffic Analysis Exfiltration Events and geographical intelligence, Insikt Group analysts identify targeted organizations by monitoring communications between victims and command-and-control (C2) servers across 30 billion daily network intelligence records. This approach allows them to identify victim organizations and sectors across malware families and detect ongoing intrusions in near real time. Recent research includes identifying five distinct activity clusters by TAG-144 (Blind Eagle) <a href="https://www.recordedfuture.com/jp/research/tag-144s-persistent-grip-on-south-american-organizations">targeting</a> Colombia government institutions.</li>
          <li><strong>Network traffic analysis and exfiltration event correlation:</strong> The team maintains an analysis pipeline that analyzes billions of network intelligence records to identify patterns indicating active compromises, persistence mechanisms, and data exfiltration. This proprietary capability enables detection of threat actor activities within minutes rather than days or weeks. Examples of recent reports include identifying victims targeted by <a href="https://www.recordedfuture.com/jp/research/graycharlie-hijacks-law-firm-sites-suspected-supply-chain-attack">GrayCharlie</a> using compromised WordPress sites.</li>
          <li><strong>Multi-source validation and cross-referencing</strong>: Analysts integrate data from over 1 million sources in the Intelligence Graph®, including the Recorded Future Platform, open web, dark web, technical feeds, malware intelligence, customer telemetry, and more. This comprehensive, multi-source approach helps them validate findings across disparate data points and pinpoint connections between threat actors, infrastructure, and targets that would be invisible when examining sources in isolation. Combining multiple sources, Insikt Group analysts <a href="https://www.recordedfuture.com/jp/research/evolution-of-the-chinese-language">reported</a> on Telegram-based “guarantee” marketplaces used by Chinese-speaking criminal groups to understand cyber and fraud campaigns.</li>
        </ul>
        <h2>Validation from experts with specialized skills</h2>
        <p>Insikt Group analysts’ multilingual analysis capabilities and cultural expertise enable them to identify and interpret threats that automated systems can’t fully contextualize.</p>
        <p>With native foreign-language skills and deep regional knowledge, analysts can analyze activity across dark web forums, underground criminal networks, and foreign-language sources, uncovering nuances in adversary communications and intent that would be lost in translation or missed entirely by automated tools.</p>
        <p>This human layer of analysis is particularly critical when monitoring threat actors operating across China, Russia, Iran, and North Korea, where understanding cultural context, geopolitical motivations, and regional dynamics is essential to accurate threat attribution and prediction.</p>
        <p>By combining deep subject-matter expertise in nation-state APT groups with continuous monitoring of global developments, Insikt Group delivers a comprehensive view of how geopolitical issues translate into cyber threats against specific organizations and sectors.</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1a0af59ff5902b8ecf406b395d1ce52d0eb34c536.png?width=750&amp;format=png&amp;optimize=medium" width="738" height="498" />
        </p>
        <h2>Research that powers the Platform and benefits the industry</h2>
        <p>Insikt Group makes its research available right inside the Recorded Future Platform. The team shares intelligence across a broad range of analytical formats: from breaking <strong>Flash Reports</strong> and <strong>Threat Leads</strong> on emerging activity, to deep-dive <strong>Cyber Threat Analyses</strong>, <strong>Actor Profiles</strong>, and <strong>Malware/Tool Profiles</strong> that map adversary behavior, capabilities, and infrastructure. For organizations tracking the broader risk environment, Insikt Group also produces <strong>Geopolitical Intelligence Summaries</strong>, <strong>Country Risk Updates</strong>, and forward-looking <strong>Geopolitical Threat Forecasts</strong>.</p>
        <p>Practitioners get hands-on support through <strong>Hunting Packages</strong> with actionable detections; <strong>TTP Instances</strong> sourced and verified across open, closed, and technical sources; and <strong>Vulnerability Intelligence</strong> to prioritize exposure. Payment fraud teams benefit from dedicated coverage including <strong>Payment Card Breach Alerts</strong>, <strong>Magecart E-Skimmer Reports</strong>, and <strong>Fraud TTP Analysis</strong>.</p>
        <p>All of this intelligence is automatically linked to Intelligence Cards—Recorded Future's consolidated profiles on entities like threat actors, IP addresses, hashes, and domains—so analysts can pivot directly from Insikt Group research to related indicators, infrastructure, and context.</p>
        <p>Customers aren't the only beneficiaries. To advance knowledge across the broader security industry, Insikt Group publishes many of its research reports on the Recorded Future blog and in publicly available threat intelligence <a href="https://www.recordedfuture.com/jp/research/insikt-group">reports</a> covering topics ranging from state-sponsored threat groups to newly emerging malware and attacker infrastructure.</p>
        <h2>A research division that stands apart in the industry</h2>
        <p>Few threat intelligence vendors can match what Insikt Group delivers as an embedded research division. Building and sustaining a team of this caliber requires significant ongoing investment, so most vendors default to automation alone. This often leaves their customers with an intelligence gap.</p>
        <p>Insikt Group analysts and their research also help drive Recorded Future product development, creating a feedback loop that continuously enhances the Platform. For customers, this means the difference between the noise of raw indicators and the signal of intelligence that’s interpreted, validated, and made actionable.</p>
        <p>To see how our comprehensive data sourcing can help your organization stay ahead of threats and mitigate business risk, <a href="https://www.recordedfuture.com/jp/get-started#book-demo">book</a> a custom demo.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1a445d21ea3cccaaef6ac0136f9ceefcca9ed5794.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Evaluating Mexico’s New Cybersecurity Plan]]></title>
            <link>https://www.recordedfuture.com/jp/research/mexico-new-cybersecurity-plan-evaluation</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/mexico-new-cybersecurity-plan-evaluation</guid>
            <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Explore an analysis of Mexico’s 2025–2030 National Cybersecurity Plan. Discover how Mexico is addressing critical threats like ransomware, organized crime, and AI-driven attacks while preparing its digital infrastructure for the 2026 FIFA World Cup and beyond]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Mexico recently <a href="https://www.portal.atdt.gob.mx/wp-content/uploads/2026/01/Plan_Nacional_de_Ciberseguridad-2.pdf">unveiled</a> a new National Cybersecurity Plan to be implemented over the remainder of this decade. The proposed plan lays the foundation to address the top cybersecurity threats Mexico has identified, including organized crime, geopolitical threats, and emerging artificial intelligence (AI) threats. The plan comes at a critical moment, as repeated cyber incidents across federal, state, and local institutions in Mexico have exposed the need for a more coordinated national response to reduce the risk of data theft, ransomware, service disruptions, and institutional reputational damage.</p>
        <p>Insikt Group analysis of cyber trends from 2020 to 2026 found that Mexico has historically been primarily impacted by ransomware, financial malware and fraud, and hacktivism. Data breaches and theft, organized crime and money laundering, and state-sponsored cybercrime have also represented significant threats. The government, healthcare, and financial sectors have been the primary targets of cyber threat actors, and ransomware continues to be the top threat to Mexican organizations. Mexico also remains an attractive target for state-sponsored cyber activity due to its deep integration with United States (US) supply chains, nearshoring-linked manufacturing base, and underdeveloped cybergovernance.</p>
        <p>Mexico is among the top five countries globally with the most documented victims of infostealers and stolen payment cards. Our research indicated that DarkForums is the most popular dark web special-access forum where threat actors discuss cyberattacks targeting Mexico. Mexican drug trafficking organizations (DTOs) are known to leverage Chinese money laundering networks (CMLNs) for their drug proceeds, relying on cryptocurrency to obfuscate their flow of illicit funds and soliciting cybercrime-as-a-service to evade arrests.</p>
        <p>The ongoing 2026 FIFA World Cup, co-hosted by Mexico, will be an initial test of the country’s ability to maintain operations and access to digital services amid increased tourism and international scrutiny. Facing this dynamic, organizations in Mexico should enhance their ability to detect cyber threats, prioritize threat visibility, and strengthen incident response planning. They should also train staff and the public on basic cyber safety, with an emphasis on building a practical understanding of how to respond quickly and effectively when incidents occur.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>Mexico’s proposed National Cybersecurity Plan outlines a path to update the country’s cyber posture at a critical moment. While previous attempts to advance national cybersecurity policy failed to get political traction, the administration of President Claudia Sheinbaum has committed to fully implementing this initiative over the course of her term, facilitated by her party’s majority control of Congress.</li>
          <li>In addition to the threats outlined in the plan, Insikt Group assesses that Mexico faces significant challenges related to ransomware, financial malware and fraud, and hacktivism. Data breaches and theft, organized crime and money laundering, and state-sponsored cyber threats also continue to pose a major challenge.</li>
          <li>As Mexico advances its new cyber policy, organizations operating in the country should consider strengthening their threat posture by leveraging cyber threat intelligence solutions, adopting international cyber standards, conducting scenario-planning exercises to improve responses to ransomware, data breaches, cyber espionage, and other threats, and educating employees and the general public.</li>
        </ul>
        <h2>Mexico’s Cybersecurity Positioning</h2>
        <p>On December 4, 2025, Mexico’s 2025–2030 National Cybersecurity Plan (hereinafter, the Plan) was published by the Mexican Digital Transformation and Telecommunications Agency (ATDT). The Plan is meant to update Mexican federal cyber policy for today’s threat environment and to create a more secure and resilient digital security policy ecosystem. While the Plan by itself does not create new cyber policies or legal frameworks, it outlines a series of benchmarks and indicators to guide progress toward that end. Ultimately, as the ATDT claims in the Plan, it is an attempt by Mexico to become a regional cyber-leader. Mexico was listed as a “Tier 2” nation in the International Telecommunication Union’s (ITU) 2024 <a href="https://www.itu.int/epublications/ru/publication/global-cybersecurity-index-2024/en">Global Cybersecurity Index</a>, placing it alongside Canada, Ecuador, and Uruguay in the upper ranks of Latin American nations for demonstrating a strong commitment to cybersecurity (Brazil and the US are the only countries in the Americas listed in Tier 1). However, the ITU identifies international cooperation as an area of growth, and Mexico is generally <a href="https://carnegieendowment.org/research/2024/05/mexicos-national-cybersecurity-policy-progress-has-stalled-under-amlo?utm_source=chatgpt.com">perceived</a> by cyber experts as lagging behind international standards in institutional capacity-building. When implemented, the ATDT claims that the Plan will “position Mexico at the forefront of regional cybersecurity, contributing not only to the protection of its own digital assets and population but also to the strengthening of regional cybersecurity in Latin America and the Caribbean.</p>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_1b8b72fdb1296a02f886b14807628c7e71bb6f857.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems]]></title>
            <link>https://www.recordedfuture.com/jp/blog/critical-fortibleed-campaign</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/critical-fortibleed-campaign</guid>
            <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A dataset containing valid administrative and VPN credentials for tens of thousands of Fortinet FortiGate firewalls.]]></description>
            <content:encoded><![CDATA[
        <p>A dataset containing valid administrative and VPN credentials for tens of thousands of Fortinet FortiGate firewalls has been attributed to a Russian-speaking threat group, with confirmed impacts across government, critical infrastructure, and multinational corporations. Organizations should verify exposure immediately and rotate credentials.</p>
        <h2>Latest Updates</h2>
        <p>Based on analysis by Insikt Group, we have determined that at least two threat actors are attempting to sell data allegedly from the FortiBleed campaign impacting FortiGate VPN credentials. Also, based on analysis by Insikt Group, we assess that only one of the two sellers of this FortiBleed data is likely credible.</p>
        <p>Insikt Group assesses that the threat actor <strong>SantaAd</strong>, a member of the top-tier Exploit Forum who posted an advertisement on June 12, 2026, claiming to auction off 34,000 lines of FortiGate VPN data, is likely a credible seller of this data. However, Insikt Group did not observe a sample posted in this advertisement thread, and at this time, we cannot confirm whether the FortiGate VPN data advertised by SantaAd is the same data involved in the FortiBleed incident.</p>
        <p>On June 21, 2026, Insikt Group identified another seller of data related to the FortiBleed campaign being offered by an illegitimate group with low credibility, leveraging the ShinyHunters branding and operating under the moniker <strong>shinymontanna</strong> within a public Telegram channel. Within this Telegram channel, shinymontanna is reusing verbatim language used in the auction post by SantaAd. Based on current and historical analysis by Insikt Group, we assess that <a href="https://app.recordedfuture.com/portal/intelligence-card/BHWGOsJ/overview?organization=uhash%3A5cJsHMHeSM"></a><strong><a href="https://app.recordedfuture.com/portal/intelligence-card/BHWGOsJ/overview?organization=uhash%3A5cJsHMHeSM">shinymontanna</a></strong> is likely attempting to re-extort victims of other threat actors and groups, as it has previously done, to capitalize on these incidents by creating greater urgency and fear to entice victims into paying. <strong>shinymontanna</strong> active since at least late fall 2025, has engaged in extortion attempts, claiming to possess sensitive data, including internal <a href="https://app.recordedfuture.com/portal/intelligence-card/I50Cee/overview?organization=uhash%3A5cJsHMHeSM"></a><a href="https://app.recordedfuture.com/portal/intelligence-card/I50Cee/overview?organization=uhash%3A5cJsHMHeSM">databases</a> and employee information, and has set ransom demands ranging from $100,000 to $2 million for the data's removal. The group has used <a href="https://app.recordedfuture.com/portal/intelligence-card/LEpDn3/overview?organization=uhash%3A5cJsHMHeSM"></a><a href="https://app.recordedfuture.com/portal/intelligence-card/LEpDn3/overview?organization=uhash%3A5cJsHMHeSM">Telegram</a> for communication and advertisement of their exploits, including illegitimate forums such as <a href="https://app.recordedfuture.com/portal/intelligence-card/cxDRA5/overview?organization=uhash%3A5cJsHMHeSM"></a><a href="https://app.recordedfuture.com/portal/intelligence-card/cxDRA5/overview?organization=uhash%3A5cJsHMHeSM">BreachForums</a> clones and copies in order to build credibility.</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_15c9f70afcf9ae6f823bf2d049773f6723a70cb3d.png?width=750&amp;format=png&amp;optimize=medium" width="459" height="921" />
        </p>
        <p><em>Figure 1:</em> <em><a href="https://app.recordedfuture.com/portal/intelligence-card/BHWGOsJ/overview?organization=uhash%3A5cJsHMHeSM">shinymontanna</a></em> <em>claiming responsibility for the</em> <em><a href="https://app.recordedfuture.com/portal/intelligence-card/BLV4oqH/overview?organization=uhash%3A5cJsHMHeSM"></a><a href="https://app.recordedfuture.com/portal/intelligence-card/BLV4oqH/overview?organization=uhash%3A5cJsHMHeSM">FortiBleed</a></em> <em>incident in the Telegram channel The Underground _ Uwu 😻 (Source: Recorded Future)</em></p>
        <h2>What Happened</h2>
        <p>On June 13, 2026, security researcher Volodymyr "Bob" Diachenko reported on the "FortiBleed" dataset, which allegedly contains valid administrative and SSL VPN credentials for approximately 73,932 FortiGate firewall URLs across 194 countries and more than 21,600 domains. Diachenko attributed the campaign to a Russian-speaking threat group.</p>
        <p>Cybersecurity researcher Kevin Beaumont and threat intelligence firm <a href="https://www.hudsonrock.com/fortinet">Hudson Rock</a> subsequently validated portions of the dataset. Beaumont confirmed that sampled administrative credentials were authentic. Many affected devices reportedly remained online at the time of disclosure, ran recent FortiOS versions, and had management interfaces exposed to the internet.</p>
        <p>Affected organizations span government, telecommunications, financial services, healthcare, manufacturing, and critical infrastructure sectors, including multinational corporations.</p>
        <h2>How the Attack Was Executed</h2>
        <p>According to Diachenko's investigation, threat actors:</p>
        <ul>
          <li>Conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets</li>
          <li>Conducted approximately 2.1 billion credential attempts against 163,650 Microsoft SQL Server (MSSQL) systems</li>
          <li>Intercepted SSL VPN authentication hashes</li>
          <li>Used a 45-GPU cluster managed through Hashtopolis to crack hashes and recover plaintext credentials</li>
          <li>Accessed internal Active Directory environments using recovered credentials</li>
        </ul>
        <p>Researchers assessed that the dataset likely originated from exported FortiGate configuration files, which enabled offline credential recovery without ongoing access to the targeted devices.</p>
        <h2>Scale and Impact</h2>
        <p>The FortiBleed dataset covers organizations in 194 countries. Confirmed or reported compromises include organizations in Japan, Taiwan, Vietnam, Iraq, and Türkiye. Among those affected is a Turkish NATO defense contractor from which threat actors allegedly exfiltrated classified documents.</p>
        <h2>Why This Matters</h2>
        <p>Several factors make FortiBleed a high-priority incident:</p>
        <ul>
          <li>A subset of credentials have been independently verified as authentic</li>
          <li>Affected devices in many cases remain online with no indication of remediation</li>
          <li>The campaign's scale (73,932 firewall URLs, 194 countries) makes this one of the largest confirmed FortiGate credential exposures on record</li>
          <li>Attribution to a Russian-speaking threat group, combined with confirmed targeting of a NATO defense contractor, raises the likelihood of espionage objectives alongside opportunistic access</li>
          <li>The offline cracking methodology means organizations may have no logs of the initial credential theft</li>
        </ul>
        <h2>Timeline of Events</h2>
        <ul>
          <li><strong>June 13, 2026</strong>: Researcher Volodymyr Diachenko publicly reports the FortiBleed dataset and attributes activity to a Russian-speaking threat group</li>
          <li><strong>June 13, 2026</strong>: Kevin Beaumont publishes analysis confirming sampled credentials are authentic; notes many affected devices remain online and internet-exposed</li>
          <li><strong>June 13, 2026</strong>: Hudson Rock validates portions of the dataset and releases a <a href="http://hudsonrock.com/fortinet">free FortiBleed lookup tool</a> for organizations to check domain exposure</li>
        </ul>
        <h2>Recorded Future Independent Analysis</h2>
        <p>Insikt Group analysts identified malicious activity originating from the IP address 85[.]11[.]187[.]8, which is linked to the FortiBleed attacks, during internal analysis and associated it with AS211486 within the 85[.]11[.]187[.]0/24 range. Analysts observed HTTP activity on port 9999 on June 7, 2026, and SSH, VNC, RDP, and additional attack-capture-related activity from June 14 to June 15, 2026.</p>
        <h3>Artifacts identified on this infrastructure were consistent with a full credential harvesting and follow-on intrusion workflow, including:</h3>
        <ul>
          <li>A sniffer log associated with Fortinet credential capture (fg_capture.log);</li>
          <li>Cracking orchestration files tied to Hashcat, Hashtopolis, and Telegram-coordinated tasking (bot.py, hashpanel.log, setup_hashcat.sh, and setup_hashtopolis.sh;</li>
          <li>Active Directory and LDAP enumeration scripts (ad_enum.py and ad_full_audit.py);</li>
          <li>Password-spraying tooling (spray_*.sh, spray_*.py, and spray_results.txt);</li>
          <li>SMB/DFS collection scripts with staged exfiltration capability backup_dfs.py, backup_dfs2.py, spider.py, and smb_test.py); and</li>
          <li>Log-clearing markers were also present, indicating efforts to remove evidence of activity.</li>
        </ul>
        <p>A June 18, 2026 PwnDefend blog post corroborated these findings by independently identifying 85[.]11[.]187[.]8 as a source IP associated with the FortiBleed campaign. The overlap between Insikt Group's internal findings and subsequent public reporting increases confidence in this IP's association with FortiBleed-related credential harvesting, cracking, and follow-on network access activity.</p>
        <h2>What You Need to Do Now</h2>
        <p>Immediate actions if your organization runs Fortinet:</p>
        <ul>
          <li>Rotate all FortiGate admin and SSL VPN credentials immediately</li>
          <li>Enforce multi-factor authentication on all remote and administrative access</li>
          <li>Review Fortinet logs for unusual logins, admin sessions, config changes, and new accounts. Consider replacing devices that have had suspicious activity.</li>
          <li>Restrict or remove internet exposure for management interfaces</li>
          <li>Patch FortiOS and review hardening settings</li>
          <li>Hunt for downstream compromise inside the network if exposed credentials were in use</li>
        </ul>
        <p>Recorded Future customers with affected domains will receive automated credential alerts if their organization is in the dataset as sources are ingested into the Platform. Customers can access related data from any of the following sources:</p>
        <ul>
          <li><strong>FortiBleed URL, Login, Password (ULP) Credential Leak</strong></li>
          <li><strong>FortiBleed Login and Password List</strong></li>
          <li><strong>FortiBleed Impacted Domains</strong></li>
          <li><strong>FortiBleed Domain Attribution</strong></li>
        </ul>
        <p>Recorded Future customers can access the full Analyst Note and FortiBleed Intelligence Card in the Recorded Future Portal for additional indicators, affected organization context, and threat actor attribution detail.</p>
        <p>Learn how to stay ahead of emerging threats. <a href="https://www.recordedfuture.com/jp/get-started">Understand all of the critical vulnerabilities that may be affecting your organization. Speak to our threat intelligence experts today</a><u>.</u></p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1d652826bfdaff7cf36752ed0f9f7e7c6af3a80f3.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The Purchase Scam Tactic Headed  for the World Cup | Recorded Future]]></title>
            <link>https://www.recordedfuture.com/jp/blog/world-cup-purchase-scam-tactics</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/world-cup-purchase-scam-tactics</guid>
            <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A purchase scam tactic hijacks organic search through compromised sites, and it’s built to scale into 2026 FIFA World Cup fraud. How it works and how to respond.]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>Recorded Future's Payment Fraud Intelligence team continues to monitor a purchase scam tactic that pulls victims from organic search rather than paid ads by compromising legitimate websites. The scam domains never appear in search results themselves, which means the operations are likely hidden from standard search monitoring and could survive the takedown of any single domain or merchant account. The same tactic is already surfacing in World Cup-themed fraud, and it’s positioned to scale across event-driven scams through 2026.</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1cdf8f4f2c2d92de6a15bf93d2058210f6b3db851.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[State Digital Surveillance Risk Landscape]]></title>
            <link>https://www.recordedfuture.com/jp/research/state-digital-surveillance-risk-landscape</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/state-digital-surveillance-risk-landscape</guid>
            <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Explore the state digital surveillance risk landscape. Learn how governments use spyware, AI, and network interception to monitor travelers and how to mitigate these risks.]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Insikt Group assesses that government digital surveillance activities pose a high or very high risk in 31 countries, where state actors exploit telecommunications infrastructure, homegrown and commercial spyware, and artificial intelligence (AI)-powered tools to monitor foreign nationals and business travelers with little to no legal accountability. A further 55 countries categorized as medium risk frequently deploy less-sophisticated surveillance capabilities to target political opposition and dissent –– highlighting the need for organizations to adopt appropriate mitigation measures in jurisdictions with limited oversight mechanisms and track records of surveillance targeting foreign entities or supporting domestic repression.</p>
        <p>Insikt Group has identified five broad categories of digital surveillance capabilities built in-house or acquired by governments: network interception, endpoint compromise, platform-level access, public space surveillance, and data aggregation. The risk of a government abusing these capabilities is almost certainly higher in jurisdictions lacking independent oversight mechanisms or clear delineations of the legal, necessary, and proportional use of these capabilities, in line with international standards.</p>
        <p>Foreign nationals and business travelers who fail to adequately understand and prepare for digital surveillance risks prior to traveling or conducting operations in a given location can face significant personal and organizational damages, including sensitive data breaches, IP theft, targeted intelligence operations, reputational harm, and increased risks from physical threats or detention.</p>
        <p>As such, individuals traveling abroad and their respective organizations should implement mitigation measures to protect sensitive data, commensurate with the level of state surveillance risk in the destination country. These measures range from maintaining standard security hygiene in lower-risk environments to using sterile, non-corporate devices when operating in high-risk jurisdictions.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>Insikt Group assesses that there are “high” or “very high” levels of digital surveillance risk in 31 countries due to their use of advanced surveillance capabilities against foreign businesses, travelers, and government critics, with limited to no oversight.</li>
          <li>A further 74 countries have “medium” levels of digital surveillance risk. While 55 of these countries are not known to have deployed advanced surveillance capabilities, there is evidence that their governments have deployed less sophisticated surveillance measures for a variety of purposes, which may include monitoring political opposition, human rights activists, and journalists. The remainder (19) of countries in this category possess advanced surveillance capabilities, but are not known to typically use them in violation of national or international laws.</li>
          <li>By exploiting control over telecommunications infrastructure and online platforms, governments can conduct mass, indiscriminate monitoring of traffic and user data. The risk of abuse of network interception and platform-level access is almost certainly greatest where judicial authorization requirements and procedural safeguards are weak.</li>
          <li>The proliferation of commercial spyware, AI-powered public security infrastructure, and increasing collection of biometric and personal data almost certainly enables governments to build comprehensive digital profiles of individuals and leverage them for targeted surveillance operations.</li>
          <li>Digital surveillance that is not subject to robust oversight and does not abide by the principles of legality, necessity, and proportionality very likely incurs heightened operational, reputational, and legal costs for organizations and individuals, including the loss of sensitive data, the proliferation of cyber vulnerabilities, and legal and physical risks.</li>
        </ul>
        <h2>Components of Surveillance Risk</h2>
        <p>Insikt Group regularly assesses risks to business travelers and foreign nationals from government-run digital surveillance operations in 193 countries using Recorded Future’s Country Risk analytic framework. Customers can access Country Risk analysis by querying for State Surveillance Notes in the Recorded Future Intelligence Operations Platform. State Surveillance Notes assess the overall level of state surveillance risk in a given country based on three primary categories:</p>
        <ul>
          <li><strong>Surveillance Capabilities:</strong> The ability of intelligence services, law enforcement agencies, or other state-affiliated or directed entities to undertake digital surveillance, and the scope of these digital surveillance capabilities. This category includes the capabilities of a variety of state and state-nexus actors, including specialized surveillance agencies with broad access to digital infrastructure, state-affiliated groups that deploy spyware for cyber espionage, and individual law enforcement units that carry out traditional wiretapping.</li>
        </ul>
        <ul>
          <li><strong>History of Digital Surveillance Operations:</strong> A government’s historical willingness to carry out unlawful, arbitrary, or overbroad digital surveillance operations. This can include surveillance that violates national law — such as government entities monitoring communications without appropriate authorization — but also covers surveillance that may be sanctioned under national legislation but violates international <a href="https://www.ohchr.org/en/privacy-in-the-digital-age/international-standards">principles</a> of legality, necessity, and proportionality.</li>
        </ul>
        <ul>
          <li><strong>Oversight Mechanisms:</strong> The existence and efficacy of judicial, legislative, or independent oversight bodies that approve and monitor a government’s digital surveillance operations for compliance with domestic and international law.</li>
        </ul>
        <p>A comprehensive evaluation of state surveillance risk in a country requires a composite assessment that takes into account all three categories. For example, a country purchasing high-profile spyware may not, by itself, indicate a high level of risk to business travelers or foreign nationals, provided that the government has a good track record of respecting domestic and international privacy protections and has strong judicial and legislative oversight of intelligence and security agencies. In contrast, a country with less advanced capabilities, but strict control over internet infrastructure and few restrictions on the government’s ability to collect user data, likely poses a greater risk to travelers’ and foreign nationals’ data security.</p>
        <p>Insikt Group assesses whether a country’s history of digital surveillance constitutes a risk to foreign nationals and travelers based on its alignment with international principles on privacy and digital rights. Article 12 of the United Nations (UN) <a href="https://www.un.org/sites/un2.un.org/files/2021/03/udhr.pdf">Universal Declaration of Human Rights</a> establishes that no individual “shall be subjected to arbitrary interference with his privacy, family, home, or correspondence”. A 2022 UN General Assembly <a href="https://docs.un.org/en/A/RES/77/211">resolution</a> on privacy in the digital age states that</p>
        <p>“unlawful or arbitrary surveillance and/or interception of communications, as well as the unlawful or arbitrary collection of personal data, hacking and the unlawful use of biometric technologies, as highly intrusive acts, violate the right to privacy” and that states should ensure that any interference with this right is consistent with principles of “legality, necessity, and proportionality.”</p>
        <p>“Legality,” in this formulation, <a href="https://docs.un.org/en/A/RES/77/211">requires</a> that surveillance or interception be prescribed by “a legal framework, which must be publicly accessible, clear, precise, comprehensive and non-discriminatory.” Surveillance must also be <a href="https://necessaryandproportionate.org/principles/">necessary</a> to further the purposes identified in corresponding law, take the least intrusive form required to do so, and be proportionate in scope to the interest being protected.</p>
        <h3>Key Components of State Digital Surveillance Risk</h3>
        <div>
          <div>
            <div>
              <h3>Capabilities</h3>
            </div>
            <div>
              <h3>Surveillance History</h3>
            </div>
            <div>
              <h3>Oversight</h3>
            </div>
          </div>
          <div>
            <div>
              <p>What technologies support a government’s ability to conduct surveillance?</p>
              <p>Do capabilities enable mass surveillance or data collection?</p>
              <p>Who are the primary providers of surveillance technologies?</p>
              <p>Which government entities have access to these surveillance capabilities?</p>
            </div>
            <div>
              <p>Who is monitored, and under what conditions?</p>
              <p>Do authorities surveil activists, journalists, foreign diplomats, or business representatives?</p>
              <p>Does surveillance align with international and domestic law?</p>
              <p>Are government security and intelligence entities linked to rights violations?</p>
            </div>
            <div>
              <p>Does surveillance require prior judicial authorization?</p>
              <p>Do judicial, legislative, or expert oversight bodies review surveillance programs’ compliance with domestic and international law?</p>
              <p>Are oversight bodies independent, impartial, and effective?</p>
            </div>
          </div>
        </div>
        <p><em><strong>Table 1:</strong></em> <em>State surveillance risk level is a function of not only a jurisdiction’s surveillance capabilities, but also its history of deployment of those capabilities and oversight mechanisms (Source: Recorded Future)</em></p>
        <p>Applying these criteria, and based on data collected from 2024 to 2026, Insikt Group has assessed the level of risk associated with state digital surveillance in 193 countries:</p>
        <ul>
          <li>Six countries (3%) –– Belarus, China, Iran, Myanmar, North Korea, and Russia –– are “very high risk,” denoting evidence of advanced surveillance capabilities, a lack of independent oversight, regular surveillance targeting foreign businesses and travelers, and widespread suppression of political opposition or dissent.</li>
          <li>25 countries (13%) are “high risk,” indicating evidence of moderate to advanced surveillance capabilities, limited independent oversight, and the use of surveillance tools to repress domestic political opposition, activism, or reporting critical of the government.</li>
          <li>74 countries (38%) are “medium risk,” either indicating evidence of advanced surveillance capabilities that are not typically used in violation of national or international laws (19 countries), or evidence of less advanced capabilities that are frequently employed to suppress political dissent and activism (55 countries). While countries in this risk tier may have established systems for oversight or judicial review, government surveillance operations do not always abide by their purview.</li>
          <li>65 countries (34%) are “low risk,” indicating evidence of moderate to advanced surveillance capabilities exercised under strong oversight with established records of avoiding unlawful or arbitrary surveillance (39 countries), or evidence of limited surveillance capabilities (26).</li>
          <li>23 countries (12%) are “very low risk,” indicating minimal ability to conduct digital surveillance, well-established oversight mechanisms, and no indications of surveillance abuses.</li>
        </ul>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="A map of the world color-coded by state digital surveillance risk levels, ranging from medium to very high," src="https://www.recordedfuture.com/jp/media_132c535c37e904b7a13918843dee2c99d6b7ea883.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1555" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1</strong>: State surveillance risks by country from medium to very high risk based on data collected from 2024 to 2026 (Source: Recorded Future)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_1b8d61d216e8bbbac039c70f224e63c286ab899bb.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine]]></title>
            <link>https://www.recordedfuture.com/jp/blog/proprietary-collection-engine</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/proprietary-collection-engine</guid>
            <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Learn how Recorded Future’s proprietary collection engine empowers organizations to move beyond reactive security. Discover the power of our four unique intelligence source types—technical, underground, community, and open-source—working together to provide proactive, full-lifecycle threat protection.]]></description>
            <content:encoded><![CDATA[
        <p><strong>Four Critical Source Types. One Platform. Recorded Future is the Only Threat Intelligence Vendor that Collects and Analyzes Across Four Types of Data Sources.</strong></p>
        <p>When a critical vulnerability emerges, most organizations scramble for answers.</p>
        <p>What’s being exploited?<br />Who’s targeting it?<br />Are we exposed?</p>
        <p>During the emergence of the React2Shell vulnerability, one Recorded Future customer didn’t rely on speculation. Using Recorded Future’s IP scanning intelligence, they identified which IPs were actively scanning for exploitation, analyzed the exact request patterns being used, and immediately assessed their own exposure.</p>
        <p>Instead of reacting to headlines, they acted on <strong>real-time intelligence</strong>.</p>
        <p>In the <a href="https://www.recordedfuture.com/jp/blog/recorded-future-holistic-sourcing-wins">first</a> article in our series covering our unique data sourcing model, we looked at why source scale and diversity are essential for maximum threat protection. Now we’ll explain the four source types in more detail to see how, together, they empower our customers to prioritize, pinpoint, and act faster to stop threats.</p>
        <p>This is the power of Recorded Future’s <strong>technical collection engine</strong>.</p>
        <h2>Technical intelligence at internet scale</h2>
        <p>Recorded Future continuously collects and analyzes telemetry from across the internet, including:</p>
        <ul>
          <li>Network traffic analysis across billions of daily network intelligence records (with over 200 points of presence (PoP))</li>
          <li>Internet-wide scanning and infrastructure monitoring</li>
          <li>Malware detonation and behavioral analysis</li>
          <li>Vulnerability exploitation tracking</li>
        </ul>
        <p>This technical intelligence provides direct visibility into attacker infrastructure, behavior, and intent.</p>
        <h2>Finding what others miss</h2>
        <p>Technical collection becomes most valuable when it reveals what’s hidden.</p>
        <p>In one investigation, Recorded Future identified suspicious traffic on a specific port through its Malicious Traffic Analysis. This insight led a security team to uncover additional command-and-control communication that had been missed due to incomplete logging, expanding the scope of the compromise.</p>
        <p>This isn’t just detection—it’s <strong>discovery</strong>.</p>
        <h2>Deep malware intelligence through sandboxing</h2>
        <p>Understanding malware requires more than static indicators.</p>
        <p>Recorded Future processes over <strong>1.5 million malware samples daily</strong> through its sandbox, enabling deep behavioral analysis of:</p>
        <ul>
          <li>Command-line execution</li>
          <li>Process activity</li>
          <li>Network communication</li>
          <li>Exploit techniques</li>
        </ul>
        <p>This allows analysts to move beyond “Is this malicious?” to:</p>
        <ul>
          <li>How does it behave?</li>
          <li>What infrastructure does it use?</li>
          <li>How can we detect it elsewhere?</li>
        </ul>
        <p>Customers consistently highlight this capability as transformative.</p>
        <p>In one case, a security analyst identified a unique command-line artifact within sandbox results. By pivoting on that behavior in their environment, they uncovered an additional infection vector that would have otherwise gone undetected—avoiding a far more complex incident response scenario.</p>
        <h2>Intelligence from the underground</h2>
        <p>Technical signals alone don’t tell the full story.</p>
        <p>Recorded Future augments telemetry with intelligence from criminal forums, marketplaces, and adversary communications, revealing:</p>
        <ul>
          <li>Stolen data and credentials</li>
          <li>Emerging attack techniques</li>
          <li>Threat actor intent</li>
          <li>Ransomware victimology</li>
          <li>Telegram</li>
        </ul>
        <p>This provides critical context for prioritizing risk and understanding adversary motivations.</p>
        <h2>Community intelligence: strength in numbers</h2>
        <p>Recorded Future’s Collective Insights capability aggregates detections across organizations, helping customers identify patterns they might not see alone. This is especially important for preparing for monthly C-suite briefs on the latest threat assessments.</p>
        <p>One logistics customer used this capability to investigate a multi-stage intrusion, correlating activity across their environment and linking it to nation-state actors in real time. Another customer uses Collective Insights to provide clear visibility into the specific malware most frequently blocked within their own environment, rather than relying on general trends.</p>
        <p>This shared intelligence transforms isolated detections into <strong>campaign-level understanding</strong>.</p>
        <h2>Proactive defense in practice</h2>
        <p>This combination of technical, underground, and community intelligence enables proactive defense.</p>
        <p>Customers often use Recorded Future’s Threat Map to identify an emerging threat actor and deploy detections in advance. Weeks later, when the actor launches a phishing campaign, customers can immediately detect and block the activity—preventing compromise before it begins.</p>
        <h2>Where open source fits</h2>
        <p>Open-source intelligence provides valuable context, but on its own it’s incomplete. Without technical telemetry, behavioral analysis, and external digital risk monitoring, organizations risk seeing only part of the threat landscape.</p>
        <p>At Recorded Future, open sources are one part of a broader intelligence ecosystem that also supports data leakage detection, code repository monitoring, social media monitoring, and analysis of web infrastructure and content—including HTML and DOM elements—to identify brand abuse, exposed data, impersonation, and other external threats.</p>
        <h2>The bottom line</h2>
        <p>Recorded Future’s technical collection engine doesn’t just gather data. It reveals:</p>
        <ul>
          <li>Who’s attacking</li>
          <li>How attacks are executed</li>
          <li>Where infrastructure is operating</li>
          <li>When action is required</li>
        </ul>
        <p><strong>One platform for comprehensive threat intelligence</strong></p>
        <p>While some platforms focus on immediate detection, the Recorded Future Platform maintains years of historical data to reveal long-term patterns. And it automatically connects intelligence from diverse sources, turning separate data streams into unified insights.</p>
        <p>From initial reconnaissance through criminal planning, active infrastructure attacks, and malware deployment, our four intelligence source types work together to enable proactive defense across the entire attack lifecycle.</p>
        <p>In the next blog in our series, we’ll show how human experts connect the dots, validating our intelligence and making it actionable so you can prevent threats.</p>
        <p>To see our four types of data sources in action in the Recorded Future Platform, <a href="https://www.recordedfuture.com/jp/get-started#book-demo">request</a> a custom demo.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1a445d21ea3cccaaef6ac0136f9ceefcca9ed5794.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Recorded Future Launches Impact and Metrics Dashboard]]></title>
            <link>https://www.recordedfuture.com/jp/blog/impact-metrics-dashboard</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/impact-metrics-dashboard</guid>
            <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[See the business value of your intelligence program in one live, continuously updated dashboard, built for the conversations that matter most with the executives who own budget and strategy.]]></description>
            <content:encoded><![CDATA[
        <p>Today, Recorded Future is announcing the <strong>Impact and Metrics Dashboard</strong>, a new way for every Recorded Future customer to see the value their intelligence program generates without building reports by hand. The dashboard pulls data from your environment, alerts, integrations, threat detections, and analyst activity, then surfaces the metrics that map to the business and security outcomes your leadership cares about.</p>
        <p>Security teams have always known that intelligence drives better outcomes. The hard part has been proving it in the language of the business. Boards, CFOs, and CIOs aren't asking for threat counts. They want measurable risk reduction tied to business context, and they want it in numbers they can defend.</p>
        <p>Our <a href="https://pages.recordedfutureext.com/how-recorded-future-drives-roi"></a><a href="https://pages.recordedfutureext.com/how-recorded-future-drives-roi">2025 ROI Report</a>, validated across nearly 300 customers, puts numbers to what security teams already know. Recorded Future customers have reported achieving <strong>351.3% ROI annually</strong>. 57% say the platform has substantially reduced their overall cyber risk. 96% would recommend it to a peer.</p>
        <p>But the numbers that resonate most are not the averages. They are the attacks that your team was able to get ahead of. Ransomware stopped before detonation. Credentials reset before an adversary could use them. Fraud campaigns contained before they could reach customers. Until now, capturing that story meant pulling data from across the platform, stitching it together by hand, and rebuilding the same readout every quarter.</p>
        <p>The most powerful version of that story is yours and that is what the Impact and Metrics Dashboard is built to show.</p>
        <h2>What the dashboard covers</h2>
        <p><strong>Platform-Wide Security Value:</strong> Your headline number. Aggregate risk reduction and intelligence coverage across your environment, built for leadership conversations.</p>
        <p><strong>Threat Prioritization:</strong> See which threat actors and malware families are relevant to your organization, and how Recorded Future AI cuts noise so your team focuses on what matters. Customers who aligned their alerting to PIRs reported identifying new threats <strong>65% faster</strong>.</p>
        <p><strong>Threat Detection:</strong> Understand how intelligence is moving through your security stack, from malware detected in your telemetry to integrations and threat hunting activity. Customers often receive critical alerts hours or days earlier than from other vendors.</p>
        <p><strong>Digital Risk Protection:</strong> Quantify exposure reduced from fraud, brand impersonation, and credential threats. For organizations with significant brand or customer risk, this is where ROI becomes immediately tangible and immediately explainable to a CFO.</p>
        <p><strong>Account &amp; Credential Monitoring:</strong> See identity threats surfaced and remediated before they became incidents.</p>
        <p><strong>Recorded Future AI &amp; Insikt GroupⓇ Research:</strong> Recorded Future’s expert Intelligence team &amp; AI does the work for you, providing deeper insights than most teams could do alone. Measure analyst hours recaptured through AI-powered automation and the volume of expert research your team has put to work. Your efficiency case, in your own numbers.</p>
        <p>Today the dashboard surfaces key metrics to start the conversation and give your team something concrete to point to. Over time the calculations will get more personalized, the benchmarks more specific to your organization, and the integration with your business context deeper.</p>
        <p>The Impact and Metrics Dashboard is available now for every customer. To find it, navigate to Dashboards &gt; Impact and Metrics in your Recorded Future instance. For setup help or questions, contact your Technical Account Manager (TAM).</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_16b723149e1b7a9aafafdffa83d43e9fb70b897d9.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1272" />
        </p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_16aac93a975dc700635f38a08a9b3d99d45567122.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Cyber-Enabled Maritime Sanctions Evasion]]></title>
            <link>https://www.recordedfuture.com/jp/research/cyber-maritime-sanctions-evasion</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/cyber-maritime-sanctions-evasion</guid>
            <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Discover how Iranian and Russian shadow fleets use a vast network of fake maritime websites and fraudulent documents to evade international sanctions]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Iranian and Russian shadow fleet vessels, along with multiple sanctions evasion networks (SENs), are using online infrastructure likely designed to facilitate sanctions evasion. The infrastructure consists of inauthentic websites impersonating ship registries, national maritime administrations, seafarer training and certification organizations, protection and indemnity (P&amp;I) clubs, and ship classification societies, effectively replicating key layers of the maritime compliance stack. The websites are likely being used to circumvent maritime compliance mechanisms by generating and corroborating false documents and certificates.</p>
        <p>The online infrastructure is consistent with a service-provider model in which threat actors offer reusable digital infrastructure, documentation, and identities, rather than operating as centrally coordinated, country-specific networks. Three identified clusters of online activity –– designated as Alpha, Bravo, and Charlie for the purposes of this report –– have several technical overlaps, suggesting these clusters may form a broader, loosely connected ecosystem of online infrastructure supporting multiple SENs. This activity also aligns with prior reporting by <a href="https://www.bellingcat.com/news/2026/02/19/shipwrecks-sham-papers-and-false-flags-tracking-the-company-behind-it-all/">Bellingcat</a> and <a href="https://www.lloydslist.com/LL1154326/Massive-fraudulent-flag-operation-linking-over-20-separate-fake-sites-uncovered">Lloyd’s List</a> and demonstrates potential links between the two reports across these three clusters.</p>
        <p>This infrastructure blends established sanctions evasion practices, such as exploiting weak jurisdictional oversight in under-resourced jurisdictions to conduct fraudulent ship flag registrations, with increasingly cyber-enabled tactics such as automated document generation and layered infrastructure to produce fraudulent documents and credible front companies, complicating detection and enforcement.</p>
        <p>Cyber-enabled SENs almost certainly undermine sanctions compliance mechanisms by developing credible but fraudulent maritime organizations, increasing the risk of due diligence failures and regulatory exposure. Organizations in the maritime and shipping sectors should integrate independent verification and cyber threat intelligence into compliance workflows to proactively identify fraudulent online infrastructure. Governments whose authorities are regularly impersonated by SENs and associated service providers should prioritize coordinated identification and disruption of fraudulent infrastructure, particularly where threat actors claim multi-jurisdictional legitimacy.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>SENs tied to the Iranian and Russian shadow fleets are likely using over 36 inauthentic websites in three distinct clusters. Insikt Group identified explicit connections between these websites and seventeen vessels, the majority of which have already been sanctioned by the United States (US) Department of the Treasury (USDT)’s Office of Foreign Asset Control (OFAC) and by other countries.</li>
          <li>Inauthentic websites identified as part of these clusters routinely impersonate national maritime administrations and ship registries from countries such as the Comoros and Benin, as well as Bhutan, Cameroon, Chad, Equatorial Guinea, Gambia, Haiti, Malawi, Nicaragua, and Zambia.</li>
          <li>Other websites also aim to establish fictional ship classification societies as credible <a href="https://www.imo.org/en/ourwork/iiis/pages/recognized-organizations.aspx">registered organizations</a> (ROs), in addition to several websites acting as fictional seafarer training and certification organizations and P&amp;I clubs.</li>
          <li>One website impersonates the Benin Maritime Administration and provides a self-service tool to generate fraudulent seafarer documents from the governments of Benin, the Comoros, and Nicaragua.</li>
          <li>Attribution for at least two of the clusters documented in this report includes Cluster Alpha, which is likely to have been at least partially developed by an Indian web development company, Oceaniek Technologies. Cluster Bravo is linked to two Syrian nationals, one of whom has previous historical involvement in illicit activity. Cluster Charlie remains unattributed, although it shares technical and design characteristics with Cluster Bravo.</li>
        </ul>
        <h2>Background</h2>
        <p>Three partially overlapping clusters of online infrastructure are likely being used by both the Iranian and Russian shadow fleets to evade sanctions (<strong>Figure 1</strong>). The three clusters (designated Alpha, Bravo, and Charlie) are connected through shared infrastructure, consistent domain registration patterns, and recurring operational security (OPSEC) mistakes.</p>
        <p>The activity described in this report also overlaps with two previously unconnected activity clusters described by <a href="https://www.bellingcat.com/news/2026/02/19/shipwrecks-sham-papers-and-false-flags-tracking-the-company-behind-it-all/">Bellingcat</a> and <a href="https://www.lloydslist.com/LL1154326/Massive-fraudulent-flag-operation-linking-over-20-separate-fake-sites-uncovered">Lloyd’s List</a> –– the first tied to Indian web development company Oceaniek Technologies, and the second to a cluster of fraudulent ship registries centered around the domain marinegov[.]net. This activity also aligns with prior <a href="https://bsky.app/profile/did:plc:2hnbryw5nya2kriog5i2nefh">reporting</a> from independent researcher Christian Panton, who collaborated with both Bellingcat and Lloyd’s List.</p>
        <p>Unlike traditional intrusion sets, these websites enabling maritime fraud and sanctions evasion form a complex network involving front companies, individuals, and vessels. However, Insikt Group has established initial attribution to one of the clusters to two Syrian nationals, with one individual having a record of previous involvement in illicit activities.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="diagram showing three partially overlapping clusters—labeled Alpha, Bravo, and Charlie" src="https://www.recordedfuture.com/jp/media_10c0847b07bf802cea5fb70c03f82b65e95eb0e68.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1499" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1</strong>: Clusters identified by Insikt Group (Source: Recorded Future)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_12cb79eec13b6af7520af3c1ae6768c0f4b25e945.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[2026 FIFA World Cup: What Public Safety Officials Need to Know]]></title>
            <link>https://www.recordedfuture.com/jp/blog/2026-fifa-world-cup-cyber-physical-threats-security-guide</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/2026-fifa-world-cup-cyber-physical-threats-security-guide</guid>
            <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Prepare for the 2026 FIFA World Cup with expert analysis of the physical and cyber threat landscape. Discover key mitigation strategies for host city officials to ensure public safety]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>Starting tomorrow, millions of people will gather in sixteen host cities across the United States, Canada, and Mexico to cheer on their teams in the 2026 FIFA World Cup. Securing the tournament will require preparing for a mix of physical security risks, cyber threats, scams, protests, politically motivated activity, and reputational disruption tied to one of the world’s most visible sporting events.<br /><br />The World Cup’s global profile creates an attractive target environment for a wide range of threat actors. Cybercriminals are already exploiting tournament demand through fraudulent domains, fake stores, credential-harvesting sites, and advertising campaigns. Hacktivists and influence operators will likely try to use the event’s visibility to amplify political narratives or claim responsibility for disruptive activity. At the same time, public safety officials must manage the physical security challenges associated with large crowds, soft targets, protests, transportation hubs, hospitality infrastructure, and fan zones.<br /><br />Together, these risks create a blended cyber-physical threat environment that requires coordination across public safety, cybersecurity, fraud, legal, communications, brand protection, executive protection, travel security, and third-party risk teams.</div>
          </div>
        </div>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="An assessment of physical, cyber, and fraud threats to the 2026 FIFA World Cup, visualizing various risk categories associated with the event" src="https://www.recordedfuture.com/jp/media_1164cbfb999d049abe8f62a8888046cc849206f6f.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1455" />
            </div>
          </div>
          <div>
            <div>
              <p><strong>Figure 1:</strong> Assessment of physical, cyber, and fraud risks affecting the 2026 FIFA World Cup</p>
              <p>(Source: Recorded Future)</p>
            </div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1bd1b16a64c5889ff9d94763b1d5354f0c5c0abd7.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[China's Noncombatant Evacuation Operations: 2005–2025]]></title>
            <link>https://www.recordedfuture.com/jp/blog/china-noncombatant-evacuation-operations-2005-2025</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/china-noncombatant-evacuation-operations-2005-2025</guid>
            <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Explore the Insikt Group study on 37 Chinese noncombatant evacuation operations (NEOs) from 2005–2025, revealing how China leverages SOEs and civilian resources for its overseas interests]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>
              <p>Over the past two decades, noncombatant evacuation operations (NEOs) have <a href="https://www.routledge.com/Chinas-Strong-Arm-Protecting-Citizens-and-Assets-Abroad/Parello-Plesner-Duchatel/p/book/9781138947269">emerged</a> as an important <a href="https://global.oup.com/academic/product/protecting-chinas-interests-overseas-9780198867395?cc=us&amp;lang=en&amp;">tool</a> for <a href="https://ndupress.ndu.edu/Publications/Books/The-PLA-and-Contingency-Planning-in-China/">protecting</a> China’s overseas <a href="https://web.archive.org/web/20190922161625/http://english.www.gov.cn/archive/white_paper/2014/08/23/content_281474982986506.htm">interests</a>. To assess China’s NEO capabilities for the US Army War College China Landpower Studies Center’s <a href="https://ssi.armywarcollege.edu/SSI-Media/Recent-Publications/Article/4461809/2026-carlisle-conference-on-the-pla-the-plas-capability-to-react-to-crises/">2026 Carlisle Conference on the PLA</a> (People’s Liberation Army), Insikt Group built an original dataset of 37 Chinese NEOs carried out between January 2005 and August 2025. This blog post has been adapted from Insikt Group’s conference paper, and our “China 2005–2025 Noncombatant Evacuation Operation Dataset” is attached as a PDF.<br /><br />One of Insikt Group’s most notable findings is that, over the past twenty years, China has consistently mobilized civilian resources to facilitate NEOs, demonstrating China’s reliance on these resources for NEOs and its capability to call upon diverse instruments of national power to protect overseas interests. During this period, at least 65% of China’s NEOs involved support from Chinese state-owned enterprises (SOEs), private enterprises, or United Front/civil society organizations located in the host country, third-party countries, or China. The contributions of SOEs, private enterprises, and United Front/civil society organizations to China’s NEOs include:</p>
              <ul>
                <li>Organizing evacuation efforts on the ground</li>
                <li>Communicating official instructions</li>
                <li>Providing air, land, and maritime transportation</li>
                <li>Providing relief to evacuees once they arrive in neighboring countries or return to China-</li>
              </ul>
              <p><br />The Chinese Communist Party (CCP) and the Chinese government have continued to take advantage of civilian resources for NEOs since August 2025 — such as for its <a href="https://web.archive.org/web/20260301043818/https://www.globaltimes.cn/page/202602/1355925.shtml">Iran NEO</a> in early 2026 — and will almost certainly continue to mobilize these resources in the future.</p>
            </div>
          </div>
        </div>
        <h2>Overview of China’s NEOs</h2>
        <p>China carried out at least 37 NEOs in 28 different countries between 2005 and 2025 (see image below). China carried out eleven NEOs in Africa, nine in the Middle East, and nine in Asia, with the other eight occurring in the Caribbean, Pacific Islands, Europe, and North America. China conducted multiple NEOs in the Central African Republic, Haiti, Iran, Israel, Kyrgyzstan, Lebanon, Libya, and South Sudan.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Map highlighting 28 countries in which China carried out Noncombatant Evacuation Operations (2005-2025)" src="https://www.recordedfuture.com/jp/media_1582d18df3b0768454a59bd2f08d2b4a09ca77884.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1427" />
            </div>
          </div>
          <div>
            <div>The 28 countries in which China carried out a NEO between 2005 and 2025 (Source: Recorded Future)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1b1d5e25aa9dbcf984eeef976c7fd8a80d54e53e4.jpg?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars]]></title>
            <link>https://www.recordedfuture.com/jp/research/russia-defense-base-economy-risks-wars</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/russia-defense-base-economy-risks-wars</guid>
            <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Western sanctions have tied Russia's elite patronage to the defense sector. Learn why this creates a domestic imperative for Putin to pursue perpetual war]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Since Russia’s full-scale invasion of Ukraine in February 2022, and the subsequent increase in Western sanctions on Russian individuals and firms, Russia’s economy has become increasingly skewed toward the defense sector. This has very likely led Russian political elites to increasingly draw patronage flows from defense-related expenditures. The wide range of sanctions has likely made it difficult for elites to diversify the sources of their graft, leaving them increasingly dependent on defense contracts for illicit funds.</p>
        <p>As Russian President Vladimir Putin uses the distribution and withdrawal of patronage flows as a key way to maintain elite loyalty, a steady stream of defense expenditures has likely become an increasingly important cornerstone for Putin’s ability to maintain domestic political stability. Since maintaining domestic political stability is critical to Putin’s political survival, he very likely sees maintaining current defense expenditures as not only a foreign policy priority, but also a domestic political imperative. A decrease in defense expenditures would likely result in a decline in patronage flows to elites, thereby raising the prospect of elite discontent and greater difficulty in maintaining political stability.</p>
        <p>Insikt Group therefore assesses that Putin is likely incentivized to engage in conflict abroad, not only for geopolitical purposes, but also to maintain high levels of defense spending. Should the war in Ukraine end without sanctions abatement –– and thus without providing a pathway for economic and patronage flow diversification –– Putin would likely seek alternative venues for mobilization to ensure defense-related patronage flows continue. Likely target states include non-NATO states close to Russia, including Moldova.</p>
        <p>Public- and private-sector entities based in Europe and those with investment in Russia or users there are therefore likely to face a high-risk, unpredictable Russia-nexus cyber, physical, and economic threat environment, as long as sanctions preclude diversification of patronage flows beyond the defense sector.</p>
        <p>As such, political settlement in Ukraine, coupled with sanctions rollbacks and security guarantees for Ukraine and other non-NATO states close to Russia, such as Moldova, likely would raise the cost of starting a conflict elsewhere while providing Putin with a pathway to diversify his elites’ patronage flows, thereby reducing his incentive to fund Russia’s patronage networks via mobilization.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>Since the 2022 invasion of Ukraine, Russia’s economy has become increasingly dependent on military spending, with defense expenditures reaching an estimated 7.2% of GDP and 32% of the federal budget by 2025.</li>
          <li>The military-industrial complex now employs approximately 3.5 million Russians, accounting for roughly 5% of the total labor force, while the production of civilian goods, such as cars and home appliances, has stagnated or declined.</li>
          <li>Systematic Western sanctions have limited the avenues Russian elites have to accumulate illicit wealth, forcing Russian political and business elites to rely increasingly on defense contracts for patronage and graft.</li>
          <li>As a decrease in defense spending would likely reduce the patronage flows necessary to maintain elite loyalty and domestic stability, Putin is likely incentivized to maintain high levels of military mobilization, even if the war in Ukraine were to end.</li>
          <li>Putin’s likely domestic political motivation to maintain military mobilization –– whether in Ukraine or elsewhere –– means that dissuading Putin from pursuing further interventions abroad likely would require not only negotiating a peace in Ukraine and providing security guarantees for Kyiv, but also alleviating sanctions on Russia, thereby providing Putin a pathway to diversify the sources of elite patronage</li>
        </ul>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_19a85845f30901e501173e8e946d48fb5ee1752cf.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[May 2026 CVE Landscape]]></title>
            <link>https://www.recordedfuture.com/jp/blog/may-2026-cve-landscape</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/may-2026-cve-landscape</guid>
            <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[In May 2026, Insikt Group® identified 41 high-impact vulnerabilities that should be prioritized for remediation, all of which had a Very Critical Recorded Future Risk Score. This represents a 11% increase from last month.]]></description>
            <content:encoded><![CDATA[
        <p>In May 2026, <a href="https://www.recordedfuture.com/jp/research/insikt-group">Insikt Group®</a> identified <strong>41 high-impact vulnerabilities that should be prioritized for remediation</strong>, all of which had a Very Critical Recorded Future Risk Score. This represents an 11% increase from last month.</p>
        <p>These vulnerabilities affected products from 20 vendors. 21 of the 41 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 19 were surfaced through honeypot data, and one was reported by a cybersecurity vendor.</p>
        <p>The 41 vulnerabilities in this report affected products from 20 vendors. Vercel accounted for approximately 27% of the vulnerabilities, driven by honeypot-sourced Next.js activity. The remaining exposure was concentrated across a range of enterprise software, security, networking, developer tooling, and cloud-related products.</p>
        <h2>Quick Reference: May 2026 Vulnerability Table</h2>
        <p><em>All 22 vulnerabilities below were actively exploited in May 2026. This table does not include the 19 CVEs associated with honeypot activity, which are available to Recorded Future customers via the CVE Monthly Report. The table below also provides examples of public PoCs identified by Insikt Group®. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.</em></p>
        <div>
          <div>
            <div><strong>#</strong></div>
            <div><strong>Vulnerability</strong></div>
            <div><strong>Risk</strong><br /><strong>Score</strong></div>
            <div><strong>Vendor/Product</strong></div>
            <div><strong>KEV</strong></div>
            <div><strong>Malware Analysis</strong></div>
            <div><strong>RCE</strong></div>
            <div><strong>PoC</strong></div>
          </div>
          <div>
            <div>1</div>
            <div>CVE-2008-4250</div>
            <div>99</div>
            <div>Microsoft Windows</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://www.exploit-db.com/exploits/7132">✓ Link</a></div>
          </div>
          <div>
            <div>2</div>
            <div>CVE-2009-1537</div>
            <div>99</div>
            <div>Microsoft DirectX</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>3</div>
            <div>CVE-2009-3459</div>
            <div>99</div>
            <div>Adobe Acrobat and Reader</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>4</div>
            <div>CVE-2010-0249</div>
            <div>99</div>
            <div>Microsoft Internet Explorer</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="http://www.exploit-db.com/exploits/11167">✓ Link</a></div>
          </div>
          <div>
            <div>5</div>
            <div>CVE-2010-0806</div>
            <div>99</div>
            <div>Microsoft Internet Explorer</div>
            <div>✓</div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>6</div>
            <div>CVE-2025-34291</div>
            <div>99</div>
            <div>Langflow</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai-agent-workflow-platform">✓ Link</a></div>
          </div>
          <div>
            <div>7</div>
            <div>CVE-2026-0257</div>
            <div>99</div>
            <div>Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-0257&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>8</div>
            <div>CVE-2026-0300</div>
            <div>99</div>
            <div>Palo Alto Networks PAN-OS, Cloud NGFW, Prisma Access</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-0300&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>9</div>
            <div>CVE-2026-20182</div>
            <div>99</div>
            <div>Cisco Catalyst SD-WAN and SD-WAN Manager</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-20182&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>10</div>
            <div>CVE-2026-31431</div>
            <div>99</div>
            <div>Linux Kernel</div>
            <div>✓</div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-31431&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>11</div>
            <div>CVE-2026-34926</div>
            <div>99</div>
            <div>Trend Micro Apex One (On-Premise)</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>12</div>
            <div>CVE-2026-41091</div>
            <div>99</div>
            <div>Microsoft Defender</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/0xBlackash/CVE-2026-41091">✓ Link</a></div>
          </div>
          <div>
            <div>13</div>
            <div>CVE-2026-42208</div>
            <div>99</div>
            <div>BerriAI LiteLLM</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-42208&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>14</div>
            <div>CVE-2026-42897</div>
            <div>99</div>
            <div>Microsoft Exchange Server</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/atiilla/CVE-2026-42897">✓ Link</a></div>
          </div>
          <div>
            <div>15</div>
            <div>CVE-2026-45321</div>
            <div>99</div>
            <div>TanStack (Multiple Packages)</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-45321&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>16</div>
            <div>CVE-2026-45498</div>
            <div>99</div>
            <div>Microsoft Defender</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>17</div>
            <div>CVE-2026-48027</div>
            <div>99</div>
            <div>Nx Console</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>18</div>
            <div>CVE-2026-48172</div>
            <div>99</div>
            <div>LiteSpeed cPanel Plugin</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-48172&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>19</div>
            <div>CVE-2026-6973</div>
            <div>99</div>
            <div>Ivanti Endpoint Manager Mobile (EPMM)</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>20</div>
            <div>CVE-2026-8398</div>
            <div>99</div>
            <div>Daemon Tools Lite</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>21</div>
            <div>CVE-2026-9082</div>
            <div>99</div>
            <div>Drupal Core</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-9082&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>22</div>
            <div>CVE-2026-26980</div>
            <div>99</div>
            <div>Ghost CMS</div>
            <div></div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div></div>
            <div><a href="https://github.com/dinosn/ghost-cve-2026-26980">✓ Link</a></div>
          </div>
        </div>
        <p><em><strong>Table 1:</strong></em> <em>List of vulnerabilities that were actively exploited in May, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).</em></p>
        <h2>Key Trends: May 2026</h2>
        <ul>
          <li>In May 2026, threat actors exploited a Ghost CMS vulnerability in large-scale ClickFix and FakeCaptcha poisoning campaigns.
            <ul>
              <li>The campaigns used compromised Ghost CMS websites to inject malicious JavaScript, redirect victims through social engineering lures, and stage dropper and loader payloads from attacker-controlled infrastructure.</li>
            </ul>
          </li>
          <li>12 of the 41 vulnerabilities enabled remote code execution (RCE), affecting products from 8 vendors: Microsoft, Adobe, Langflow, Palo Alto Networks, Apache, openDCIM, Fortinet, and Ivanti.</li>
          <li>Insikt Group identified public proof-of-concept (PoC) exploits for 32 of the 41 vulnerabilities reported this month.</li>
          <li>The most commonly observed flaws this month were CWE-79 (Cross-site Scripting), CWE-506 (Embedded Malicious Code), and CWE-89 (SQL Injection), with three CVEs each.</li>
          <li>5 of the 41 vulnerabilities in this month’s prominent vulnerabilities table were first disclosed between 2008 and 2010, making them at least 15 years old, with the oldest vulnerability being approximately 18 years old.
            <ul>
              <li>This reinforces our finding that attackers continue to exploit long-known weaknesses in environments where patching has lagged.</li>
              <li>Additionally, the fastest observed time from a vulnerability’s public disclosure to exploitation was less than one day.</li>
            </ul>
          </li>
        </ul>
        <h2>Exploitation Analysis</h2>
        <p>This section highlights some of the highest-impact, actively exploited vulnerabilities this month, specifically those linked to known threat actor campaigns or that have public PoC exploits available. Vulnerabilities with no meaningful public technical detail are summarized in the quick reference table above only.</p>
        <h2>Threat Actors Exploit CVE-2026-26980 in Ghost CMS To Conduct Large-Scale ClickFix Poisoning Campaigns, Sample Available From Recorded Future Malware Intelligence</h2>
        <p>On May 21, 2026, cybersecurity firm XLab published a <a href="https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/">technical analysis</a> detailing large-scale ClickFix poisoning campaigns targeting vulnerable Ghost Content Management System (CMS) instances by exploiting CVE-2026-26980. Ghost CMS allows users to create, manage, and publish content for blogs, media sites, newsletters, and subscription-based websites through a node.js-based publishing platform.</p>
        <p>CVE-2026-26980 is a critical SQL injection vulnerability in Ghost CMS that allows unauthenticated threat actors to extract Ghost Admin API Keys and modify website content through the Ghost Admin API.</p>
        <p>As <a href="https://www.recordedfuture.com/jp/research/clickfix-campaigns-targeting-windows-and-macos">previously reported</a> by Insikt Group®, at least two threat groups exploited CVE-2026-26980 to inject malicious JavaScript into more than 700 compromised Ghost CMS websites across industries, including blockchain, artificial intelligence (AI), and financial technology (fintech). According to XLab, the threat actors used the compromised websites to deliver ClickFix and FakeCaptcha social engineering attacks that tricked victims into executing malicious commands and malware payloads on their systems.</p>
        <p>Insikt Group® obtained one of the malicious samples, <code>UtilifySetup.exe</code>, from Recorded Future <a href="https://www.recordedfuture.com/jp/products/threat-intelligence/malware-intelligence">Malware Intelligence</a>. The sample matched the sandbox YARA rule for detecting Inno Setup packaging. Based on sandbox and static code analysis, the sample performs the following actions on a victim’s machine:</p>
        <ul>
          <li>Conducts DLL injection</li>
          <li>Retrieves the system language and geolocation using the Windows registry</li>
          <li>Drops files named <code>UtilifySetup.tmp</code> (SHA256: 7790fd1035266000ed6d6cc35822f7683f5271663af8a5b5effadff85316df6d) and <code>Grape.exe</code></li>
          <li>Enumerates files and directories</li>
          <li>Retrieves system information</li>
          <li>Delays execution using the Sleep API function for evasion</li>
          <li>Detects debuggers using the <code>GetTickCount</code> API function to compare the timing and the <code>IsDebuggerPresent</code> API function</li>
          <li>Creates a file inside the <code>C:\Users\user\AppData\Local\SuperMaxionQuickMaxlite</code> directory, corroborating XLab’s analysis</li>
          <li>Terminates running processes</li>
        </ul>
        <p>Sandbox analysis categorized <code>UtilifySetup.tmp</code> as malicious due to the sample exhibiting discovery capabilities. Based on sandbox and static code analysis, the sample performs the following actions on a victim’s machine:</p>
        <ul>
          <li>Conducts DLL injection</li>
          <li>Retrieves the system language and geolocation using the Windows registry</li>
          <li>Executes <code>UtilifySetup.exe</code> installer from the <code>%Temp%</code> directory using internal Inno Setup /SL5 launch parameters</li>
          <li>Executes a file named <code>Grape.exe</code> inside the <code>C:\Users\user\AppData\Local\SuperMaxionQuickMaxlite</code> directory</li>
        </ul>
        <p>Once executed, <code>Grape.exe</code> performs the following actions on a victim’s machine:</p>
        <ul>
          <li>Adds a Windows registry Run key entry named <code>electron.app.Grape</code> set to execute itself when the victim logs in</li>
          <li>Enumerates running processes</li>
          <li>Sends DNS request to <code>web-telegram[.]ug</code></li>
        </ul>
        <p>Further technical details associated with this activity, including sample analysis, MITRE ATT&amp;CK techniques, and IoCs, are available to Recorded Future customers via Insikt Group® reporting.</p>
        <p>Recorded Future customers can also access <a href="https://www.recordedfuture.com/jp/products/threat-intelligence/malware-intelligence">Malware Intelligence</a> queries that surface samples communicating with campaign-associated URLs, domains, and IP addresses.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1720aa516c85e3e0338c7cc0d81f4ae569e0dce5f.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1095" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em>Risk Rules History from</em> <em><a href="https://www.recordedfuture.com/jp/products/vulnerability-intelligence">Vulnerability Intelligence</a></em> <em>Card® for CVE-2026-26980 in Recorded Future (Source: Recorded Future)</em></div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1239191713c0e7359a6e3e0dd047fe76e065dcc92.jpg?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Why Holistic Sourcing Wins: The Numbers Behind the Recorded Future Advantage]]></title>
            <link>https://www.recordedfuture.com/jp/blog/recorded-future-holistic-sourcing-wins</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/recorded-future-holistic-sourcing-wins</guid>
            <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Recorded Future’s Intelligence Graph® uses holistic sourcing across 1M+ sources for complete threat intelligence and proactive defense.]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>Threats don't operate in silos, and neither should your intelligence. This post, the first in a three-part series, breaks down why comprehensive sourcing is the foundation of effective threat intelligence -- and how Recorded Future's Intelligence Graph® monitors over one million sources across technical, criminal, collective, and open-source domains to surface what narrow or siloed solutions miss. From nation-state TTPs to criminal infrastructure to credential leaks, complete coverage is what separates awareness from action.</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1c33725653d37008dda6f111b94b468e5a9197eb5.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Threats to the 2026 FIFA World Cup]]></title>
            <link>https://www.recordedfuture.com/jp/research/2026-fifa-world-cup-threats</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/2026-fifa-world-cup-threats</guid>
            <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Threat assessment for the 2026 FIFA World Cup (US, Mexico, Canada) covering organized crime, AI-powered cyber fraud, state espionage, and political influence operations.]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>The 2026 FIFA World Cup, which takes place across sixteen host cities in the United States (US), Mexico, and Canada, presents a complex threat environment across multiple security domains. The tournament’s global visibility creates opportunities for both financially and geopolitically motivated threat actors to target attendees, affiliated organizations, sponsors, vendors, and event-supporting infrastructure.</p>
        <p>Physical security will almost certainly remain the highest priority for event coordinators and local government officials, given the high levels of international attention and the concentration of large crowds in host cities spanning three countries and multiple, distinct security environments. Mexico’s host cities face the highest physical risk due to the persistent presence of local and transnational criminal organizations (TCOs), with elevated concerns around theft, extortion, kidnapping, and fraud. US and Canadian host cities likely face a more limited threat from violent extremists, with greater risks to soft targets such as fan zones, watch parties, transit hubs, and other crowded public areas.</p>
        <p>Civil unrest and disruptive protests are also very likely in a majority of host cities. Localized travel disruptions are especially likely in Mexico, where prior demonstrations have already blocked roads near World Cup venues. Large police or military deployments near event sites will likely increase the risk of confrontation.</p>
        <p>The most immediate risk to corporate sponsors and affiliates is likely cybercriminal exploitation of World Cup demand and branding. Recorded Future’s Payment Fraud Intelligence team has already identified World Cup-themed purchase scams, fake FIFA-branded stores, and spoofed FIFA and host city domains. Carders are also likely to leverage stolen payment card credentials to fraudulently purchase event tickets and travel-related services for rapid resale and monetization. Efforts to use individuals’ interest in the World Cup to deliver malware or carry out data extortion or fraud will likely accelerate as the tournament approaches. Threat actors will likely continue to use AI-generated content to scale fraud, impersonation, phishing, smishing, and social engineering campaigns.</p>
        <p>The concentration of senior government officials, diplomats, security personnel, corporate executives, and media at World Cup events also very likely increases the risk of cyber espionage and disruptive cyber incidents. Russian, Chinese, and Iranian state-sponsored threat groups will likely use the tournament as an intelligence collection opportunity, targeting executives, VIP attendees, national delegations, media partners, telecommunications providers, airlines, hotels, event logistics firms, and commercial affiliates. China is most likely to pursue targeted espionage, while Russia and Iran pose a higher risk of more disruptive attacks through proxy hacktivism.</p>
        <p>Influence activity related to the tournament remains largely overt, driven by state media and diplomatic messaging from Russia, China, and Iran. These narratives focus on host-country legitimacy, Iran’s conditional participation, visa and access issues, public safety, immigration, ticketing, and alleged politicization of the event. Covert influence activity has so far been limited and opportunistic, but could increase as the tournament approaches, particularly around geopolitical flashpoints or viral news events.</p>
        <p>Organizations involved in or exposed to the World Cup should prioritize proactive monitoring of location-specific physical security risks, protest activity, cybercriminal infrastructure, phishing and credential exposure, malicious traffic, ransomware indicators, and influence operations. Cyber indicators such as increased scanning activity or newly registered domains linked to FIFA or host cities may indicate an expansion of criminal or espionage activity. Developments around geopolitical flashpoints such as the war in Iran may increase the likelihood of attempts to disrupt the tournament through cyber or physical attacks.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>World Cup crowds will likely elevate physical security risks around match venues and fan areas, exacerbated by factors such as TCO activity in Mexico and impending primary elections and 250th Independence Day celebrations in the US.</li>
          <li>Opportunistic criminal activities tied to organized crime very likely constitute the largest physical security risks to Mexico’s World Cup host cities, while US venues face very likely less substantial (but nonetheless tangible) threats from violent extremists, particularly homegrown violent extremists (HVEs).</li>
          <li>Cybercriminal threat actors are exploiting World Cup-themed branding via purchase scams and phishing infrastructures, with AI-generated content likely enabling operations to surpass volumes observed during prior World Cups. Carders frequently use fraudulent ticket purchases and resale schemes as a rapid monetization method for stolen payment card credentials.</li>
          <li>Russian, Chinese, and Iranian state-sponsored threat groups will likely use the World Cup as an intelligence collection opportunity, while Russia and Iran pose additional risks of disruptive cyber operations, particularly from proxies and hacktivist personas.</li>
          <li>World Cup-related influence activity from Russia, China, and Iran is driven overwhelmingly through overt state media and diplomatic messaging, while observed covert activity remains limited, opportunistic, and largely secondary to broader geopolitical narratives about Iran, host-country legitimacy, and US access and security policies.</li>
        </ul>
        <h2>Country Risk</h2>
        <p>Insikt Group assessed four categories of country-level risk in World Cup host countries: security and crime data; network intrusion activity, which measures Malicious Traffic Analysis events targeting each country; ransomware attacks targeting victims in each country; and data privacy and surveillance-related risks, accessible in the Recorded Future Intelligence Operations Platform as State Surveillance risk. While public reporting indicates declining crime rates in many World Cup host cities, violent crime risks are almost certainly greatest in Mexico; opportunistic crime, such as theft, likely presents the greatest physical security risk in Canadian and US host cities. By comparison, threats to data security and privacy are likely greatest in the US and Canada, given the higher volume of malicious cyber activity targeting US and Canadian entities. Factors complicating the security environment across World Cup host nations include TCO operations in Mexico; 250th anniversary celebrations in the US; and the lead-up to the US midterm elections in November 2026, including summer primary elections.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="A country level security environment chart broken down by Security and Crime, Network Intrusion Activity, Ransomware Targeting and State Surveillance for Canada, Mexico and United States" src="https://www.recordedfuture.com/jp/media_19976375ba1f1f25d1eec0340dc6a783ae956305f.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="913" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1</strong>: Composite Country Risk Scores for Canada, Mexico, and the US (Source: Recorded Future)</div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_1fa682a223635a37c9900e39ae2db21f0dc0fb241.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Remembering Sir Alex Younger]]></title>
            <link>https://www.recordedfuture.com/jp/blog/remembering-sir-alex-younger</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/remembering-sir-alex-younger</guid>
            <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A personal tribute to Sir Alex Younger, former head of MI6, on the friendship, lessons, and clarity he brought to Recorded Future and to those who knew him.]]></description>
            <content:encoded><![CDATA[
        <p>There are moments when you meet a person who you immediately know will have a formative influence on you — a person you will learn from, who you will respect, who you will follow anywhere, who you will listen to, who will be your friend. Sir Alex was just that.</p>
        <p>I was lucky to meet Sir Alex just as he was leaving MI6 in 2020. I traveled to London, having to navigate a few Covid restrictions. I asked him if this would cause problems. He smiled: “It is always better to ask for forgiveness than seek permission,” he said. Immediately I knew that this was someone I would get along with very well.</p>
        <p>The objective was straightforward: I was hoping to recruit him to the Recorded Future board of directors, which we eventually accomplished after significant complications got in the way, once again solved by the previous method.</p>
        <p>Sir Alex joined a Recorded Future board meeting in New York. As I welcomed him, Alex — smiling characteristically — introduced himself as having run the world’s best intelligence agency, a pointed reminder that superb people, tradecraft, and pedigree can rival any scale. And we wanted to learn from the best.</p>
        <p>My assumption, as much as one should not make them, was that Alex could teach us everything in intelligence, except for perhaps around the technical SIGINT-like apparatus that is at the core of Recorded Future. Yet, in our first discussion, talking about “connecting dots,” Alex said, “it is not about connecting dots, it is about connecting entire collections,” which became the very underpinning of how we build our Intelligence Graph®. I was humbled, having underestimated him, and it taught me a valuable lesson.</p>
        <p>Yet, the confidence of having run the world’s best intelligence agency did not at all hold back Alex from asking even the most basic questions. Coming from public service, driving revenue was not a familiar concept. As opposed to most senior characters who would do anything to not seem to have all the answers, Alex, early in the first meeting, when hearing the terms ARR and revenue, raised his hand and said, “please explain annualized revenue.” That is the sign of somebody who always wanted to learn and would not let pride get in the way of gaining insights.</p>
        <p>Sir Alex brought great moral clarity, yet not the kind that is based on anger, “you’re either with us or against us,” rather, the kind that leads to an alliance of peers sharing in values that can defeat any autocratic counterpart. Teamwork, he would say, is the unique strength of the West, as we can build on trust, whereas our adversaries fundamentally cannot.</p>
        <p>Speaking at the Recorded Future 2023 Predict conference, our audience spellbound, Sir Alex paraphrased Milton Friedman: “No individual can make a pencil alone.” He was cheered by everyone, and we know that this was the answer to beat our adversaries.</p>
        <p>Over the last few months, I asked Alex for some favors, and I now find myself wondering whether I asked too much of him. He gave a briefing to thousands of Recorded Future clients on Iran with an energy and intellect that would put anyone to shame. And more recently, I asked him for help with a personal endeavour, which in hindsight was too much to ask at the time, yet he did something amazing.</p>
        <p>I can only hope that I can be such a friend to my friends as Alex was to me.</p>
        <p>Six months ago, when Alex was in the midst of treatment, I asked him if I could take him for a special dinner. We enjoyed amazing food and, truth be told, even more amazing wine. I came early to the restaurant and suggested to them, “he may eat and drink a little, please do not make a fuss about that.” Yet, Alex went at the food and wine with a vengeance, claiming that his treatment left him very hungry. If there ever was a fighting spirit, it was his.</p>
        <p>
          <img loading="lazy" alt="Sir Alex and Christoper sitting at a restaurant and a picture of the course menu on the left." src="https://www.recordedfuture.com/jp/media_1a6cd8aa62d35e646745b37cdc6abdbf342d79aa8.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="946" />
        </p>
        <p>Please join my Recorded Future colleagues in our cheers for Sir Alex Younger and thoughts for Sarah and their family.</p>
        <p>I’m certain that he would want us to take the fight to the bad guys and build even greater alliances with our friends.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_11fb4d20a4aa7d0507492273773ba1976b49b62d3.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Iran Expands Handala Brand to Physical Threats]]></title>
            <link>https://www.recordedfuture.com/jp/research/iran-handala-physical-threats</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/iran-handala-physical-threats</guid>
            <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Iran's MOIS expands its Handala brand to hybrid cyber and physical threat operations, recruiting proxies to conduct attacks, espionage, and sabotage against US and Israeli interests]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Iran’s Ministry of Intelligence (MOIS) has likely broadened the use of its “Handala” brand to encompass MOIS’s external physical and influence operations targeting US and Israeli interests. Since the beginning of the Iran War, Insikt Group has observed significant overlaps in the online activities of Handala Hack Team, a newly created, Handala-branded persona referring to itself as the “Handala Popular Resistance Front” (HPRF), and three influence operations networks previously identified by Insikt Group. Based on frequent amplification and cross-posting of claims and content between Handala Hack Team and these four additional entities, we now attribute these groups to MOIS, with varying degrees of confidence.</p>
        <p>The nexus between these personas and MOIS, as well as their multidomain tactics, techniques, and procedures (TTPs) and targeting, likely reflects how MOIS’s external operations have shifted in response to the Iran War. Notably, the HPRF and the three influence operations networks all almost certainly share a modus operandi: their administrators solicit individuals to conduct physical attacks and espionage targeting US and Israeli entities, on behalf of Iranian intelligence agencies, for a financial reward. By encompassing these groups under the Handala brand, MOIS likely seeks to take advantage of Handala’s global recognition to amplify its solicitation efforts.</p>
        <p>MOIS’s likely coordination of distinct cyber, physical, and influence personas under a single brand very likely amplifies physical and cyber threats to targeted individuals and facilities. Handala-linked physical threat actors could almost certainly leverage the recognition of the brand’s hacktivist personas to recruit individuals to conduct targeted violent attacks, espionage, sabotage, or other physical threat activities. Shared resources, intelligence, and coordination efforts from a centralized source likely increase the impact of an attack. This very likely entails heightened risks for US and Israeli law enforcement, military, and intelligence agencies and their personnel, in addition to energy, transportation, and research organizations operating in the region.</p>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_14c4348cdfe3e4e2b574896b502432695b25c37a9.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It.]]></title>
            <link>https://www.recordedfuture.com/jp/blog/vulnerability-board-conversation</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/vulnerability-board-conversation</guid>
            <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Boards are asking about AI-driven vulnerability discovery. The leaders who answer that question well will come out with more credibility and more resources. Here's how to be one of them.]]></description>
            <content:encoded><![CDATA[
        <p>I've had some version of the same conversation dozens of times since Mythos and Daybreak emerged. CISOs want to know how worried they should be. My honest answer: less than the headlines suggest, and more than most programs are currently prepared for.</p>
        <p>Last year, roughly 50,000 software vulnerabilities were disclosed. Recorded Future tracked 446 that were actually <a href="https://www.recordedfuture.com/jp/blog/ai-hype-vs-reality">weaponized by threat actors</a>. That's less than 1%. The problem was never finding vulnerabilities. It was always knowing which ones adversaries will actually use.</p>
        <p>AI makes that distinction harder. Discovery accelerates for everyone, the noise grows faster than any team can manually triage, and the window between a disclosed vulnerability and a working exploit keeps shrinking. Security leaders who've built intelligence-led programs are ready for what's coming. For them, Mythos isn't a crisis. It's the moment their program finally gets the attention it deserves, including in the boardroom.</p>
        <h2>The threat got faster. The fundamentals didn't.</h2>
        <p>The instinct to treat AI-assisted vulnerability discovery as a wholesale transformation of the threat landscape isn't quite right, and that imprecision will hurt you in a board conversation.</p>
        <p>What's changed is speed. AI has compressed the time between a disclosed vulnerability and a working exploit from days to minutes. Your team has to match that tempo.</p>
        <p>What hasn't changed is the fundamental prioritization problem. Disclosed vulnerabilities have more than doubled over the last five years, from roughly 21,000 in 2021 to approximately 50,000 in 2025. That growth happened before AI-assisted discovery became widely accessible. AI makes that challenge faster and more consequential. It doesn't make it new.</p>
        <p>That distinction matters because it changes the conversation from "we need to completely rebuild our security program" to "we need to make sure our intelligence capability is operating at the speed the threat environment now demands." The first conversation is expensive and destabilizing. The second is actionable.</p>
        <h2>Most programs have a triage problem, not a discovery problem</h2>
        <p>When an AI model returns hundreds of new vulnerability findings, the bottleneck shifts immediately to prioritization. In most organizations, that process is still largely manual. Analysts research each finding, assess severity, cross-reference existing guidance, and attempt to sequence a response. At the volume and velocity these models produce, that workflow can’t keep pace.</p>
        <p>The result is a backlog where genuinely critical exposures sit alongside noise, and triage decisions get made without the context needed to get them right. That's not a tooling problem. It's an intelligence problem.</p>
        <p>The organizations handling this well have built a layer between discovery and action that automatically correlates every finding against real-world adversary activity, flags vulnerabilities tied to active campaigns, and tells the analyst what it means and what to do about it, not just what was found. Raw discovery tells you that you have a problem. Intelligence-led response tells you which one to solve first, then hunts it down autonomously at machine speed.</p>
        <p>There's a second exposure worth naming, and it can produce an uncomfortable board conversation. Most enterprise security investment is concentrated on what enters the environment and what executes at the endpoint. AI-assisted discovery surfaces a different category of risk: exposures that already exist inside the environment, in software running on your infrastructure today, in third-party components that weren't fully inventoried, in vendor systems connected to yours in ways that aren't fully mapped.</p>
        <p>Organizations that have concentrated their posture at the edge may find that some of their most consequential vulnerabilities sit somewhere else. That's a hard answer to give a board that just read about Mythos. It's better to surface it yourself than to have someone else surface it for you.</p>
        <h2>The programs that didn't panic had something in common</h2>
        <p>The CISOs I talk to who've been building intelligence-led programs for years have handled Mythos differently than organizations that haven't. They didn't need to rebuild anything from the ground up. They used the moment to sharpen programs they'd already been investing in.</p>
        <p>But not every organization was already there when Mythos was announced, and that's the more important story for most security leaders reading this. The announcement was a forcing function. The organizations that treated it as one are already in a different position than the ones that didn't.</p>
        <p>A financial services customer who came to us shortly after the Mythos announcement is a good example of what moving quickly actually produces. They rebuilt their vulnerability workflow around our automation capability and within two weeks their team had recovered over 20 hours a week that had previously gone to manual triage and research. Those aren't hours saved on busywork. They're hours now going toward work that actually reduces exposure. And when the next wave hits, they won't be caught flat-footed.</p>
        <p>What made that possible wasn't just better tooling. It was an intelligence layer that automatically matches vulnerabilities to known threat actors, ties findings to active campaigns where relevant, and scores on real-world exploitation evidence rather than theoretical severity. Every finding arrives with the context an analyst needs to act, without hours of manual research standing between the signal and a response.</p>
        <p>The practical outcome is coverage at scale without proportionally growing the team. That's what operating at machine speed means in practice, and it can hold up in a board conversation for a simple reason: it's not just a security answer, it's a business one.</p>
        <h2>What wins the board conversation</h2>
        <p>Boards are asking about AI-driven vulnerability discovery because it's broken into mainstream coverage in a way most threat developments haven't. That attention isn't going away. Security leaders who can walk into that conversation with a clear, specific answer about how they're managing the risk will come out with more credibility and more resource authority.</p>
        <p>Mythos and Daybreak are the start of a longer trend. The right response isn't to treat each new model as a fresh crisis. It's to build the intelligence foundation that makes your program resilient regardless of what comes next. When you've done that, AI-assisted discovery stops being a source of anxiety and becomes what it should be: a faster path to finding and fixing what actually matters.</p>
        <p><em>Ready to go deeper on the operational response? Recorded Future Chief Product Officer Jamie Zajac lays out the full playbook</em> <em><a href="https://www.recordedfuture.com/jp/blog/ai-vulnerability-playbook">here</a>.</em></p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_17d0cb439a585bf962b1a79093d5c706376b68404.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026]]></title>
            <link>https://www.recordedfuture.com/jp/blog/ai-vulnerability-playbook</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/ai-vulnerability-playbook</guid>
            <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Frontier AI models like Mythos are making vulnerability discovery fast and cheap. Here's how defenders use threat intelligence and agentic processing to prioritize and act at the same speed.]]></description>
            <content:encoded><![CDATA[
        <h2>Key Takeaways</h2>
        <ul>
          <li><strong>Discovery has been commoditized.</strong> Frontier AI models like Mythos and GPT 5.5 are making vulnerability discovery cheap, fast, and broadly accessible.</li>
          <li><strong>The defender's job is to match the speed.</strong> Manual triage has lost the throughput race.</li>
          <li><strong>Threat intelligence is the prioritization layer at machine speed.</strong> Recorded Future Intelligence observed only 446 actively exploited CVEs in 2025 against approximately 50,000 disclosed — less than 1%.</li>
          <li><strong>Recorded Future's agentic processing plus Autonomous Threat Operations can be the answer.</strong> It offers detection signatures in just 31 minutes and automated action across more than 100 integrations, with third-party reach coming soon. Attackers are operating at this speed. Your defenses have to match them.</li>
        </ul>
        <p>It’s now a question I get daily: “What is Recorded Future doing about Mythos?”</p>
        <p>It's a fair question. Anthropic's Project Glasswing announcement, paired with the vulnerability research benchmarks coming out of OpenAI's GPT 5.5, has made AI-driven vulnerability discovery a board-level topic in a matter of weeks.</p>
        <p>To answer that question, first we need to discuss the operational problem defenders actually face and why <a href="https://www.recordedfuture.com/jp/threat-intelligence">threat intelligence</a> can be the best way to counter it at machine speed. Then we'll get into what Recorded Future is already deploying to solve it: our agentic processing.</p>
        <h2>The problem: drowning in signal, starving for context</h2>
        <p>Even before AI and the news of Mythos’ capabilities and speed, defenders were struggling. Signal volume was outpacing analyst capacity. Coverage gaps widened daily as long-tail vendors and niche platforms went unmonitored. Raw findings arrived without root cause, threat-actor relevance, or vetted remediation paths. Producing one analyst-grade enrichment took hours of senior researcher time. The math didn't work at enterprise scale.</p>
        <h2>The reality check: 50,000 disclosed, 446 actually exploited</h2>
        <p>The data point that should anchor any conversation about the AI vulnerability surge: The NVD disclosed approximately 50,000 CVEs in 2025. Recorded Future Intelligence observed only 446 actively exploited in the wild — <a href="https://www.recordedfuture.com/jp/blog/ai-hype-vs-reality">less than 1%</a>.</p>
        <p>Finding vulnerabilities is one thing, but knowing which ones matter, to which environments, against which adversaries, and with which compensating controls already in place is a whole different matter. <a href="https://www.forrester.com/blogs/project-glasswing-shows-that-ai-will-break-the-vulnerability-management-playbook/">Forrester put it directly</a>: “<em>The limiting factor in security is no longer the ability and knowledge to find problems — it's the ability to absorb, prioritize, and act on them before adversaries do.”</em> The bottleneck has always been on the absorb-prioritize-act side. The find side was never the problem.</p>
        <p>Frontier AI models accelerate the finding side. Threat intelligence is what helps close the prioritization gap on the fixing side.</p>
        <h2>The prioritization filter: what turns 50,000 into 446</h2>
        <p>Threat intelligence is operational, not philosophical. It comes down to four signals that distinguish the small fraction of CVEs adversaries actually weaponize from the overwhelming majority that they don't. These four signals are non-negotiable to be able to get to the prioritizing at speed and scale:</p>
        <ol>
          <li><strong>A live risk score.</strong> A composite index of exploitation likelihood and impact, recalculated continuously as evidence shifts. Not a static CVSS rating; a live measure of which vulnerabilities are weaponizable, exploitable in modern environments, and likely to be picked up by threat actors.</li>
          <li><strong>Active exploitation in the wild.</strong> Observed exploitation evidence — not theoretical PoC availability, but documented use against real systems by real actors. Sources include open and dark web telemetry, vendor disclosures, government advisories (CISA KEV catalog and equivalents), and primary research like what Insikt Group® produces.</li>
          <li><strong>Ransomware actor association.</strong> Mapping CVEs to specific ransomware operators and access broker activity. The same vulnerability used by a financially motivated ransomware affiliate against your sector is a different incident than the same CVE in a state-actor toolkit targeting a different region.</li>
          <li><strong>Sector and campaign targeting.</strong> Which threat actors are targeting your industry, which TTPs they're using, which exposures map to known tooling.</li>
        </ol>
        <p>Together, these four signals are how you prioritize what actually matters for any given defender.</p>
        <h2>Recorded Future's answer: agentic processing plus Autonomous Threat Operations</h2>
        <p>If attackers are moving at Mythos speed, your defenses need to keep up using agentic processing and Autonomous Threat Operations. This is my answer to the question we started with about what Recorded Future is doing about the new world we live in.</p>
        <p>Agentic processing is the production system that turns exposure signals into deployable intelligence. The pipeline reads descriptions, vendor advisories, and patch diffs the moment they appear. It produces production-ready detection signatures — documented detection logic, evidence specification, passive fingerprinting strategy. It writes analyst-grade enrichment for every finding — root cause, exploit mechanics, threat-actor associations, prioritized defensive controls with deploy-time and false-positive estimates, validated remediation tasks with acceptance criteria and rollback plans.</p>
        <p>It’s end-to-end target: identification to deployment in customer environments in only 31 minutes. Internal averages run lower. No security team operating manual triage workflows is matching that throughput.</p>
        <p>That content can reach every relevant control point in your environment through <a href="https://www.recordedfuture.com/jp/products/autonomous-threat-operations">Autonomous Threat Operations (ATO)</a>.</p>
        <p>ATO turns agentic-processing outputs and correlated intelligence into operational action across over 100 integrations spanning SIEM, SOAR, EDR/XDR, NGFW, vulnerability management, threat intelligence platforms, identity and access management, email and cloud security, GRC, and threat-informed defense. It continuously deploys priority intelligence, runs autonomous threat hunts, pushes detection rules, and takes preventive action without analyst hours spent on manual correlation. The 8-to-12 hours of weekly correlation work most analyst teams perform manually is almost entirely eliminated. The hunting cadence becomes 24/7.</p>
        <p>Soon, ATO will do this across your attack surface and third parties, as vendor exposure has been the most common path to breach for the past three years.</p>
        <p>The five-stage pipeline that produces all of this — threat signals, intelligent enrichment, validation and verification, structured output, and customer workflow — runs continuously. Production-ready content is in customer environments within minutes of the originating disclosure across every category of threat the platform detects.</p>
        <h2>Why agentic processing is different, and why your organization needs it</h2>
        <p>Four things distinguish agentic processing from anything a security team can build manually:</p>
        <ol>
          <li><strong>Hours → minutes.</strong> A complete enriched finding can be produced in minutes, not the hours of manual research the same output used to require.</li>
          <li><strong>Order-of-magnitude efficiency.</strong> Based on Recorded Future R&amp;D findings, per-vulnerability triage runs at 40x the efficiency of manual research effort, enabling coverage at scale your team cannot achieve by hand.</li>
          <li><strong>Long-tail coverage.</strong> Localized vendors, niche platforms, and legacy systems become economically viable to cover at breadth.</li>
          <li><strong>Always current.</strong> Continuous refresh cycles keep intelligence accurate as threats evolve.</li>
        </ol>
        <p>These benefits represent the difference between preventing threats pre-attack and absorbing the damage after.</p>
        <p>Let’s look at an example of what agentic processing does at machine speed.</p>
        <h2>React2Shell with agentic processing</h2>
        <p>Take <a href="https://www.recordedfuture.com/jp/blog/december-2025-cve-landscape">CVE-2025-55182</a> — React2Shell, a pre-authentication remote code execution vulnerability in React Server Components. Within minutes of disclosure, agentic processing produced:</p>
        <ol>
          <li>An Attack Surface Intelligence (ASI) detection signature with documented detection logic, evidence specification, and passive fingerprinting strategy</li>
          <li>Root cause and exploit mechanics down to the specific code path</li>
          <li>Active campaigns, threat-actor associations, observed exploitation evidence</li>
          <li>Confidence-graded indicators of compromise with detection commands</li>
          <li>Prioritized defensive controls with deploy-time and false-positive estimates</li>
          <li>Manual validation procedures, remediation tasks with acceptance criteria and rollback plans, and post-remediation verification commands</li>
        </ol>
        <p>In this new Mythos age, this type of agentic processing and speed is going to be required as the new baseline.</p>
        <h2>Beyond vulnerabilities: the same playbook generalizes</h2>
        <p>Vulnerability disclosure is the most visible trigger for the intelligence-at-speed pattern, but it isn't the only one. The same operational logic applies wherever a new threat signal surfaces and a defender needs to act on it before the adversary monetizes it.</p>
        <p>When a brand impersonation site is stood up, the defensive sequence is the same: detection, intelligence enrichment (registrant, registrar, hosting infrastructure, historical campaign association), prioritized defensive controls (takedown coordination, blocking at email and web layers, alerting affected employees), and verification that the takedown landed. Recorded Future's Digital Risk Protection runs this loop continuously across the open, deep, and dark web.</p>
        <p>When a stolen credential surfaces in an infostealer log market, Identity Intelligence runs the same pattern: detection of credentials tied to your environment, enrichment with infection context (malware family, device, other credentials in the same log, MFA cookie capture status), prioritized response (force password reset, revoke active sessions, alert the user), and verification.</p>
        <p>The pattern is the posture. Apply intelligence at machine speed wherever the adversary is acting, across every category of threat surface. Vulnerabilities are one trigger. The work generalizes. Recorded Future is operationalizing intelligence at machine speed across our four solutions, <a href="https://www.recordedfuture.com/jp/products/cyber-operations">Cyber Operations</a>, <a href="https://www.recordedfuture.com/jp/use-case/digital-risk">Digital Risk Protection</a>, <a href="https://www.recordedfuture.com/jp/products/third-party-intelligence">Third-Party Risk</a>, and <a href="https://www.recordedfuture.com/jp/products/payment-fraud-intelligence">Payment Fraud Intelligence</a>.</p>
        <h2>What this means for defenders</h2>
        <p>The operational response to AI-driven vulnerability discovery is what separates organizations that contain exposures from those that wake up to incident response calls.</p>
        <p>We are seeing customers set up automation to move faster in response to this new reality. A large enterprise in the financial services sector used Recorded Future to transform their vulnerability management workflow. Following a major patching effort across the organization, the team built out automation between their vulnerability scanning and IT service management tools. The result: a streamlined, repeatable process and an estimated weekly time savings of over 20 hours for the team.</p>
        <p>We recommend taking these five actions so you can respond as well:</p>
        <ol>
          <li><strong>Move to autonomous intelligence-led security.</strong> Asset inventories are no longer sufficient without knowing if a vulnerability exists, if it is a priority, and what the blast radius is.</li>
          <li><strong>Compress your disclosure-to-detection cycle to minutes.</strong> Manual signature creation runs in days. Adversaries are moving in hours. Whatever your current cycle time, halving it is now baseline.</li>
          <li><strong>Demand intelligence-led prioritization, not severity scores.</strong> CVSS and EPSS describe the universe of vulnerabilities, not which ones are being weaponized against your sector this quarter. Threat intelligence helps you prioritize.</li>
          <li><strong>Action across the full stack, not just the endpoint.</strong> AI-driven discovery surfaces flaws in app code, kernels, libraries, and cloud configurations. Defensive response requires reaching wherever the attacker might use the bug.</li>
          <li><strong>Apply the same posture across all four threat surfaces.</strong> Cyber Operations, Digital Risk Protection, Third-Party Risk, and Payment Fraud all face the same AI-augmented attacker clock speed.</li>
        </ol>
        <p>AI-driven vulnerability discovery is here. The big question is whether your systems can operate at attacker speed, with a depth of intelligence that survives executive scrutiny. If the answer isn’t a confident yes, then Mythos and the category behind it have already shifted the math against you.</p>
        <p><strong>See it in production.</strong> <a href="https://www.recordedfuture.com/jp/get-started">Request a demo</a> to see Recorded Future Intelligence and Autonomous Threat Operations turn a vulnerability disclosure into deployable detection and action across your stack within minutes.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_10e10999bf1cb32b3906e06bc966c422681896652.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[April 2026 CVE Landscape]]></title>
            <link>https://www.recordedfuture.com/jp/blog/april-cve-landscape</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/april-cve-landscape</guid>
            <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[In April 2026, Insikt Group® identified 37 high-impact vulnerabilities that should be prioritized for remediation, 35 of which had a Very Critical Recorded Future Risk Score. This represents a 19% increase from last month.]]></description>
            <content:encoded><![CDATA[
        <p>In April 2026, <a href="https://www.recordedfuture.com/jp/research/insikt-group">Insikt Group®</a> identified <strong>37 high-impact vulnerabilities that should be prioritized for remediation</strong>, 35 of which had a Very Critical Recorded Future Risk Score. This represents a 19% increase from last month.</p>
        <p>31 of the 37 were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, and six were surfaced only through honeypot data. Those six CVEs associated with honeypots are available only to Recorded Future customers.</p>
        <p>Those 37 vulnerabilities affected products from 23 vendors. Microsoft accounted for approximately 22%, while the remaining exposure was concentrated across a range of enterprise-facing vendors, particularly security and systems management tools, collaboration and server platforms, developer and application-delivery software, remote support tools, and network-edge infrastructure.</p>
        <p>In April, Insikt Group created Nuclei templates for the missing authentication vulnerabilities in Nginx UI (CVE-2026-33032) and Marimo (CVE-2026-39987). These Nuclei templates are available to Recorded Future customers.</p>
        <h2>Quick Reference: April 2026 Vulnerability Table</h2>
        <p><em>All 31 vulnerabilities below were actively exploited in April 2026. This table does not include the 6 CVEs associated with honeypot activity. The table below also provides examples of public PoCs identified by Insikt Group®. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.</em></p>
        <div>
          <div>
            <div><strong>#</strong></div>
            <div><strong>Vulnerability</strong></div>
            <div><strong>Risk</strong><br /><strong>Score</strong></div>
            <div><strong>Vendor/Product</strong></div>
            <div><strong>KEV</strong></div>
            <div><strong>Malware Analysis</strong></div>
            <div><strong>RCE</strong></div>
            <div><strong>PoC</strong></div>
          </div>
          <div>
            <div>1</div>
            <div>CVE-2009-0238</div>
            <div>99</div>
            <div>Microsoft Office Excel, Excel Viewer, Office Compatibility Pack, Office</div>
            <div>✓</div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>2</div>
            <div>CVE-2012-1854</div>
            <div>99</div>
            <div>Microsoft Office, Visual Basic for Applications</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>3</div>
            <div>CVE-2020-9715</div>
            <div>99</div>
            <div>Adobe Acrobat, Acrobat Reader</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/">✓ Link</a></div>
          </div>
          <div>
            <div>4</div>
            <div>CVE-2023-21529</div>
            <div>99</div>
            <div>Microsoft Exchange Server</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>5</div>
            <div>CVE-2023-27351</div>
            <div>99</div>
            <div>PaperCut NG, MF</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>6</div>
            <div>CVE-2023-36424</div>
            <div>99</div>
            <div>Microsoft Windows Server</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/zerozenxlabs/CVE-2023-36424">✓ Link</a></div>
          </div>
          <div>
            <div>7</div>
            <div>CVE-2024-1708</div>
            <div>99</div>
            <div>ConnectWise ScreenConnect</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass">✓ Link</a></div>
          </div>
          <div>
            <div>8</div>
            <div>CVE-2024-27199</div>
            <div>99</div>
            <div>JetBrains TeamCity On-Premises</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2024-27199&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>9</div>
            <div>CVE-2024-57726</div>
            <div>99</div>
            <div>SimpleHelp remote support software</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>10</div>
            <div>CVE-2024-57728</div>
            <div>99</div>
            <div>SimpleHelp remote support software</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>11</div>
            <div>CVE-2024-7399</div>
            <div>99</div>
            <div>Samsung MagicINFO Server</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/davidxbors/CVE-2024-7399-POC">✓ Link</a></div>
          </div>
          <div>
            <div>12</div>
            <div>CVE-2025-2749</div>
            <div>99</div>
            <div>Kentico Xperience</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms/">✓ Link</a></div>
          </div>
          <div>
            <div>13</div>
            <div>CVE-2025-29635</div>
            <div>99</div>
            <div>D-Link DIR-823X</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div></div>
          </div>
          <div>
            <div>14</div>
            <div>CVE-2025-32975</div>
            <div>99</div>
            <div>Quest KACE Systems Management Appliance</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>15</div>
            <div>CVE-2025-48700</div>
            <div>99</div>
            <div>Synacor Zimbra Collaboration Suite (ZCS)</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>16</div>
            <div>CVE-2025-60710</div>
            <div>99</div>
            <div>Windows Server Host Process for Windows Tasks</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2025-60710&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>17</div>
            <div>CVE-2026-1340</div>
            <div>99</div>
            <div>Ivanti Endpoint Manager Mobile</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-1340&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>18</div>
            <div>CVE-2026-20122</div>
            <div>99</div>
            <div>Cisco Catalyst SD-WAN Manager</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>19</div>
            <div>CVE-2026-20128</div>
            <div>99</div>
            <div>Cisco Catalyst SD-WAN Manager</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>20</div>
            <div>CVE-2026-20133</div>
            <div>99</div>
            <div>Cisco Catalyst SD-WAN Manager</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div></div>
          </div>
          <div>
            <div>21</div>
            <div>CVE-2026-21643</div>
            <div>99</div>
            <div>Fortinet FortiClient EMS</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-21643&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>22</div>
            <div>CVE-2026-32201</div>
            <div>99</div>
            <div>Microsoft SharePoint Server</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/B1tBit/CVE-2026-32201-exploit">✓ Link</a></div>
          </div>
          <div>
            <div>23</div>
            <div>CVE-2026-32202</div>
            <div>99</div>
            <div>Windows Shell</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-32202&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>24</div>
            <div>CVE-2026-33825</div>
            <div>99</div>
            <div>Microsoft Defender</div>
            <div>✓</div>
            <div>
              <p>✓</p>
              <p>(available to Recorded Future Customers)</p>
            </div>
            <div></div>
            <div><a href="https://github.com/search?q=CVE-2026-33825&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>25</div>
            <div>CVE-2026-34197</div>
            <div>99</div>
            <div>Apache ActiveMQ, ActiveMQ Broker</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-34197&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>26</div>
            <div>CVE-2026-34621</div>
            <div>99</div>
            <div>Adobe Acrobat, Acrobat Reader</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-34621&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>27</div>
            <div>CVE-2026-35616</div>
            <div>99</div>
            <div>Fortinet FortiClient EMS</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-35616&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>28</div>
            <div>CVE-2026-39987</div>
            <div>99</div>
            <div>Marimo</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-39987&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>29</div>
            <div>CVE-2026-41940</div>
            <div>99</div>
            <div>cPanel, WHM, WP Squared</div>
            <div>✓</div>
            <div></div>
            <div></div>
            <div><a href="https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py">✓ Link</a></div>
          </div>
          <div>
            <div>30</div>
            <div>CVE-2026-3502</div>
            <div>89</div>
            <div>TrueConf Client</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-3502&amp;type=repositories">✓ Link</a></div>
          </div>
          <div>
            <div>31</div>
            <div>CVE-2026-5281</div>
            <div>89</div>
            <div>Dawn in Google Chrome</div>
            <div>✓</div>
            <div></div>
            <div>✓</div>
            <div><a href="https://github.com/search?q=CVE-2026-5281&amp;type=repositories">✓ Link</a></div>
          </div>
        </div>
        <p><em><strong>Table 1:</strong></em> <em>List of vulnerabilities that were actively exploited in April based on Recorded Future data (excluding honeypot-sourced CVEs).</em></p>
        <h2>Key Trends: March 2026</h2>
        <ul>
          <li>In April 2026, seven of the 37 vulnerabilities in this report were linked to ransomware activity.
            <ul>
              <li>Six are explicitly tied to Storm-1175's Medusa ransomware operations.</li>
              <li>CISA has also linked CVE-2026-41940 with known ransomware use (Sorry Ransomware, per open source reporting).</li>
              <li>Additionally, threat actors exploited CVE-2024-3721 in TBK DVR devices to deliver the Nexcorium botnet.</li>
            </ul>
          </li>
          <li>Sixteen of the 37 vulnerabilities enabled remote code execution (RCE), affecting products from twelve vendors: Adobe, Apache, D-Link, Fortinet, Google, Ivanti, Kentico, Marimo, Microsoft, SimpleHelp, TrueConf, and Wazuh.</li>
          <li>Insikt Group® identified public proof-of-concept (PoC) exploits for 24 of the 37 vulnerabilities in this report.</li>
          <li>The most commonly observed flaws this month were CWE-22 (Path Traversal), followed by CWE-94 (Code Injection), CWE-20 (Improper Input Validation), and CWE-306 (Missing Authentication for Critical Function).</li>
          <li>Three of the 37 vulnerabilities are at least five years old, with the oldest approximately seventeen years old, reinforcing how attackers continue to exploit long-known weaknesses in environments where patching has lagged. Additionally, the fastest observed time from a vulnerability’s public disclosure to exploitation was two days.</li>
        </ul>
        <h2>Exploitation Analysis</h2>
        <p>This section highlights some of the highest-impact, actively exploited vulnerabilities this month, specifically those linked to known threat actor campaigns, that have public PoC exploits available, or for which Insikt Group® has created Nuclei templates to detect the vulnerability. Vulnerabilities with no meaningful public technical detail are summarized in the disclosures table only.</p>
        <h2>Threat Actors Exploit TBK DVR Vulnerability (CVE-2024-3721) to Deliver Nexcorium</h2>
        <p>On April 17, 2026, FortiGuard Labs (@FortiGuardLabs on X, formerly known as Twitter), associated with Fortinet (@Fortinet), published a <a href="https://www.fortinet.com/blog/threat-research/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign">technical analysis</a> detailing a campaign that exploits TBK Digital Video Recorder (DVR) devices to deliver Nexcorium, a Mirai-based botnet. A TBK DVR device is a surveillance system recorder that captures, stores, and allows playback or remote viewing of video from connected security cameras. According to FortiGuard Labs, Nexcorium targets TBK DVR-4104 and DVR-4216 systems by exploiting CVE-2024-3721, an operating system (OS) command injection vulnerability that allows remote threat actors to execute arbitrary system commands.</p>
        <p>Based on FortiGuard Labs’ analysis, the campaign begins with the exploitation of CVE-2024-3721 through crafted requests that manipulate the <code>mdb</code> and <code>mdc</code> arguments in TBK DVR devices, which delivers a downloader script named <code>dvr</code>. The exploit includes the HTTP header <code>X-Hacked-By</code> with the value <code>Nexus Team - Exploited By Erratic</code>. The <code>dvr</code> script retrieves Nexcorium binaries with filenames beginning with <code>nexuscorp</code> for architectures such as ARM, MIPS R3000, and x86-64. The <code>dvr</code> script then sets the Nexcorium binaries’ permissions to <code>777</code>, and executes them with an argument that identifies the compromised system.</p>
        <p>Further technical details associated with this activity, including sample analysis and IoCs, are available to Recorded Future customers via Insikt Group reporting.</p>
        <p>Recorded Future customers can also access <a href="https://www.recordedfuture.com/jp/products/threat-intelligence/malware-intelligence">Malware Intelligence</a> queries, which surface samples that connect to <em>known network indicators.</em></p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 1: Vulnerability Intelligence Card® for CVE-2024-3721 in Recorded Future" src="https://www.recordedfuture.com/jp/media_11798d7a139f57447a6450de776e335b4a9ca2a24.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1012" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em><a href="https://www.recordedfuture.com/jp/products/vulnerability-intelligence">Vulnerability Intelligence</a></em> <em>Card® for CVE-2024-3721 in Recorded Future (Source: Recorded Future)</em></div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1239191713c0e7359a6e3e0dd047fe76e065dcc92.jpg?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals]]></title>
            <link>https://www.recordedfuture.com/jp/blog/nist-nvd-enrichment</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/nist-nvd-enrichment</guid>
            <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[NVD enrichment now covers only 15–20% of CVEs. Learn how Recorded Future Vulnerability Intelligence prioritizes risk using real attacker behavior signals.]]></description>
            <content:encoded><![CDATA[
        <p>As of April 15, 2026, <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth">NIST</a> enriches only CVEs that appear in the CISA Known Exploited Vulnerabilities catalog, federal government software, or software designated critical under Executive Order 14028. Everything else carries a "Lowest Priority" status: no CVSS score, no affected product mappings, no weakness classification. NIST enriched roughly 42,000 CVEs in 2025, and submissions in early 2026 are running about a third higher year-over-year. Industry <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-nist-nvd-enrichment-policy-change-20260419/">estimates</a> suggest the prioritized categories will cover only 15–20% of anticipated CVE volume going forward.</p>
        <p>For teams whose vulnerability management workflows depend on CVSS scores from NVD, this could create an operational gap. The CVEs in the unenriched backlog can signify real vulnerabilities affecting real software. They don't necessarily stop mattering because NIST didn't get to them.</p>
        <p>Recorded Future does not believe that the solution is to source CVSS scores faster. Instead, Recorded Future endeavors to provide the signals that actually reflect attacker behavior. CVSS was designed to characterize the technical properties of a vulnerability — attack vector, complexity, required privileges, potential impact. <a href="https://www.recordedfuture.com/jp/blog/addressing-the-vulnerability-prioritization-challenge">CVSS was not designed</a> with patch prioritization as a prime concern. This distinction has always existed; the growing gap in NVD enrichment increases the importance of the right intelligence and insights that can capture attacker behavior in real time.</p>
        <h2>Where vulnerability risk actually originates</h2>
        <p>Exploit code surfaces on GitHub. Proof-of-concept development gets discussed in offensive security forums and underground communities. Ransomware operators evaluate which vulnerabilities fit their deployment pipelines. Threat actors incorporate specific CVEs into their toolkits and begin scanning in search of exploitable targets.</p>
        <p>At some point during or after that sequence, a CVE gets assigned and, under the previous policy, would eventually be enriched by NVD. By the time a practitioner sees a CVSS score in their scanner, the risk may already have materialized.</p>
        <p>The delay between attacker use and the assignment of a CVE and CVSS score is not a new dynamic. For this reason, Recorded Future's vulnerability Risk Scores were never built to depend on NVD enrichment.</p>
        <p>The intelligence that determines whether a vulnerability is dangerous originates in the technical communities, underground markets, exploit repositories, and malware ecosystems where attackers work. It does not come from institutional databases processing CVEs up to weeks or months post-assignment. NVD's policy change doesn't create a gap in Recorded Future's coverage because NVD is not the primary signal behind Recorded Future Vulnerability Intelligence.</p>
        <h2>What the model actually weighs</h2>
        <p>Recorded Future's risk scoring maps directly to the <a href="https://www.recordedfuture.com/jp/blog/tracking-the-vulnerability-weaponization-lifecycle">vulnerability weaponization lifecycle</a>. Many of the signals fire based on where a CVE sits on that path, not on what NIST has or hasn't scored.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 1: The vulnerability weaponization lifecycle, as displayed on Recorded Future’s Vulnerability Intelligence dashboard" src="https://www.recordedfuture.com/jp/media_18e7b00a771089f31bd5d71e189e3c85e8ab169fd.png?width=750&amp;format=png&amp;optimize=medium" width="1690" height="540" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1:</strong> The vulnerability weaponization lifecycle, as displayed on Recorded Future’s Vulnerability Intelligence dashboard (Source: Recorded Future).</div>
          </div>
        </div>
        <p>The signals that carry the most weight are those tied to active exploitation in the wild — malware samples observed by Recorded Future's collection infrastructure, ransomware operations validated by Insikt Group® analysts, and other direct evidence of attacker use. Confirmed exploitation activity carries the most weight in the model, regardless of a CVE's CVSS score. These are the signals that answer the question practitioners actually need answered: is someone using this right now?</p>
        <p>Below active exploitation, the model tracks proof-of-concept availability, including the distinction between a verified and unverified PoC. Verified exploit code that demonstrates remote execution is a materially different signal from an unverified proof of concept of unknown reliability. As an example, exploit code on GitHub is not theoretical risk; it usually compresses the time between disclosure and weaponization. Recorded Future Risk Scores treat it accordingly.</p>
        <p>In addition to these collection and analytic capabilities, Recorded Future tracks web reporting about a CVE before NVD has published enrichment data. For the majority of new CVEs going forward, this pre-NVD signal may be the earliest structured intelligence available anywhere. A CVE that NIST has marked Lowest Priority can still accumulate signals across many dimensions. As a result, the absence of a CVSS score in NVD doesn't create a blind spot in Recorded Future's assessment.</p>
        <h2>CVSS still matters. It just isn't the foundation.</h2>
        <p>CVSS scores flow into the model from multiple sources. Many CVE numbering authorities (CNAs) supply CVSS scores at the point of submission, and CVSS coverage across published CVEs <a href="https://jerrygamblin.com/2026/01/01/2025-cve-data-review/">remained above 90% in 2025</a> even as NVD's independent enrichment narrowed. That doesn't mean CNA-supplied scores are interchangeable with NVD's. Academic analyses of dual-scored CVEs have documented <a href="https://dl.acm.org/doi/fullHtml/10.1145/3697090.3697109">divergence rates above 50% throughout the past decade, reaching 70% in 2023</a>, with disagreements sometimes large enough to move a vulnerability across severity tiers. For CVEs where neither NVD nor a CNA has provided scoring, Recorded Future independently assigns scores through its own analysis. CVSS occupies one position in the model, alongside signals grounded in observable attacker behavior, and those signals operate independently of whether a CVSS score exists at all.</p>
        <h2>What to do with this</h2>
        <p>Audit where your prioritization signals come from. If your program is relying entirely or primarily on CVSS scores pulled from NVD, you may have exposure, not just from the existing backlog, but from every new CVE entering the ecosystem under the new policy.</p>
        <p><a href="https://www.recordedfuture.com/jp/products/vulnerability-intelligence">Recorded Future Vulnerability Intelligence</a>, as a part of the <a href="https://www.recordedfuture.com/jp/products/cyber-operations">Cyber Operations</a> solution, scores every CVE against the full signal set — exploitation activity, malware and ransomware associations, proof-of-concept availability, threat actor targeting, and analyst-validated intelligence. All independent of NVD's enrichment pipeline. See this prioritization and automation in action with this click-through <strong><a href="https://play.goconsensus.com/ubf3a3558">tour</a></strong>.</p>
        <p>See how Vulnerability Intelligence integrates with your existing vulnerability management workflow — <a href="https://www.recordedfuture.com/jp/demo">request a demo</a>.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_12365bca04a8a5a9269eace3f5e532561c2ba3ae9.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defense]]></title>
            <link>https://www.recordedfuture.com/jp/blog/ai-intelligence-cyber-defense</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/ai-intelligence-cyber-defense</guid>
            <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The real question in modern cyber defense isn't who has more technology. It's who uses their resources more efficiently. Here's how AI fused with threat intelligence tips that balance.]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Artificial intelligence is often discussed as a tool for automating and accelerating existing cybersecurity workflows. While that framing is accurate, it is incomplete. The most consequential shift occurs when AI is combined with <a href="https://www.recordedfuture.com/jp/products/threat-intelligence">threat intelligence</a> — both intelligence about attacker capabilities and TTPs, and intelligence about our own defensive weaknesses and exposure. This combination produces qualitatively new defensive capabilities that may, for the first time, begin to structurally narrow the long-standing asymmetry between attackers and defenders.</p>
        <p>This memo examines what is genuinely new about AI-enabled defense, with particular emphasis on how the fusion of threat intelligence and AI reasoning changes the strategic calculus. It also argues that in the end, it is a question of who can most efficiently use scarce resources (compute and energy) to get the upper hand. Intelligence guides defenders in how to best use these resources to defend, thereby changing the balance of power against adversaries.</p>
        <h2>The Traditional Defender’s Dilemma</h2>
        <p>The core asymmetry in cybersecurity is well understood: defenders must protect every possible attack surface, while attackers only need to find one exploitable weakness. Defenders operate under constraints — budgets, compliance mandates, uptime requirements — while attackers can be patient, selective, and asymmetric.</p>
        <p>Traditionally, threat intelligence has been consumed by defenders as a feed: indicators of compromise, malware signatures, and published advisories. This intelligence was valuable but largely reactive and disconnected from the defender’s own environment. Knowing that a threat group uses a particular technique is only useful if you can rapidly assess whether that technique works against your infrastructure. That assessment has historically required scarce human expertise, time, and tooling — precisely the resources defenders lack.</p>
        <h2>The Automation Layer: Real But Evolutionary</h2>
        <p>A significant portion of AI’s current impact on defense is best described as automation of existing processes: faster alert triage, automated enrichment, accelerated patch prioritisation, and AI-assisted Tier 1 SOC analysis. These improvements are valuable — they compress response times, reduce analyst fatigue, and address chronic staffing shortages — but they are conceptually extensions of workflows that already existed.</p>
        <p>Similarly, AI can automate the ingestion and normalisation of threat intelligence feeds, reducing the manual work of parsing reports and extracting indicators. This is useful, but it does not change what defenders can fundamentally do with that intelligence. The real transformation lies elsewhere.</p>
        <h2>The Convergence: Where Threat Intelligence Meets AI Reasoning</h2>
        <p>The most significant shift is not AI applied to defense in isolation, nor threat intelligence consumed as a feed. It is the convergence of the two: AI systems that can reason simultaneously over what attackers are doing and what defenders are exposed to, in real time, at scale. This convergence produces capabilities that did not previously exist.</p>
        <h3>1. Connecting Attacker TTPs to Your Actual Exposure</h3>
        <p>Traditionally, a threat intelligence report might tell you that a particular adversary group is exploiting a vulnerability in a specific product, or is targeting your sector using a known technique chain. Acting on that information used to require an analyst to manually map those TTPs against your environment: do we run that product? Is the vulnerable version deployed? Are the relevant network paths open? Are our detection rules adequate for that technique?</p>
        <p>AI can perform this mapping continuously and at scale. When a new threat report lands, an AI system can immediately cross-reference the described TTPs against a live model of your infrastructure, your patching state, your detection coverage, and your segmentation — and surface a prioritised assessment of actual risk, not theoretical risk. This transforms threat intelligence from awareness into actionable, environment-specific defense guidance.</p>
        <h3>2. Fusing Offensive Intelligence With Defensive Weakness Data</h3>
        <p>Defenders have long maintained two separate bodies of knowledge: external threat intelligence (what adversaries are capable of and likely to do) and internal vulnerability and exposure data (what weaknesses exist in our own environment). These have typically lived in different systems, managed by different teams, and reconciled manually and infrequently.</p>
        <p>AI enables continuous fusion of these two streams. A model can hold both the attacker’s perspective — known TTPs, targeting patterns, tooling, and objectives — and the defender’s perspective — unpatched systems, misconfigured controls, overprivileged accounts, and detection gaps — and reason about the intersection. The result is not a vulnerability list or a threat report, but an integrated picture of where the attacker’s capabilities meet our specific weaknesses. This is the analysis that the best red teams produce during an engagement, except it can now run continuously rather than quarterly.</p>
        <h3>3. Predictive Prioritisation Based on Adversary Behaviour</h3>
        <p>Patch prioritisation has traditionally been driven by CVSS scores — a measure of theoretical severity that ignores both attacker intent and environmental context. AI models trained on threat intelligence can reorder priorities based on which vulnerabilities are actually being exploited in the wild, by which adversary groups, against which sectors, using which delivery mechanisms. Combined with internal exposure data, this enables prioritisation that better reflects real-world risk rather than abstract severity.</p>
        <p>The same logic applies to detection engineering. Rather than building detections for every possible technique, AI can identify the techniques most likely to be used against your specific environment — based on who is targeting your sector, what tools they use, and where your coverage gaps are — and focus engineering effort where it matters most. In fact, in most cases AI will be able to build those detectors for you!</p>
        <h3>4. Reasoning Over Context at Scale</h3>
        <p>Traditional detection systems correlate events against rules. AI models can reason about events holistically, synthesising partial logs, ambiguous telemetry, and unusual configuration changes into a judgment that approximates what a senior analyst would conclude. Crucially, this reasoning can be informed by threat intelligence: not just “is this anomalous?” but “is this consistent with the tradecraft of groups known to target us?” That contextual layer makes detection both more accurate and more relevant.</p>
        <h3>5. Continuous Attack-Path Modelling</h3>
        <p>Historically, understanding one’s own exposure was a periodic exercise: run a penetration test, receive a report, remediate, repeat. AI enables a living model of the environment that continuously re-evaluates exploitable paths to critical assets as conditions change. When this model is enriched with threat intelligence — particularly information about which attack paths adversaries actually favour, and which tools they use to traverse them — the result is a dynamic, threat-informed view of exposure that stays up to date automatically, not only when your manual pen testers or red team have time to update it.</p>
        <h3>6. Adversarial Prediction During Active Incidents</h3>
        <p>During an active incident, experienced responders draw on their knowledge of attacker behaviour to anticipate likely next moves. AI models trained on threat intelligence and historical incident data can encode this reasoning and make it available to any response team. If the model recognises that the observed initial access technique and lateral movement pattern are consistent with a known adversary group, it can predict likely next steps — which credentials they will target, which persistence mechanisms they prefer, which data they are likely to exfiltrate — and help defenders get ahead of the intrusion rather than simply reacting to each new indicator.</p>
        <h2>Turning the Tables: AI-Enabled Deception</h2>
        <p>The capabilities described above are fundamentally defensive: detecting, predicting, and prioritising. But the convergence of AI and threat intelligence also opens a qualitatively different category of action — using intelligence about the attacker to actively mislead them.</p>
        <h3>From Static Honeypots to Adaptive Deception</h3>
        <p>Deception technologies such as honeypots and honeytokens have existed for decades, but they have always been constrained by how static and labour-intensive they are to deploy convincingly. A skilled attacker can often identify a honeypot by its lack of realistic activity, stale data, or inconsistencies with the surrounding environment. AI removes these constraints. AI-generated deception environments can include realistic-looking decoy infrastructure — fake services, plausible file shares, synthetic credentials, even simulated user activity patterns — that adapts dynamically in response to attacker behaviour. Rather than a static trap that a competent adversary recognises and avoids, the defender can maintain a deception layer that evolves to stay convincing.</p>
        <h3>Intelligence-Informed Decoy Placement</h3>
        <p>This capability ties directly into the threat intelligence fusion described above. If you know which TTPs a likely adversary uses, which attack paths they favour, and where your real weaknesses are, AI can place decoys precisely along the routes those adversaries are most likely to take. The deception is no longer generic; it is tailored to the specific threat. A decoy credential can mimic the type of service account the adversary’s tooling is known to target. A fake file share can contain documents plausible enough to absorb attacker time and attention, and simultaneously provide new intelligence about the adversary. The threat intelligence that informs your defensive posture simultaneously informs your deception strategy. This is “Machine Counter Intelligence”!</p>
        <h3>Imposing Costs and Eroding Attacker Confidence</h3>
        <p>AI-generated deception at scale inverts a piece of the traditional asymmetry. Attackers who encounter a pervasive deception layer must spend significant time and effort distinguishing real assets from fake ones. Every interaction with a decoy wastes their resources, degrades their confidence in the intelligence they have gathered, and increases the risk that they will trigger an alert. In effect, the attacker now faces a version of the defender’s dilemma: they must verify everything, while the defender only needs one decoy to succeed.</p>
        <h3>Active Intelligence Collection Through Engagement</h3>
        <p>Perhaps most significantly, AI can interact with attackers inside deception environments in ways that feel plausible, drawing out more of their tooling, techniques, and objectives. This turns deception from a passive tripwire into an active intelligence-gathering operation. The tradecraft revealed through these engagements feeds back into the threat intelligence cycle, improving the defender’s understanding of the adversary and refining future defensive and deceptive measures. The result is a virtuous loop: intelligence informs deception, deception generates new intelligence.</p>
        <p>There is an inherent tension in active deception engagement: traditional incident response doctrine prioritises minimising dwell time, while deception-based intelligence collection deliberately extends it. The risks are real — containment failure if the deception boundary isn't airtight, resource cost of sustained monitoring, potential legal and regulatory questions about why an attacker was permitted to remain active, and the possibility that a sophisticated adversary recognises the deception and feeds false signals back to poison your intelligence. These risks do not invalidate the approach, but they define the conditions under which it works. Active engagement requires genuinely isolated deception infrastructure, and clear decision frameworks for when to engage.</p>
        <h2>Democratising Access to Intelligence-Driven Defense</h2>
        <p>A less obvious but structurally significant change is that AI lowers the barrier to performing intelligence-driven defense. When an analyst can query in plain language — “which of our externally-facing systems are vulnerable to techniques used by a certain threat group in the last 90 days?” — and receive an accurate, contextualised answer, the skill requirement for effective threat-informed defense drops substantially. This is not doing an old thing faster; it is enabling a different operating model in which threat intelligence becomes a working tool for the entire security team, not just the analysts who specialise in it.</p>
        <h2>Strategic Implications</h2>
        <p>The most profound implication is that defenders have historically been reactive because they lacked the cognitive bandwidth to continuously fuse offensive intelligence with their own exposure data. AI makes this fusion not only possible but economically viable for organisations that could never previously afford dedicated threat intelligence teams, red teams, and continuous assessment programmes.</p>
        <p>This changes the nature of the defender’s dilemma. The traditional framing — “defenders must protect everything; attackers only need one way in” — assumed that defenders could not know, in real time, which parts of their attack surface are most likely to be targeted. AI-enabled threat intelligence fusion challenges that assumption. If defenders can continuously identify the most probable attack paths based on current adversary behaviour and their own specific weaknesses, they can concentrate resources where they matter most. The dilemma does not disappear, but the defender is no longer operating blindly, but can take control.</p>
        <p>The key asymmetry is therefore shifting from “attacker versus defender” to “AI-augmented versus non-augmented.” Organisations that integrate AI with robust threat intelligence programmes may find themselves closer to parity with attackers than at any point in the history of the field. Those that do not will face an even steeper version of the traditional dilemma, as AI-empowered adversaries exploit the widening gap.</p>
        <h2>Final Words</h2>
        <p>The emergence of fully autonomous AI agents on both sides raises unresolved questions. If attackers deploy autonomous offensive agents that can chain exploits and adapt to defenses without human guidance, defenders will need equally <a href="https://www.recordedfuture.com/jp/products/autonomous-threat-operations">autonomous systems</a> — systems that consume threat intelligence, assess exposure, and act on the results without waiting for human approval. The governance, trust, and control challenges this creates are substantial, but the journey towards this goal must begin now.</p>
        <p>There is also a risk that the intelligence-AI feedback loop becomes adversarial in new ways. Sophisticated attackers who understand that defenders are using AI to map TTPs against exposure may deliberately vary their tradecraft to evade predictive models, or generate false signals to misdirect AI-driven defense. The quality and provenance of threat intelligence will become even more critical as AI amplifies both its value and the consequences of acting on flawed data — we need automation-grade intelligence!</p>
        <p>We have not changed the basic equation: defenders must still know and mitigate every weakness, while the attacker needs only one. AI does not abolish that asymmetry, and claiming otherwise would be dishonest. What AI fused with threat intelligence does is change the terms of the contest. Instead of defending blind — treating every weakness as equally likely to be exploited — defenders can now continuously map attacker capabilities against their own specific exposure, concentrate resources on the paths adversaries actually use, and impose real friction through deception that degrades the attacker's speed advantage. The attacker still only needs one weakness, but they are now searching for it in an environment that fights back: one that predicts where they will look, places convincing traps along those paths, and learns from every encounter.</p>
        <p>The defender may never achieve dominance, but the era of structural helplessness — of knowing that the asymmetry is permanent and unmanageable — is ending for organisations willing to invest in these capabilities. Parity in an adversarial contest is not a consolation prize; it is the condition under which skill, preparation, and operational discipline start to matter more than structural advantage.</p>
        <p>
          <img loading="lazy" alt="Diagram showing how AI-powered Deception Networks flip the defender's dilemma in cyber defense" src="https://www.recordedfuture.com/jp/media_1707d442f02e8e99cfdfd6d19515acdbd873428fc.png?width=750&amp;format=png&amp;optimize=medium" width="1536" height="1024" />
        </p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_13b569c09b60aec5ed3bd7a9827785d349f512d95.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Working in London at the World’s Largest Intelligence Company]]></title>
            <link>https://www.recordedfuture.com/jp/blog/working-for-recorded-future-london</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/working-for-recorded-future-london</guid>
            <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[See what it is like to work at the Recorded Future London office.]]></description>
            <content:encoded><![CDATA[
        <h2>Intro</h2>
        <p>There’s a certain energy you can only find at Recorded Future. Take that energy and bring it to London’s “Silicon Roundabout” and you get the perfect spot for Futurists to build and innovate.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1b4c2914a5020e28b188422104cf064507932f990.png?width=750&amp;format=png&amp;optimize=medium" width="1416" height="942" />
            </div>
          </div>
          <div>
            <div>Recorded Future's office @ The Bower on Old Street. Source: <a href="https://www.theboweroldst.com/">https://www.theboweroldst.com/</a></div>
          </div>
        </div>
        <p>Across the globe, Recorded Future is 1000+ employees working towards the same mission: Securing Our World With Intelligence.</p>
        <p>Our London office – one of our most storied hubs – hosts a range of departments supporting both local, regional, and global operations. The office brings together 100+ cross-functional professionals from People &amp; Talent Acquisition, Finance, Sales, Marketing, Global Services, Research, and more!</p>
        <h2>Looking back: From the Attic to The Bower</h2>
        <p>Our story in London didn’t start in the high-rise, but in a converted attic with just a handful of people and a big mission.</p>
        <div>
          <div>
            <div>When I first joined, we were in the attic of a 3-story building.It was full of great people and energy; the immediate feeling I got was that everyone was building something great together.”</div>
          </div>
          <div>
            <div>
              <p>Joe Rooke</p>
              <p>Director Risk Insights, Insikt Group</p>
            </div>
          </div>
        </div>
        <p>This passion for building something great fueled incredible growth. Sam Pullen, Director of Intelligence Services, remembers when the entire EMEA team was just about 20 people. Since 2018, we’ve gone from service a few dozen customers in the region to ~700 now.</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_10deb562a661affd0c40624252b9254a9984c517e.png?width=750&amp;format=png&amp;optimize=medium" width="1130" height="1500" />
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1d271208d375759d0ff85a24b23becdece7d6bf08.png?width=750&amp;format=png&amp;optimize=medium" width="1130" height="1500" />
        </p>
        <p><strong>On the left</strong>: First Recorded Future office in London. <strong>On the right:</strong> Recorded Future's newest office</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1987f91030d330231b063ab5a5f15c947ad011e5f.png?width=750&amp;format=png&amp;optimize=medium" width="1536" height="2048" />
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_188751864711b193d7a1b99cbd61b292548c6a24a.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="1536" height="2048" />
        </p>
        <p><strong>On the left:</strong> First Recorded Future office in London. <strong>On the right:</strong> Recorded Future's newest office</p>
        <h2>Inside the Office</h2>
        <p>This modern high-rise building’s open-plan layout offers quite a few collaboration spaces across our office, where the team likes to have small team meetings, breaks, or even lunch.</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1002d0e142947532c93a5af8e8f8d572d0ce5a199.png?width=750&amp;format=png&amp;optimize=medium" width="1536" height="2048" />
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_141b3b979302f05f0b823995a79d0fa510ee4f2b3.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="1536" height="2048" />
        </p>
        <p>Like all Recorded Future offices, our meeting rooms follow a unique naming convention. While Boston uses countries, and Sweden volcanoes - London chose islands. Rumors say we picked islands following a 95-day rain streak – we can neither confirm nor deny. So, in our London office, you’ll find Futurists collaborating in rooms like Bora Bora, Crete, and even San Andres.</p>
        <h2>Our Culture</h2>
        <p>What truly defines our London office is the sense of camaraderie – whether that’s competing in a friendly team padel game, testing your dartboard skills, or truly memorable summer &amp; end of year celebrations.</p>
        <div>
          <div>
            <div>The culture at the London office has always been welcoming and inclusive. The BDRs are the soul of the office, and you can always rely on them for a good conversation over a cup of tea.</div>
          </div>
          <div>
            <div>Sam Pullen</div>
          </div>
        </div>
        <p>Whether over summer picnics and pedalos in Hyde Park years, playing 5-a-side football in the pouring rain, or at the most recent Christmas party at the Savoy - our Futurists celebrate wins together.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1681dbbda15a9f6267c8ead7b85d0818eb3cdbc92.png?width=750&amp;format=png&amp;optimize=medium" width="1536" height="2048" />
            </div>
          </div>
          <div>
            <div>
              <h6>Friendly Team Padel Game at Canary Wharf</h6>
            </div>
          </div>
        </div>
        <h2>Onwards &amp; Upwards: Why Recorded Future</h2>
        <p>We asked Sam and Joe what has been the highlight of their long tenure at Recorded Future: the opportunity to build. For Sam, it has been the opportunity to build great relationships with clients over nearly a decade. For Joe, it has been the opportunity to build new solutions and new ways to work towards our mission.</p>
        <div>
          <div>
            <div>The company offers opportunities to builders. If you are willing to take the initiative to make something better, you are not stopped. That is rare.</div>
          </div>
          <div>
            <div>
              <p>Joe Rooke</p>
              <p>Director Risk Insights, Insikt Group</p>
            </div>
          </div>
        </div>
        <p>Ready for your next move? <a href="https://www.recordedfuture.com/jp/work-with-us">Join the team!</a></p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1323d11d2859ec0745253085de01bb1caae51e1c7.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Quantum Risk Explained]]></title>
            <link>https://www.recordedfuture.com/jp/research/quantum-risk-explained</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/quantum-risk-explained</guid>
            <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Learn how the "Harvest Now, Decrypt Later" (HNDL) risk exposes long-lived sensitive data today, regardless of when Cryptographically Relevant Quantum Computers (CRQCs) arrive.]]></description>
            <content:encoded><![CDATA[
        <h2>Summary</h2>
        <ul>
          <li>Quantum computing is moving from theory toward early practical use, with direct implications for encryption, authentication, and long-term data confidentiality.</li>
          <li>The primary risk is the eventual emergence of cryptographically relevant quantum computers (CRQCs), which would break today’s public-key cryptography and undermine encryption, digital identity, and software trust at scale.</li>
          <li>Quantum risk is already present: “harvest now, decrypt later” activity exposes long-lived sensitive data today, regardless of when CRQCs ultimately arrive.</li>
          <li>Regulatory mandates and procurement standards are accelerating post-quantum cryptography (PQC) adoption, making quantum readiness a multi-year compliance and resilience priority.</li>
          <li>Organizations that delay preparation beyond 2026 are likely to face compressed migration timelines, higher transition costs, and increased operational disruption.</li>
        </ul>
        <h2>Quantum Computing Explained</h2>
        <p>Quantum computing applies principles of physics to solve certain complex problems far more efficiently than classical computers. Its security relevance lies primarily in cryptanalysis and optimization: A sufficiently powerful quantum computer will reduce the calculations required to protect today's public-key encryption from thousands of years to hours or less. Researchers have used the term “Q-Day” to refer to the hypothetical point at which quantum computers will be powerful enough to break encryption.</p>
        <p>Quantum computing is now moving from theory toward early practical use, bringing “Q-Day” closer to reality. Industry estimates suggest quantum computing alone could generate up to <a href="https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/quantum-technology-sees-record-investments-progress-on-talent-gap">$1.3 trillion</a> in value by 2035. Major cloud providers, including <a href="https://newsroom.ibm.com/blog-ibm-collaborates-across-four-national-quantum-innovation-centers-to-help-drive-the-future-of-quantum-centric-supercomputing">IBM</a>, <a href="https://blog.google/innovation-and-ai/technology/research/google-willow-quantum-chip/">Google</a>, and <a href="https://azure.microsoft.com/en-us/blog/quantum/2025/02/19/microsoft-unveils-majorana-1-the-worlds-first-quantum-processor-powered-by-topological-qubits/">Microsoft</a>, are expanding their quantum services, while specialised firms such as <a href="https://www.quantinuum.com/blog/quantinuum-nvidia-partnership">Quantinuum</a> and <a href="https://www.psiquantum.com/news-import/inside-construct">PsiQuantum</a> continue to improve system stability and error correction. While these advances are not yet transformative, they are consistent with the early stages of commercial adoption.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 1: Key risks of quantum computing" src="https://www.recordedfuture.com/jp/media_1ff047594639919ef4ac5e248c6a4c0dbaefadde7.png?width=750&amp;format=png&amp;optimize=medium" width="1694" height="684" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em>Key risks of quantum computing (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p>Alongside its potential benefits across <a href="https://www.bis.org/publ/bppdf/bispap149.htm">finance</a>, <a href="https://www.mckinsey.com/industries/life-sciences/our-insights/the-quantum-revolution-in-pharma-faster-smarter-and-more-precise">pharmaceuticals</a>, <a href="https://geopoliticalfutures.com/the-military-benefits-of-quantum-technology/">defense</a>, and other sectors, quantum computing introduces four key security risks.</p>
        <h3>Risk 1: Breaking Public-Key Encryption</h3>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 2: Potential impacts of breaking public-key encryption" src="https://www.recordedfuture.com/jp/media_1cc307e86e38c263825fc4b05767a676b3784d969.png?width=750&amp;format=png&amp;optimize=medium" width="1014" height="862" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 2:</strong></em> <em>Potential impacts of breaking public-key encryption (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p><br />The most critical risk is the eventual <a href="https://www.nist.gov/cybersecurity/what-post-quantum-cryptography">arrival</a> of cryptographically relevant quantum computers (CRQCs), systems <a href="https://qubip.eu/cryptographically-relevant-quantum-computers-a-2025-perspective/">capable</a> of breaking widely used public-key algorithms such as RSA, Elliptic Curve Cryptography (ECC), and Diffie-Hellman. These algorithms underpin internet communications (Transport Layer Security [TLS], virtual private networks [VPNs], Secure Shell [SSH]), identity and access management, industrial and internet-of-things (IoT) systems, and the integrity of software supply chains.</p>
        <p>If broken, threat actors could decrypt sensitive data, impersonate trusted systems, and undermine digital authentication. This could enable:</p>
        <ul>
          <li>Forged digital signatures</li>
          <li>Compromised code-signing pipelines</li>
          <li>Spoofed websites, identities, and certificates</li>
          <li>Manipulated financial transactions and legal documents</li>
        </ul>
        <h3>Risk 2: Harvest Now, Decrypt Later (HNDL)</h3>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 3: “Harvest now, decrypt later” workflow" src="https://www.recordedfuture.com/jp/media_108f2318ba28848f615e8c1c9e9430771a2e2cda0.png?width=750&amp;format=png&amp;optimize=medium" width="1526" height="594" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 3: “</strong>Harvest now, decrypt later” workflow (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p>Although cryptographically relevant quantum computers (CRQCs) may still be years away, the risk is already materializing through “<a href="https://www.federalreserve.gov/econres/feds/files/2025093pap.pdf">harvest now, decrypt later</a>” (HNDL) activity. State-sponsored threat actors are <a href="https://www.techmonitor.ai/hardware/quantum/harvest-now-decrypt-later-cyberattack-quantum-computer">likely</a> collecting and storing encrypted data today with the intent to decrypt it once quantum capabilities mature. A 2021 Booz Allen Hamilton <a href="https://www.nextgov.com/emerging-tech/2021/11/report-china-may-steal-encrypted-government-data-now-decrypt-quantum-computers-later/187020/">assessment</a> found that Chinese economic espionage operations are likely targeting encrypted data with long-term intelligence value, including biometric identifiers, covert source identities, and weapons designs.</p>
        <p>Large-scale routing manipulation offers one method for intercepting such data. Researchers at the US Naval War College and Tel Aviv University <a href="https://digitalcommons.usf.edu/cgi/viewcontent.cgi?article=1050&amp;context=mca">documented</a> systematic Border Gateway Protocol (BGP) hijacking by China Telecom between 2016 and 2019, which redirected traffic from US, Canadian, and Scandinavian networks through Chinese infrastructure. These types of operations align with a long-term HNDL collection strategy.</p>
        <p>Under the HNDL model, exposure occurs at the moment data is transmitted or stored, not when it is eventually decrypted. The primary risk, therefore, centers on long-lived data: information that must remain confidential for a decade or more, or whose sensitivity does not diminish over time, such as government and national security records, intellectual property and trade secrets, personal identifiers, financial data, biometric templates, healthcare records, and legal archives. For these data classes, compromise may not be immediately visible, but once decrypted, the consequences are irreversible. As a result, organizations holding long-lived sensitive data face near-term strategic risk regardless of when CRQCs become operational.</p>
        <p>Large-scale routing manipulation offers one method for intercepting such data. Researchers at the US Naval War College and Tel Aviv University <a href="https://digitalcommons.usf.edu/cgi/viewcontent.cgi?article=1050&amp;context=mca">documented</a> systematic Border Gateway Protocol (BGP) hijacking by China Telecom between 2016 and 2019, which redirected traffic from US, Canadian, and Scandinavian networks through Chinese infrastructure. These types of operations align with a long-term HNDL collection strategy.</p>
        <p>Under the HNDL model, exposure occurs at the moment data is transmitted or stored, not when it is eventually decrypted. The primary risk, therefore, centers on long-lived data: information that must remain confidential for a decade or more, or whose sensitivity does not diminish over time, such as government and national security records, intellectual property and trade secrets, personal identifiers, financial data, biometric templates, healthcare records, and legal archives. For these data classes, compromise may not be immediately visible, but once decrypted, the consequences are irreversible. As a result, organizations holding long-lived sensitive data face near-term strategic risk regardless of when CRQCs become operational.</p>
        <h3>Risk 3: Quantum-Accelerated Brute-Force Attacks (Grover’s Algorithm)</h3>
        <p>Quantum computing does not break modern symmetric encryption outright, but it can accelerate search-intensive tasks through techniques such as <a href="https://learn.microsoft.com/en-us/azure/quantum/concepts-grovers">Grover’s algorithm</a>. This reduces defender reaction time and increases the effectiveness of weak or legacy cryptographic implementations. In practice, this could enable faster brute-force attempts against outdated encryption, quicker identification of exposed secrets or misconfigurations, and more efficient malware tuning and exploit development.</p>
        <p>Recent <a href="https://thequantuminsider.com/2025/02/20/silicon-quantum-computing-executes-high-fidelity-grovers-algorithm-without-qec-but-scaling-challenges-remain/">demonstrations</a>, such as Silicon Quantum Computing’s high-accuracy implementation on a four-qubit processor, remain limited in scale but reflect steady progress toward these capabilities. However, Grover’s algorithm is constrained by high hardware requirements and limited parallelization. As a result, modern symmetric algorithms such as AES-128/192/256 are expected to remain secure for the foreseeable future, while environments with poor cryptographic hygiene will be affected first.</p>
        <h3>Risk 4: Quantum- and AI-Enhanced Vulnerability Discovery</h3>
        <p>Quantum capability will not develop in isolation. As quantum systems improve optimization and search performance, and AI automates reconnaissance, exploit development, and lateral movement, adversaries are likely to operate at <a href="https://thequantuminsider.com/2026/02/09/from-quantum-threat-to-ai-exposure-why-security-is-converging-faster-than-enterprises-expect/">unprecedented speed and scale</a>. Rather than identifying isolated weaknesses, attackers could rapidly map entire attack surfaces, chain misconfigurations, and deploy optimized malware variants in near real time. <a href="https://eprint.iacr.org/2024/169">Research</a> from 2024 demonstrates that machine-learning classifiers can already recover full cryptographic keys from PQC implementations using only a few hundred power traces, underscoring that even post-quantum algorithms will require hardened deployment.</p>
        <p>This convergence of AI and quantum technologies could significantly increase an attacker's operational tempo and amplify the impact of individual security lapses. The risk is compounded by the fact that a rising number of organizations carry substantial <a href="https://fintechmagazine.com/articles/why-the-finance-sector-grapples-with-software-security-debt">security debt</a>, with many reporting slow remediation cycles that leave vulnerabilities exposed for extended periods.</p>
        <h2>When Will CRQCs Arrive?</h2>
        <p>There is no definitive timeline for CRQCs. Most <a href="https://postquantum.com/q-day/q-day-predictions/">projections</a> place their arrival in the mid-to-late 2030s, with credible breakthroughs possible earlier in the decade. These estimates should be treated with caution: forecasting is inherently uncertain because progress in quantum error correction and qubit scaling occurs in uneven advances rather than linear progression.</p>
        <p>For security leaders, the precise date of “Q-Day” is less important than the lifecycle of deployed systems. Infrastructure implemented today may remain operational when CRQCs emerge. Current cryptographic decisions are therefore future-binding.</p>
        <p>Under the HNDL model, quantum risk is already material for long-lived data. Preparedness, visibility, and cryptographic agility matter more than timeline prediction.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 4: No definitive timeline for CRQCs" src="https://www.recordedfuture.com/jp/media_17371c5ac255f5ec94d1a64506d10b47e30510d9e.png?width=750&amp;format=png&amp;optimize=medium" width="1539" height="589" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 4:</strong></em> <em>No definitive timeline for CRQCs (Source: Recorded Future)</em></div>
          </div>
        </div>
        <h2>How Should Organizations Prepare?</h2>
        <p>The transition to post-quantum cryptography (PQC) is no longer a theoretical exercise. It is increasingly driven by regulation, procurement requirements, and emerging industry norms. These developments should be interpreted as operational signals necessitating forward planning.</p>
        <p>In the US, the <a href="https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/Quantum%20Computing%20Cybersecurity%20Preparedness%20Act.pdf">Quantum Computing Cybersecurity Preparedness Act</a> requires federal agencies to inventory quantum-vulnerable cryptography and develop migration plans. NIST’s <a href="https://www.federalregister.gov/documents/2024/08/14/2024-17956/announcing-issuance-of-federal-information-processing-standards-fips-fips-203-module-lattice-based">2024 PQC standards</a> now set the baseline for federal procurement and are rapidly becoming global reference points. In parallel, <a href="https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF">Commercial National Security Algorithm (CNSA) 2.0</a> defines approved algorithms and transition timelines for national security systems, with full migration targeted by 2035. Similar momentum is building in Europe. The <a href="https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-act">EU Cybersecurity Act</a> and national quantum-preparedness strategies are accelerating early adoption, particularly across critical infrastructure sectors such as energy and transportation.</p>
        <p>Although many of these mandates formally apply to public-sector systems, their practical impact extends well beyond government. Procurement requirements and supply-chain expectations are translating policy into commercial pressure. As a result, cryptographic inventory, structured migration planning, vendor alignment, and crypto-agility are likely to become baseline governance expectations rather than optional best practices. Boards are beginning to treat quantum risk as a strategic planning issue, not a distant technical concern, with some sectors allocating dedicated quantum-security budgets <a href="https://investor.forrester.com/news-releases/news-release-details/forresters-2026-technology-security-predictions-ais-hype-fades">approaching 5%</a> of total cybersecurity spend to support preparation.</p>
        <p>Industry coordination further reinforces this direction of travel. Financial institutions, payment networks, and telecommunications providers are forming quantum-readiness <a href="https://www.fsisac.com/hubfs/Knowledge/PQC/FutureState.pdf">working groups</a> to align migration timelines and manage shared dependencies. SWIFT is developing PQC migration <a href="https://wqs.events/swift-migration-to-post-quantum-cryptography-a-comprehensive-implementation-guide/">guidance</a> for its global messaging network, and Mastercard has released a PQC migration <a href="https://www.mastercard.com/content/dam/mccom/shared/news-and-trends/stories/2025/quantum-explainer-and-white-paper/Migration-to-post-quantum-cryptography-WhitePaper_2025.pdf">white paper</a> outlining practical transition steps.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Figure 5: Planning for the uncertain arrival of CRQCs" src="https://www.recordedfuture.com/jp/media_1e73ead952dab51913768a583bb5c28d81cad1eb2.png?width=750&amp;format=png&amp;optimize=medium" width="1036" height="459" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 5:</strong></em> <em>Planning for the uncertain arrival of CRQCs (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p>As the HNDL risk window narrows, organizations that begin structured preparation now are likely to manage transition risk deliberately and cost-effectively. Security leaders should ensure they understand where quantum-vulnerable cryptography resides, how regulatory obligations may cascade through customers and partners, and whether critical suppliers have credible PQC transition roadmaps. Those that delay risk compressed timelines, regulatory pressure, and materially higher transition costs later in the decade. Specific technical and governance steps are detailed in the Mitigations section.</p>
        <h2>Outlook</h2>
        <p><strong>HNDL activity will continue to expand.</strong><br />State-sponsored threat actors are highly likely to increase long-term interception and storage of encrypted data, particularly from sectors handling information with long confidentiality lifetimes. Even as storage economics fluctuate, scalable interception infrastructure and economically sustainable long-term storage models enable continued accumulation of high-value encrypted material. Demonstrated routing manipulation <a href="https://digitalcommons.usf.edu/cgi/viewcontent.cgi?article=1050&amp;context=mca">capabilities</a> further support persistent collection at scale, ensuring exposure continues to build regardless of when CRQCs ultimately arrive.</p>
        <p><strong>Attacker operational tempo will increase.</strong><br />The convergence of AI-enabled automation with quantum-accelerated search and optimization is likely to compress defender response windows and amplify the impact of existing security debt. Organizations reliant on legacy cryptography and slow remediation cycles will feel this pressure first.</p>
        <p><strong>Regulatory and procurement pressure will intensify.</strong><br />Post-quantum readiness is increasingly likely to become a baseline requirement for regulated markets, government contracts, and high-trust supply chains. US and European initiatives are formalizing transition timelines, and these mandates will propagate through vendor ecosystems, reframing quantum preparedness as a competitive requirement rather than a discretionary control.</p>
        <p><strong>Migration risk will become a primary enterprise challenge.</strong><br />Organizations that delay cryptographic inventories and crypto-agility investments are likely to face compressed transition timelines, higher costs, and greater operational disruption as standards mature and vendor dependencies shift.</p>
        <h2>Mitigations</h2>
        <p>Organizations should treat quantum resilience as a phased program aligned to visibility, flexibility, and systemic risk reduction, with leaders actively testing assumptions at each stage.</p>
        <h3>Short-term (2026): Establish visibility and prioritization</h3>
        <p>Security teams should maintain a comprehensive cryptographic inventory, identifying quantum-vulnerable algorithms across applications, infrastructure, and third-party dependencies, as well as public key infrastructure (PKI), operational technology, and IoT environments, and mapping them to data sensitivity and confidentiality requirements.</p>
        <p>Leaders should be asking:</p>
        <ul>
          <li>Do we have an enterprise-wide inventory of where quantum-vulnerable cryptography is embedded, including in legacy and third-party systems?</li>
          <li>Which data assets must remain confidential for a decade or more, and are they currently protected by algorithms likely to be broken by CRQCs?</li>
        </ul>
        <h3>Medium-term (2026–2028): Enable flexibility</h3>
        <p>Organizations should design for cryptographic agility, ensuring that new systems and major upgrades allow algorithm replacement without architectural redesign. Vendors supporting long-lived products should provide credible PQC transition roadmaps aligned to emerging standards.</p>
        <p>Leaders should be asking:</p>
        <ul>
          <li>Are we continuing to deploy systems that hard-code cryptographic algorithms, thereby increasing future migration risk?</li>
          <li>Do our critical suppliers have credible, time-bound PQC transition plans, and how exposed would we be if they fell behind?</li>
        </ul>
        <h3>Long-term (2028-onwards): Reduce systemic exposure</h3>
        <p>Migration should prioritize long-lived data and high-trust functions, including identity infrastructure, code signing, certificate management, secure build pipelines, and critical third-party software. Strengthening software and supply-chain integrity will be essential to minimizing cascading risk during transition.</p>
        <p>CISOs should be asking:</p>
        <ul>
          <li>Which enterprise trust anchors (for example, certificate authorities, signing keys, or hardware security modules) would create systemic impact if rendered vulnerable in a post-quantum scenario?</li>
          <li>Can we rotate and replace cryptographic components at scale without operational disruption if migration timelines compress unexpectedly?</li>
        </ul>
        <p>Recorded Future intelligence can support these efforts by tracking emerging cryptographic risks through our <a href="https://www.recordedfuture.com/jp/products/threat-intelligence">Threat Intelligence Module</a>, identifying exposed dependencies through our <a href="https://www.recordedfuture.com/jp/products/attack-surface-intelligence">Attack Surface Intelligence</a>, and assessing third-party quantum readiness as standards and vendor capabilities evolve through our <a href="https://www.recordedfuture.com/jp/products/third-party-intelligence">Third-Party Intelligence Module</a>.</p>
        <h2>Risk Scenario</h2>
        <p>GridCore Systems is a US-based provider of industrial control systems (ICS) and grid-management software for electric utilities nationwide. The firm relies on quantum-vulnerable public-key cryptography (RSA/ECC) for remote access, software signing, and secure data exchange with utilities and regulators, and has not yet completed a post-quantum cryptographic transition.</p>
        <h3>First-Order Implications</h3>
        <div>
          <div>
            <div>
              <h3>Threat</h3>
            </div>
            <div>
              <h3>Risk</h3>
            </div>
          </div>
          <div>
            <div>Adversaries intercept GridCore’s encrypted communications and software-update traffic for long-term storage under a harvest-now, decrypt-later (HNDL) model, while exploiting an exposed support system to map cryptographic dependencies.</div>
            <div>
              <ul>
                <li><strong>Legal or compliance failure:</strong> Exposure of regulated energy-sector data triggers scrutiny under North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) and federal cybersecurity requirements.</li>
                <li><strong>Operational disruption:</strong> Incident response and emergency access restrictions delay maintenance and update cycles for utility customers.</li>
                <li><strong>Brand impairment:</strong> Disclosure of quantum-readiness gaps undermines customer and regulator confidence.</li>
              </ul>
            </div>
          </div>
        </div>
        <h3>Second-Order Implications</h3>
        <div>
          <div>
            <div>
              <h3>Threat</h3>
            </div>
            <div>
              <h3>Risk</h3>
            </div>
          </div>
          <div>
            <div>Attackers leverage harvested metadata and mapped trust relationships to position for future cryptographic compromise, focusing on software-signing infrastructure and authentication mechanisms.</div>
            <div>
              <ul>
                <li><strong>Operational disruption:</strong> Utilities delay deployments and require additional validation of software integrity and access controls.</li>
                <li><strong>Brand impairment:</strong> Public concerns over update authenticity erode GridCore’s reputation as a trusted infrastructure provider.</li>
                <li><strong>Competitive disadvantage:</strong> Customers begin to favor vendors with demonstrable post-quantum migration progress.</li>
              </ul>
            </div>
          </div>
        </div>
        <h3>Third-Order Implications</h3>
        <div>
          <div>
            <div>
              <h3>Threat</h3>
            </div>
            <div>
              <h3>Risk</h3>
            </div>
          </div>
          <div>
            <div>Following the emergence of cryptographically relevant quantum computers, previously harvested data is decrypted, exposing historical grid telemetry, credentials, and engineering documentation.</div>
            <div>
              <ul>
                <li><strong>Operational disruption:</strong> Adversaries plan targeted intrusions or disrupt contingencies during periods of geopolitical tension.</li>
                <li><strong>Legal or compliance failure:</strong> Retroactive exposure of protected data leads to long-term regulatory action and contractual liability.</li>
                <li><strong>Competitive disadvantage:</strong> GridCore loses preferred-vendor status and future contracts to quantum-ready competitors.</li>
              </ul>
            </div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_1163dd082af56f227c5eaa25ef0f7c257c8609133.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Recorded Future Named a Leader in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. And there’s more.]]></title>
            <link>https://www.recordedfuture.com/jp/blog/recorded-future-named-a-leader</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/recorded-future-named-a-leader</guid>
            <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Recorded Future shares exciting developments since being named a leader.]]></description>
            <content:encoded><![CDATA[
        <p>For security professionals evaluating threat intelligence vendors, the Gartner Magic Quadrant offers an indispensable perspective. Gartner analysts’ thorough and nuanced analysis cuts through the noise, making it easier for teams to understand each platform’s approach, strengths, and considerations—and helping them determine whether a particular vendor fits their organization’s unique needs.</p>
        <p>That’s why we’re honored to share that Gartner has named Recorded Future a Leader in the first-ever Magic Quadrant™ for Cyberthreat Intelligence Technologies. <a href="https://go.recordedfuture.com/2026GartnerMQ.html?utm_source=website&amp;utm_medium=article&amp;utm_campaign=fy26-global-gartnermq">This new report</a> evaluated 17 vendors in the space, providing a comprehensive look at the competitive landscape.</p>
        <p>“In our view, being recognized as a Leader means something specific to us: we feel it reflects our ability to help our customers with the outcomes they depend on. These include stopping threats pre-attack, running intelligence autonomously at a scale no human team can match, and making every security control they own more effective," said Colin Mahony, CEO, Recorded Future. “We believe this recognition reflects both the trust our customers place in us and the strength of the outcomes we help them achieve.”</p>
        <h2>A research methodology that prioritizes customer voice</h2>
        <p>A Gartner Magic Quadrant is a culmination of research in a specific market, giving you a wide-angle view of the relative positions of the market’s competitors. By applying a graphical treatment and a uniform set of evaluation criteria, a Magic Quadrant helps you quickly ascertain how well technology providers are executing their stated visions and how well they are performing against Gartner’s market view.</p>
        <p>For Recorded Future, this meant that Gartner analysts spoke directly with our customers about their real-world experiences—the challenges they face, how they use our Platform, and the outcomes they've realized. We feel their voices shaped our position in the Magic Quadrant, just as they’ve always shaped our product offerings and roadmap.</p>
        <p>The new Gartner report offers a snapshot of what the analysts heard from customers. We haven’t stopped working since then and there’s much to talk about.</p>
        <h2>There’s more… the next phase of threat intelligence</h2>
        <p>In conversations throughout 2025, our customers gave us their thoughts about product complexity, pricing models, and the challenges of scaling intelligence across their teams. As a result of their input, we’ve fundamentally changed how they can access and make the most of Recorded Future threat intelligence.</p>
        <p>Here are the highlights of our continued commitment to simplicity and innovation to provide better experiences for our customers in 2026:</p>
        <p><strong>1. Goodbye, modules. Hello, simplicity. Meet our four new solutions.</strong><br />Our <a href="https://www.recordedfuture.com/jp/solutions-overview">four new solution areas</a> cover the four major attack surfaces—an organization’s systems, brand, supply chain, and payment methods:</p>
        <ul>
          <li><strong>Cyber Operations</strong>—This foundational solution empowers security teams with the intelligence to monitor and prioritize threats and vulnerabilities, get in-depth malware insights, triage alerts and detect threats, and stand up an intelligence-driven defense.</li>
          <li><strong>Digital Risk Protection</strong>—Also foundational, this solution allows teams to monitor malicious sites, code repositories, and the dark web to detect brand abuse, employee credential compromise, and other threats to digital trust.</li>
          <li><strong>Third-Party Risk</strong>—This solution enables teams to continuously assess supplier security posture with real-time intelligence, accurate risk ratings, vendor action plans, and more.</li>
          <li><strong>Payment Fraud</strong>—With this solution, teams can detect and prevent card-not-present fraud with intelligence that identifies compromised payment data before it's used.</li>
        </ul>
        <p>The solutions are built on a unified intelligence foundation to provide consistency, accuracy, and alignment around shared security outcomes. And they integrate with other security solutions like CrowdStrike Falcon and Google SecOps, bringing the benefits of Recorded Future intelligence and rich context directly into common SIEM and EDR workflows.</p>
        <p><strong>2. New pricing packages for less friction, more intelligence</strong><br />We’re offering the four solutions in <a href="https://www.recordedfuture.com/jp/blog/recorded-future-solutions-packages">new pricing packages</a> designed to fit customer needs:</p>
        <ul>
          <li><strong>Simplicity</strong>—Customers can purchase one package instead of juggling multiple modules</li>
          <li><strong>End-to-end workflows</strong>—Packages cover full use cases, complete with the key capabilities to get the job done</li>
          <li><strong>Wider access</strong>—Higher tiers offer unlimited seats, so everyone now can be intelligence-led.</li>
        </ul>
        <p>In addition, integrations are included. Now your tools in the security stack—SIEM, SOAR, firewall, endpoint protection, ticketing system, and more—can leverage Recorded Future intelligence without integration fees or limitations.</p>
        <p><strong>3. Expansion into Latin America</strong><br />The threat landscape knows no geographical borders, and neither do we. We’ve expanded Recorded Future’s operations into Latin America, giving security teams in the region better access to the expertise and support they need to mount a successful proactive defense.</p>
        <p><strong>4. Autonomous Threat Operations for autonomous defense</strong><br />In February, we launched <a href="https://www.recordedfuture.com/jp/products/autonomous-threat-operations">Autonomous Threat Operations</a> to help customers move from isolated threat intelligence insights and manual workflows to automated and continuous defensive actions across the entire security ecosystem. Complete with AI-powered, 24/7 autonomous threat hunting and multi-source correlation in the Intelligence Graph®.</p>
        <p>As we continue to build on our vision of moving from automated to autonomous operations, we’re developing Recorded Future AI and agentic experiences to help our customers reduce alert fatigue, save time on research, and run threat hunts faster so they can detect and defend at scale.</p>
        <h2>Explore the Gartner Magic Quadrant report today</h2>
        <p>We’re proud to be recognized by Gartner as a Leader in Cyberthreat Intelligence Technology, and we’ll continue innovating for our customers to help them mitigate risk and stay ahead of evolving threats.</p>
        <p><a href="https://go.recordedfuture.com/2026GartnerMQ.html?utm_source=website&amp;utm_medium=article&amp;utm_campaign=fy26-global-gartnermq">Get the report</a> to review Gartner analysis and see how Recorded Future fits your CTI program needs.</p>
        <p>____________________________________________________________________________________________________________________________________</p>
        <p>Gartner, Magic Quadrant for Cyberthreat Intelligence Technologies, By <a href="https://www.gartner.com/analyst/b9c908b87ba1">Jonathan Nunez</a>, <a href="https://www.gartner.com/analyst/b9c909b579a5">Carlos De Sola Caraballo</a>, <a href="https://www.gartner.com/analyst/b9cb03bf7ca6">Jaime Anderson</a>, 04 May 2026.</p>
        <p><em>Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates.</em></p>
        <p><em>Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.</em></p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1a5c3484e52ab4160760d9e31ebcdb3ac05008a87.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Threat Activity Enablers: The Backbone of Today’s Threat Landscape]]></title>
            <link>https://www.recordedfuture.com/jp/blog/threat-activity-enablers</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/threat-activity-enablers</guid>
            <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Behind every ransomware demand, botnet, or threat activity group is a server sitting in a data center.]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>This article introduces threat activity enablers (TAEs), the infrastructure providers and networks that underpin modern cyber threats across both criminal and state-sponsored activity. These entities sustain operations by enabling resilient, high-risk infrastructure that persists despite sanctions, takedowns, and public exposure.</div>
          </div>
        </div>
        <p>Behind every ransomware demand, botnet, or threat activity group is a server sitting in a data center. While most legitimate hosting providers evict threat actors once identified, a specific class of providers does the opposite. Recorded Future<sup>®</sup> calls these providers threat activity enablers(TAEs).</p>
        <h2>What Is a Threat Activity Enabler?</h2>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1fed9a2196f01bb447c257ef0819ce6ecec676dec.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="2048" height="1908" />
            </div>
          </div>
          <div>
            <div>Figure 1: Overview of threat activity enablers’ patterns, ecosystem, and impact</div>
          </div>
        </div>
        <p>A threat activity enabler (TAE) is an individual, organization, or service provider that supports malicious cyber activity by providing infrastructure or services leveraged by threat actors. More commonly, this includes providers that lack a formal physical or virtual storefront, conduct business only via email or messaging platforms, and do not enforce know-your-customer (KYC) policies. It also includes hosting providers that selectively respond to abuse reports or law enforcement inquiries to maintain plausible deniability, as well as more traditional self-proclaimed “bulletproof” providers that openly ignore oversight or advertise non-cooperation.<br /><br />TAE networks serve as the backbone for ransomware groups, infostealer campaigns, botnets, and even state-sponsored threat actor operations. What distinguishes TAE networks is the sustained concentration of malicious infrastructure within their networks.</p>
        <h2>How TAEs Operate</h2>
        <p>TAEs are masters of obfuscation and are highly resilient, hiding behind layers of decoy companies to evade accountability. They use several core tactics:</p>
        <ul>
          <li><strong>Corporate Shell Games</strong>: They establish front companies across multiple jurisdictions to create legal distance between the infrastructure and the operators.</li>
          <li><strong>Strategic Resource Control</strong>: They often operate as local internet registries (LIRs). This gives them direct control over IP resources and autonomous systems (ASNs), allowing them to manipulate network resources at will.</li>
          <li><strong>Rapid Rebranding</strong>: When a network becomes too "hot" due to scrutiny, TAEs rapidly transfer IP address prefixes to a newly registered, clean-looking entity.</li>
        </ul>
        <h2>Identifying High-Risk TAE Networks</h2>
        <p>Recorded Future actively identifies high-risk TAE networks through its Network Threat Density List. These networks are ranked by their Threat Density Score, calculated from the concentration of validated malicious activity relative to the total number of IP address prefixes a network announces.</p>
        <p>This approach cuts through the noise to quickly expose infrastructure that is disproportionately associated with threat activity, a core characteristic of TAEs, allowing network defenders to prioritize the infrastructure most likely to pose material risk.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Chart" src="https://www.recordedfuture.com/jp/media_16c51cd61c26920af1bcad502b85b34a3369920e2.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1386" />
            </div>
          </div>
          <div>
            <div>Figure 2: High-risk suspected or confirmed TAE networks in 2025, ranked by Threat Density Score</div>
          </div>
        </div>
        <h2>From Insight to Action</h2>
        <p>Tracking TAE networks allows security teams to move from reacting to individual threats to proactively managing infrastructure risk. In practice, this means applying TAE intelligence across three core areas: prevention, detection, and exposure.</p>
        <h2>Operationalize TAE Intelligence</h2>
        <div>
          <div>
            <div><a href="/jp/data/blog/threat-activity-blog-icon-card.json">https://ja-jp-9fb48d285d9c21c53.getsmartling.com/jp/data/blog/threat-activity-blog-icon-card.json</a></div>
          </div>
        </div>
        <p>Figure 3: Three steps for operationalizing TAE intelligence</p>
        <p>TAEs are persistent and continuously evolving, adapting quickly in response to sanctions, enforcement actions, and exposure. While their identities may change, their underlying infrastructure patterns often remain consistent.</p>
        <h2>The "metaspinner" Case Study</h2>
        <p>In April 2025, a TAE tracked by Recorded Future, Virtualine Technologies, shifted its IPv4 resources to a newly registered network that fraudulently impersonated a legitimate German software firm, <a href="https://www.recordedfuture.com/jp/research/malicious-infrastructure-finds-stability-with-aurologic-gmbh">metaspinner net GmbH</a>. Because this provider’s historical infrastructure patterns were already being tracked, the newly created network was immediately identified as a front. Within weeks, this network became a primary distribution hub for malware families such as Latrodectus and AsyncRAT. When the operation was eventually exposed, Virtualine Technologies simply pivoted the infrastructure to a new identity within one of its existing autonomous systems to maintain its operations.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Chart" src="https://www.recordedfuture.com/jp/media_1d882e5b2ce38b5df856f2ffebbe35125e3e77824.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1386" />
            </div>
          </div>
          <div>
            <div>Figure 4: Validated malicious activity associated with Virtualine Technologies in 2025</div>
          </div>
        </div>
        <p>This case underscores the reality of TAE networks: while identities, ownership records, and corporate fronts may change, the underlying infrastructure and its associated risk persist, making continuous tracking essential to identifying and prioritizing the networks that will drive future threat activity, as demonstrated by Virtualine subsequently emerging as the highest-risk TAE network in 2025.</p>
        <h2>The Stark Industries Case Study</h2>
        <p>In May 2025, the European Union sanctioned UK-registered hosting provider Stark Industries Solutions and its executives for enabling Russian state-sponsored cyber operations. However, enforcement did not halt Stark Industries’ operations. In the weeks leading up to the sanctions announcement, Stark Industries began transferring IP resources, modifying RIPE registrations, and shifting infrastructure to affiliated entities.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_190a9bd2b2490f6e609299c7228f2bf256f70bfbc.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="829" />
            </div>
          </div>
          <div>
            <div>Figure 5: Timeline of Stark Industries-related events in 2025</div>
          </div>
        </div>
        <p>Despite the sanctions, the underlying infrastructure, routing relationships, and operational patterns remained traceable across these new fronts. Continuous monitoring of TAE ecosystems enables defenders to detect these pivots in near real time, revealing continuity beneath corporate rebrands and legal restructurings. This case underscores a broader reality: sanctions may change names and ownership records, but without infrastructure-level visibility, the enabling networks behind malicious activity often persist.</p>
        <h2>What This Means for Security Leaders</h2>
        <p>TAEs represent an ongoing challenge. While individual campaigns and threat actors may come and go, the infrastructure that supports them remains adaptive and deliberately resilient.</p>
        <p>For security leaders, this requires an additional shift from solely reacting to individual indicators to understanding and prioritizing the infrastructure that enables threat activity at scale. By identifying and tracking high-risk networks, organizations can reduce investigative noise, focus resources on the most impactful threats, and take proactive steps to limit exposure before attacks materialize.</p>
        <p>Ultimately, addressing TAEs is not just about detection; it’s also about disrupting the conditions that enable modern cyber threats to operate.</p>
        <h2>Questions You Should Be Asking</h2>
        <ul>
          <li>How much of your network communicates with high-risk infrastructure?</li>
          <li>Are you prioritizing alerts involving high-risk networks?</li>
          <li>Is TAE or ASN risk intelligence integrated into your detection and triage workflows to ensure the highest-risk activity is addressed first?</li>
          <li>Do any of your third-party providers rely on TAE-linked infrastructure?</li>
          <li>Do you have hidden exposure to TAE networks?</li>
          <li>Are your controls dynamically adjusting to infrastructure risk?</li>
          <li>Can you proactively restrict or challenge traffic to and from high-risk networks?</li>
        </ul>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_10569a4d0a64470c8d18b5af323b45569f74f4659.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Hacking Embodied AI]]></title>
            <link>https://www.recordedfuture.com/jp/research/hacking-embodied-ai</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/hacking-embodied-ai</guid>
            <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Embodied AI, intelligent systems in physical forms such as humanoid and quadruped robots, is moving from spectacle to staffing plans.]]></description>
            <content:encoded><![CDATA[
        <h2>Summary</h2>
        <p><strong>Embodied AI has arrived.</strong>. Humanoid and quadruped robots are moving off factory floors and into everyday operations, military deployments, and critical infrastructure. Technological advances in large language models LLMs and robotics are enabling robots to perform complex tasks autonomously.</p>
        <p><strong>Security has not kept pace.</strong> Researchers have demonstrated that commercially available robots can be hijacked over Bluetooth, covertly exfiltrate audio, video, and spatial data to servers in China, and even infect neighboring robots wirelessly, forming physical botnets. If unaddressed, these security weaknesses are set to scale massively once humanoid robots are fully integrated into critical workflows.</p>
        <p><strong>The risks need to be taken extremely seriously.</strong> A robot should be treated less like a machine on the balance sheet and more like a cyber-physical endpoint with cameras, microphones, radios, cloud dependencies, and motors. That means tougher procurement, tighter network controls, continuous vulnerability monitoring, and a credible plan for operational continuity if a fleet has to be pulled offline.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Summary of Unitree G1 vulnerabilities, associated business risks" src="https://www.recordedfuture.com/jp/media_1aa3ae8873074d3668f2fc7ff1af6da284b4aef6c.png?width=750&amp;format=png&amp;optimize=medium" width="1972" height="988" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em>Summary of Unitree G1 vulnerabilities, associated business risks, mapped CVEs, and observed network activity (IPs and data exfiltration rates) (Source: Recorded Future)</em></div>
          </div>
        </div>
        <h2>Analysis</h2>
        <h3><strong>Market Drivers of Embodied AI Adoption</strong></h3>
        <p>Embodied AI, intelligent systems in physical forms such as humanoid and quadruped robots, is moving from spectacle to staffing plans.</p>
        <p>The shift is being driven as much by demographics as by technological progress. There are growing <a href="https://www.oecd.org/en/publications/oecd-employment-outlook-2025_194a947b-en/full-report/editorial-from-job-shortage-to-labour-shortage-the-new-challenge-of-population-ageing_77cf5ed3.html">reports</a> that the working-age population worldwide has begun to <a href="https://www.economist.com/leaders/2025/09/11/dont-panic-about-the-global-fertility-crash">decline</a>. China, an economic success story, has seen its population also <a href="https://edition.cnn.com/2026/02/13/china/china-population-robots-intl-hnk-dst">decline</a> again in 2025 as births hit a record low. These trends do not make large-scale automation inevitable, but they seriously strengthen the economic <a href="https://edition.cnn.com/2026/02/13/china/china-population-robots-intl-hnk-dst">case</a> for it in both corporate and government decision-making.</p>
        <p>The International Federation of Robotics <a href="https://ifr.org/ifr-press-releases/news/top-5-global-robotics-trends-2026">identifies</a> labor shortages, real-world testing of humanoid robots, and increasing attention to safety and cybersecurity as defining trends for 2026. Some early <a href="https://www.nytimes.com/2026/02/12/us/elliq-ai-robot-senior-companion.html">deployments</a> of embodied AI reinforce this trajectory. BMW <a href="https://www.bmwgroup.com/en/news/general/2026/humanoid-robot-in-leipzig.html">reports</a> that the Figure 02 humanoid robot has assisted in the production of more than 30,000 X3 vehicles, while GXO and Agility Robotics <a href="https://www.agilityrobotics.com/content/gxo-signs-industry-first-multi-year-agreement-with-agility-robotics">describe</a> their partnership (established in 2024) as “the first formal commercial deployment of humanoid robots.” In high-risk environments, Sellafield is <a href="https://www.gov.uk/government/case-studies/how-are-robot-dogs-helping-clean-up-sellafield">deploying</a> quadruped robots to reduce human exposure in nuclear decommissioning.</p>
        <p>Capital markets are also responding. Unitree filed for a <a href="https://www.reuters.com/world/asia-pacific/unitree-plans-shanghai-ipo-testing-interest-humanoid-robots-2026-03-20/">reported</a> $610 million initial public offering (IPO) in Shanghai in March 2026. Taken together, these signals suggest that robots are leaving pilot programs and becoming operational.</p>
        <p>That transition makes the security question immediate rather than theoretical.</p>
        <h3><strong>Expanding Attack Surface in Embodied AI Systems</strong></h3>
        <p>Unlike traditional IT assets, embodied AI systems combine multiple high-risk components in a single platform: cameras, microphones, sensors, wireless radios, cloud connectivity, and physical actuation. This convergence creates a broad and under-secured attack surface.</p>
        <p>A compromised robot can exfiltrate sensitive environmental and operational data, provide persistent remote access to internal networks, and interact physically with its environment, potentially causing unintended physical effects. This elevates robots from conventional endpoints to cyber-physical systems with both digital and real-world consequences.</p>
        <p>The risk is compounded by architectural choices. Many platforms rely on cloud-dependent telemetry, wireless provisioning interfaces, and centralized control mechanisms. These design decisions create multiple entry points for attackers and increase the likelihood of compromise across entire fleets of embodied AI systems.</p>
        <h3><em><strong>Demonstrated Vulnerabilities and Exploits</strong></em></h3>
        <p>The risks are no longer theoretical. Documented vulnerabilities show that commercially available robots can be compromised with relative ease. Unlike traditional cyber threats, which mostly affect the digital world, exploiting robots enables attackers to manipulate the physical world, maximizing the potential for harm.</p>
        <p>In 2025, <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2894"></a>researchers discovered an undocumented <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2894">backdoor</a> in Unitree’s Go1 quadruped robot that enabled remote access via the CloudSail service. Axios <a href="https://www.axios.com/2025/04/01/threat-spotlight-backdoor-in-chinese-robots-future-of-cybersecurity">reported</a> that an exposed web application programming interface (API) could allow attackers to locate devices globally and, if a robot was online, view live camera feeds without authentication. Where default credentials remained unchanged, full device control was possible. Whether described as a backdoor or a design failure, the implication is the same: robots may be <a href="https://go.censys.com/rs/120-HWT-117/images/2024SOTIR.pdf">reachable</a> in ways operators do not anticipate, just like any other Internet of Things (IoT) device.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Summary of vulnerabilities affecting the Unitree Go1 robot with intelligence card insights" src="https://www.recordedfuture.com/jp/media_10c6d2ab723f9be0642a77952e5837e537162dc36.png?width=750&amp;format=png&amp;optimize=medium" width="1988" height="666" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 2:</strong></em> <em>Summary of vulnerabilities affecting the Unitree Go1 robot, with Intelligence Card insights from the Recorded Future Intelligence Operations Platform (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p>Further research <a href="https://arxiv.org/pdf/2509.14139">disclosed</a> a critical vulnerability in the Bluetooth Low Energy and Wi-Fi provisioning interface used by multiple Unitree models, including the Go2, B2, G1, R1, and H1 robots. According to both the <a href="https://github.com/Bin4ry/UniPwn">UniPwn research</a> and <a href="https://spectrum.ieee.org/unitree-robot-exploit">IEEE Spectrum</a>, the flaw combined hard-coded cryptographic keys, trivial authentication bypass, and command injection in the Wi-Fi setup process. An attacker within radio range could obtain root-level access without physical contact, giving them control over the robot.</p>
        <p>Because the exploit propagates wirelessly, a single compromised device can enable lateral movement across nearby robots. This creates a fleet-level compromise scenario in which multiple units can be controlled simultaneously. The result resembles a physical botnet capable of both digital and physical actions.</p>
        <p>Surveillance risks are equally significant. Researchers <a href="https://medium.com/@creed_1732/the-unitree-g1-security-crisis-explains-how-a-humanoid-robot-became-a-spy-and-cyber-weapon-439180135ba1">wrote</a> that the Unitree G1 robot continuously exfiltrated multimodal sensor and service-state telemetry every 300 seconds without the operator’s knowledge. This included streaming data to external servers, potentially including audio, video, and spatial mapping. A robot operating inside a plant or laboratory may therefore be mapping the environment in real time.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Unitree G1 quietly transmitting audio, video and sensor data" src="https://www.recordedfuture.com/jp/media_15d15fd08649b1406a5b4df4e3a993de07f8d7cf2.png?width=750&amp;format=png&amp;optimize=medium" width="1962" height="902" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 3:</strong></em> <em>Researchers</em> <em><a href="https://web.archive.org/web/20250927205104/https://www.zmescience.com/science/news-science/cybersecurity-experts-say-these-humanoid-robots-secretly-send-data-to-china-and-let-hackers-take-over-your-network/">found</a></em> <em>Unitree’s G1 quietly transmitting audio, video, and sensor data to the IP address (43[.]175[.]229[.]18) without user awareness (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p>The attack surface extends beyond firmware and networking layers. Researchers <a href="https://www.yicaiglobal.com/news/chinese-cybersecurity-expert-hacks-control-system-of-unitrees-humanoid-robot-in-one-minute">showed</a> they could take control of a Unitree humanoid in about a minute, bypass its normal controller, and trigger physical actions. Demonstrations at GEEKCon in Shanghai <a href="https://interestingengineering.com/ai-robotics/security-flaw-could-allow-hackers-control-robots">indicated</a> that both voice commands and short-range wireless exploits could hijack robots and propagate attacks to nearby units, including those not actively in use.</p>
        <p>At the software layer, embodied AI systems introduce <a href="https://www.universityofcalifornia.edu/news/misleading-text-physical-world-can-hijack-ai-enabled-robots">additional</a> risks due to their reliance on large vision-language models. Researchers <a href="https://arxiv.org/abs/2510.00181">demonstrated</a> that physical-world text can influence system behavior, as injected visual prompts were shown to <a href="https://www.universityofcalifornia.edu/news/misleading-text-physical-world-can-hijack-ai-enabled-robots">steer</a> autonomous driving, drone landing, and tracking tasks without compromising the underlying software. This would enable threat actors to take control of a self-driving car or turn a drone into their own surveillance feed by embedding a visual prompt in the environment, such as <a href="https://thehackernews.com/2017/08/self-driving-car-hacking.html">hiding</a> a message on a stop sign.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Chinese robotic systems demonstrated during military training" src="https://www.recordedfuture.com/jp/media_1e9fd27d1aeb85db2aab9347d688949b559683e3b.png?width=750&amp;format=png&amp;optimize=medium" width="1292" height="602" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 4:</strong></em> <em>Chinese robotic systems demonstrated during military training exercises (left) (Source:</em> <em><a href="https://youtu.be/3m3iUHplvQE?si=yQYNuXsPDW7y6cxn">ABC YouTube</a>); Concept rendering of the Atlas 2.0 robot operating in a next-generation factory environment (right) (Source:</em> <em><a href="https://www.youtube.com/watch?v=rrUHZKlrxms">Boston Dynamics YouTube</a>)</em></div>
          </div>
        </div>
        <h3><em><strong>Systemic and Operational Risk Implications</strong></em></h3>
        <p>The implications extend beyond individual devices to organizational and systemic risk. Embodied AI systems are already being deployed in environments where compromise has consequences beyond data loss. Manipulation or malfunction of robots during critical operations would have outsized economic or public safety consequences. Militaries are also experimenting with robotic systems (see <strong>Figure 4</strong>).</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Droid TW 12.7 machine gun drone" src="https://www.recordedfuture.com/jp/media_1f75bf259dda7b9c0821f98385522c9836e7e503b.png?width=750&amp;format=png&amp;optimize=medium" width="1136" height="1092" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 5:</strong></em> <em>Droid TW 12.7 machine gun drone, deployed by Ukrainian forces to capture Russian positions without ground troops (Source:</em> <em><a href="https://www.telegraph.co.uk/world-news/2026/04/14/ukraine-forces-russians-to-surrender-using-only-robots/">The Telegraph</a>)</em></div>
          </div>
        </div>
        <p>In 2024, the Golden Dragon exercise between Cambodia and China <a href="https://apnews.com/article/01090258ee039fa29db09aa59a5ba91b">featured</a> robot dogs among the systems on display. Meanwhile, in the US, politicians have begun <a href="https://www.fdd.org/analysis/2026/03/27/as-chinese-robotics-industry-surges-senate-considers-limited-federal-procurement-ban/">pushing</a> for Unitree to be designated as a federal supply-chain risk, reflecting national security concerns about commercial robotics platforms. This is a very similar move to Poland’s <a href="https://apnews.com/article/poland-army-chinese-vehicle-ban-spying-data-20bf62e4eeb5d809f7b6dea34662550f">ban</a> on sensor-rich vehicles accessing military sites to limit surveillance risk. Ukraine has successfully <a href="http://bbc.com/news/articles/c62662gzlp8o">deployed</a> ground-based robots and drones in combat operations, marking a significant shift in modern warfare. In a landmark operation in April 2026, Ukrainian forces <a href="https://www.telegraph.co.uk/world-news/2026/04/14/ukraine-forces-russians-to-surrender-using-only-robots/">captured</a> a Russian position using only unmanned systems — the first recorded instance of a robot-only assault in the conflict.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Flow Chart" src="https://www.recordedfuture.com/jp/media_1b10c93a859048bb11894c72a1e477fc54448b962.png?width=750&amp;format=png&amp;optimize=medium" width="1300" height="394" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 6:</strong></em> <em>A single vulnerability can simultaneously produce operational, data, safety, and strategic risks (Source: Recorded Future)</em></div>
          </div>
        </div>
        <p>As adoption scales, these risks become interconnected. A vulnerability affecting one platform or vendor could propagate across fleets, sites, or sectors, creating systemic exposure.</p>
        <p>At the same time, the pace of commercial development is outstripping regulatory oversight. Bank of America <a href="https://www.theregister.com/2025/12/09/humanoid_robot_security/">estimates</a> that as many as three billion humanoid robots could be in operation by 2060. This convergence of demographic pressure, advancing AI capabilities, and falling production costs suggests that large-scale human-machine coexistence is highly <a href="https://www.recordedfuture.com/jp/research/future-humanoid-robotics">probable</a>.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Summary of the factors fueling growth in robotics production" src="https://www.recordedfuture.com/jp/media_1b9f3585e3ed774b03686576399efbfd92c89cc5a.png?width=750&amp;format=png&amp;optimize=medium" width="1332" height="476" />
            </div>
          </div>
          <div>
            <div>
              <p><em><strong>Figure 7:</strong></em> <em>Summary of the factors fueling growth in robotics production, illustrated by</em> <em><a href="https://institute.bankofamerica.com/content/dam/transformation/humanoid-robots.pdf">Bank of America data</a></em></p>
              <p><em>(Source: Recorded Future)</em></p>
            </div>
          </div>
        </div>
        <p>Securing embodied AI systems is therefore not a peripheral technical issue. It is a strategic requirement that must be addressed before widespread deployment locks in insecure architectures at scale.</p>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_165d0d375ab46bd1deb3705cf840ece4d870213cb.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The Iran War: What You Need to Know]]></title>
            <link>https://www.recordedfuture.com/jp/blog/the-iran-war-what-you-need-to-know</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/the-iran-war-what-you-need-to-know</guid>
            <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Insikt Group tracks the cyber, physical, and geopolitical components of the US-Israeli strikes on Iran — with continuously updated threat analysis and scenarios.]]></description>
            <content:encoded><![CDATA[
        <p><em>Last updated: 1 May 2026 at 1500 GMT</em></p>
        <div>
          <div>
            <div>
              <p><strong>New from Insikt Group: Iran War — Future Scenarios and Business Implications</strong></p>
              <p>Insikt Group has published a dedicated Cone of Plausibility analysis examining how the Iran conflict could evolve over the next 6–12 months — from a fragile ceasefire baseline to regional war, regime collapse, and nuclear crisis. Each scenario includes business implications and 0–90 day priority actions.<a href="https://www.recordedfuture.com/jp"></a></p>
            </div>
          </div>
          <div>
            <div><a href="https://www.recordedfuture.com/jp/research/iran-war-future-scenarios">Read the full analysis.</a></div>
          </div>
        </div>
        <p>This report is updated as the situation evolves across the geopolitical, cyber, and influence operations dimensions of this conflict. It will be of greatest interest to organizations in the US, Israel, and Gulf states concerned about targeting by Iranian state-sponsored or state-aligned threat actors, as well as those with exposure to energy markets, maritime shipping, and critical infrastructure potentially impacted by regional escalation.</p>
        <h3>The Latest Updates</h3>
        <h3>Geopolitical Landscape</h3>
        <ul>
          <li><strong>Iran’s hardliners are driving strategic deadlock, blockade resilience, and Strait closure.</strong> Insikt Group assesses Iran’s calculus is very likely shaped by IRGC influence and hardliner dominance: Supreme Leader Khamenei’s April 30 <a href="https://www.reuters.com/world/middle-east/irans-supreme-leader-mojtaba-khamenei-says-new-phase-taking-shape-gulf-strait-2026-04-30/">statement</a> frames Iranian control of the Strait of Hormuz as a post-American regional order, chief negotiator Ghalibaf has <a href="https://www.jns.org/news/world/ghalibaf-said-to-step-down-as-irans-top-negotiator-amid-internal-rifts">reportedly</a> resigned after a reprimand for raising nuclear issues in talks, and Iran’s public position has converged on a single precondition — the US must lift its naval blockade before negotiations can resume.</li>
          <li><strong>The US blockade has cut Iranian oil exports by ~70% but has not achieved its strategic objectives.</strong> Iran faces critical oil storage constraints — Bloomberg reported 22 days or less of unused capacity as of April 27 — yet Insikt Group assesses Iran can very likely survive the current pressure level, and the full financial blow will lag three to four months as ~130 million barrels already loaded before the blockade remain in transit.</li>
          <li><strong>Maritime standoff deepens as Iran seizes vessels, lays additional mines, and ceasefire talks stall.</strong> Following the US seizure of the Touska, the IRGC seized the MSC Francesca and Epaminondes and fired on a third vessel transiting the Strait; the IRGC reportedly dropped additional mines during the final week of April, and the Pentagon assesses mine-clearing could take up to six months after a formal end to hostilities.</li>
        </ul>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1639b94af082849a6929a572441c5012d6e2eb22d.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Risk Scenarios for the US’s Strategic Pivot]]></title>
            <link>https://www.recordedfuture.com/jp/research/us-strategic-pivot</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/us-strategic-pivot</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The United States (US) is shifting toward a more force-driven security strategy primarily relying on military operations and economic pressure to counter transnational criminal organizations and limit Chinese, Russian, and Iranian influence in the Western Hemisphere.]]></description>
            <content:encoded><![CDATA[
        <h2>Summary</h2>
        <p>The United States (US) is shifting toward a more force-driven security strategy primarily relying on military operations and economic pressure to counter transnational criminal organizations and limit Chinese, Russian, and Iranian influence in the Western Hemisphere.</p>
        <p>Regional outcomes diverge across three core scenarios:</p>
        <ul>
          <li>US-aligned authoritarian cooperation with fragile stability</li>
          <li>Political fragmentation enabling criminal expansion and governance breakdown</li>
          <li>A strategic realignment toward BRICS that reduces US influence and increases great power competition</li>
        </ul>
        <p>Each scenario increases the risks of political instability, regulatory fragmentation, and cyber threats, including increased surveillance, cybercrime, and targeting of critical infrastructure and multinational businesses.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Chart of possible scenarios resulting from the US’s strategic pivot to Western Hemisphere security" src="https://www.recordedfuture.com/jp/media_184d5d3f6d8f667e949ae56dfe34d14ab26453183.png?width=750&amp;format=png&amp;optimize=medium" width="1132" height="634" />
            </div>
          </div>
          <div>
            <div>
              <p><em><strong>Figure 1:</strong></em> <em>Overview of possible scenarios resulting from the US’s strategic pivot to Western Hemisphere security</em></p>
              <p><em>(Source: Recorded Future)</em></p>
            </div>
          </div>
        </div>
        <h2>Analysis</h2>
        <p>The US <a href="https://www.whitehouse.gov/wp-content/uploads/2025/12/2025-National-Security-Strategy.pdf">2025 National Security Strategy</a> formalized a shift toward hemispheric priorities and narrower strategic objectives. This shift had been building throughout President Donald Trump’s first term:</p>
        <ul>
          <li>January 2025: An <a href="http://whitehouse.gov/presidential-actions/2025/01/designating-cartels-and-other-organizations-as-foreign-terrorist-organizations-and-specially-designated-global-terrorists/">executive order</a> formally designates cartels as foreign terrorist organizations.</li>
          <li>August 2025: The president signed a <a href="https://www.nytimes.com/2025/08/08/us/trump-military-drug-cartels.html">classified order</a> directing military action against cartels beyond traditional law-enforcement frameworks.</li>
          <li>September 2025: US forces carried out the first strike on alleged drug-trafficking vessels. Since then, more than <a href="https://www.nytimes.com/article/trump-drug-boat-strikes-timeline.html">two dozen</a> kinetic strikes in the Caribbean and Eastern Pacific have resulted in over 100 fatalities.</li>
          <li>December 2025: The US begins <a href="https://www.bloomberg.com/news/newsletters/2025-12-17/trump-turns-up-the-heat-on-venezuela-s-maduro-with-oil-blockade">seizing</a> oil tankers accused of sanctions evasion.</li>
          <li>January 2026: The US launches a special <a href="https://www.brookings.edu/articles/making-sense-of-the-us-military-operation-in-venezuela/">operation</a> to capture and extract Venezuelan President Nicolás Maduro to face drug trafficking charges in court.</li>
          <li>March 2026: The US <a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/03/the-united-states-to-host-the-shield-of-the-americas-summit">launches</a> the “Shield of the Americas” initiative, intended to counter drug trafficking, transnational criminal networks, and illegal migration in the Western Hemisphere. In an address to Congress two weeks later, the commander of US Southern Command reinforced a greater military role in countering foreign terrorist organizations (FTOs) and managing other security priorities in the region.</li>
        </ul>
        <p>Taken together, these moves suggest a shift from a law-enforcement-led regional security model toward more overt coercion driven by military intervention.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="US military activity in Latin America has increased significantly since the August 2025 order directing chart" src="https://www.recordedfuture.com/jp/media_18d2414b9b576da747707cc8bd5a0864c3d6cd795.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="976" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 2:</strong></em> <em>US military activity in Latin America has increased significantly since the August 2025 order directing action against cartels (Source:</em> Recorded Future<em>)</em></div>
          </div>
        </div>
        <p>At a strategic level, US objectives remain centered on limiting transnational criminal activity and countering external competitors. Transnational criminal organizations are framed as a primary threat vector due to their role in narcotics trafficking and financial crime. China’s growing economic presence, anchored in <a href="https://www.cfr.org/backgrounders/china-influence-latin-america-argentina-brazil-venezuela-security-energy-bri">trade</a> and <a href="https://www.cfr.org/backgrounders/chinas-massive-belt-and-road-initiative">Belt and Road Initiative</a> (BRI) infrastructure, is also seen as a threat to US interests. Russia and Iran maintain more targeted but persistent footholds, particularly through surveillance coordination in Nicaragua, Cuba, and Venezuela. US policy is oriented toward constraining adversary influence while reinforcing its own economic and security partnerships. The US is pursuing these objectives through a combination of expanded military operations, law enforcement activity, and coercive economic measures, including tariffs and sanctions tied to political alignment.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="US naval and air assets have been deployed to the Caribbean" src="https://www.recordedfuture.com/jp/media_1ab5267640450aa0511cee30072624e50e2d4b14d.png?width=750&amp;format=png&amp;optimize=medium" width="1600" height="1143" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 3:</strong></em> <em>US naval and air assets have been deployed to the Caribbean to counter drug trafficking (Source:</em> <em><a href="https://www.newsweek.com/list-us-navy-ships-venezuela-trump-maduro-2123734">Newsweek</a>)</em></div>
          </div>
        </div>
        <h2>Scenarios</h2>
        <p>The shift toward prioritizing US influence in the Western Hemisphere over other national security objectives will likely reshape the regional risk landscape. To assess the potential medium-term outcomes, Recorded Future identified key drivers and established baseline assumptions that underpin scenario development.</p>
        <div>
          <div>
            <div>
              <h3>Drivers</h3>
            </div>
            <div>
              <h3>Assumptions</h3>
            </div>
          </div>
          <div>
            <div>
              <p>● Increased US military interventions against alleged transnational criminal organizations TCOs and enablers</p>
              <p>● Expanding role of TCOs and armed groups in regional instability</p>
              <p>● Existing security cooperation between the US and Latin America LATAM governments</p>
              <p>● Growing Chinese economic and infrastructure investment in LATAM</p>
              <p>● Historical and ongoing relationships between Russia, Iran, and LATAM (notably Venezuela, Cuba, and Nicaragua)</p>
              <p>● Increased adoption of commercial spyware and surveillance tools by LATAM governments</p>
            </div>
            <div>
              <p>● US policy will prioritize countering malign influence and security threats within the Western Hemisphere over other regions</p>
              <p>● Policy direction will remain sensitive to domestic political cycles in both the US and Latin America, creating potential for shifts following elections</p>
              <p>● The US will favor limited-duration, high-impact interventions over prolonged military or large-scale nation-building efforts</p>
              <p>● China will continue to expand its economic and diplomatic engagement in Latin America, positioning itself as an alternative partner (instead of the US</p>
              <p>● Russia and Iran will seek to exploit opportunities to challenge US influence in the region, particularly through relationships with anti-US governments</p>
              <p>● Regional governments will continue to leverage emerging surveillance and cyber capabilities to address internal security challenges</p>
            </div>
          </div>
        </div>
        <p>The following scenarios explore potential outcomes as the US reorients its security strategy toward the Western Hemisphere:</p>
        <h3>Scenario 1: Initial Authoritarian Stability</h3>
        <p>In this scenario, the US successfully asserts influence over historically adversarial authoritarian regimes, notably Venezuela and Cuba. These governments pivot toward cooperation with the US on trade, energy, and security, while maintaining repressive political systems domestically. US intervention has already reshaped Venezuela’s leadership and opened pathways for Western energy investment, while Cuba has responded to continued pressure by showing openness to economic reforms. Meanwhile, democracies like Colombia and Ecuador may adopt more coercive internal security postures, particularly in states facing cartel violence, in response to US pressure.</p>
        <p>The US takes more aggressive measures to deter and counter non-Western infrastructure investments, leading to a relative diminishment in the influence of China and Russia as US engagement deepens. However, both powers will likely retain significant hemispheric influence and may pursue limited, asymmetric responses rather than direct confrontation.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="interim Venezuelan president Delcy Rodriguez" src="https://www.recordedfuture.com/jp/media_111b2e95859bd404752f47f5313e6d94a6f625b18.png?width=750&amp;format=png&amp;optimize=medium" width="478" height="718" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 4:</strong></em> <em>US President Trump has praised interim Venezuelan president Delcy Rodriguez (Image source:</em> <em><a href="https://www.lemonde.fr/en/international/article/2026/03/05/trump-and-venezuela-s-rodriguez-exchange-lavish-praise-amid-oil-partnership_6751110_4.html">Le Mond</a>e)</em></div>
          </div>
        </div>
        <div>
          <div>
            <div>
              <h3>Organizational Risks</h3>
            </div>
            <div>
              <h3>Cyber Risks</h3>
            </div>
          </div>
          <div>
            <div>
              <p>● <strong>Operational disruption:</strong> This outcome may appear stable in the short term but is likely structurally fragile, as it depends on sustained coercive pressure and political alignment. Electoral changes will almost certainly bring in a new set of priorities and approaches to the region. This will create an operating environment at high risk of disruption.</p>
              <p>● <strong>Reputational damage:</strong> Companies seen as being too close to one political bloc or regime may face reputational damage as policies reverse.</p>
            </div>
            <div>
              <p>● <strong>Chinese and Russian state-sponsored actors</strong> will likely increase cyber operations against expanding US assets in the region, particularly in telecommunications and energy, to gather information or conduct strategic, limited disruption.</p>
              <p>● <strong>Surveillance, including the use of commercial spyware</strong>, will almost certainly increase as states escalate law enforcement operations against cartels and non-state armed groups.</p>
            </div>
          </div>
        </div>
        <h3>Scenario 2: Fragmentation and Criminal Expansion</h3>
        <p>US intervention produces a political backlash, weakening democracies and fueling the collapse of transitional regimes. Inconsistent or heavy-handed military actions against alleged criminals increase public outrage, leading to electoral turnover and instability. As governments escalate repression to maintain control, resistance movements and localized violence intensify, further eroding state authority. This dynamic creates governance vacuums that strengthen TCOs, particularly in border regions. In this environment, cartels and armed groups re-emerge as dominant power brokers, reversing gains in regional security and leading to a resurgence in criminal activity and violence.</p>
        <div>
          <div>
            <div>
              <h3>Organizational Risks</h3>
            </div>
            <div>
              <h3>Cyber Risks</h3>
            </div>
          </div>
          <div>
            <div>
              <p><strong>● Operational disruption:</strong> Violence and corruption will likely increase instability. Further, regime collapse in Cuba or Venezuela would provide a haven for criminal groups.</p>
              <p><strong>● Financial fraud:</strong> Expanding criminal influence increases the likelihood of cyber or violent crimes, such as fraud or extortion.</p>
            </div>
            <div>
              <p><strong>● Industrial-scale cybercrime operations,</strong> similar to the <a href="https://www.cnn.com/2026/01/04/asia/china-myanmar-scam-crime-families-intl-hnk-dst">scam call centers</a> in under-governed regions of Myanmar, may increase under cartel control. This would scale up <a href="https://home.treasury.gov/news/press-releases/sb0400">fraud</a>, cryptocurrency theft, and money laundering operations, likely targeting Spanish-, Portuguese-, and English-speaking populations.</p>
              <p><strong>● Internet blackouts</strong> are used as a weapon by governments struggling to maintain control, causing instability in communications and other infrastructure.</p>
            </div>
          </div>
        </div>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Chancay “megaport” in Chancay, Peru" src="https://www.recordedfuture.com/jp/media_1d79f6835c4ded2959094ccfc0073104712bc799d.png?width=750&amp;format=png&amp;optimize=medium" width="960" height="600" />
            </div>
          </div>
          <div>
            <div>
              <p><em><strong>Figure 5:</strong></em> <em>Chancay “megaport” in Chancay, Peru, is funded under China’s Belt and Road Initiative</em></p>
              <p><em>(Image source:</em> <em><a href="https://chinaglobalsouth.com/analysis/belt-road-initiative-record-2025/">China’s Global South Project)</a></em></p>
            </div>
          </div>
        </div>
        <h3>Scenario 3: Accelerated Pivot to China</h3>
        <p>The US’s overreliance on military solutions at the expense of soft power enables China to position itself as an appealing alternative partner by offering positive incentives and stable, long-term policy-making. As a result, LATAM governments across the ideological spectrum quietly accelerate their pivot toward China, building on existing trade and investment ties. As this trend continues, LATAM governments feel emboldened to adopt more overt mechanisms to resist US influence, including legal challenges to military operations and regulations targeting US companies. Both China and Russia are able to increase their economic footprint and political influence in the region, especially if the US becomes less willing to maintain a consistent security presence.</p>
        <div>
          <div>
            <div>
              <h3>Organizational Risks</h3>
            </div>
            <div>
              <h3>Cyber Risks</h3>
            </div>
          </div>
          <div>
            <div>
              <p><strong>● Competitive disadvantage:</strong> Expanding Chinese and Russian economic influence may displace US companies in key sectors such as energy, agriculture, telecommunications, and infrastructure, reducing market access and long-term competitiveness</p>
              <p><strong>● Legal and compliance failure:</strong> A more hostile regulatory environment could limit operations or force costly restructuring</p>
            </div>
            <div>
              <p><strong>● China and Russia gain a greater surveillance foothold,</strong> taking advantage of LATAM countriesʼ construction of telecommunications and “<a href="https://www.ifri.org/sites/default/files/migrated_files/documents/atoms/files/ekman_smart_cities_battleground.pdf">Smart Cities</a>ˮ infrastructure using companies like Huawei, as well as the use of Russian digital <a href="https://app.recordedfuture.com/portal/research/insikt/doc:2Oyt8T">surveillance</a> technology, to ensure visibility.</p>
              <p><strong>● Increased data sovereignty and related technology regulations</strong> can disrupt regional and global business operations, particularly for cloud services, financial systems, and multinational supply chains.</p>
            </div>
          </div>
        </div>
        <h2>Outlook</h2>
        <p>The scenarios are not mutually exclusive: multiple outcomes can play out in different countries or regions across Latin America. Below are key indicators to monitor to anticipate which outcome is more likely to emerge:</p>
        <ul>
          <li><strong>Election Outcomes:</strong> Colombia, Peru, and Brazil all have elections in the next year; a change in leadership may reflect popular dissatisfaction with the current government’s foreign policy, precipitating a policy shift. Furthermore, a decisive Republican defeat in the US midterms may reduce appetite for foreign intervention, leading to inconsistent policy.</li>
          <li><strong>US Intervention in Cuba:</strong> The US government is strongly signaling its intention to replace or significantly reform Cuba’s long-standing Communist regime. The success of the operation and the willingness of the US to back a transitional or reform government will determine which scenario described above plays out.</li>
          <li><strong>LATAM Security Cooperations:</strong> Criminal groups and militias thrive in contested or under-governed regions, such as along borders. Look for signed agreements and joint operations as signs of cooperation — or the lack thereof signalling potential breakdown in security coordination and a greater likelihood of criminal expansion.</li>
          <li><strong>The China Alternative:</strong> While China is likely to want to avoid direct confrontation over influence in the Western Hemisphere, the CCP may seek to offer more positive incentives to increase its economic footprint in the region, such as continued investments in ports, telecommunications, and other critical infrastructure.</li>
          <li><strong>The War in Iran:</strong> Even though it’s happening on the other side of the world, the Iran war is likely to shape how the US pursues military operations in the Western Hemisphere. Battlefield setbacks could decrease appetite for military intervention, or energy security pressures could increase the imperative to ensure influence.</li>
        </ul>
        <h2>Mitigations</h2>
        <ul>
          <li><strong>Strengthen cyber resilience and third-party risk management:</strong> Enhance monitoring and defenses for critical infrastructure, telecommunications, and cloud environments. Use Recorded Future’s <strong>Geopolitical Intelligence</strong> module to understand the surveillance risk in countries where you operate. Conduct regular assessments of vendors and partners to reduce exposure to espionage, surveillance, and cybercrime.</li>
          <li><strong>Prepare for regulatory fragmentation and data localization requirements:</strong> Develop flexible compliance frameworks that can adapt to diverging data sovereignty laws, sanctions regimes, and trade restrictions. This includes establishing localized data storage where necessary and maintaining legal contingency plans for rapid policy changes.</li>
          <li><strong>Enhance crisis response and continuity planning:</strong> Build scenario-based contingency plans for political instability, violence, or infrastructure disruption (such as internet outages or supply-chain interruptions), which are routinely monitored in the Geopolitical Intelligence module. Contingency planning should include evacuation preparation, alternative logistics routes, and redundant communications systems to ensure operational continuity across volatile environments.</li>
        </ul>
        <h2>Further Reading</h2>
        <div>
          <div>
            <div>
              <h3>Source</h3>
            </div>
            <div>
              <h3>Title</h3>
            </div>
          </div>
          <div>
            <div><strong>Insikt Group</strong></div>
            <div><a href="https://www.recordedfuture.com/jp/research/latin-america-and-the-caribbean-cybercrime-landscape">Latin America and the Caribbean Cybercrime Landscape</a></div>
          </div>
          <div>
            <div><strong>Insikt Group</strong></div>
            <div><a href="https://www.recordedfuture.com/jp/research/understanding-and-anticipating-venezuelan-government-actions">Understanding and Anticipating Venezuelan Government Actions</a></div>
          </div>
          <div>
            <div><strong>Recorded Future Blog</strong></div>
            <div><a href="https://www.recordedfuture.com/jp/blog/latin-america-cybersecurity-turning-point">Latin America’s Cybersecurity Turning Point: From Reactive Defense to Threat Intelligence</a></div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_131592ae03a082c06f2e749215e98832923fd7b5d.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Building with AI: Here's What No Briefing Will Tell You]]></title>
            <link>https://www.recordedfuture.com/jp/blog/building-with-ai</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/building-with-ai</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[What building with AI for three months revealed about four leadership blind spots executives can't afford to ignore: the comprehension gap, eroding competitive moats, deployment complexity, and what "senior" really means now.]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>
              <ul>
                <li>Executives making AI decisions without hands-on building experience have a comprehension gap that no briefing can close.</li>
                <li>AI is rapidly eroding most traditional competitive moats, and proprietary data's real value now comes down to how long it would take a competitor to reconstruct it.</li>
                <li>As AI equalizes development speed, the most valuable engineers are those with sharp judgment and companies need to actively protect the foundational skills that make that judgment possible</li>
              </ul>
            </div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_16b1d84f79c0e64645df026a3bf75634a68678460.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[The Money Mule Solution: What Every Scam Has in Common]]></title>
            <link>https://www.recordedfuture.com/jp/blog/money-mule-solution</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/money-mule-solution</guid>
            <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Learn how mule account intelligence — not tactic-tracking — is the most effective lever for preventing APP fraud before funds move.]]></description>
            <content:encoded><![CDATA[
        <div>
          <div>
            <div>
              <ul>
                <li><strong>Scams are a $450B–$1T global problem</strong>, and unlike card fraud, they don't require a breach; just convincing a victim to send money themselves.</li>
                <li><strong>The mule account is the most stable target</strong>: every scam needs an exit point, and intelligence gathered before a transaction occurs is more actionable than behavioral monitoring after the fact.</li>
                <li><strong>CYBERA's approach uses agentic personas</strong> to engage active scammers and extract verified mule account details, confirmed intelligence, not probabilistic scoring.</li>
                <li><strong>Regulatory pressure is accelerating</strong>: the UK already mandates APP fraud reimbursement, and the US, Canada, and Australia are following, raising the stakes for institutions that don't act proactively.</li>
              </ul>
            </div>
          </div>
        </div>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_163af009dcce942c2656525fa83eab645571db892.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Lazarus Doesn't Need AGI]]></title>
            <link>https://www.recordedfuture.com/jp/blog/lazarus-does-not-need-agi</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/lazarus-does-not-need-agi</guid>
            <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Explore the 2026 Claude Mythos breach, supply chain risks, and the $2B+ crypto theft pipeline.]]></description>
            <content:encoded><![CDATA[
        <p>Last week’s <a href="https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users"></a><a href="https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users">reporting</a> on unauthorized access to Claude Mythos reads as an AI security story. It is also, structurally, a North Korea (DPRK) story. Even if the current suspects turn out to be Discord hobbyists.</p>
        <p>Mythos was meant to be contained. Within hours of the public <a href="https://www.anthropic.com/project/glasswing"></a><a href="https://www.anthropic.com/project/glasswing">Project Glasswing announcement</a>, a third-party contractor environment became the access vector. Not because Anthropic did something wrong. Because controlled release, at the scale modern enterprise software operates, is a goal rather than a guarantee.</p>
        <p>The interesting question isn’t who got in this time. It’s who gets in next, and their economics.</p>
        <h2>What happened?</h2>
        <p>The group accessed Mythos the same day it was announced, guessing the endpoint based on Anthropic’s naming conventions for prior models. The vector was an individual employed at a third-party contractor, not Anthropic’s core infrastructure. Source characterizations point to a research community “not wreaking havoc” with the model.</p>
        <h3>The misread</h3>
        <p>If the coverage only centers on Anthropic’s security posture or the AI safety debate, we’re missing an important angle.</p>
        <p>The structural signal is that any preview or controlled-access model release has porous boundaries by design. Access controls on paper (contracts, NDAs, approved vendor lists) differ from those in practice. Every partner brings their own contractors, endpoints, and people with legitimate credentials and uneven security hygiene. That is the real control surface, not the cryptographic perimeter around the model itself. Which makes this a supply chain problem that happens to be about AI, not an AI problem that happens to involve vendors.</p>
        <h3>The blind spot</h3>
        <p>AI policy discourse is locked on US versus China, including energy, chip controls, export rules, sovereign AI posture, and who wins the race.</p>
        <p>Structurally missing from the larger conversation is the one state actor whose entire foreign currency revenue stream is cyber-enabled theft. DPRK doesn’t need to win any race. They need a 20-30% productivity gain in existing operations.</p>
        <p>The pipeline is documented. Insikt Group’s <a href="https://www.recordedfuture.com/jp/research/crypto-country-north-koreas-targeting-cryptocurrency"></a><em><a href="https://www.recordedfuture.com/jp/research/crypto-country-north-koreas-targeting-cryptocurrency">Crypto Country</a></em> estimated that regime-linked cryptocurrency theft reached roughly $3 billion through 2023. The <a href="https://www.state.gov/releases/office-of-the-spokesperson/2025/10/joint-statement-of-the-multilateral-sanctions-monitoring-team-msmt-on-the-report-covering-dprk-cyber-and-it-worker-activities">Multilateral Sanctions Monitoring Team</a> (successor to the UN Panel of Experts after Russia’s 2024 veto) has since done the harder primary work. MSMT’s October 2025 report documents $2.8 billion stolen from cryptocurrency companies between January 2024 and September 2025 across more than 40 heists, with proceeds explicitly tied to WMD and ballistic missile program funding. <a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/01/the-democratic-peoples-republic-of-koreas-violations-and-evasions-of-un-sanctions-through-cyber-and-it-worker-activities/">The State Department updated the tally in January 2026</a>: another $400 million stolen in the three months since publication, bringing the 2025 totals above $2 billion.</p>
        <p><strong>Every successful crypto exchange intrusion ends up on a launch pad.</strong></p>
        <h2>Why North Korea wants the next model</h2>
        <p>Crypto exchange intrusions are labor-intensive at every phase. Recon, social engineering at scale (fake developer personas on GitHub and LinkedIn, spear-phishing of individual engineers at wallet providers), credential harvesting, post-exploit lateral movement, key extraction, and <a href="https://www.amazon.com/Lazarus-Heist-Hollywood-Finance-Inside/dp/024155425X"></a><a href="https://www.amazon.com/Lazarus-Heist-Hollywood-Finance-Inside/dp/024155425X">laundering</a>.</p>
        <p>Agentic capability compresses the cycle to include the same operator-hours, more successful intrusions, and more stolen $$$ per operator.</p>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_15f31a75ee8d7950daa388a7f6eaceb059a2ebffa.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1215" />
        </p>
        <p>Bybit is an easy example. <a href="https://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hack">The FBI attributed approximately $1.5 billion in stolen virtual assets to TraderTraitor</a> in February 2025. <a href="https://fortune.com/crypto/2025/03/04/north-korea-bybit-hack-ethereum-safe-dprk-lazarus-group-tradertraitor/">The intrusion chain</a> ran months of patient targeting against a single Safe{Wallet} system administrator via phishing, followed by post-compromise operational patience. These types of attacks are expensive, time-intensive, and still extraordinarily productive.</p>
        <p>Lazarus and TraderTraitor don’t need AGI. They need the productivity lift that turns a junior operator into a senior one and shaves weeks off the planning phase. It doesn’t have to be Mythos specifically. Any comparable capability through a comparable vector does the job.</p>
        <p>Better tools mean more successful intrusions. More successful intrusions mean more stolen crypto. More stolen crypto means more missiles.</p>
        <h2>Three access patterns</h2>
        <p>Three different tradecraft patterns keep getting conflated in media coverage. They are not the same TTP, and treating them as one weakens the response on all three.</p>
        <p><strong>1. Contractor misuse.</strong> A legitimately credentialed employee at a third-party vendor uses their access for unauthorized purposes. This is the Mythos story. The credentials and access are real, though the intent is variable. Defenses (easy to say, hard to do well): telemetry, behavioral monitoring, and least-privilege scoping at the vendor tier.</p>
        <p><strong>2. Fraudulent hiring.</strong> An adversary places its own operatives inside the target through stolen or synthetic identities, often via remote IT contracting. This is the DPRK IT worker scheme. Insikt’s <a href="https://www.recordedfuture.com/jp/research/inside-the-scam-north-koreas-it-worker-threat"></a><em><a href="https://www.recordedfuture.com/jp/research/inside-the-scam-north-koreas-it-worker-threat">Inside the Scam</a></em> documents PurpleBravo’s infrastructure: front companies in China spoofing legitimate IT firms, and a malware ecosystem (BeaverTail, InvisibleFerret, OtterCookie) targeting the cryptocurrency industry. The credentials are real, but the identities are fake. Defenses: identity verification at hire (in-person interviews to avoid AI tricks), ongoing personnel vetting, geographic and behavioral baselining.</p>
        <p><strong>3. Supply chain compromise</strong>. A trusted vendor’s systems get breached, and the attacker uses that vendor’s legitimate distribution channel to reach the real target. <a href="https://intelligence2risk.substack.com/p/digital-supply-chain-breach"></a><a href="https://intelligence2risk.substack.com/p/digital-supply-chain-breach">TeamPCP’s March 2026 LiteLLM compromise</a> hit the AI toolchain directly, poisoning Trivy (a defensive security scanner) to reach a package with 95 million monthly downloads. Defenses: build-pipeline integrity, dependency monitoring, signed artifacts.</p>
        <p>These three attack vectors converge on the same truth. Any preview or limited-release AI program that depends on third parties is exposed to all three vectors simultaneously. DPRK is the actor most motivated across the full triangle because the revenue case is specific, measurable, and directly beneficial for the regime. They are incentivized to be “AI native.”</p>
        <h3>So what?</h3>
        <p>In the security industry, we need to stop thinking about AI access as purely a lab problem when it’s also a sanctions problem. The great-power competition framing obscures the actor already online, with a rich history of monetizing cyber heists to fund missiles.</p>
        <p>“Limited release” is a wonderful bumper sticker. The AI reality, from a threat-modeling perspective, is a countdown to turbo-charging adversarial capabilities.</p>
        <h3>Now what?</h3>
        <p>The honest conversation is that perimeter-style AI “controlled access” is less effective against State-sponsored adversaries. A productive security path is a distinct preview infrastructure, aggressive telemetry, canaries, and third-party access tied to personnel-level vetting rather than contractual attestation. (Guessable endpoints should be the first thing dead.)</p>
        <p>Crypto exchanges and custodians: your threat model needs to anticipate what Lazarus can do 3 to 6 months from now, not what they did last quarter. Assume they improve faster than your defenses do.</p>
        <p>Policymakers: DPRK is a first-class entity in AI access governance. The Multilateral Sanctions Monitoring Team framework already documents cyber-enabled sanctions evasion thoroughly. What it doesn’t yet do is name AI capability access as a sanctions-relevant category. Dual-use export controls have governed the transfer of semiconductor and missile technology for decades. AI capability is the obvious next category.</p>
        <p>Corporate CISOs (outside the AI-lab orbit): your third-party contractor environments are now inside the AI capability threat surface, whether you opted in or not. Inventory accordingly.</p>
        <h2>Close</h2>
        <p>
          <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1ca2bf6995854d8b040cb1aac51172cac2a249bf3.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1282" />
        </p>
        <p>Mythos is a preview of an access pattern. Any actor whose business model is stealing money to build weapons will find the third-party seam. This time, it was hobbyists. DPRK has spent two decades proving why nonproliferation is the right frame here.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1cd4a735414dc9382080bc199d70d19bf3a8c153e.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[From Overwhelmed to Autonomous: Rethinking Threat Intelligence in 2026]]></title>
            <link>https://www.recordedfuture.com/jp/blog/rethinking-threat-intelligence-in-2026</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/rethinking-threat-intelligence-in-2026</guid>
            <pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[For most security teams today, volume and access to intelligence isn’t the problem. It’s the speed at which they can turn that intelligence into action. .]]></description>
            <content:encoded><![CDATA[
        <h2>Key Takeaways</h2>
        <ul>
          <li>The real challenge in cybersecurity isn’t intelligence or visibility, it’s speed. Attackers operate at machine speed, while most organizations are still constrained by manual, human-driven workflows.</li>
          <li>Traditional threat intelligence falls short because it stops at insight. To reduce risk effectively, intelligence must not only inform decisions but also actively drive response.</li>
          <li>Fragmentation across cyber, fraud, and third-party risk creates exploitable gaps. A unified, intelligence-driven approach is essential to understanding and addressing modern threats holistically.</li>
          <li>Autonomous defense is the path forward. By enabling continuous, real-time action across the attack surface, organizations can close the speed gap and move from reactive security to proactive risk reduction.</li>
        </ul>
        <p>For most security teams today, volume and access to intelligence isn’t the problem. It’s the speed at which they can turn that intelligence into action.</p>
        <p>Over the last decade, organizations have invested heavily in threat intelligence and cybersecurity. Global security spending has surged <a href="https://www.gartner.com/en/newsroom/press-releases/2024-08-28-gartner-forecasts-global-information-security-spending-to-grow-15-percent-in-2025">past $200 billion annually, growing double digits year over year,</a> while <a href="https://nationalcioreview.com/articles-insights/information-security/the-cost-of-good-security-analyzing-2024s-cyber-budget-trends">security’s share of IT budgets has climbed from under 9% to more than 13%</a>. Most CISOs report continued budget increases, and enterprises are making billion-dollar investments in intelligence capabilities.</p>
        <p>And yet, breaches still happen. Fraud still slips through. Third-party risk still catches teams off guard. The issue isn’t visibility. It’s the growing gap between how fast threats move and how fast organizations can respond.</p>
        <p>Attackers now operate at machine speed, leveraging automation and AI to identify vulnerabilities, launch campaigns, and exploit opportunities in real time. Most security teams, however, are still constrained by manual workflows, fragmented systems, and processes that require human intervention at every step. That mismatch is where risk can accumulate—and where even well-resourced teams fall behind.</p>
        <div>
          <div>
            <div>What many organizations are discovering is that the problem isn’t a lack of intelligence. The problem is their inability to turn the insights into contextualized, intelligence-led actions.</div>
          </div>
          <div>
            <div></div>
          </div>
        </div>
        <h2>The Hidden Cost of Human-Speed Security</h2>
        <p>For many organizations, this gap shows up in subtle but compounding ways. Analysts spend hours triaging alerts, trying to determine which signals actually matter. Security teams often discover incidents after damage has already occurred, not because the data wasn’t there, but because it couldn’t be acted on quickly enough. Across the organization, teams responsible for cyber operations, fraud, and third-party risk operate in silos, each with their own tools and workflows, rarely sharing a unified view of risk.</p>
        <p>At the same time, expectations from leadership have shifted. Executives and boards no longer want activity metrics—<a href="https://www.idc.com/resource-center/blog/from-cyber-risk-to-business-risk-how-cisos-should-engage-the-board-in-2026">they want clear evidence that security investments are reducing business risk</a>. But when intelligence is not clearly connected to action from security teams, that proof becomes difficult to deliver.</p>
        <p>Traditional threat intelligence was designed to inform decisions made by humans, at human speed. In today’s environment, that model introduces delay. And delay, in cybersecurity, is increasingly indistinguishable from exposure.</p>
        <h2>Intelligence That Acts, Not Just Informs</h2>
        <p>Closing the speed gap requires more than incremental improvements. It requires a shift in how organizations think about intelligence altogether. Moving forward, the future of cybersecurity must be more than just intelligence-led—it must be intelligence-acted.</p>
        <p>In this model, intelligence doesn’t sit in dashboards waiting for analysts to interpret it. It continuously correlates signals, prioritizes what matters, and drives action across the security environment automatically. Instead of asking teams to move faster, it enables the entire system to operate at the speed of the threat.</p>
        <p>This is the foundation of autonomous defense, and it’s the future of effective, machine-speed cybersecurity.</p>
        <h2>From Reactive to Autonomous: A New Operating Model</h2>
        <p>Autonomous defense fundamentally changes the role of the security team. Rather than serving as the bottleneck between detection and response, analysts become decision-makers operating on top of continuously running intelligence.</p>
        <p>Recorded Future’s <a href="https://www.recordedfuture.com/jp/products/autonomous-threat-operations">Autonomous Threat Operations</a> brings this model to life by eliminating the manual steps that slow teams down. It ingests and correlates intelligence from multiple sources, applies context in real time, and triggers actions across existing security tools—all without requiring constant human input.</p>
        <p>The impact of such a dramatic shift is immediate and measurable. Threat hunting becomes continuous instead of periodic. Alerts arrive enriched with context, reducing the time needed to investigate and respond. Detection and remediation workflows execute automatically, freeing analysts to focus on strategic threats rather than routine triage.</p>
        <p>Just as importantly, this approach transforms how organizations measure success. Instead of tracking activity—alerts processed, queries written, incidents reviewed—teams can demonstrate real outcomes: faster response times, reduced exposure, and a clearer connection between intelligence and risk reduction; the latter of which is becoming increasingly necessary for organizational buy-in.</p>
        <p>This is so much more than just adding another tool to the stack. Instead, it’s about making every existing control smarter, faster, and more effective. And it’s paying off. On average, <a href="https://app.userevidence.com/assets/1334BMEJ">security teams using Recorded Future save up to 100 hours per week through improved analyst productivity</a>, allowing teams to redirect effort toward threat hunting and proactive defense instead of repetitive manual analysis.</p>
        <h2>The Bigger Challenge: Fragmented Visibility Across the Attack Surface</h2>
        <p>Speed alone, however, is only part of the equation. Many organizations are also limited by how they view risk. Threats today don’t respect organizational boundaries. A phishing campaign can lead to credential theft, which can then be used to access systems, exploit third-party relationships, or enable fraudulent transactions. These events are connected, but still far too many organizations manage them in isolation.</p>
        <p>Cyber operations teams focus on internal threats. Fraud teams monitor transactions. Risk teams assess vendors. Each group has visibility into part of the problem, but no one has a complete picture. This fragmentation creates blind spots, and attackers are increasingly skilled at navigating between them.</p>
        <h2>A Unified Approach to Risk</h2>
        <p>To effectively reduce risk, organizations need more than faster response times. They need a connected understanding of their entire attack surface, along with the ability to act across it in a coordinated way.</p>
        <p>Recorded Future addresses this through four core solution areas—<a href="https://www.recordedfuture.com/jp/products/cyber-operations">Cyber Operations</a>, <a href="https://www.recordedfuture.com/jp/use-case/digital-risk">Digital Risk Protection</a>, <a href="https://www.recordedfuture.com/jp/products/third-party-intelligence">Third-Party Risk</a>, and <a href="https://www.recordedfuture.com/jp/products/payment-fraud-intelligence">Payment Fraud Intelligence</a>—all built on a single, integrated intelligence foundation.</p>
        <p>In <a href="https://assets.recordedfuture.com/Datasheets/2026_0313%20-%20CyberOps%20Datasheet.pdf">cyber operations</a>, this means moving beyond alert overload to real-time prioritization. Instead of forcing analysts to sift through volumes of data, intelligence surfaces the threats that are most relevant to the organization’s environment and enables immediate action. The combination of prioritization and automation allows teams to reduce noise while improving both detection speed and response quality.</p>
        <p>In <a href="https://assets.recordedfuture.com/Datasheets/2026_0313%20-%20Digital%20Risk%20Protection.pdf">digital risk protection</a>, the focus shifts beyond the traditional perimeter. Today’s attackers target brands, customers, and executives just as frequently as they target infrastructure. By monitoring the open, <a href="https://www.recordedfuture.com/jp/blog/dark-web-threat-intelligence">deep, and dark web</a>, Recorded Future provides visibility into impersonation campaigns, credential exposure, and emerging threats long before they impact the organization. More importantly, it enables rapid response, whether that means taking down fraudulent domains or preventing account takeover attempts.</p>
        <p><a href="https://assets.recordedfuture.com/Datasheets/Datasheet_Third-Party_Risk.pdf">Third-party risk</a> represents another growing challenge. As organizations expand their ecosystems, they inherit risk from vendors and partners, often without real-time visibility. Third-party involvement in breaches has reached a <a href="https://deepstrike.io/blog/cybersecurity-statistics-2025-threats-trends-challenges">staggering 30%, up from just 15% a year ago</a>. Static assessments and periodic reviews can’t keep pace with how quickly vendor risk evolves today. Continuous monitoring, grounded in real-world intelligence, allows organizations to detect issues earlier, respond faster, and maintain a more accurate understanding of their exposure.</p>
        <div>
          <div>
            <div>Threat intelligence-driven security is vital. It’s the eyes and ears of a security team. You can’t protect yourself against what you don’t know. A couple times now, Recorded Future has alerted us to something prior to the third-party vendor. That’s huge when we’re trying to protect our data.</div>
          </div>
          <div>
            <div>
              <p>Natalie Salisbury</p>
              <p>Strategic Threat Intelligence Analyst, Novavax</p>
            </div>
          </div>
        </div>
        <p>In the realm of <a href="https://assets.recordedfuture.com/Datasheets/2026_0310%20-%20Payment%20Fraud%20Intelligence.pdf">payment fraud</a> intelligence, the shift is equally significant. There were some <a href="https://www.recordedfuture.com/jp/research/annual-payment-fraud-intelligence-report-2024">269 million records posted</a> across dark and clear web platforms in 2024, and a tripling of certain e-skimmer infections. It’s important to keep in mind that fraud doesn’t begin at the moment of transaction. Rather, it begins much earlier, in the environments where stolen data is exchanged and tested. Recorded Future provides comprehensive coverage across the complete payment fraud lifecycle. Sophisticated cleanup and normalization techniques result in better data quality and richer data sets, reducing manual research and enabling high confidence mitigation actions. By identifying these signals upstream and intervening, organizations can stop fraud before it’s executed, reducing both financial loss and customer impact.</p>
        <h2>One Intelligence Foundation. Total Visibility.</h2>
        <p>What makes this approach fundamentally different is that these capabilities are not delivered as isolated solutions. They are unified through the <a href="https://www.recordedfuture.com/jp/platform">Recorded Future Intelligence Platform</a>, which correlates data across millions of sources and billions of entities to provide a single, coherent view of risk.</p>
        <p>This unified foundation enables organizations to connect signals that would otherwise remain siloed. Threat actors, infrastructure, vulnerabilities, and campaigns are all linked, allowing teams to understand not just what is happening, but what is likely to happen next.</p>
        <p>That level of visibility is what makes autonomous defense possible. And not just within a single domain, but across the entire attack surface.</p>
        <p>The urgency behind this shift cannot be overstated. Attackers are already operating at machine speed, using automation to scale their efforts and reduce the time between discovery and exploitation. At the same time, organizations that rely on manual processes are finding it increasingly difficult to keep up.</p>
        <p>The consequences of this gap are significant. Longer dwell times allow attackers to entrench themselves more deeply. Delayed responses increase the cost and impact of incidents. And as breaches and fraud events become more visible, customer trust becomes harder to maintain.</p>
        <p>This is no longer a question of optimization. It’s a question of whether existing operating models can keep pace with the reality of modern threats.</p>
        <h2>Rethinking What Threat Intelligence Should Do</h2>
        <p>As organizations evaluate their approach to cybersecurity, the role of threat intelligence needs to be reconsidered. It is no longer enough for intelligence to provide visibility. It must enable action. It must operate in real time. And it must extend across the full scope of organizational risk—not just one domain at a time.</p>
        <p>Equally important, it must deliver outcomes that matter to the business. Faster detection, reduced exposure, and measurable risk reduction are no longer aspirational. They are essential for enterprise security in the modern, AI-powered threat landscape.</p>
        <p>The goal for most organizations isn’t to replace their security stack. It’s to make it work better. By enabling intelligence to act autonomously, connecting visibility across domains, and aligning security operations with the speed of modern threats, organizations can close the gap that has long existed between insight and action. Recorded Future is built to make that possible.</p>
        <p>If your team is still struggling with alert fatigue, delayed responses, or fragmented visibility, the issue may not be a lack of resources. It may be a limitation in how intelligence is being applied.</p>
        <p>Now is the time to rethink that model.</p>
        <p><strong>Connect with Recorded Future to see how autonomous defense can help your organization move at the speed of today’s threats—and stay ahead of what comes next.</strong></p>
        <p><em><a href="https://www.recordedfuture.com/jp/get-started">Contact us</a></em></p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_12d6bc15802a3569cc98a12874c0790ad0d3cfa5f.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Critical minerals and cyber operations]]></title>
            <link>https://www.recordedfuture.com/jp/research/critical-minerals-and-cyber-operations</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/critical-minerals-and-cyber-operations</guid>
            <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Learn how critical minerals and rare earth elements (REEs) are evolving from commodities into strategic flashpoints. Explore the geopolitical risks of China’s refining dominance, the race for resources in the Arctic and space, and the rising threat of state-sponsored cyber operations targeting the global mining sector.]]></description>
            <content:encoded><![CDATA[
        <h2>Summary</h2>
        <p>Critical elements and rare earth elements REEs are no longer commodities; they are <strong>strategic dependencies.</strong> Chinaʼs dominance in processing and refining provides it with enormous geopolitical leverage over other industrialized economies.</p>
        <p>Geopolitical competition over mining and refining critical elements and REEs is accelerating. <strong>Competition to mine them will almost certainly expand</strong> into the Arctic, Greenland, Antarctica, the seabed, and space. These emerging arenas introduce legal ambiguity, environmental tension, and strategic rivalry, creating new geopolitical flashpoints.</p>
        <p><strong>Cyber operations are increasingly intertwined</strong> with resource competition. Insikt Group has identified state-sponsored and criminally aligned cyber threat actors targeting mining organizations to gain a strategic advantage. As critical mineral supply chains grow in importance, cyber activity targeting the sector is expected to increase, with criminal groups potentially serving as proxies or access brokers for state-backed operations.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1c74b54ae4c681cd320d850bd40417b927d75d257.png?width=750&amp;format=png&amp;optimize=medium" width="939" height="590" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1</strong>: Map of where critical elements and REEs are being mined or have been located, along with key findings in the report Source: Recorded Future)</div>
          </div>
        </div>
        <h2>Analysis</h2>
        <h3>What Are Rare Earth Elements and Critical Elements?</h3>
        <p><strong><a href="https://www.usgs.gov/centers/national-minerals-information-center/rare-earths-statistics-and-information">Rare earth elements (REEs)</a></strong> are a group of seventeen metals that are essential to modern technologies. REEs are vital to the <a href="https://www.mckinsey.com/featured-insights/mckinsey-explainers/what-are-industry-4-0-the-fourth-industrial-revolution-and-4ir">Fourth Industrial Revolution</a>, a term for the current era of connectivity, advanced analytics, automation, and advanced manufacturing technology. REEs are used in small but essential quantities; they significantly impact the efficiency, precision, and reliability of equipment. They also differ from most other critical elements because they are difficult to process and refine. The refining process requires complex separation, making supply chains slow to build and capital-intensive.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1a528cc8e110e6b3d1a5a7fd49d20c970c824068e.png?width=750&amp;format=png&amp;optimize=medium" width="446" height="182" />
            </div>
          </div>
          <div>
            <div><strong>Figure 2:</strong> Simplified REE production process from mining to refining (Source: Recorded Future)</div>
          </div>
        </div>
        <p><strong><a href="https://www.usgs.gov/news/science-snippet/interior-department-releases-final-2025-list-critical-minerals">Critical elements</a></strong> such as lithium, copper, nickel, cobalt, and graphite are primarily used as structural, conductive, or energy-storage materials and are consumed in much larger quantities. These elements form the physical backbone of products like batteries, wiring, and digital infrastructure. In simple terms, critical elements build the systems, and REEs enable the systems to perform at high levels.</p>
        <h3>Where Are REEs and Critical Elements Located?</h3>
        <p><strong>On land,</strong> critical elements are unevenly distributed globally, with mining concentrated in a few countries. REEs are primarily mined in China, with significant deposits in Australia and the United States (US).</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1937ab6649fb947acb48c88041aaade797e285913.png?width=750&amp;format=png&amp;optimize=medium" width="463" height="309" />
            </div>
          </div>
          <div>
            <div><strong>Figure 3:</strong> The distribution of where critical minerals were mined in 2023 Source: <a href="https://www.wri.org/insights/critical-minerals-explained">World Resources Institute</a>)</div>
          </div>
        </div>
        <p><strong>The seabed</strong> is an <a href="https://foreignpolicy.com/2025/06/04/seabed-china-russia-unclos/#cookie_message_anchor">emerging</a> arena for mining due to vast critical mineral reserves that are believed to lie on the ocean floor. On the seabed, <a href="https://www.gao.gov/products/gao-22-105507">minerals</a> are packed into potato-sized nodules, form hard crusts, accumulate in sediment layers, and are emitted from hydrothermal vents. In April 2025, the Trump administration <a href="https://www.wsj.com/articles/trump-signs-executive-order-calling-for-u-s-deep-sea-mining-f1c35516">issued</a> an executive order directing the US to rapidly scale its capability to mine and process seabed critical elements. Meanwhile, China continues to <a href="https://discoveryalert.com.au/seabed-mining-2026-implications-underwater-technologies/">expand</a> its deep-sea mining capabilities. Japan is also accelerating its deep-sea mining program and, in February 2026, <a href="https://www.japantimes.co.jp/news/2026/02/02/japan/japan-rare-earth-deep-sea/">recovered</a> REEs from 6,000 meters below the surface of the Pacific Ocean.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_13a82f103bfeeb975adbb457b49881c13e2e03072.png?width=750&amp;format=png&amp;optimize=medium" width="463" height="251" />
            </div>
          </div>
          <div>
            <div><strong>Figure 4:</strong> Diagram showing how minerals containing critical elements can be extracted from the seabed Source: <a href="https://www.gao.gov/products/gao-22-105507">US Government Accountability Office</a>)</div>
          </div>
        </div>
        <p><strong>Arctic</strong> ice volume has <a href="https://www.economist.com/finance-and-economics/2025/01/23/the-arctic-climate-changes-great-economic-opportunity">declined</a> by more than 70% since the 1980s, opening new shipping routes and exposing vast natural resources. As ice retreats, significant <a href="https://www.oxfordenergy.org/wpcms/wp-content/uploads/2025/02/SP36-Critical-Minerals-in-the-Arctic.pdf">deposits</a> of critical elements such as cobalt, tin, and REEs are becoming accessible, alongside oil and gas reserves. Mineral-rich seabed nodules are also being <a href="https://www.economist.com/europe/2021/11/27/riches-lie-below-the-waters-of-russias-arctic">uncovered</a>, attracting increasing interest from both nation-states and private investors.</p>
        <p><strong>Greenland</strong> <a href="https://www.bbc.co.uk/news/articles/cly9230yw15o">contains</a> 25 of the European Commission’s 34 designated critical raw materials as well as substantial oil and gas potential. Mining remains <a href="https://www.ft.com/content/efe3f385-7c7a-4a75-8dd3-ee245019d794">difficult</a> due to harsh conditions and limited infrastructure, but continued ice retreat combined with sufficient capital investment could unlock resources of major economic and geopolitical importance.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1a21568577dceb08174b6afe7d8d98c163bad5053.png?width=750&amp;format=png&amp;optimize=medium" width="1600" height="745" />
            </div>
          </div>
          <div>
            <div><strong>Figures 5 and 6</strong>: Map showing critical minerals located on Greenland (left) Source: <a href="http://telegraph.co.uk/business/2026/01/10/trumps-plan-to-make-greenlanders-an-offer-they-cant-refuse/">The Telegraph</a>);Map showing critical minerals in the Arctic region (right) Source: <a href="https://www.economist.com/finance-and-economics/2025/01/23/the-arctic-climate-changes-great-economic-opportunity">The Economist</a>)</div>
          </div>
        </div>
        <p><strong>Antarctica</strong> is currently <a href="https://discoveringantarctica.org.uk/challenges/sustainability/future-of-antarctica/">off-limits</a> to mining until at least 2048 under a 1991 environmental agreement that designated the continent as a natural reserve. Antarctica is believed to hold significant reserves of oil, coal, and iron ore, which are already attracting growing interest for the future. China and Russia have <a href="https://www.csis.org/analysis/what-can-united-states-do-counter-growing-chinese-and-russian-influence-antarctica">announced</a> plans to expand their presence in Antarctica. China’s <a href="https://foreignpolicy.com/2025/05/19/antarctica-south-pole-china-russia-resources-geopolitics-treaty-security/">intentions</a> appear to be focused on resource exploitation, which could open up a new geopolitical fault line, this time in the South Pole.</p>
        <p><strong>Space</strong> is quickly becoming the next frontier for critical resource extraction. Critical elements are <a href="https://www.bbc.co.uk/future/article/20250320-how-close-are-we-really-to-mining-asteroids">abundant</a> on asteroids and on the Moon. As <a href="https://www.recordedfuture.com/jp/blog/convergence-space-cyber">companies</a> move toward space mining, the US and China are simultaneously <a href="https://www.wired.com/story/china-us-moon-race-trump-losing/">racing</a> to establish a permanent presence in space by the 2030s, intensifying an already highly competitive astropolitical environment.</p>
        <h3>What Is the Geopolitical Importance of REEs and Critical Elements?</h3>
        <p>Because industrialized nations need critical elements and REEs to manufacture advanced technologies, global demand is <a href="https://www.wri.org/insights/critical-minerals-explained">rapidly</a> accelerating. China’s <a href="https://www.goldmansachs.com/insights/articles/resource-realism-the-geopolitics-of-critical-mineral-supply-chains">control</a> over critical elements and REEs stems primarily from its dominance of processing and refining rather than extraction. By controlling much of the world’s REE separation and refining capacity, China holds significant leverage over global supply chains and strategic technologies.</p>
        <p>This reliance has heightened <a href="https://www.economist.com/briefing/2025/10/23/china-is-using-americas-own-trade-weapons-to-beat-it">anxiety</a> in the US over access to critical and rare earth elements. In 2025, China demonstrated its leverage by threatening to <a href="https://www.politico.com/news/2025/07/04/us-china-trade-war-exports-00440019">suspend</a> REE exports to the US, which <a href="https://www.bbc.co.uk/news/articles/cql2x6d2zkgo">compelled</a> Washington to back away from plans to restrict the transfer of critical semiconductor technology.</p>
        <p>The US government has since accelerated international critical minerals <a href="https://www.iiss.org/online-analysis/online-analysis/2026/01/us-critical-minerals-diplomacy-from-america-first-deals-to-pax-silica/">deals</a> and begun <a href="https://www.independent.co.uk/news/world/americas/donald-trump-china-pentagon-oklahoma-howard-lutnick-b2907759.html">investing</a> in US mining operations to minimize its reliance on China, where <a href="https://apnews.com/article/usa-rare-earth-trump-commerce-4c012d70ad172f12d9e3aca24508e766">over</a> 90% of the world’s REEs are processed. Furthermore, we are now seeing the US strategically <a href="https://www.bloomberg.com/news/articles/2026-02-02/trump-launches-12-billion-minerals-stockpile-to-counter-china">stockpiling</a> critical minerals and seeking to form “<a href="https://www.reuters.com/world/china/us-hosts-countries-talks-weaken-chinas-grip-critical-minerals-2026-02-04/">critical minerals trade blocs</a>.”</p>
        <h3>Have Any Cyberattacks Been Linked to REEs and Critical Elements?</h3>
        <p>State-sponsored cyber capabilities are deployed to support national objectives linked to mining operations and the exploration of new critical minerals.</p>
        <p>In 2021, Insikt Group identified infrastructure previously linked to APT15, a Chinese state-sponsored threat actor targeting a Canada-based mining company focused on mining zinc, copper, and lead. While there is no public record of Chinese investment in that specific mining company, Chinese firms <a href="https://web.archive.org/web/20230208082223/https://www.yicaiglobal.com/news/chinese-miners-chengxin-zangge-hold-onto-canadian-lithium-assets-despite-exit-order">invested</a> approximately CAD 40 million (USD $30 million) in other Canadian lithium miners during the same period. Ottawa later <a href="https://www.fdiintelligence.com/content/1f4c378e-e103-51a8-828f-12eeaa8a7073">forced</a> those companies to divest on national security grounds.</p>
        <p>In 2025, Insikt Group identified several Chinese state-sponsored threat actors targeting an organization focused on monitoring and regulating seabed mining. These cyberattacks occurred around the same time that China entered into seabed exploration and mining <a href="https://natoassociation.ca/beneath-the-surface-chinas-deep-sea-diplomacy-in-the-pacific-ocean/">partnerships</a> with nations such as the Cook Islands, Kiribati, and Tonga. This campaign was almost certainly driven by a desire to gain advanced insight into deep-sea mining rules and rival nations' positions, helping it protect its critical minerals dominance and secure strategic seabed access ahead of its competitors.</p>
        <p>Between January 2021 and January 2026, Insikt Group identified multiple sophisticated cyber operations targeting Indonesia. While not every intrusion can be conclusively attributed to mining activity, these attacks align with China’s strategic interest in Indonesia’s natural resources; for example, Chinese companies <a href="https://www.aspistrategist.org.au/chinas-investment-in-indonesia-is-its-global-critical-minerals-template/">control</a> about 75% of Indonesia’s nickel refining capacity. Furthermore, Indonesia <a href="https://www.eria.org/news-and-views/indonesia-s-critical-minerals-moment--turning-resource-wealth-into-rules-based-prosperity">holds</a> approximately 55 million metric tons of nickel reserves, which is over 40% of global reserves.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_13cd150a6919671816dae8ff5df5748fb81fade17.png?width=750&amp;format=png&amp;optimize=medium" width="1140" height="700" />
            </div>
          </div>
          <div>
            <div><strong>Figure 7:</strong> Timeline of Chinese cyber threat actor campaigns identified by Insikt Group targeting Indonesia from January 2021 to January 2026,alongside large mining deals Source: Recorded Future)</div>
          </div>
        </div>
        <p>In 2025, a hacker group known as Silent Lynx (or YoroTrooper) was <a href="https://therecord.media/hackers-pose-kyrgyz-officials-russia-cyber-espionage">reported</a> to be targeting Russia's mining sector. Security researchers <a href="https://therecord.media/kazakhstan-hackers-target-governments-commonwealth-of-independent-states-yorotrooper-cisco">assessed</a> that Silent Lynx is likely Kazakhstan-based, due to its language fluency, use of local currency, and regional targeting.</p>
        <p>Ransomware and criminal cyber groups frequently target the mining sector, primarily for financial gain. As the sector’s global economic importance grows, it may attract increased extortion efforts. Insikt Group has previously <a href="https://www.recordedfuture.com/jp/research/dark-covenant-3-controlled-impunity-and-russias-cybercriminals">identified</a> ransomware groups operating in close coordination with state actors, effectively using ransomware as a smokescreen; as a result, we cannot rule out criminal groups increasingly providing access to mining organizations for state-sponsored cyber operations.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1ac32a6fbc42d1c481756fc15e5c91251cd9e25ca.png?width=750&amp;format=png&amp;optimize=medium" width="987" height="341" />
            </div>
          </div>
          <div>
            <div><strong>Figure 8:</strong> Data from Recorded Futureʼs Ransomware Dashboard showing the top five ransomware groups targeting the mining and metals sector in 2025 Source: Recorded Future)</div>
          </div>
        </div>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_120e8fbdd71d3c012b84311ac0c104b77f91af32c.png?width=750&amp;format=png&amp;optimize=medium" width="1019" height="585" />
            </div>
          </div>
          <div>
            <div>
              <p><strong>Figure 9:</strong> Timeline from January 2021 to January 2026 showing mining companies being named on ransomware extortion sites,</p>
              <p>alongside mining company access being sold on dark web sites Source: Recorded Future)</p>
            </div>
          </div>
        </div>
        <p>In 2024, Northern Minerals, an Australian rare earths producer, was <a href="https://www.bloomberg.com/news/articles/2024-06-04/australian-rare-earths-miner-hit-by-cybersecurity-breac">compromised</a> by the ransomware group <a href="https://www.scworld.com/brief/data-breach-confirmed-by-northern-minerals-after-bianlian-leak">BianLian</a>. They published stolen data on the dark web shortly after Northern Minerals ordered Chinese-linked investors to divest their 10.4% stake. BianLian is a financially motivated group that opportunistically targets multiple sectors and is <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a">believed</a> to be operated by Russia-based threat actors. While this leak was likely financially driven, state collusion cannot be ruled out, as state-sponsored threat actors increasingly <a href="https://www.recordedfuture.com/jp/research/dark-covenant-3-controlled-impunity-and-russias-cybercriminals">hide</a> operations behind criminal activity.</p>
        <h2>Outlook</h2>
        <p>The US and its allies will almost certainly intensify efforts to <strong>reduce strategic dependence on China</strong> for critical minerals. This is because control of mineral supply chains will be a decisive factor in determining leadership in the Fourth Industrial Revolution.</p>
        <p>Mining activity will almost certainly <strong>expand into new frontiers</strong>, including the deep sea, the Arctic, and Antarctica, permanently reshaping both economic competition and geopolitical risk.</p>
        <p>Space will very likely <a href="https://www.recordedfuture.com/jp/research/space-and-cyber-race-above-battle-below">emerge</a> as the <strong>final frontier for resource extraction</strong>. The US and China will accelerate competition to secure access to lunar and asteroid-based minerals, extending terrestrial resource rivalries beyond Earth’s orbit.</p>
        <p>State-sponsored cyber threat actors operating on behalf of industrialized nations will almost certainly increase their focus <strong>on targeting mining companies and governments</strong> operating in strategically significant mining regions.</p>
        <p>Criminal cyber activity will very likely increasingly serve as a <strong>smokescreen or initial access vector</strong> for state-sponsored operations targeting critical mineral mining companies.</p>
        <h3>Recommended D3FEND Actions</h3>
        <div>
          <div>
            <div><strong><a href="https://d3fend.mitre.org/technique/d3f:AccessMediation/">Access Mediation</a></strong> <strong>(D3-AMED)</strong></div>
            <div>Tighten who can access sensitive supply-chain data</div>
          </div>
          <div>
            <div><strong><a href="https://d3fend.mitre.org/technique/d3f:NetworkAccessMediation/">Network Access Mediation</a></strong> <strong>(D3-NAM)</strong></div>
            <div>Control access to key network systems</div>
          </div>
          <div>
            <div><strong><a href="https://d3fend.mitre.org/technique/d3f:Multi-factorAuthentication/">Multi-factor Authentication</a></strong> <strong>(D3-MFA)</strong></div>
            <div>Reduce account takeover risk on the systems that hold this data</div>
          </div>
          <div>
            <div><strong><a href="https://d3fend.mitre.org/technique/d3f:RestoreDiskImage/">Restore Disk Image</a></strong> <strong>(D3-RDI)</strong></div>
            <div>Recover quickly from ransomware or destructive attacks</div>
          </div>
          <div>
            <div><strong><a href="https://d3fend.mitre.org/technique/d3f:ReissueCredential/">Reissue Credential</a></strong> <strong>(D3-RIC)</strong></div>
            <div>Replace compromised credentials quickly at scale</div>
          </div>
          <div>
            <div><strong><a href="https://d3fend.mitre.org/technique/d3f:CredentialRotation/">Credential Rotation</a></strong> <strong>(D3-CRO)</strong></div>
            <div>Shorten the “useful life” of stolen credentials and keys</div>
          </div>
        </div>
        <h3>Further Reading</h3>
        <div>
          <div>
            <div>
              <h3>Source</h3>
            </div>
            <div>
              <h3>Title</h3>
            </div>
          </div>
          <div>
            <div>Recorded Future</div>
            <div><a href="https://www.recordedfuture.com/jp/blog/convergence-space-cyber">The convergence of space and cyber: An evolving threat landscape</a></div>
          </div>
          <div>
            <div>Insikt Group</div>
            <div><a href="https://www.recordedfuture.com/jp/research/state-of-security">2026 State of Security</a></div>
          </div>
          <div>
            <div>Foreign Policy</div>
            <div><a href="https://foreignpolicy.com/2025/06/04/seabed-china-russia-unclos/#cookie_message_anchor">The Seabed Is Now a Battlefield</a></div>
          </div>
          <div>
            <div>The Economist</div>
            <div><a href="https://www.economist.com/graphic-detail/2025/03/24/a-visual-guide-to-critical-materials-and-rare-earths">A visual guide to critical materials and rare earths</a></div>
          </div>
        </div>
        <h2>Mitigations</h2>
        <p><strong>Know your exposure to changes in critical mineral supplies:</strong> Map the locations of critical minerals in your products and suppliers, and identify potential single points of failure.<br /><strong>Resilience question:</strong> <em>Are there any single points of failure in critical products or business lines if China were to restrict the supply of REEs?</em></p>
        <p><strong>Build a fallback plan:</strong> Put backup suppliers, alternate materials, and realistic inventory buffers in place for the highest-risk supplies your organization relies on.<br /><strong>Resilience question:</strong> <em>What is our Plan B for our top three critical electronic supplies, such as laptops?</em></p>
        <p><strong>Prepare for criminal and state-sponsored cyberattacks:</strong> If you operate in or supply the mining and critical minerals sector, treat criminal intrusions as potentially more than financially motivated. In some cases, they may serve as cover for espionage. Actively monitor the latest indicators of compromise (IoCs) and the tactics, techniques, and procedures (TTPs) associated with threat actors known to target the sector or government bodies responsible for nation-state mining interests. Use Recorded Future’s <a href="https://www.recordedfuture.com/jp/products/threat-intelligence">Threat Intelligence Module</a> to monitor for dark web and closed-source mentions tied to mining targeting.<br /><strong>Resilience question:</strong> <em>If we’re hit with ransomware, how quickly can we restore operations? Do we have backup systems and data?</em></p>
        <p><strong>Map out your supply-chain risks:</strong> If your organization operates in or near the mining industry, you might have robust security measures — but your suppliers might not. Use Recorded Future’s <a href="https://www.recordedfuture.com/jp/products/third-party-intelligence">Third-Party Intelligence Module</a> to identify risks in your supply chain.<br /><strong>Resilience question:</strong> <em>Which supplier or contractor would cause us the most problems if they were hacked, and could they be easily hacked from what we can identify?</em></p>
        <p><strong>Monitor the new mining hotspots:</strong> Track developments in the Arctic, Greenland, Antarctica, deep-sea mining, and space, as rules and conflicts there can quickly affect supply and reputation. Use Recorded Future’s <a href="https://www.recordedfuture.com/jp/products/geopolitical-intelligence">Geopolitical Intelligence Module</a> to gain visibility into new mining contracts and potential geopolitical risks from new deals.<br /><strong>Resilience question:</strong> <em>What early warning signs are we monitoring that could disrupt our supply chain in the next 6–12 months?</em></p>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_190a8600b3b90022a74115178c103f4973ccd0512.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Today, trust is the superpower that makes innovation possible]]></title>
            <link>https://www.recordedfuture.com/jp/blog/trust-is-a-superpower</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/trust-is-a-superpower</guid>
            <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[How better intelligence and collaboration can unlock new opportunities for growth and greater financial health for more people.]]></description>
            <content:encoded><![CDATA[
        <p>The paradoxes of today’s digital world are well-known to anyone with a smartphone.</p>
        <p>Over the last decade, connectivity has expanded, yet the world has become more fragmented. Our everyday lives are more digital, but we spend more time parsing text messages for scams or deliberating the authenticity of potential deepfakes. Technology is delivering great productivity gains to small businesses while making them a larger target for cybercriminals.</p>
        <p>In this environment, exposure becomes the default: Access points are growing, control is hard and reacting to change stops working. AI intensifies these dynamics because it compresses time for everyone, including adversaries.</p>
        <p>Today, trust has become the most critical tool to move all businesses forward. Without trust, even the best ideas stall. People hesitate, adoption slows and growth stagnates.</p>
        <p>Trust used to be something businesses tried to repair after a breach. Now it must be the starting point, and something to nurture and continuously prove in a world that has fundamentally changed.</p>
        <p>It would be impossible to eliminate the risk entirely. Some estimates project <a href="https://www.statista.com/forecasts/1280009/cost-cybercrime-worldwide/">cybercrime could cost the world $15.6 trillion</a> annually before 2030, <a href="https://www.worlddata.info/largest-economies.php">surpassing all but two</a> of the world’s largest economies. Instead, the goal must be to build the ability to see sooner, decide faster and limit impact when, not if, something breaks. Trust today is all about bringing together speed, intelligence and collaboration, and that’s exactly what we’re developing across our teams.</p>
        <p>Getting this right isn’t just good business sense, but the only way to ensure new technologies are embraced and economies can keep growing.</p>
        <h2>The advantage is intelligence</h2>
        <p>Real advantage comes from understanding context and connecting signals across systems. That’s what turns data into better decisions. This kind of intelligence increases speed, reduces risk and enables proactive action. With the right intelligence, teams can hunt for threats continuously, test assumptions and act before harm occurs, not just triage alerts after the fact.</p>
        <p>You can see this shift in how the payments industry is evolving, including the work we’re doing by bringing Recorded Future’s threat intelligence together with Mastercard’s security capabilities, payments infrastructure and partnership models. We’re helping organizations understand where risk concentrates, how it propagates, and how quick, collective action can reduce the cost of cybercrime.</p>
        <p>Faster insights mean earlier action, which minimizes impact — and deepens trust.</p>
        <h2>Trust is built through collaboration</h2>
        <p>Security doesn’t scale through isolated heroics. It scales through ecosystems: shared signals, shared standards and partners who can move together as new threats arise, attack vectors shift and failures spread.</p>
        <p>Resilience is strongest when public and private sectors plan, exercise and respond together, rather than in parallel. Different players have different sightlines in the digital ecosystem. Startups look at the edges of innovation. Enterprises understand the realities of operating in today’s environment. Governments see where systemic risk concentrates. When those visions combine, our shields strengthen and expand, pushing cybercriminals out of the frame.</p>
        <p>During our time here in Miami for the <a href="https://emergeamericas.com/">eMerge Americas conference</a>, we’ve had the opportunity to speak to enterprises, startups, investors and government leaders about the need to accelerate resilience in Latin America, where the digital economy is booming but security hasn’t always kept pace. The region has the world’s fastest-growing rate of disclosed cyber incidents — in 2025 alone, <a href="https://www.recordedfuture.com/jp/research/latin-america-and-the-caribbean-cybercrime-landscape">Recorded Future tracked</a> 452 ransomware incidents — but only seven countries have developed cybersecurity plans protecting critical infrastructure, and only 20 have formal computer security incident response teams.</p>
        <p>That gap is where trust breaks, and where more collaboration can become a growth necessity. We can’t build sustainable economic growth in Latin America without building digital trust and cyber resilience. That’s why we are deepening our footprint here, enhancing regional threat intelligence and resilience and paving the way for stronger public-private collaboration to address these complex risks.</p>
        <p>Secure digital access unlocks economic opportunity — and insecurity shuts it down fast. For a first-time digital user, one fraud incident can be enough to opt out for good. For a small business, one account takeover can wipe out months of progress. That’s why trust is inextricably linked to financial health. People can’t build stability on top of systems they’re afraid to use. At Mastercard, we’ve <a href="https://www.mastercard.com/us/en/news-and-trends/stories/2026/mastercard-500-million-commitment.html">committed to connecting and protecting 500 million people and small businesses by 2030</a>, because secure participation is foundational, not optional.</p>
        <p>The bar for digital innovation today is not what we can deliver, but what people will trust enough to use, depend upon and harness for their own financial health. Because in the end, trust is the superpower.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_1a779e8a128e82a969d30b523eb27ea00232c78e2.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[Evolution of Chinese-Language Guarantee Telegram Marketplaces]]></title>
            <link>https://www.recordedfuture.com/jp/research/evolution-of-the-chinese-language</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/research/evolution-of-the-chinese-language</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Chinese-language, Telegram-based “guarantee” marketplaces are increasingly popular among Chinese-speaking criminal groups despite the widely publicized shutdown of Huione Guarantee in 2025.]]></description>
            <content:encoded><![CDATA[
        <h2>Executive Summary</h2>
        <p>Chinese-language, Telegram-based “guarantee” marketplaces are increasingly popular among Chinese-speaking criminal groups despite the widely publicized shutdown of Huione Guarantee in 2025. Although these guarantee marketplaces operate similarly to Huione Guarantee, they differ in their focus on particular aspects of cybercrime and in their targeting of specific geographies. To better understand these Chinese-language guarantee marketplaces, Insikt Group observed and analyzed another increasingly popular guarantee marketplace, dubbed Dabai Guarantee (“大白担保”).</p>
        <p>Given that guarantee marketplaces typically involve hundreds to thousands of public and private channels, this report outlines how Insikt Group analysts navigated through just one of the Telegram channels belonging to Dabai Guarantee’s large infrastructure. The channel is known as Dabai Guarantee Public Group 301 (@DBTM301), and its main objective is to conduct “sweeping” operations (using illicit techniques to make purchases of physical goods at retailers or to withdraw and transact at country-specific ATMs) in South Korea and Japan. This report also includes the visible organizational structure of Dabai Guarantee Public Group 301, key rules, staff, and customer service functions.</p>
        <p>This report primarily serves as an introduction to understanding how Chinese-language, Telegram-based guarantee marketplaces work and how to navigate them. It also includes interpretations of multiple criminal terminologies used by Chinese-speaking criminals, which are pivotal to understanding how Chinese cybercrime evolves over time. The cyber and fraud campaigns being promoted and launched on Dabai Guarantee and other similar guarantee marketplaces can negatively impact retail, banking, contactless payment providers, insurance companies, and individuals vulnerable to scam-related campaigns.</p>
        <h2>Key Findings</h2>
        <ul>
          <li>Dabai Guarantee is a platform that enables multiple Chinese-speaking threat groups with strong presences across multiple countries to coordinate and launch global-scale fraud and cyber campaigns.</li>
          <li>Chinese-speaking syndicates are using Dabai Guarantee as a platform to facilitate campaigns involving financial and retail fraud, such as ATM withdrawal and ghost-tapping.</li>
          <li>Criminal groups participating in campaigns are often siloed, acting independently, and restricting the sharing of information, resources, and goals, thereby creating barriers to tracking their activities.</li>
          <li>Unlike conventional ghost-tapping campaigns that mainly target luxury businesses, “sweeping teams” typically purchase goods that are less expensive but still considered valuable to criminal groups and are relatively easy to transport (such as women’s cosmetics and tobacco products), likely to avoid detection by law enforcement. The sweeping teams eventually resell them in other markets for cash.</li>
          <li>Dabai Guarantee’s bot search function makes it easy for Chinese-speaking criminals to enter specific search terms and be matched with existing public groups running those campaigns.</li>
        </ul>
        <h2>Background</h2>
        <p>Chinese-language guarantee marketplaces first emerged around 2021 with the launch of Huione Guarantee, serving as reliable alternatives to traditional dark web marketplaces accessible via the Tor network. Owners of traditional dark web marketplaces, such as Exchange Market and Chang’An Sleepless Night, have close to full control over advertisements and transactions. These guarantee marketplaces seek to eliminate distrust stemming from criminal groups scamming one another, dark web marketplaces shutting down, potential exit scams, and parties failing to honor terms that were previously agreed upon. Furthermore, guarantee marketplaces operate on publicly accessible Telegram channels by design; these public channels are meant to be found and appeal to a wider Chinese-speaking audience that uses Telegram, noting that most Chinese criminals still use Telegram rather than Tor for communication.</p>
        <p>Guarantee marketplaces are often different from typical peer-to-peer (P2P) transactions between threat actors. Guarantee marketplaces are one-stop shops that handle and facilitate all cryptocurrency transactions (typically Tether/USDT) and mediation services between parties, whereas P2P transactions typically take place directly between users or through a third-party escrow service. The preferred cryptocurrency of Chinese-speaking threat actors is USDT, a stablecoin pegged to the US dollar that maintains anonymity. Stablecoins are a type of cryptocurrency designed to maintain a stable value by pegging themselves to reserve assets, most commonly the US dollar, to mitigate the volatility of cryptocurrencies like Bitcoin. According to Chainalysis’s 2026 <a href="https://www.chainalysis.com/reports/crypto-crime-2026/">Crypto Crime Report</a>, stablecoins have come to dominate the landscape of illicit transactions, accounting for 84% of all illicit transaction volume in 2025. Chinese cybercriminals <a href="https://www.binance.com/en/square/post/21486862841738">prefer</a> using stablecoins such as USDT due to their combination of price stability, ease of border transfer, and relative anonymity. USDT also helps Chinese cybercriminals bypass China’s strict capital controls and traditional banking scrutiny to move money across borders.</p>
        <p>In January 2025, Insikt Group published a report on the Chinese-language guarantee marketplace Huione Guarantee, “Huione Guarantee Serves as a One-Stop Shop for Chinese-Speaking Cybercriminals.” The report described the activities facilitated by Huione Guarantee, which include investment fraud, money laundering, and various online scams. Despite Huione Guarantee’s shutdown on May 13, 2025, Insikt Group observed that other guarantee marketplaces, such as Tudou and Xinbi, <a href="https://www.elliptic.co/blog/telegram-dark-markets-expand-to-fill-the-gap-left-by-huione-guarantee">stepped in</a> to fill the void left by Huione Guarantee's closure. According to Elliptic, Tudou Guarantee also <a href="https://www.elliptic.co/blog/tudou-guarantee-winds-down-operations-after-12-billion-in-transactions">shut down</a> its operations in January 2026, after processing $12 billion in transactions. Even though Xinbi Guarantee was previously <a href="https://www.elliptic.co/blog/elliptic-data-telegram-market-takedown">reported</a> to have shut down, it has since been rebuilt and maintains a presence on Telegram as of this writing. Other, but not widely reported, active Chinese-language guarantee marketplaces operating on Telegram (besides Dabai Guarantee) are Yinuo, BoChuang, and Ouyi.</p>
        <p>Guarantee marketplaces can also facilitate new attack vectors such as ghost-tapping. In July 2025, Insikt Group published a report titled “<a href="https://www.recordedfuture.com/jp/research/ghost-tapping-chinese-criminal-ecosystem">Ghost-Tapping and the Chinese Cybercriminal Retail Fraud Ecosystem</a>,” which details how Chinese-speaking cybercriminals and syndicates work together to conduct retail fraud using near-field communications (NFC) relay tactics. As of February 2026, Insikt Group observed that Dabai Guarantee has emerged as a major player in Chinese-language cybercrime, with its Telegram-based infrastructure resembling that of Huione Guarantee and offering malicious services similar to those advertised on Huione Guarantee, which is now defunct.</p>
        <h2>Dabai Guarantee Overview</h2>
        <p>Dabai Guarantee is a Telegram-based marketplace, consisting of thousands of public and private Chinese-language Telegram groups, that operates in a manner similar to Huione, Tudou, and Xinbi guarantees; many of these services cater to “small to medium-sized clients.” However, the operators of Dabai Guarantee do not maintain a clearnet website; they operate solely on Telegram, likely due to operational security (OPSEC) concerns. Operators of Dabai Guarantee likely chose not to have a clearnet website in light of Huione’s “bad OPSEC” practices — Huione Guarantee’s clearnet website made tracking much easier for law enforcement officials and researchers, which likely contributed to FinCEN <a href="https://www.fincen.gov/news/news-releases/fincen-finds-cambodia-based-huione-group-be-primary-money-laundering-concern">sanctioning</a> the organization in May 2025. The Dabai platform is populated with third-party vendors providing various services that facilitate cybercriminal and fraud activities, including money laundering methods and services, compromised social media and e-commerce accounts, SIM cards, personally identifiable information (PII), malware-as-a-service (MaaS), deepfake technology, know-your-customer (KYC) bypass services, and more.</p>
        <p>Dabai Guarantee was likely founded in December 2024, based on its Telegram Channel’s creation date. There are currently six known official main Telegram channels:</p>
        <ul>
          <li>“公群导航 @dabai” (@dabai_a): “Public Group for Navigation Purpose”, 15,372 subscribers, as of this writing</li>
          <li>“大白担保大群” (@dabai_c): “Dabai Guarantee Big Group”, 19,225 members, as of this writing</li>
          <li>“大白供需频道” (@dabaiyajing): “Dabai Supply and Demand Channel”, 17,085 subscribers, as of this writing</li>
          <li>“大白担保规则” (@dabai_e): “Dabai Guarantee rules”, 428 subscribers, as of this writing</li>
          <li>“大白担保客服人员名单” (@dabai_f): “Dabai customer service list”, 527 subscribers, as of this writing</li>
          <li>“大白担保 @dabai” (@dabai): “Dabai Guarantee bot channel”</li>
        </ul>
        <p>Dabai Guarantee’s public navigation channel, 公群导航 @dabai, is used to direct threat actors to different private/public Telegram channels to coordinate and collaborate on campaigns targeting both Chinese-speaking and non-Chinese-speaking victims. Below is a list of the service categories offered on the public Telegram groups on Dabai Guarantee. Each category has subcategories for more specific services. Each public Telegram group has a unique group number, the amount of the deposit made to Dabai Guarantee in USDT, the handles of group administrators and customer service representatives, the transaction rules, and a dedicated cryptocurrency wallet. More information can be found in Figure 1. These specialized channels include the following:</p>
        <ul>
          <li>“海外钓鱼类” (“Overseas Phishing”) — Coordinate phishing campaigns against individuals residing outside of China</li>
          <li>“买卖类” (“Trading”) — Buy and sell gift cards, databases, SIM cards, social media burner accounts, IP addresses, and physical goods</li>
          <li>“引流类” (“Traffic generation methods”) — Overseas SMS blasts, Baidu promotions, chat scripts, and other services</li>
          <li>“承兑类” (“Acceptance methods”) — Payment methods accepted by merchants include Alipay, WeChat Pay, and cryptocurrencies</li>
          <li>“通道合作类” (“Cooperation Channels”) — Motorcade teams to conduct overseas operations such as collecting or making payments via cash and cryptocurrencies, and logistic operations to move physical goods</li>
          <li>“短视频类” (“Short Videos”) — Short Douyin videos for promotions</li>
          <li>“合作类” (“Cooperation”) — ID Loans, Apple IDs, courier delivery services, and burner mobile phones</li>
          <li>“服务类” (“Services”) — SMS verification, file lookup, and graphic design services</li>
          <li>“卡商类” (“Carding Merchants”) — Money laundering through bank cards and contactless cash withdrawal without cards</li>
          <li>“搭建类” (“Developers”) — Software and bot setup services, and Apple signing/server/VPN/domain setup services</li>
          <li>“其他类” (“Others”) — Other miscellaneous fraud services, social escort services, police impersonation, artificial intelligence (AI), and search engine optimization (SEO)-related services</li>
          <li>“游戏类公群” (“Gaming-related public groups”) — Online gambling and video games</li>
        </ul>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1ac90e51716ded086084b8b61e326f067431b0df5.png?width=750&amp;format=png&amp;optimize=medium" width="1080" height="1416" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 1:</strong></em> <em>Dabai Guarantee’s public navigation purpose Telegram channel “公群导航 @dabai”, with listed categories</em> <em>(Source: Telegram)</em></div>
          </div>
        </div>
        <h2>Dabai Guarantee’s Rules (@dabai_e)</h2>
        <p>Dabai Guarantee’s rules channel (@dabai_e) has posted rules to prevent impersonation of the marketplace and to prevent users from creating their own “public groups” that are not officially regulated by Dabai Guarantee’s administrators. Some of the rules also showcase Dabai Guarantee’s OPSEC measures to prevent scamming and impersonation. The original Chinese text is in <strong>Appendix B</strong>. The following are some key rules:</p>
        <ul>
          <li>Members are not allowed to create their own public group channel without Dabai Guarantee`s approval.</li>
          <li>Members are not allowed to have private dealings with other parties or platforms, as Dabai Guarantee only guarantees transactions conducted on its platform. Dabai Guarantee also does not provide assurances for transactions with the Public Group “boss” or any other administrator. This means that no individual should have any transactions with the boss directly and should instead use Dabai Guarantee’s funds transfer mechanism.</li>
          <li>Individuals who initiate a chat session with you are 100% scammers; members are to block and refrain from chatting with them.</li>
          <li>The cryptocurrency address belonging to Dabai Guarantee is unique, and anyone sending other deposit addresses is a scammer.</li>
          <li>After members have staked their cryptocurrency as deposits, they are required to send Dabai Guarantee’s leadership screenshots of the deposit to @dabai for verification and confirmation. Any losses resulting from failure to contact @dabai will be the member’s responsibility.</li>
        </ul>
        <h2>Case Study: Public Group 301</h2>
        <h3>Group Structure</h3>
        <p>For this report, we will use the Telegram channel “Public Group 301,” which belongs to Dabai Guarantee, as a case study. This is not meant to be a comprehensive analysis of Dabai Guarantee’s massive infrastructure and that of other Chinese-language guarantee marketplaces. It is difficult to accurately quantify how many “Public Group” channels and threat groups are on Dabai Guarantee, as the numbers tagged to Public Groups are not assigned in chronological order, resulting in a lack of visibility — unlike Huione Guarantee, which had a clearnet website that listed the Public Group channels to redirect threat actors. Although there are thousands of channels belonging to Dabai Guarantee alone, understanding Public Group 301’s structure can at least provide insight into how threat actors use Dabai Guarantee in their campaigns.</p>
        <p>In guarantee marketplaces, threat actors looking to launch campaigns typically deposit USDT to start a public Telegram group approved by Dabai Guarantee. This model ensures that criminal syndicates do not have to deal with other threat actors directly, but have Dabai Guarantee as a mediator. In the case of Dabai Guarantee’s Public Group 301, affiliate threat groups do not have to engage directly with the group’s leader, @J0hnNo1, and instead receive payments from Dabai Guarantee after the completion of tasks required by @J0hnNo1. Guarantee marketplaces such as Huione, Tudou, Xinbi, and Dabai seek to eliminate the “lack of trust” among Chinese-speaking threat actors. These marketplaces are designed to become trusted platforms that foster coordination and cooperation between different Chinese-speaking criminal groups to achieve their objectives.</p>
        <p>Insikt Group navigated through Public Group 301’s Telegram infrastructure in order to identify the redirection flow. As shown in <strong>Figure 1</strong>, each category contains a hyperlink that redirects to other channels. From <strong>Figure 1</strong>, selecting category 5, sub-category 2 (“海外扫货车队”, or “Overseas Goods Sweeping Team”) redirected to a pinned message as seen in <strong>Figure 2</strong>. This message lists four different public channels (“公群”) containing campaigns targeting the US, Canada, South Korea, and Japan.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1dc5740cc91bfbd31fc40fea4e2d2e57696d5a535.png?width=750&amp;format=png&amp;optimize=medium" width="522" height="370" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 2:</strong></em> <em>Selecting “海外扫货车队” (Overseas Goods Sweeping Team) redirects users to four different Telegram groups, where threat actors are seen discussing and showing off their financial crime-related achievements in countries such as the US, Canada, South Korea, and Japan (Source: Telegram)</em></div>
          </div>
        </div>
        <p>As seen in <strong>Figure 2</strong>, “公群” refers to unique Public Group channels for specific purposes or operations. Each public channel here contains a numerical group identifier and a “U” deposit amount, where “U” refers to USDT. For example, “公群935已押2000U” refers to Public Group Number 935, with 2,000 USDT already being deposited in Dabai Guarantee to start the campaign. The naming convention for these Public Groups is ”dbtmxxx”; in this case, Public Group Number 935 will have the Telegram channel @dbtm935. When selecting the second option, “公群301已押1000U韩国，日本扫货组”, which means Public Group Number 301, with 1,000 USDT already deposited to “sweep goods” in South Korea and Japan, the corresponding Telegram channel is @dbtm301.</p>
        <p>Upon further investigation and analysis of the channel, Insikt Group assesses that “sweeping goods” refers to the use of illicit means, such as ghost-tapping, to purchase physical goods at physical retail stores (in this case, in South Korea and Japan). This activity also includes ATM cash withdrawals at Japanese or South Korean ATMs.</p>
        <h2>Key Personnel Involved in Public Group 301</h2>
        <p>The following terms are important for understanding the operations of criminals involved in Public Group 301, and the entire Dabai Guarantee infrastructure more broadly:</p>
        <ul>
          <li><strong>Boss (“群老板”)</strong>: The main coordinator overseeing a group’s operations. These individuals are not directly related to Dabai Guarantee and operate more like customers, making use of Dabai Guarantee’s infrastructure to lay out tasks and promising payouts in USDT upon completion. The boss will typically start a campaign by placing significant deposits into Dabai Guarantee’s USDT cryptocurrency addresses (“上押地址”) in order to get Dabai Guarantee’s administrators to approve the creation of a Public Group channel. In Dabai Guarantee’s Public Group 301 (@dbtm301), @J0hnNo1 is the boss of the channel. We observed that this threat actor intends to conduct ghost-tapping and fraud campaigns in Japan and South Korea, with the key objective of obtaining physical goods, cash, and funds through unauthorized transactions. Once the boss confirms receipt of the items and is satisfied with the outcome, they can ask Dabai Guarantee to release the payment to the criminals who participated in the requested task.</li>
          <li><strong>Channel Administrators (“管理员”)</strong>: Dabai Guarantee’s personnel who act as intermediaries between the boss and other Chinese syndicates, ensuring that the boss gets the items and physical cash, while the Chinese syndicates are paid in USDT. These are the people who will process the payments. Channel administrators will also inspect video evidence provided by sweeping and “goods-receiving” teams and wait for confirmation from the boss that everything is satisfactory before releasing payments to the various Chinese-speaking criminal groups.</li>
          <li><strong>Chinese Syndicates (“犯罪组织”)</strong>: Teams in charge of providing the people (“mules”) to form sweeping and goods-receiving teams. These syndicates will coordinate with the boss and receive payment in USDT after completing the required jobs.</li>
          <li><strong>Sweeping Teams (“扫货队”)</strong>: Personnel tasked by the boss or other administrators with obtaining physical goods or conducting ATM cash withdrawals, typically through illegal methods such as ghost-tapping or financial fraud, and to eventually transfer the goods to “goods receiving” teams.</li>
          <li><strong>Goods Receiving Teams</strong> <strong>(“收货队”)</strong>: Personnel tasked by either the boss or their respective Chinese syndicates with receiving goods from sweeping teams; the items will eventually have to reach the “goods inspection teams.”</li>
          <li><strong>Goods Inspection Teams</strong> <strong>(“检货队”)</strong>: Personnel tasked with physically inspecting the goods and cash being delivered by the sweeping or goods-receiving teams, typically appointed by bosses. When the “goods receiving” team is appointed by the boss, it is also possible that the “goods receiving” and “goods inspection” teams are composed of the same personnel, each fulfilling multiple roles. These teams will inform the boss whether the physical goods are satisfactory, and the boss will proceed to ask Dabai Guarantee to release the payment to the sweeping and goods-receiving teams.</li>
        </ul>
        <p>Insikt Group assesses that individuals in the sweeping, goods receiving, and goods inspection teams act as mules, and these teams likely consist of Chinese-speaking tourists who can amass large quantities of physical goods and cash and exit the targeted countries as soon as possible. It is also likely that Chinese-speaking groups have members who are long-term residents of the countries targeted by the operations, such as South Korea and Japan.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1ce97c73277009b6799b7752814a9e1939b12c826.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1136" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 3:</strong></em> <em>Simplified illustration of Dabai Guarantee Public Group 301’s structure (Source: Recorded Future Data)</em></div>
          </div>
        </div>
        <p><strong>Figure 3</strong> is a simplified illustration of Dabai Guarantee’s Public Group 301’s organizational structure. The barrier to entry for participating in “sweeping operations” is low, as participants just need to have the legal right to enter Japan or South Korea, pose as tourists, and follow the instructions given by the boss and other administrators. We estimate that there are likely more than a dozen sweeping teams linked to Dabai Guarantee operating in Japan and South Korea alone. Sweeping teams are likely assigned to obtain certain goods and cash in very specific areas and do not coordinate with one another because they are being deployed by different Chinese syndicates. This model suggests that operations are siloed, where teams act as independent, isolated units that restrict the sharing of information, resources, and goals.</p>
        <p><strong>Figure 4</strong> shows the Telegram structure of Public Group 301, where @J0hnNo1 is the channel's boss. The channel is also composed of multiple Dabai Guarantee customer service staff, who serve as administrators. The original creator of the channel is @dbwb22; the Telegram account is no longer active, and @dbwb22 is no longer listed as one of Dabai Guarantee’s official customer service agents.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_12cb2147fb7aff18951a78baf893e89a34edd837f.png?width=750&amp;format=png&amp;optimize=medium" width="782" height="2004" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 4:</strong></em> <em>List of key personnel in Dabai Guarantee’s Public Group 301 (@dbtm301); @J0hnNo1 is listed as this group’s public channel boss (Source: Telegram)</em></div>
          </div>
        </div>
        <p>The distribution of these teams significantly complicates efforts by researchers and law enforcement agencies to track and deter such criminal activities. For example, if members of “Sweeping Team A” are arrested for retail or financial fraud, law enforcement agencies will still need to locate the members of the “Goods Receiving Teams” and “Goods Inspection Teams” before they can even get close to decoding the identity of the boss, who is most likely coordinating operations from a location outside Japan or South Korea’s jurisdiction, such as Cambodia or Myanmar. Additionally, these sweeping teams most likely consist of low-level mules who are considered “expendables” by their Chinese syndicate recruiters. The screenshots in <strong>Figures 6, 7, 8, 9, and 10</strong> illustrate the siloed operations conducted by different sweeping teams.</p>
        <p><strong>Figure 5</strong> shows Dabai Guarantee customer service personnel @dbtm9 helping to set up public Telegram channel 301 on March 21, 2025, and serving as the channel’s key administrator. This individual serves as a mediator to facilitate transactions and dealings between the boss and other threat actors. The total amount of USDT deposited on that date was 485 USDT; as of this writing, it has risen to 1,000 USDT. The purpose of this channel is to encourage other threat actors to cooperate by taking part in sweeping and goods-receiving operations in Japan and South Korea. In the conversation below, the boss stated that the deposit amount will increase in proportion to the transaction amount. Insikt Group assesses that this would mean the sum of deposit scales with the size of operations in Japan and South Korea.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1e4ba0252148a2f85be1271c5233aa23507494356.png?width=750&amp;format=png&amp;optimize=medium" width="1684" height="1472" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 5:</strong></em> <em>Screenshot of Public Group 301’s (@dbtm301) administrator (@dbtm9) establishing a group for “sweeping goods” and “receiving goods” operations in South Korea and Japan</em></div>
          </div>
        </div>
        <p><strong>Figure 6</strong> shows that the boss is looking to recruit sweeping teams to conduct operations in Seoul, South Korea. The main objective is to purchase cosmetics, and once the goods have been delivered, the rewards will be “high.” The final sentence uses the term “速度快”, which means that the boss welcomes any sweeping team that can conduct and complete these operations quickly.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1cd95d17ea177ec9d4e1b12fc8c5afc5e93de569c.png?width=750&amp;format=png&amp;optimize=medium" width="998" height="308" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 6:</strong></em> <em>Screenshot of Public Group 301 “boss” @J0hnNo1 recruiting sweeping teams to purchase cosmetics in Seoul, South Korea (Source: Telegram)</em></div>
          </div>
        </div>
        <p><strong>Figure 7</strong> features a sweeping team involved in purchasing tobacco-related products from the Terea brand at a CU store, a South Korean convenience store chain in Seoul, South Korea. It is clear that the boss has goods from specific brands they wish to obtain, and such goods may be resold for cash in other foreign markets at a later date, likely at a lower price to obtain hard currency as soon as possible. Insikt Group assesses that the items are very likely purchased using the ghost-tapping attack vector or through stolen payment card information. This reflects a shift from targeting luxury retailers to smaller-sized businesses, likely to avoid arousing suspicion from law enforcement authorities</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1ec36809b177102807f30cd70ff0013ec163416c0.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="960" height="1280" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 7:</strong></em> <em>Public Group 301’s boss @J0hnNo1 showing a CU receipt of tobacco sticks belonging to the Terea brand totaling 288,000 won, worth approximately $196 on March 25, 2025 (Source: Telegram)</em></div>
          </div>
        </div>
        <p><strong>Figure 8</strong> shows an Apple Store receipt listing unspecified Apple products totaling 499,600 yen (approximately $3,145.66, as of this writing). Public Group 301’s boss @J0hnNo1 also stated, “Who said there are no large transactions in Japan? Just a single receipt amounted to 500,000 Yen.” This is likely a post encouraging syndicates to send more sweeping teams to acquire as many Apple products as possible, while hinting that the rewards could be lucrative.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_197847c84c68f184bea9d618c370a0a4d8560fb9c.png?width=750&amp;format=png&amp;optimize=medium" width="772" height="1770" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 8:</strong></em> <em>Public Group 301’s boss @J0hnNo1 showing an Apple store receipt of items totaling 499,600 yen, approximately $3,145.66 on December 28, 2025 (Source: Telegram)</em></div>
          </div>
        </div>
        <p><strong>Figure 9</strong> provides some evidence that Vietnamese individuals are also involved in sweeping operations. In the top-left corner of the iPhone in the image, the Vietnamese phrase "Không có SIM" means "No SIM card." This indicates that the person holding the phone is very likely a Vietnamese-speaking individual conducting unauthorized banking transactions using burner iPhones. Every single burner phone appears to be tagged with a label, which is very similar to the tactics, techniques, and procedures (TTPs) we documented in our Insikt Group report on ghost-tapping. It is also likely that this individual understands Japanese in addition to Chinese, as they were observed interacting with a Japanese banking application that displayed processed transactions. The transactions shown in the screenshot are dated between July 30, 2025, and August 28, 2025. The ability to use Japanese banking applications is an indicator that this individual is legally residing in Japan. In general, most Japanese banks require foreigners to close their bank accounts before leaving permanently; these regulations are <a href="https://www.sbishinseibank.co.jp/english/powerflex/closing_account.html">implemented</a> by major Japanese banks such as Shinsei Bank.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1b0942315a93ecff4b6991a5404f277d589afeedf.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="960" height="1280" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 9:</strong></em> <em>Image posted by Public Group 301’s boss @J0hnNo1 involving multiple unauthorized banking transactions from July 30, 2025, to August 2025. Insikt Group assesses that this is indicative of a ghost-tapping campaign targeting Japanese retail businesses involving multiple Apple burner iPhones on August 28, 2025 (Source: Telegram)</em></div>
          </div>
        </div>
        <p><strong>Figure 10</strong> shows what appears to be an ATM cash withdrawal or transfer attempt at a Japanese ATM at an unspecified bank. This screenshot is also likely shown as an example of what sweeping teams in charge of withdrawing and transferring cash are expected and required to do.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1d6df5acc276b6ea526ffbf9567dd7154e6dd5dc1.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="960" height="1280" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 10:</strong></em> <em>Public Group 301’s boss @J0hnNo1 posted an image of what Insikt Group assesses to be an ATM cash withdrawal/transfer using a Japanese ATM machine on April 23, 2025 (Source: Telegram)</em></div>
          </div>
        </div>
        <p><strong>Figure 11</strong> shows a cryptocurrency transaction of 10,629 USDT via the Tron (TRX) network to a sweeping team for the successful completion of the “mission.” The boss @J0hnNo1 thanked the sweeping team coordinator without identifying them. The exact phrase used while posting the image was “感谢老板信任”, which translates from Chinese to “Thank you boss for trusting me.” Boss, in this context, refers to the Chinese syndicates that provide the sweeping teams for successful operations. In the entire Dabai Guarantee Public Group 301 channel, there were many screenshots of such cryptocurrency transactions being sent to teams that participated in sweeping operations. The boss redacts recipients' cryptocurrency wallet addresses to prevent law enforcement agencies from tracking them. The TRON wallet address used by Public Group 301 is TByDzGWCirpCABaUorkhz5eWhjyDdYWgSo, as shown in <strong>Figure 11</strong>; this wallet address has facilitated a total of 2,943 transactions as of this writing.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_104ad8a1582e89967c3c09082c6db0503fa4c2c0d.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="946" height="2048" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 11:</strong></em> <em>Multiple screenshots involving USDT transactions are posted on the channel, likely for transparency and to reassure the sweeping teams (Source: Telegram)</em></div>
          </div>
        </div>
        <h2>Dabai Guarantee’s Staff and Customer Service Functions (@dabai_f)</h2>
        <p>Dabai Guarantee maintains a list of its official staff and customer service agents on its Telegram channel @dabai_f to facilitate the creation of Public Group channels and transactions. This system also helps prevent impersonation and scamming. Members are to contact customer service agents directly for any queries or concerns. The staff and customer service teams usually provide the functions listed in <strong>Tables 1 and 2</strong>; the customer service agents are listed in <strong>Figure 12</strong> by their functions and Telegram handles.</p>
        <div>
          <div>
            <div>Chinese Term</div>
            <div>English Term</div>
            <div>Explanation of Function</div>
            <div>Telegram Moniker/Channel</div>
          </div>
          <div>
            <div>大白公群</div>
            <div>Main Dabai Public Group</div>
            <div>Dabai Guarantee’s directory, to help threat actors navigate through different aspects of cybercrime</div>
            <div>@dabai_a</div>
          </div>
          <div>
            <div>供求信息</div>
            <div>Supply and demand information</div>
            <div>A channel where Dabai Guarantee’s administrators post advertisements on behalf of their customers (other threat actors)</div>
            <div>@dabaiyajing</div>
          </div>
          <div>
            <div>核心大群</div>
            <div>Core group</div>
            <div>A channel where other threat actors can post their own advertisements and URLs for their websites, as well as key contact information, such as Telegram monikers</div>
            <div>@dabai_c</div>
          </div>
          <div>
            <div>客服频道</div>
            <div>Dabai Guarantee’s official customer service channel</div>
            <div>A channel for individuals to reach out to customer service officers who cater to different categories of cybercrime</div>
            <div>@dabai_f</div>
          </div>
          <div>
            <div>人工客服 @dabai 咨询、拉群、广告</div>
            <div>Human customer service agents for consultation, group chat, and advertising</div>
            <div>A bot channel that redirects individuals to human customer service agents for consultation, group chat, and advertising</div>
            <div>@dabai</div>
          </div>
          <div>
            <div>人工客服 @dabai 会员、解封、投诉</div>
            <div>Human customer service agents for membership queries, unblocking accounts, and complaints</div>
            <div>A bot channel that redirects individuals to human customer service agents for membership queries, unblocking accounts, and complaints</div>
            <div>@dabai</div>
          </div>
          <div>
            <div>人工客服 @dabai 验群、丢失群恢复</div>
            <div>Human customer service agents for group verification and lost group recovery</div>
            <div>
              <p>This is to prevent impersonation, such as threat actors starting their own Public Group that is not officially approved by Dabai Guarantee.</p>
              <p>There may be instances where Telegram deletes public channels for violating the terms of service, and the customer service team offers a service to restore them (This happened to Huione and Xinbi Guarantee; many of their channels were deleted by Telegram).</p>
            </div>
            <div>@dabai</div>
          </div>
          <div>
            <div>人工客服 @dabai 纠纷仲裁、资源对接</div>
            <div>Human customer service agents for dispute arbitration and resource matching</div>
            <div>
              <p>Customer service agents will attempt to resolve disputes between criminal groups when an unsatisfactory outcome is reached for one or more parties. They can also moderate disputes on transactions between buyers and sellers.</p>
              <p>Resource matching refers to customer service agents attempting to match criminal groups to certain existing groups that are already participating in specific campaigns. In addition, customer service agents can connect buyers with sellers of goods and services.</p>
            </div>
            <div>@dabai</div>
          </div>
          <div>
            <div>24小时客服机器人</div>
            <div>24-hour customer service bot</div>
            <div>@dabai</div>
          </div>
          <div>
            <div>公群报备机器人</div>
            <div>Public Group reporting bot</div>
            <div>A bot that assists members in reporting violations of the terms of service</div>
            <div>@dbhwbb_BOT</div>
          </div>
          <div>
            <div>公群记账机器人</div>
            <div>Public Group accounting bot</div>
            <div>A bot that can help to look up transactions, real-time USDT pricing in relation to Chinese Renminbi (RMB), and cryptocurrency wallet monitoring</div>
            <div>@dbjz_bot</div>
          </div>
          <div>
            <div>
              <p>客服人员名单 (@dbtm0 - @dbtm10 ）</p>
              <p>所有号标配 +888 虚拟号 没有一律骗子</p>
            </div>
            <div>
              <p>Customer service staff lists (@dbtm0 – @dbtm10)</p>
              <p>All customer service numbers come with a +888 virtual number. Any number without this is a scam.</p>
            </div>
            <div>@dbtm0 – @dbtm10</div>
          </div>
        </div>
        <p><em><strong>Table 1:</strong></em> <em>List of Dabai Guarantee’s official staff and functions (Source: Telegram, Recorded Future)</em></p>
        <div>
          <div>
            <div>Chinese Term</div>
            <div>English Term</div>
            <div>Explanation of Function</div>
            <div>Telegram Moniker/Channel</div>
          </div>
          <div>
            <div>业务号（大白）</div>
            <div>Business account (Dabai)</div>
            <div>A business account belonging to a person called Dabai, with no specific function stated</div>
            <div>@dbtm1</div>
          </div>
          <div>
            <div>业务号（萌萌）</div>
            <div>Business account (“Mengmeng” — Admin’s moniker)</div>
            <div>A business account belonging to a person called Mengmeng, with no specific function stated</div>
            <div>@dbtm9</div>
          </div>
          <div>
            <div>专群交易员</div>
            <div>Specialist traders</div>
            <div>A group of agents well-versed in certain types of trade to facilitate coordination and cooperation in the public channels</div>
            <div>
              <p>@dbtm0</p>
              <p>@dbtm3</p>
              <p>@dbtm4</p>
            </div>
          </div>
          <div>
            <div>公群交易员</div>
            <div>Public Group traders</div>
            <div>A group of agents who facilitate cryptocurrency transactions, receive deposits, and release payments to other criminal groups</div>
            <div>
              <p>@dbtm7</p>
              <p>@dbtm8</p>
              <p>@dbtm10</p>
            </div>
          </div>
          <div>
            <div>公群巡查号</div>
            <div>Public Group patrol account</div>
            <div>A group of agents who direct individuals to specific Public Group channels based on what they are looking for</div>
            <div>@dbtm2</div>
          </div>
          <div>
            <div>担保仲裁号</div>
            <div>Guarantee arbitration number</div>
            <div>A case reference number assigned by agents for any disputes between parties</div>
            <div>@dbtm5</div>
          </div>
          <div>
            <div>资源对接号</div>
            <div>Resource docking number</div>
            <div>A unique number is assigned to a case or transaction to track conversational and transaction records</div>
            <div>@dbtm6</div>
          </div>
        </div>
        <p><em><strong>Table 2:</strong></em> <em>List of Dabai Guarantee’s customer service agents (Source: Telegram, Recorded Future)</em></p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_115f4cbdef7c0992c48bda0b9b9ad1ce45fc57c4d.png?width=750&amp;format=png&amp;optimize=medium" width="946" height="1794" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 12:</strong></em> <em>Dabai Guarantee customer service Telegram channel “大白担保客服人员名单” (@dabai_f) provides a list of customer service agents (Source: Telegram)</em></div>
          </div>
        </div>
        <h2>Automated Bot System Directs Chinese Syndicates to Relevant Public Groups for Existing Campaigns</h2>
        <p>Insikt Group analyzed the public administrator bot @dbdbqg_bot to observe how a Dabai Guarantee user would be routed by the platform to participate in cybercriminal activities. To use this functionality, individuals must enter search terms in Mandarin. We used the terms 远程 (remote) and 数据 (data), which returned three and ten public channels, respectively. When querying for the term “远程” (remote), which typically refers to ghost-tapping campaigns involving NFC relay methods, three Public Group channels appeared as relevant results. When querying for the term “数据” (data), which typically refers to databases, ten Public Group channels specializing in datasets appeared in the results. In addition, using a country as a search term, such as 美国 (US), will also return results that show fraud or cyber campaigns targeting the US. This bot function demonstrates how easy it is for criminal groups to search for relevant groups, determine which campaigns they wish to participate in, and identify the types of datasets they are interested in procuring. <strong>Table 3</strong> shows the number of Public Group channels involved in fraud or cyber campaigns for the search terms; specific details are not listed due to certain global entities named in the Public Group channels belonging to Dabai Guarantee.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_15f049bcf72922d6642cce624cc2defd779717f0b.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1499" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 13:</strong></em> <em>Dabai Guarantee’s public administrator bot @dbdbqg_bot has a search function that will return results relevant to the individual’s search (Source: Recorded Future Data)</em></div>
          </div>
        </div>
        <div>
          <div>
            <div>Chinese Criminal Lingo and Corresponding English Meaning</div>
            <div>Number of Channels Returned as Search Results</div>
            <div>Explanation of Function</div>
            <div>Telegram Channels</div>
          </div>
          <div>
            <div>远程 (Remote)</div>
            <div>3</div>
            <div>Ghost-tapping/remote NFC-related payment card fraud involving point-of-sale (POS) terminals</div>
            <div>
              <p>@dbtm153 (64 members, 800 USDT deposit as of writing)</p>
              <p>@dbtm439 (49 members, 777 USDT deposit as of writing)</p>
              <p>@dbtm307 (268 members, 500 USDT deposit as of writing)</p>
            </div>
          </div>
          <div>
            <div>数据 (Data)</div>
            <div>10</div>
            <div>Threat actors buying and selling databases</div>
            <div>
              <p>@dbtm123 (519 members, 888 USDT deposit as of writing)</p>
              <p>@dbtm99 (49 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm688 (151 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm369 (65 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm567 (80 members, 2,888 USDT deposit as of writing)</p>
              <p>@dbtm449 (177 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm298 (145 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm327 (89 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm211 (836 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm816 (851 members, 500 USDT deposit as of writing)</p>
            </div>
          </div>
          <div>
            <div>美国 (US)</div>
            <div>2</div>
            <div>Fraud or cyber campaigns targeting US entities</div>
            <div>
              <p>@dbtm322 (338 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm932 (956 members, 500 USDT deposit as of writing)</p>
            </div>
          </div>
          <div>
            <div>钓鱼 (Phishing)</div>
            <div>1</div>
            <div>Phishing campaigns</div>
            <div>@dbtm142 (234 members, 500 USDT deposit as of writing)</div>
          </div>
          <div>
            <div>账号 (Account)</div>
            <div>2</div>
            <div>Burner accounts being used for fraud campaigns</div>
            <div>
              <p>@dbtm322 (338 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm425 (60 members, 500 USDT deposit as of writing)</p>
            </div>
          </div>
          <div>
            <div>银行 (Bank)</div>
            <div>2</div>
            <div>Fraud campaigns targeting or involving banks worldwide</div>
            <div>
              <p>@dbtm420 (117 members, 500 USDT deposit as of writing)</p>
              <p>@dbtm138 (50 members, 1,000 USDT deposit as of writing)</p>
            </div>
          </div>
        </div>
        <p><em><strong>Table 3:</strong></em> <em>Search results of Dabai Guarantee’s Public Group channels using their bot function (Source: Telegram, Recorded Future)</em></p>
        <h2>Outlook</h2>
        <p>Even with guarantee marketplaces such as Huione Guarantee being shut down, many Chinese criminals are likely turning to these Telegram-based guarantee marketplaces to sell illicit goods and to offer their services. Guarantee marketplaces such as Dabai Guarantee have demonstrated their ability to coordinate operations in countries such as Japan, South Korea, Canada, and the US by using Chinese-speaking individuals who are traveling or residing in those geographies to conduct retail and financial fraud. Over time, Dabai Guarantee may be able to establish itself as a trusted escrow platform for Chinese syndicates to rely on, despite the growing competition from existing and new guarantee marketplaces. There is also a possibility that operators of other guarantee marketplaces could execute an exit scam, leading to a loss of trust in guarantee marketplaces as a whole among Chinese criminals.</p>
        <p>Threat actors such as @J0hnNo1, the leader of Dabai Guarantee Public Group 301, seek to obtain physical goods and foreign currency through illegal means, giving specific instructions to different syndicates to complete their objectives. Such operations are scalable on demand and will become harder to track and disrupt over time due to the siloed nature of the sweeping and goods-receiving teams. This report showcases the activities and structure of a single group (Public Group 301), which is only one group among hundreds under Dabai Guarantee’s decentralized and growing infrastructure. Ghost-tapping and ATM withdrawals are commonly used by Chinese-speaking criminals for money laundering, and we will likely continue to see more threat actors facilitating such financial and retail-related crime on multiple guarantee marketplaces.</p>
        <p>Insikt Group assesses that Chinese syndicates will continue to recruit and deploy non-Chinese individuals with specific language skills to participate in campaigns, as exemplified by the Vietnamese individual mentioned in <strong>Figure 9</strong>.</p>
        <p>Insikt Group assesses that guarantee marketplaces have solidified themselves as a major alternative to traditional Chinese-language dark web marketplaces. This decentralized model is becoming increasingly popular among the global Chinese-speaking criminal diaspora, enabling criminals without sophisticated skillsets to coordinate with syndicates and participate in operations that require physical elements.</p>
        <h2>Appendix A: Glossary of Terms</h2>
        <div>
          <div>
            <div>Chinese</div>
            <div>Direct Translation</div>
            <div>Definition with Relevant Context</div>
          </div>
          <div>
            <div>公群</div>
            <div>Public Group</div>
            <div>Public Telegram channel/group facilitates a specific campaign, usually ending with a number; for example, 公群 1025 means Public Group 1025</div>
          </div>
          <div>
            <div>飞机</div>
            <div>Plane</div>
            <div>Cryptocurrency</div>
          </div>
          <div>
            <div>退押</div>
            <div>Backing down</div>
            <div>Withdrawal of funds from a Public Group</div>
          </div>
          <div>
            <div>交易所地址</div>
            <div>Transaction address</div>
            <div>Cryptocurrency transaction wallet address</div>
          </div>
          <div>
            <div>上押地址</div>
            <div>Betting/Staking Address</div>
            <div>Unique cryptocurrency addresses owned by Dabai Guarantee are usually listed in Public Groups. Threat actors who wish to launch a specific campaign must stake enough cryptocurrency as a deposit to create a Public Group channel; they will become the channel's “boss.”</div>
          </div>
          <div>
            <div>私下拉群做单</div>
            <div>Privately soliciting orders</div>
          </div>
          <div>
            <div>拉黑</div>
            <div>Blackmail</div>
            <div>When an individual blocks someone who contacts them directly (Dabai Guarantee’s staff will never initiate private chats with any individual)</div>
          </div>
          <div>
            <div>拉群</div>
            <div>Pull the crowd</div>
            <div>Start a new public Telegram group and get people to join it so other criminal groups can participate in a new, specific campaign</div>
          </div>
          <div>
            <div>扫货</div>
            <div>Sweep goods</div>
            <div>To obtain physical goods or conduct ATM cash withdrawals, typically through illegal methods such as ghost-tapping or financial fraud</div>
          </div>
          <div>
            <div>收货</div>
            <div>Receive goods</div>
            <div>To receive goods, typically obtained by sweeping teams via illegal means</div>
          </div>
          <div>
            <div>群老板</div>
            <div>Group boss</div>
            <div>Main coordinator to coordinate with other Chinese-speaking criminal groups for cyber and/or fraud campaigns; individuals who staked USDT to get approval to start a Public Group channel on Dabai Guarantee</div>
          </div>
          <div>
            <div>冒充</div>
            <div>Impersonate</div>
            <div>Some scammers may impersonate group bosses or create Telegram groups with the intention of scamming other Chinese syndicates.</div>
          </div>
          <div>
            <div>钱包监听</div>
            <div>Wallet monitoring</div>
            <div>To monitor cryptocurrency transactions in real time</div>
          </div>
          <div>
            <div>实时U价</div>
            <div>Real-time USDT value in relation to the Chinese Renminbi</div>
          </div>
        </div>
        <h2>Appendix B: Key Rules Written in Mandarin</h2>
        <p><em>(Translation available on p. 7)</em></p>
        <p>⚠️交易注意事项⚠️</p>
        <p>1.进群交易请先看置顶里面的群规则，交易过程请严格按照交易规则进行，群内所有事情请联系群内交易员 ，私下交易或者其他地方交易，后果自负，大白担保只担保本群内的交易。</p>
        <p>2.大白担保业务只担保我们的公群内已经报备过的交易，我们不为公群老板或者其他管理员个人做担保，公群群老板对自己的业务员负责，如果群内业务员违规操作，由公群老板负责。</p>
        <p>3.禁止以公群名义私下拉群做单，禁止金额不透明，如被用户举报后果自负。</p>
        <p>4.大白担保工作人员不会主动私聊你，主动私聊你的100%都是骗子，请直接拉黑。</p>
        <p>5.大白担保的上押地址是唯一的,发其它上押地址的一定是骗子,请大家远离骗子。</p>
        <p>6.客户上押后,请及时发送上押截图与我们 @dabai 核实确认,如长时间未找 @dabai 核实确认押金而造成的损失由自己负责。</p>
      ]]></content:encoded>
            <category>Research (Insikt)</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/research/media_12a2b50348f87fdac796e23309b50952256de876b.gif?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
        <item>
            <title><![CDATA[AI Hype vs. Reality: Is AI Really Rewriting the Vulnerability Equation?]]></title>
            <link>https://www.recordedfuture.com/jp/blog/ai-hype-vs-reality</link>
            <guid isPermaLink="false">https://www.recordedfuture.com/jp/blog/ai-hype-vs-reality</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[AI vulnerability research and discovery capabilities are improving, but they have not changed the fundamentals of vulnerability management.]]></description>
            <content:encoded><![CDATA[
        <p>AI vulnerability research and discovery capabilities are improving, but they have not changed the fundamentals of vulnerability management. Instead, they are scaling up problems familiar to vulnerability managers: patch prioritization and remediation backlogs.</p>
        <p>For defenders, the timeline for determining which vulnerabilities matter most and remediating them before exploitation begins is narrowing, even as the overall volume of vulnerabilities rises. Organizations that rely on manual prioritization, slow patch cycles, or legacy software will face growing operational and security risks.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_1fb4a4f2fe7e8c18423993bce78372f9b03bc2cb9.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="1111" />
            </div>
          </div>
          <div>
            <div><strong>Figure 1:</strong> Reality versus hype of automated vulnerability research</div>
          </div>
        </div>
        <h2>The Vulnerability to Exploit Ratio</h2>
        <p>Vulnerabilities are software flaws attackers can use to gain access, run malicious code, escalate privileges, or disrupt operations. However, not every bug becomes a real-world threat: many are hard to reach, difficult to weaponize, or simply not worth an attacker’s time.</p>
        <p>The total number of disclosed vulnerabilities has increased sharply in recent years, rising from roughly 21,000 in 2021 to nearly 50,000 in 2025. Part of that increase likely reflects stronger disclosure practices and bug bounty activity, though software growth, a broader attack surface, and more systematic reporting also play a role. Nonetheless, in 2025, Recorded Future only identified 446 vulnerabilities that were actively exploited in the wild, a reminder that confirmed exploitations remain a small fraction of total disclosures.</p>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="Chart" src="https://www.recordedfuture.com/jp/media_18527fc82a41818c43e47e083747868e40ae2a8c2.jpg?width=750&amp;format=jpg&amp;optimize=medium" width="704" height="413" />
            </div>
          </div>
          <div>
            <div><em><strong>Figure 2:</strong></em> <em>Yearly comparison of disclosed CVEs against CVEs with public exploits and vulnerabilities assessed as actively exploited by the Cybersecurity and Infrastructure Agency’s Known Exploited Vulnerabilities (KEV) Catalog and Recorded Future, 2021-2025</em></div>
          </div>
        </div>
        <p>This is because attackers do not exploit every bug they find. Instead, they focus on developing exploits for the small subset of vulnerabilities that offer the best combination of reach, reliability, and return on investment, such as flaws that can be exploited remotely or affect widely used software. In other words, a vulnerability still has to be validated, turned into a reliable exploit, matched to a target, and integrated into an attack path worth the effort.</p>
        <p>When a flaw matches the criteria, however, exploitation can <a href="https://www.vulncheck.com/blog/state-of-exploitation-2026">move quickly</a>. VulnCheck found that nearly 29% of KEVs in 2025 were exploited on or before CVE publication, a slight increase from the previous year, indicating the continued prevalence of zero-days and n-days. Much as their legitimate counterparts use AI in software development, adversaries are <a href="https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/">already using</a> AI to accelerate parts of the attack workflow, including vulnerability research, exploit-path analysis, and malware development, even if its precise effect on exploitation timelines is hard to quantify. <a href="https://zerodayclock.com/collapse#the-math">Some trackers</a> estimate the median time-to-exploit may now be measured in hours rather than days, demonstrating the shortening window of time to act on a high-impact vulnerability.</p>
        <h2>How AI Changes the Equation</h2>
        <p>Anthropic and OpenAI recently drew significant attention through their limited release of what they claimed were uniquely powerful cyber defense models. An independent <a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities">evaluation</a> of Anthropic’s Mythos found significant improvements in multi-step cyberattack simulations. However, AI-assisted vulnerability discovery and penetration testing predate these models, and most frontier models have <a href="https://c3.unu.edu/blog/large-language-models-in-vulnerability-research-opportunities-and-responsibilities">already demonstrated</a> the ability to identify vulnerabilities and assist with exploit development. At present, these tools are still most effective in the hands of capable operators rather than enabling frictionless, low-skill exploitation at scale. This matters, too, as even if these capabilities are used primarily by security researchers in the near term, the resulting increase in disclosures, proofs of concept, and validated findings still adds to the defensive burden.</p>
        <p>This impacts vulnerability management in three important ways:</p>
        <ul>
          <li><strong>More credible vulnerability reports to triage:</strong> New agentic systems can do more than flag suspicious code; they can reason through program behavior, validate findings, and help identify which weaknesses appear most exploitable.</li>
          <li><strong>Less time to mitigate exploitable vulnerabilities:</strong> Large-language models (LLMs) are accelerating the speed and scale of weaponization, meaning the path from disclosure to exploit could go from hours to minutes.</li>
          <li><strong>Reduced the cost of exploit development:</strong> Emerging models appear more capable of producing proof-of-concept exploit code, testing attack paths, and helping skilled operators iterate toward weaponizable exploits faster than before.</li>
        </ul>
        <div>
          <div>
            <div>
              <img loading="lazy" alt="" src="https://www.recordedfuture.com/jp/media_10874cbebef535ea3d33f126ec3451367c311bee9.png?width=750&amp;format=png&amp;optimize=medium" width="2048" height="990" />
            </div>
          </div>
          <div>
            <div><strong>Figure 3:</strong> The vulnerability equation: How automated capabilities will likely impact reporting, exploit development, and impact</div>
          </div>
        </div>
        <h3>More Reports, More Noise</h3>
        <p>Using AI agents for software code will almost certainly increase the number of reported vulnerabilities and developed proofs-of-concept. Microsoft’s April 2026 Patch Tuesday, which followed Anthropic’s Project Glasswing announcement, was the company’s second-largest on record. However, according to <a href="https://www.theregister.com/2026/04/14/microsofts_massive_patch_tuesday/">Microsoft</a>, it “does not reflect a significant increase in AI‑driven discoveries, though [they] did credit one vulnerability to an Anthropic researcher using Claude.” The more important question is not whether more flaws will be found — because they will be — but whether defenders can process, validate, and prioritize them fast enough to act.</p>
        <p>Vulnerability submissions are already overwhelming researchers’ ability to <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth">assess</a> their overall risk, creating a backlog of vulnerability enrichment and scoring. If AI sharply increases the volume of plausible findings, defenders will face even more uncertainty around which vulnerabilities represent the next high-impact systemic event and which are background noise.</p>
        <h3>Less Time to Act</h3>
        <p>For the vulnerabilities that are actually a problem, defenders have even less time to respond. Automated exploit development will likely shorten the path from discovery to proof of concept and, in some cases, to weaponization for the subset of vulnerabilities worth pursuing. Adding to the triage problem, some medium-severity or otherwise “non-critical” vulnerabilities will need to be re-evaluated as possible components of exploit chains, even if they would not normally rank as urgent on their own.</p>
        <h3>Drowning out the Alarms</h3>
        <p>Even as defenders deal with more noise, a larger volume of reported, plausible findings is likely to increase the absolute number of high-impact exploits they need to address quickly. As a result, defenders face an even greater challenge in identifying the small subset of issues that matter most before attackers do.</p>
        <p>This does not mean every newly disclosed flaw will be weaponized, or that high-impact, “internet-breaking” events will become commonplace; however, even a modest increase in exploited vulnerabilities puts more pressure on prioritization, patching speed, and compensating controls, especially for organizations already struggling with manual triage, slow patch cycles, or legacy software.</p>
        <h2>How to Use Automation for Good</h2>
        <p>For most organizations, the immediate risk is not that every vulnerability will suddenly be exploited, but that defenders will have less time to determine which findings matter most. Vulnerability discovery and exposure management should therefore be treated as related but distinct problems: AI may increase the number of findings, but defenders still need context to determine which exposures are actually reachable, high-impact, and worth urgent remediation.</p>
        <p>In this environment, using AI-enabled vulnerability discovery, prioritization, and defensive remediation will be essential to keeping pace with attackers. The five actions listed in the following section can help organizations stay ahead of the threat.</p>
        <h3>1. Automate Vulnerability Prioritization and Response</h3>
        <p>Shift from CVSS-only scoring to real-time exploitability and exposure-based risk scoring to handle the surge in AI-assisted vulnerability discovery. Deploy automated scanning, validation, and threat hunting to identify exploitation activity quickly, especially in widely used software and internet-facing systems. Recorded Future’s Insikt Group regularly reports on new vulnerabilities and exploit trends and develops Nuclei templates to detect actively exploited vulnerabilities.</p>
        <h3>2. Accelerate Patching and Upgrade Cycles</h3>
        <p>As the time to exploit shifts from days to hours, the time to mitigate vulnerabilities will similarly shorten. Patch management will need to move faster, particularly for internet-facing systems, widely used software components, and critical dependencies. Automated remediation and automated compensating controls will likely become necessary to keep pace with AI-accelerated discovery. The Vulnerability Intelligence module in the Recorded Future Intelligence Operations Platform can help with prioritization based on the likelihood of exploitation. Ensure all automated actions are logged and regularly audited by a human, and require a human-in-the-loop for any actions on high-impact systems.</p>
        <h3>3. Reduce Dependence on Legacy and Unsupported Software</h3>
        <p>AI may make it easier for threat actors to identify and validate exploitable weaknesses in older, under-maintained codebases. Unsupported systems and aging software are likely to become increasingly difficult to justify unless they are strongly isolated and tightly controlled.</p>
        <h3>4. Shift Vulnerability Detection Earlier in the Software Lifecycle</h3>
        <p>Organizations should integrate automated security testing and AI-assisted vulnerability discovery into development pipelines. Early detection can help defenders fix vulnerabilities before production, reducing remediation burden later.</p>
        <h3>5. Get Ready for the Next High-Impact Event</h3>
        <p>Develop emergency response and mitigation playbooks specifically for high-impact, broadly applicable flaws, including scenarios where a patch is not immediately available. Preparation should include not just patching, but also containment measures such as segmentation, access restrictions, traffic filtering, and other compensating controls.</p>
      ]]></content:encoded>
            <category>Blog</category>
            <enclosure length="0" type="image/jpg" url="https://www.recordedfuture.com/jp/blog/media_11168f446613f5d773eced354e3680b7c6f41322f.png?width=1200&amp;format=pjpg&amp;optimize=medium"/>
        </item>
    </channel>
</rss>