Archive of

Intel 471: Criminals recruit insiders at FedEx and UPS

Cybercriminals are actively trying to recruit employees inside target organizations, because staff with legitimate access can bypass security controls that are hard to defeat from the outside. This is according to Intel 471's new report, Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services.

The threat intelligence firm found that routine tasks such as looking up information, resetting accounts, approving transactions or changing shipments are being packaged and sold as services to criminal customers.

Recruitment dominates the sample

Intel 471 analyzed 85 records. Recruitment was the largest category, with 45 records. Another 15 involved claims of insider capability, 11 of them claims of insider access. Twelve records advertised services allegedly enabled by employee privileges. The rest covered access and data offerings, a recruitment guide and a complaint.

Read More


Android 17 Advanced Protection adds spyware forensic logs

Google has added six features to Advanced Protection in Android 17. One of them targets a familiar problem in spyware investigations: the evidence often disappears from the phone once the attacker cleans up.

The question matters most to people such as journalists, who may suspect their device has been compromised and then find nothing left to examine. The new release addresses this by keeping a copy of security records away from the handset itself. People already using Advanced Protection will get a notification when the new capabilities reach their devices.

Logs that survive a cleanup

The headline feature is Intrusion Logging. It records security and network events on the device, including app activity. If a user suspects a compromise, they can download the logs, decrypt them and hand them to trusted security experts for analysis.

Read More


AI agents keep data access after tasks end, Delinea finds

Organizations are writing policies for AI tools, but many cannot enforce them when an agent actually acts. That is the main finding of Delinea's 2026 Identity Security Report: The AI Enforcement Gap. The report describes AI agents that keep their permissions long after their work is finished.

The report surveyed IT and security leaders as well as employees. Identity security teams said they are worried about two things: the ongoing access AI agents have to company systems, and the actions these agents take on behalf of users.

"Written policy is only as good as your ability to enforce it at the moment an AI agent acts," said Art Gilliland, CEO of Delinea. "Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can't see or report on what their agents actually do."

Read More


Legit Security AI agent now fixes open-source dependencies

Legit Security has expanded its Agentic Remediation feature so it now handles vulnerabilities in open-source dependencies, not only in code that a company writes itself. The goal is to take development teams from a vulnerability finding to a verified fix without anyone having to triage the issue by hand.

Until now, the agent worked on static analysis findings in first-party code, meaning code written by a company's own engineers. The new release points the same agent at packages pulled in from outside, which the company describes as the other major source of vulnerabilities in modern software.

A volume problem

Read More


Sophos CISO Advantage uses AI to prioritize security fixes

Sophos has released Sophos CISO Advantage, a service that uses agentic AI to link day-to-day security operations with longer-term security strategy. The goal is to tell businesses where their cyber risk lies, which fixes to fund first, and whether things are getting better over time.

The company says the output is written in plain language so that business leaders, not only security staff, can understand it, approve budgets and act on it. Sophos describes the offering as a new market category.

From security data to a roadmap

CISO Advantage assesses an organization's environment and maps its controls against established frameworks. These include NIST CSF (the US National Institute of Standards and Technology's Cybersecurity Framework), CIS v8, Cyber Essentials Plus (a UK certification scheme), and NCSC CAF, the Cyber Assessment Framework published by the UK's National Cyber Security Centre.

Read More