Technical ValidationResearch / emerging practice
Google documents agent-enabled credential harvesting and AI resource theft
2026-09-08Google Threat Intelligence Group / Mandiant
Google's September 8 report describes a Q2 2026 case in which attackers compromised a cloud resource and planned, built, and executed an agent-enabled credential-harvesting campaign in under six hours. It also documents theft of AI credentials and unauthorized use of victim cloud resources.
Why this is evidenceThe timeline describes one observed case, not an industry average or a claim that all attacks are autonomous. The report is newly published; the described activity occurred earlier.
See original source — Google Threat Intelligence Group / Mandiant: GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI ↗Technical ValidationOperational validation
Chrome release addresses a V8 vulnerability with an exploit in the wild
2026-09-03Google Chrome
Google's September 3 desktop release includes 12 security fixes and states that an exploit for CVE-2026-85046 exists in the wild. The notice lists Chrome 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux.
Why this is evidenceThis connects a vulnerability identifier, exploitation evidence, and a software release. The listed versions belong to this announcement; they are not a continuously maintained latest-version list. The notice does not establish victim counts or attacker identity.
See original source — Google Chrome: Stable Channel Update for Desktop — September 3, 2026 ↗Technical ValidationOperational validation
Cisco revises IOS XR hardening details on September 8
2026-09-02; revised 2026-09-08Cisco PSIRT
Cisco groups internally discovered issues under seven CVE identifiers, including two rated 9.8. It reports no known malicious use and no workarounds. Advisory version 1.4, dated September 8, updates superseded MPLS-TE software maintenance updates.
Why this is evidenceSeverity, exploitation status, and patch coverage are separate questions. Seven grouped CVE identifiers do not mean exactly seven underlying bugs. Fixed-software requirements vary by platform and release; the canonical advisory carries the current tables.
See original source — Cisco PSIRT: Cisco IOS XR Software Security Hardening Release: September 2026 ↗Technical ValidationOperational validation
Fake IT-support contacts use Teams to obtain user-approved remote access
2026-09-02Microsoft Threat Intelligence
Microsoft describes external Teams contacts impersonating support staff and persuading users to grant remote access. The documented chain includes implant deployment, discovery, and lateral movement, following user authorization through legitimate support tools.
Why this is evidenceThis is evidence of support-workflow abuse and social engineering. It does not establish a Teams software vulnerability or suggest that merely receiving a chat compromises a device.
See original source — Microsoft Threat Intelligence: Impersonating IT support: how threat actors turn a remote session into enterprise-wide access ↗Technical ValidationOperational validation
TerminalFix uses a fake verification prompt to establish a reverse tunnel
2026-08-28Microsoft Threat Intelligence
Microsoft's TerminalFix analysis describes a fake CAPTCHA prompt that persuades a user to execute a command, followed by a multistage intrusion and a reverse tunnel.
Why this is evidenceThe case connects a human verification pretext with malware execution and network access. Microsoft distinguishes observed activity from possible downstream actions; it did not observe the suggested ransomware or data-theft outcomes in this analyzed chain.
See original source — Microsoft Threat Intelligence: TerminalFix campaign deploys a reverse tunnel through multistage intrusion ↗Technical ValidationResearch / emerging practice
Invisible Unicode characters appear in phishing keyword evasion
2026-09-03Microsoft Security Research
Microsoft describes invisible Unicode characters inserted into phishing text to obstruct keyword parsing. Signature activity increased from February 9 and remained elevated on weekdays for roughly three months. Layered protections flagged most of the messages.
Why this is evidenceThis illustrates the difference between visible text and machine-processed content. It is newly published analysis of older activity, not evidence that all email protections are defeated or that every invisible character is malicious.
See original source — Microsoft Security Research: ASCII smuggling crosses over from AI prompt injection to phishing evasion ↗Technical ValidationOperational validation
Counterfeit vendor pages deliver changing malicious installers
2026-09-01Microsoft Threat Intelligence
Microsoft describes look-alike software download pages distributing malicious installers whose contents change between downloads. Observed affected devices were predominantly associated with China-based operations and Chinese-speaking users across several industries.
Why this is evidenceThe campaign illustrates brand impersonation leading to malware delivery. Impersonating a vendor's download page does not establish compromise of its official distribution. The observed geography is not a measured global scope.
See original source — Microsoft Threat Intelligence: Counterfeit installers to system compromise: Tracking a deceptive software download campaign ↗Government / AuthoritativeStandard / framework
EU manufacturer reporting duties apply from September 11, 2026
Applies 2026-09-11European Parliament and Council
The Cyber Resilience Act's Article 14 covers actively exploited vulnerabilities and severe product-security incidents: early warning within 24 hours and notification within 72 hours of awareness. Final vulnerability reports are due within 14 days after a corrective or mitigating measure becomes available; final severe-incident reports within one month after the incident notification.
Why this is evidenceArticles 14, 69, and 71 distinguish reporting triggers and transitional coverage. Article 14 applies from September 11, 2026; general application begins December 11, 2027. These are duties for in-scope manufacturers and products, not universal reporting requirements for every organization.
See original source — European Parliament and Council: Regulation (EU) 2024/2847 — Articles 14, 69 and 71 ↗Standards / FrameworkStandard / framework
NIST finalizes its CSF 2.0 informative-references guide
2026-08-25NIST
NIST finalized SP 1347 on August 25. It explains relationships between CSF 2.0 outcomes and other documents and introduces tools for finding and using those mappings.
Why this is evidenceThis is a final framework-mapping resource. A crosswalk establishes relationships between documents; it does not itself prove that an organization implemented a control or achieved an outcome.
See original source — NIST: SP 1347: NIST Cybersecurity Framework 2.0: Informative References Quick-Start Guide ↗Emerging / ResearchResearch / emerging practice
NIST releases draft guidance on AI-assisted CSF analysis
2026-08-19; comments due 2026-10-15NIST
NIST's initial public draft SP 1353 describes AI use in CSF analysis and reporting, with structured prompts, three notional use cases, and simulated organizational materials. The announcement sets an October 15, 2026 comment deadline.
Why this is evidenceThis is draft guidance on an evolving workflow, not a new mandatory standard or proof that AI-generated assessments are accurate. Its stated purpose differs from general AI best practices and comprehensive cybersecurity guidance.
See original source — NIST: Using AI for CSF 2.0 Analysis and Reporting—New Quick-Start Guide Available for Comment ↗Government / AuthoritativeMeasured outcome
Phishing and spoofing remained among the most frequently reported internet crimes
2025FBI Internet Crime Complaint CenterCross-sector
The FBI's 2025 Internet Crime Report recorded more than one million complaints overall and identified phishing/spoofing among the most frequently reported complaint categories.
Why this is evidenceThis is large-scale victim reporting evidence that phishing is not a theoretical training scenario; it remains a common real-world attack and fraud mechanism.
See original source — FBI: 2025 Internet Crime Report ↗Government / AuthoritativeMeasured outcome
Businesses reported hundreds of millions of dollars in BEC losses
2025FBI Internet Crime Complaint CenterCross-sector
The FBI's 2025 IC3 report lists reported Business Email Compromise losses above $568 million and separately documents AI-assisted BEC tactics including official-sounding executive impersonation and voice cloning.
Why this is evidenceBEC can produce major financial loss without exploiting a software vulnerability; the attacker exploits trust, business process, and identity verification.
See original source — FBI: 2025 Internet Crime Report ↗Government / AuthoritativeGovernment advisory
Scattered Spider targeted enterprise help desks and identity controls
2025-07-29FBI, CISA and international partnersCommercial facilities and other sectors
A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.
Why this is evidenceThe advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.
See original source — CISA / FBI / International Partners: Scattered Spider Joint Cybersecurity Advisory AA23-320A ↗Government / AuthoritativeOperational validation
CISA red team gained persistent access while MFA blocked access to a sensitive system
2023-02-28CISACritical infrastructure
During a CISA red-team assessment, the team gained persistent network access and moved laterally, but MFA prompts prevented access to one sensitive business system. CISA also recommended EDR, modern identity practices, centralized cybersecurity data, and Zero Trust architecture.
Why this is evidenceThis controlled assessment shows both the failure modes of incomplete monitoring and the practical defensive value of MFA, endpoint visibility, identity controls, and modern architecture.
See original source — CISA: CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks ↗Primary / ConfirmedLaw-enforcement case
Qakbot infected more than 700,000 computers and enabled ransomware operations
2023-08-29U.S. Department of Justice / FBICross-sector
The Justice Department and FBI disrupted Qakbot infrastructure after identifying more than 700,000 infected computers worldwide. Qakbot was used to deliver additional malware and ransomware.
Why this is evidenceThis provides direct law-enforcement validation of malware as a delivery and access mechanism used in broader criminal ecosystems.
See original source — U.S. Department of Justice: Qakbot Malware Disrupted in International Cyber Takedown ↗Government / AuthoritativeGovernment advisory
ALPHV/BlackCat ransomware activity documented through FBI investigations
2024-02-27FBI, CISA and HHSHealthcare and cross-sector
A joint advisory publishes indicators and tactics associated with ALPHV/BlackCat ransomware based on FBI investigations and notes that healthcare was the most commonly victimized sector among recent leaked victims.
Why this is evidenceThe advisory connects ransomware terminology to observed campaigns, indicators, tactics, victim impact, and recommended defensive actions.
See original source — CISA / FBI / HHS: #StopRansomware: ALPHV BlackCat Update ↗Primary / ConfirmedConfirmed incident
SolarWinds confirmed malicious code was inserted into Orion software builds
2020-12-14SolarWindsSoftware supply chain
SolarWinds disclosed to the SEC that a compromise of its software build system inserted a vulnerability into Orion product updates released between March and June 2020.
Why this is evidenceThis primary-source disclosure is direct evidence of software supply-chain compromise and the downstream risk created by trusted updates.
See original source — U.S. Securities and Exchange Commission: SolarWinds Form 8-K — December 14, 2020 ↗Primary / ConfirmedLaw-enforcement case
Capital One data theft exploited a misconfigured cloud-facing control
2019-07-29Capital OneFinancial services
The Justice Department described an intrusion into Capital One data through a misconfigured web application firewall; the case ultimately resulted in a federal conviction for computer intrusions and wire fraud.
Why this is evidenceThe case demonstrates how cloud security depends on configuration, identity permissions, monitoring, and data-access controls rather than the cloud provider alone.
See original source — U.S. Department of Justice: Seattle Tech Worker Arrested for Data Theft Involving Large Financial Services Company ↗Government / AuthoritativeStandard / framework
Log4Shell provides a concrete example of a CVE with remote-code-execution impact
2021-12Apache Log4j / NVDCross-sector software
NVD records CVE-2021-44228, commonly known as Log4Shell, describing how attacker-controlled JNDI endpoints could lead to arbitrary code execution in affected Log4j versions.
Why this is evidenceThis is a practical example of how a CVE identifier, severity information, affected versions, and technical impact are used together during vulnerability response.
See original source — NIST National Vulnerability Database: CVE-2021-44228 Detail ↗Standards / FrameworkStandard / framework
CVSS v4.0 formalizes severity, threat, and environmental context
2023-11-01FIRSTVulnerability management
FIRST's CVSS v4.0 specification defines Base, Threat, Environmental, and Supplemental metrics and explains that CVSS communicates vulnerability severity rather than serving as a complete business-risk score.
Why this is evidenceThe standard validates why vulnerability teams should use the vector and relevant context instead of treating one numeric score as the entire remediation decision.
See original source — FIRST: CVSS v4.0 Specification Document ↗Government / AuthoritativeOperational validation
Federal agencies were directed to adopt Zero Trust architectures
2021-2023CISA / U.S. Federal GovernmentFederal enterprise
CISA's Zero Trust Maturity Model and related federal strategy provide an implementation roadmap across identity, devices, networks, applications/workloads, and data.
Why this is evidenceZero Trust is an architecture and operating model with concrete implementation guidance, not a single vendor product or slogan.
See original source — CISA: Executive Order on Improving the Nation's Cybersecurity — Zero Trust Maturity Model ↗Government / AuthoritativeStandard / framework
CISA, USDS, and FedRAMP published a Cloud Security Technical Reference Architecture
2022-06CISA / USDS / FedRAMPFederal cloud
The Cloud Security Technical Reference Architecture documents shared-responsibility considerations, cloud service models, security posture, and migration guidance for secure federal cloud adoption.
Why this is evidenceIt validates that cloud security is a distinct architecture and governance discipline spanning provider capabilities and customer configuration responsibilities.
See original source — CISA / USDS / FedRAMP: Cloud Security Technical Reference Architecture v2.0 ↗Government / AuthoritativeOperational validation
NIST Zero Trust implementation guidance includes EDR/EPP and XDR capabilities
NIST implementation projectNIST National Cybersecurity Center of ExcellenceEnterprise architecture
NIST's Zero Trust implementation documentation describes endpoint security using EDR/EPP and notes that XDR can consolidate endpoint, network monitoring, and other security tools for automated monitoring, detection, analysis, and remediation.
Why this is evidenceThis provides neutral implementation evidence that EDR and XDR are established defensive capability patterns used inside broader enterprise architectures.
See original source — NIST NCCoE: Implementing a Zero Trust Architecture — Architecture Guidance ↗Government / AuthoritativeOperational validation
NIST practice guide implemented an XDR/SIEM capability in a healthcare reference environment
NIST SP 1800-30NIST NCCoEHealthcare
NIST SP 1800-30 implementation documentation describes an XDR system receiving log and machine data from endpoints to provide continuous visibility and detect cyber threats in a healthcare delivery environment.
Why this is evidenceThis is concrete implementation evidence for cross-source detection and response rather than a vendor-only definition.
See original source — NIST NCCoE: Securing Telehealth Remote Patient Monitoring Ecosystem — XDR Implementation ↗Standards / FrameworkStandard / framework
NIST documents centralized security log management as a foundation for detection and investigation
2006 / ongoing revisionNISTCross-sector
NIST SP 800-92 provides practical guidance for enterprise security log management and explicitly discusses centralized log management and SIEM technology.
Why this is evidenceSIEM and security-data architectures depend on reliable collection, storage, access, analysis, retention, and governance of telemetry—not merely buying a search interface.
See original source — NIST: SP 800-92 Guide to Computer Security Log Management ↗Government / AuthoritativeMeasured outcome
CISA SOAR pilot reduced an IOC response workflow from days to minutes
CISA pilotCISA / SLTT pilot participantsState and local government
CISA documented a multi-jurisdiction SOAR pilot in which automated IOC workflows reduced the timeframe from first identification to successful blocking from an average of about three days to approximately three minutes.
Why this is evidenceThis is unusually concrete public evidence that well-scoped security orchestration and automation can materially compress response time.
See original source — CISA: Indicators of Compromise Automation Pilot ↗Standards / FrameworkStandard / framework
NIST recognizes SOAR across current security guidance
CurrentNISTCross-sector
The NIST glossary maps SOAR to multiple publications, including SP 800-215 and SP 800-61 Rev. 3, establishing the term in current security architecture and incident-response guidance.
Why this is evidenceThe term is not merely vendor marketing; it appears in neutral federal security guidance and incident-response architecture.
See original source — NIST: SOAR — CSRC Glossary ↗Standards / FrameworkStandard / framework
NIST updated incident-response guidance for CSF 2.0
2025-04NISTCross-sector
NIST SP 800-61 Rev. 3 integrates incident response throughout cybersecurity risk management and focuses on improving detection, response, and recovery effectiveness.
Why this is evidenceAutomation belongs inside a governed incident-response capability; speed is useful only when the surrounding decision, evidence, containment, and recovery processes are sound.
See original source — NIST: SP 800-61 Rev. 3 — Incident Response Recommendations and Considerations ↗Technical ValidationStandard / framework
ATT&CK connects techniques to documented adversary procedures
Continuously maintainedMITRECross-sector
MITRE ATT&CK is a public knowledge base of adversary tactics and techniques that includes procedure examples showing how real threat groups and software have used those behaviors.
Why this is evidenceIt gives the encyclopedia a neutral behavioral language for connecting definitions to observed adversary activity without relying on one vendor's taxonomy.
See original source — MITRE: MITRE ATT&CK ↗Government / AuthoritativeStandard / framework
NIST AI RMF guidance calls for mechanisms to inventory AI systems
CurrentNIST AI Resource CenterAI governance
NIST's AI RMF playbook states that mechanisms should exist to inventory AI systems and describes inventories containing model/system artifacts, documentation, ownership information, data dictionaries, and incident-response information.
Why this is evidenceThis is authoritative support for the underlying transparency and inventory problem AIBOM approaches are trying to solve, even though AIBOM formats are still evolving.
See original source — NIST: AI RMF Playbook — Govern 1.6 ↗Emerging / ResearchResearch / emerging practice
NIST hosted technical work on AI Bills of Materials for supply-chain transparency
2024-09-17NISTAI supply chain
A NIST-hosted presentation focused specifically on using AI Bills of Materials to improve AI software transparency, security, trust, and supply-chain risk management.
Why this is evidenceAIBOM is an emerging practice rather than a universally settled standard; labeling the evidence this way keeps the encyclopedia accurate as the field matures.
See original source — NIST: Securing AI Ecosystems: The Critical Role of AIBOM ↗Technical ValidationResearch / emerging practice
OWASP documents excessive agency as a concrete risk in tool-using LLM systems
2025OWASP GenAI Security ProjectAI application security
OWASP describes how LLM agents with excessive functionality, permissions, or autonomy can perform damaging actions when influenced by unexpected, ambiguous, or manipulated outputs, including indirect prompt injection.
Why this is evidenceAgentic automation creates a new security boundary: the model is not only generating text but can invoke tools and change external systems.
See original source — OWASP: LLM06:2025 Excessive Agency ↗Technical ValidationMeasured outcome
Identity weaknesses played a material role in nearly 90% of Unit 42 investigations
2026-02-17Palo Alto Networks Unit 42Cross-sector
Unit 42's 2026 Global Incident Response Report says identity was involved in nearly 90% of investigated incidents and that 65% of initial access was driven by identity-based techniques, including phishing, credential misuse, and permission abuse.
Why this is evidenceThis frontline incident-response data validates identity as a primary modern attack surface rather than a supporting control category.
See original source — Palo Alto Networks Unit 42: 2026 Global Incident Response Report ↗Technical ValidationMeasured outcome
Cloud and SaaS incidents were dominated by identity compromise and data theft
2026-H1Google Cloud / MandiantCloud and SaaS
Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.
Why this is evidenceThe report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.
See original source — Google Cloud: Cloud Threat Horizons Report H1 2026 ↗Technical ValidationMeasured outcome
CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours
2026-08-03CrowdStrike Counter Adversary OperationsCross-sector
CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.
Why this is evidenceThese measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.
See original source — CrowdStrike: 2026 Threat Hunting Report ↗Technical ValidationOperational validation
Microsoft documented an AI-enabled device-code phishing campaign operating at scale
2026-04-06Microsoft Defender Security ResearchCross-sector
Microsoft observed a widespread campaign abusing OAuth device-code authentication with automated infrastructure, dynamic code generation, AI-personalized lures, token acquisition, automated reconnaissance, and malicious inbox-rule persistence.
Why this is evidenceThe campaign demonstrates that a victim can complete authentication on a legitimate Microsoft page and still authorize an attacker's session, making modern phishing a token and workflow problem rather than only a fake-password-page problem.
See original source — Microsoft Security: Inside an AI-enabled device code phishing campaign ↗Technical ValidationOperational validation
Large-scale AiTM phishing targeted more than 35,000 users across 13,000 organizations
2026-05-04Microsoft Defender Research and Microsoft Threat IntelligenceCross-sector
Microsoft analyzed a multi-stage phishing campaign observed in April 2026 that targeted more than 35,000 users across more than 13,000 organizations and ultimately used adversary-in-the-middle infrastructure to capture authentication tokens.
Why this is evidenceThis validates that session-token compromise and AiTM phishing are operating at enterprise scale and can bypass non-phishing-resistant MFA even when the user sees a legitimate authentication experience.
See original source — Microsoft Security: Breaking the code: Multi-stage 'code of conduct' phishing campaign leads to AiTM token compromise ↗Technical ValidationMeasured outcome
2026 DBIR: vulnerability exploitation became the leading breach entry point
2026-06Verizon BusinessCross-sector
Verizon's 2026 DBIR overview reports exploitation of software vulnerabilities at 31% of breach entry points, third-party involvement at 48%, and employee use of unapproved shadow AI at 45%, alongside increasing AI-driven attack speed.
Why this is evidenceThe DBIR provides broad breach-data evidence that vulnerability exploitation, third-party trust, and unmanaged AI use are not niche concerns in 2026; they are major enterprise exposure patterns.
See original source — Verizon: Vulnerability exploitation top breach entry point, 2026 DBIR finds ↗Technical ValidationMeasured outcome
CrowdStrike reported AI-enabled adversary operations up 89% year over year
2026-02-24CrowdStrikeCross-sector
CrowdStrike's 2026 Global Threat Report says AI-enabled adversary operations increased 89% year over year, average eCrime breakout time fell to 29 minutes, the fastest observed breakout was 27 seconds, and attacks increasingly traversed identity, SaaS, cloud, and unmanaged edge environments.
Why this is evidenceThe report validates both the growing operational use of AI by attackers and the shrinking time defenders have to detect and contain intrusions.
See original source — CrowdStrike: 2026 Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface ↗Emerging / ResearchResearch / emerging practice
Mandiant described AI moving from experimentation into operational adversary tradecraft
2026-03-09Google Cloud / MandiantCross-sector
Mandiant's 2026 AI Risk and Resilience report describes attackers moving beyond basic LLM use into adaptive code rewriting and agent-like workflows, while warning that shadow AI and poor AI asset visibility create significant enterprise risk.
Why this is evidenceThis distinguishes two different 2026 AI security problems: adversaries using AI to improve attacks, and organizations creating unmanaged attack surface through rapid AI adoption.
See original source — Google Cloud / Mandiant: AI Risk and Resilience ↗Government / AuthoritativeGovernment advisory
FBI warned that scammers were using AI-generated videos and voice cloning to impersonate trusted authorities
2026-07-20FBI Internet Crime Complaint CenterPublic / Cross-sector
The FBI warned of ongoing schemes impersonating IC3 and FBI personnel using AI-generated videos, spoofed websites, social media personas, and voice cloning. The advisory notes scammers can use synthetic media in real-time video chats and private communications to make fraudulent identities appear authentic.
Why this is evidenceThis is direct government validation that synthetic media is being used operationally for impersonation and fraud, reinforcing the need for independent identity verification rather than trusting voice or video appearance.
See original source — FBI / IC3: FBI Warns of Scammers Impersonating the IC3 ↗Technical ValidationOperational validation
M-Trends 2026 highlighted unmonitored Tier-0, virtualization, and edge infrastructure as persistence blind spots
2026-03-23Google Cloud / MandiantCross-sector
Mandiant's M-Trends 2026, grounded in more than 500,000 hours of incident investigations, describes sophisticated adversaries using unmonitored edge devices, virtualization stacks, and native network functionality to achieve persistence and evade conventional endpoint-focused defenses.
Why this is evidenceThe report validates that defenders need asset inventory, logging, patching, and incident-response plans for infrastructure that cannot rely on standard endpoint agents.
See original source — Google Cloud / Mandiant: M-Trends 2026: Data, Insights, and Strategies From the Frontlines ↗Government / AuthoritativeGovernment advisory
CISA validates phishing as a cross-channel social-engineering risk
2026CISACross-sector
CISA guidance treats phishing as a social-engineering problem that can use deceptive messages, links, identity cues, and multiple communication channels to steal access or manipulate users. The defensive guidance emphasizes recognition, independent verification, reporting, and stronger authentication.
Why this is evidenceIt provides a government-backed baseline for targeted phishing, SMS/QR variants, credential theft, spoofing, lookalike-domain abuse, and pressure against authentication workflows.
See original source — CISA: Recognize and Report Phishing ↗Standards / FrameworkStandard / framework
Internet standards define the SPF, DKIM and DMARC email-authentication model
2015-03IETFInternet infrastructure
RFC 7489 defines DMARC and explicitly describes how DMARC evaluates alignment using SPF and DKIM authentication results. Together the standards give domain owners and receivers mechanisms for authentication, policy, feedback, and handling unauthenticated mail.
Why this is evidenceThese controls are the technical foundation for reducing direct domain spoofing and for understanding why email authentication is stronger as a coordinated system than as isolated records.
See original source — IETF: RFC 7489 — Domain-based Message Authentication, Reporting, and Conformance ↗Standards / FrameworkStandard / framework
NIST identity guidance anchors modern authentication and least-privilege access
2025NISTCross-sector
NIST digital-identity and access-control guidance covers authenticator assurance, phishing resistance, federation, privileged access, and least-privilege principles. These concepts form the defensive foundation for reducing credential and privilege abuse.
Why this is evidenceIdentity security is not a collection of product features; it is a system of authentication strength, federation, authorization, privilege boundaries, and lifecycle controls.
See original source — NIST: SP 800-63B — Authentication and Authenticator Management ↗Technical ValidationOperational validation
OAuth enables delegated authorization and can be abused through malicious consent
2025IETF / MicrosoftCloud identity
OAuth provides scoped delegated access without sharing a user's password. Microsoft documents consent-phishing attacks in which a malicious application requests legitimate permissions and a user is socially engineered into granting access to mail, files, contacts, or other cloud data.
Why this is evidenceIt shows why application permissions and OAuth grants must be treated as first-class identity credentials and monitored independently of password resets or MFA enrollment.
See original source — Microsoft: Protect against consent phishing ↗Government / AuthoritativeOperational validation
MITRE and CISA document Active Directory credential abuse and lateral movement
2026MITRE ATT&CK / CISAEnterprise identity
MITRE ATT&CK documents Kerberoasting, Pass-the-Hash, forged Kerberos tickets, and use of alternate authentication material for lateral movement. CISA red-team and Active Directory guidance show these behaviors in realistic enterprise assessments and compromise scenarios.
Why this is evidenceIt connects abstract Active Directory terminology to repeatable post-compromise techniques attackers use to expand access and preserve control.
See original source — MITRE ATT&CK: TA0008 — Lateral Movement ↗Government / AuthoritativeGovernment advisory
Government and ATT&CK guidance validate core adversary lifecycle behaviors
2025-03CISA and international partnersCross-sector
CISA and partner guidance describes threat actors abusing native tools and trusted processes for execution, persistence, lateral movement, discovery, and credential access. MITRE ATT&CK organizes initial access, privilege escalation, persistence, and command-and-control as core adversary objectives.
Why this is evidenceThese concepts explain how attackers progress after an initial foothold and why behavior-based telemetry matters even when no obvious malware is present.
See original source — CISA and Partners: Identifying and Mitigating Living Off the Land Techniques ↗Standards / FrameworkStandard / framework
MITRE and NIST connect data theft to defensive data-loss controls
2026MITRE ATT&CK / NISTCross-sector
MITRE ATT&CK defines exfiltration as adversary behavior for stealing data, while NIST describes DLP as the ability to identify, monitor, and protect data in use, in motion, and at rest against unauthorized use or transmission.
Why this is evidenceThe pair makes the attack-and-control relationship clear: defenders need to understand both how data leaves and how policy, classification, and telemetry can constrain that movement.
See original source — NIST: Data Loss Prevention — CSRC Glossary ↗Standards / FrameworkStandard / framework
NIST and IETF standards establish modern cryptographic building blocks
2026NIST / IETFCross-sector
NIST cryptographic guidance, the Secure Hash Standard, PKI guidance, and the IETF TLS specification define core mechanisms for confidentiality, integrity, key management, certificates, and protected communications.
Why this is evidenceThese concepts are foundational dependencies for identity, secure transport, software trust, and data protection, and must be understood as a system rather than isolated acronyms.
See original source — NIST: Cryptographic Standards and Guidelines ↗Standards / FrameworkStandard / framework
NIST guidance maps traditional and modern enterprise network security controls
2022NISTEnterprise networking
NIST SP 800-215 examines modern enterprise networking and security services including firewalls, segmentation, VPN, cloud-delivered security, zero-trust access, and SASE-era architectures; NIST SP 800-94 separately covers IDS/IPS technologies.
Why this is evidenceIt shows how network security has evolved from perimeter filtering into distributed, identity-aware access and inspection across users, applications, branches, clouds, and data centers.
See original source — NIST: SP 800-215 — Guide to a Secure Enterprise Network Landscape ↗Technical ValidationResearch / emerging practice
NIST and CSA define major cloud-security capability categories
2022NIST / Cloud Security AllianceCloud
NIST includes CASB in its secure enterprise network guidance. Cloud Security Alliance describes CNAPP as an integrated model that combines posture and workload protection capabilities, including CSPM and CWPP, to contextualize and prioritize cloud risk.
Why this is evidenceLearners can distinguish overlapping cloud-security categories by the layer they protect and the questions they answer instead of treating them as interchangeable vendor labels.
See original source — Cloud Security Alliance: What is a Cloud-Native Application Protection Platform (CNAPP)? ↗Government / AuthoritativeGovernment advisory
NIST and CISA provide operational guidance for containers and Kubernetes
2022NIST / NSA / CISACloud-native infrastructure
NIST SP 800-190 covers container image, registry, orchestrator, host, and runtime security risks. NSA and CISA Kubernetes hardening guidance addresses workload, pod, network, authentication, logging, and configuration protections for clusters.
Why this is evidenceCloud-native security requires protecting both software artifacts and the orchestration control plane that runs them.
See original source — CISA: Kubernetes Hardening Guidance ↗Standards / FrameworkStandard / framework
OWASP standards and guidance validate core web and API security risks
2026OWASP FoundationSoftware and applications
OWASP ASVS and API Security guidance provide testable requirements for application and API controls, while OWASP prevention guidance covers injection and cross-site scripting as common implementation weaknesses requiring secure coding and validation.
Why this is evidenceIt grounds the application-security entries in openly maintained technical standards used by developers, testers, and security teams.
See original source — OWASP: Application Security Verification Standard ↗Government / AuthoritativeGovernment advisory
CISA KEV proves why exploitation evidence should drive remediation priority
2026CISA / NISTCross-sector
CISA's Known Exploited Vulnerabilities catalog identifies vulnerabilities confirmed to be exploited in the wild and directs organizations to prioritize remediation. NIST patch-management guidance treats patching as preventive maintenance with risk-based planning and verification.
Why this is evidenceIt connects exploit, zero-day, and RCE terminology to the operational question that matters most: whether vulnerable systems are exposed to real attacker activity and how quickly mitigations can be verified.
See original source — CISA: Known Exploited Vulnerabilities Catalog ↗Government / AuthoritativeGovernment advisory
CISA states continuous asset visibility is a precondition for cyber-risk management
2022-10CISACross-sector
CISA BOD 23-01 states that continuous and comprehensive asset visibility is a basic precondition for managing cybersecurity risk and centers recurring asset discovery and vulnerability enumeration as measurable operational activities.
Why this is evidenceAttack-surface and exposure-management programs start with the same reality: unknown assets and exposures cannot be prioritized, validated, or remediated reliably.
See original source — CISA: BOD 23-01 — Improving Asset Visibility and Vulnerability Detection on Federal Networks ↗Government / AuthoritativeOperational validation
NIST and CISA validate offensive testing as a way to expose real control gaps
2023-02NIST / CISACross-sector
NIST SP 800-115 provides guidance for security testing and assessment, while CISA red-team reporting demonstrates how authorized adversary emulation can reveal persistence, lateral movement, identity, segmentation, and monitoring weaknesses in realistic environments.
Why this is evidencePenetration, red-team, and purple-team practices differ in scope and collaboration model, but all create value by turning assumed security into evidence that controls can or cannot withstand realistic attack behavior.
See original source — CISA: CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks ↗Standards / FrameworkStandard / framework
NIST integrates incident response with evidence-driven investigation and recovery
2025-04NISTCross-sector
NIST SP 800-61 Rev. 3 integrates incident response across CSF 2.0 risk-management activities, while SP 800-86 provides practical guidance for collecting and analyzing file, operating-system, network, and application evidence during incident response.
Why this is evidenceResponse decisions are stronger when containment, recovery, and lessons learned are supported by preserved evidence and repeatable forensic practice.
See original source — NIST: SP 800-61 Rev. 3 — Incident Response Recommendations and Considerations ↗