Latest Articles
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intelligence and risk ratings in a single workflow.
0
1
PurpleDelta's Fraudulent Employment Operations
Executive Summary
Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. PurpleDelta operators maintained at least 22 fabricated personas across multiple clust
0
1
CopyCop Targets AI Investment in Armenia
The Russian influence network CopyCop (Storm-1516) very likely targeted the joint United States (US) and Armenian-backed Firebird AI data center in Hrazdan, Armenia, as part of a broader campaign to undermine Armenia's westward geopolitical and economic realignment. Between June 24 and July 13, 2026, Insikt Group documented three separate CopyCop media impersonations targeting the facility ahead of its July 2026 opening. These impersonations fabricated an imminent earthquake risk, cast doubt as
0
1
Malware Crypting Services and the Threat Actors Who Sell Them
Executive Summary
Crypting services and products modify malicious payloads to help threat actors bypass detection, complicate analysis, and preserve malware usability after exposure. Although basic crypting consists of encrypting or obfuscating a customer-supplied payload, mature providers increasingly operate as broader malware-enablement services. Their offerings often combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery
0
2
Mines, Minds, and Machines: The Journey of AI
Minerals become chips. Chips supply data centers. Data centers power the training of models, and models are acquiring arms and legs. Mines, Minds, and Machines traces the supply chain of the fourth industrial revolution, and shows how geopolitical rivalry and cyber operations now run along every link.
0
7
The Hugging Face Hack Was Cheap Persistence at Work
The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow.
The agent discovered and exploited previously unknown vulnerabilities. The more consequential development came afterward. Over a four-and-a-half-day campaign, it carried out roughly 17,600 actions against Hugging Face’s infrastructure. Most of those actions failed. The operation advanced because each failure imposed little cost, and the next attempt could begin immediately. The
0
7
July 2026 CVE Landscape
In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data.
The 85 vulnerabilities
0
3
Emerging Threats to Neurotechnology
Summary
Neurotechnology is rapidly moving beyond clinical use cases, expanding the attack surface for sensitive neurological and biometric data: As adoption grows, larger volumes of brain activity, biometric, and behavioral data will be collected by commercial platforms, creating new opportunities for data theft, misuse, and exploitation.
China and the United States (US) are engaged in strategic competition in neurotechnology development: The US leads in the number of neurotechno
0
7
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
Agentic defense will be essential to countering agentic offense. However, defenders must actively mitigate the risk of autonomous systems operating outside of their expected parameters.In July 2026, OpenAI disclosed that models undergoing an internal cybersecurity evaluation had escaped their testing environment and compromised part of Hugging Face’s production infrastructure. OpenAI characterized the event as an “unprecedented cyber incident.”The incident should put security leaders on alert, b
0
4
8 Ways AI is Changing Threat Intelligence
The fundamentals haven't changed — the clock speed has. Defending everything is still the job, but adversaries can now move at machine-speed, which means the intelligence behind every decision has to move just as fast.
AI cuts both ways. The same automation that lets defenders orchestrate faster is available to attackers too, and whoever uses it more creatively will often hold the advantage at any given moment.
Trust in automation is being built one decision at a
0
3
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
Executive Summary
The United States (US) will almost certainly remain at heightened threat from physical threat activities conducted by homegrown and domestic violent extremists (HVEs and DVEs, respectively) during the next twelve months. Since the last installation of this report in July 2025, there has been a substantial increase in mass-casualty attacks and attack plots by Islamic State (IS) supporters, assassinations and attempted assassinations of US government officials and high-pr
0
10
Dealing with AI-Generated Extortion
Proving a Negative
How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files weren’t stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors?
0
8
Ransomware is the Scoreboard
13,000.
That’s the number of ransomware victims Recorded Future has observed over the past two years.
Watching the near-real-time ransomware attacks on businesses, non-profits, and government agencies has left me, like many security professionals and board directors, pondering how and why cyber defense keeps losing this particular fight. Adversaries like Interlock and RansomHub have continued their successful march to riches over the past 18 months. The multi-billion-ruble questi
0
10
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Executive Summary
Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families through ongoing tracking of the TAG-195 MaaS ecosystem. We named two of the families "TinyEgg" and “ChonkyChicken"; the third is a modularized variant of ChonkyChicken. The fourth family, which includes a modified browser credential theft helper, we named “ChromEggscalator". TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling Insikt Group has
0
9
Modern Attack Vectors | Recorded Future
Key Takeaways
Modern threat actors have shifted from brute-forcing firewalls to compromising digital identities via stolen session cookies and credential stuffing to bypass MFA entirely
Adversaries increasingly target unpatched edge infrastructure like VPNs for zero-day access while exploiting open-source repositories to launch upstream supply chain attacks
Traditional internal security telemetry may miss critical pre-attack signals, making real-time, outsi
0
12
Threat Hunting: A Guide | Recorded Future
Enterprise security architectures have never been more heavily funded, yet the perimeter is functionally obsolete. Despite multi-million dollar investments in next-generation firewalls and complex defense stacks, sophisticated adversaries slip past automated boundaries every day. They don't break in; they log in, embedding themselves silently into the background noise of normal business operations.
To survive in this environment, modern cyber defense teams must anchor their strategy to a
0
10
Tracking Advanced Persistent Threat Groups | Recorded Future
Key takeaways
Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conducted by well-funded human adversaries (often nation-states) who target specific organizations for espionage, data theft, or critical infrastructure disruption.
Traditional security tools often fail because APT groups bypass signature-based defenses by using customized malware and Living-off-the-Land (LotL) tactics that mimic legitimate user activity inside the network.
0
10
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Executive Summary
Between January and June 2026, Tehran survived unprecedented military, economic, and political pressure by relying on its longstanding hybrid warfare model: blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. Artificial intelligence (AI) enhanced these capabilities, acting as a force multiplier and almost certainly increasing the speed, scale, and effectiveness of Iranian operations. Ultimately, Iran
0
8
The Shift: A New Era of AI Regulation
The export controls imposed on Anthropic’s Fable model mark a significant shift in United States (US) artificial intelligence (AI) policy. The controls set a precedent for treating frontier AI models as strategic assets rather than ordinary software products, creating uncertainty for enterprises adopting advanced AI. Security leaders should respond by investing in resilient, interoperable AI strategies rather than simply chasing the most powerful model available.
The
0
10
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
A fast-growing scam impersonates city and county planning departments, sending property owners real-looking invoices for fake permit fees and pressuring them to wire payment on a deadline. Because the victim authorizes the transfer, payments commonly clear the behavioral checks built to catch fraud, making beneficiary accounts one of the most reliable signals to track this campaign. Research from CYBERA, the partner behind Recorded Future® Money Mule Intelligence, maps a single active ring down
0
10
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intell
0
1
PurpleDelta's Fraudulent Employment Operations
Executive Summary
Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Futur
0
1
CopyCop Targets AI Investment in Armenia
The Russian influence network CopyCop (Storm-1516) very likely targeted the joint United States (US) and Armenian-backed
0
1
Malware Crypting Services and the Threat Actors Who Sell Them
Executive Summary
Crypting services and products modify malicious payloads to help threat actors bypass detectio
0
2
Mines, Minds, and Machines: The Journey of AI
Minerals become chips. Chips supply data centers. Data centers power the training of models, and models are acquiring ar
0
7
The Hugging Face Hack Was Cheap Persistence at Work
The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow.
T
0
7
July 2026 CVE Landscape
In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of
0
3
Emerging Threats to Neurotechnology
Summary
Neurotechnology is rapidly moving beyond clinical use cases, expanding the attack surface for sensitive
0
7
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
Agentic defense will be essential to countering agentic offense. However, defenders must actively mitigate the risk of a
0
4
8 Ways AI is Changing Threat Intelligence
The fundamentals haven't changed — the clock speed has. Defending everything is still the job, but adversaries can now m
0
3
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
Executive Summary
The United States (US) will almost certainly remain at heightened threat from physical threat
0
10
Dealing with AI-Generated Extortion
Proving a Negative
How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or
0
8
Ransomware is the Scoreboard
13,000.
That’s the number of ransomware victims Recorded Future has observed over the past two years.
Wa
0
10
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Executive Summary
Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families
0
9
Modern Attack Vectors | Recorded Future
Key Takeaways
Modern threat actors have shifted from brute-forcing firewalls to compromising digital
0
12
Threat Hunting: A Guide | Recorded Future
Enterprise security architectures have never been more heavily funded, yet the perimeter is functionally obsolete. Despi
0
10
Tracking Advanced Persistent Threat Groups | Recorded Future
Key takeaways
Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conduct
0
10
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Executive Summary
Between January and June 2026, Tehran survived unprecedented military, economic, and political
0
8
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intelligence and risk ratings in a single workflow.
0
1 👁
PurpleDelta's Fraudulent Employment Operations
Executive Summary
Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. PurpleDelta operators maintained at least 22 fabricated personas across multiple clust
0
1 👁
CopyCop Targets AI Investment in Armenia
The Russian influence network CopyCop (Storm-1516) very likely targeted the joint United States (US) and Armenian-backed Firebird AI data center in Hrazdan, Armenia, as part of a broader campaign to undermine Armenia's westward geopolitical and economic realignment. Between June 24 and July 13, 2026, Insikt Group documented three separate CopyCop media impersonations targeting the facility ahead of its July 2026 opening. These impersonations fabricated an imminent earthquake risk, cast doubt as
0
1 👁
Malware Crypting Services and the Threat Actors Who Sell Them
Executive Summary
Crypting services and products modify malicious payloads to help threat actors bypass detection, complicate analysis, and preserve malware usability after exposure. Although basic crypting consists of encrypting or obfuscating a customer-supplied payload, mature providers increasingly operate as broader malware-enablement services. Their offerings often combine payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, delivery
0
2 👁
Mines, Minds, and Machines: The Journey of AI
Minerals become chips. Chips supply data centers. Data centers power the training of models, and models are acquiring arms and legs. Mines, Minds, and Machines traces the supply chain of the fourth industrial revolution, and shows how geopolitical rivalry and cyber operations now run along every link.
0
7 👁
The Hugging Face Hack Was Cheap Persistence at Work
The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow.
The agent discovered and exploited previously unknown vulnerabilities. The more consequential development came afterward. Over a four-and-a-half-day campaign, it carried out roughly 17,600 actions against Hugging Face’s infrastructure. Most of those actions failed. The operation advanced because each failure imposed little cost, and the next attempt could begin immediately. The
0
7 👁
July 2026 CVE Landscape
In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data.
The 85 vulnerabilities
0
3 👁
Emerging Threats to Neurotechnology
Summary
Neurotechnology is rapidly moving beyond clinical use cases, expanding the attack surface for sensitive neurological and biometric data: As adoption grows, larger volumes of brain activity, biometric, and behavioral data will be collected by commercial platforms, creating new opportunities for data theft, misuse, and exploitation.
China and the United States (US) are engaged in strategic competition in neurotechnology development: The US leads in the number of neurotechno
0
7 👁
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
Agentic defense will be essential to countering agentic offense. However, defenders must actively mitigate the risk of autonomous systems operating outside of their expected parameters.In July 2026, OpenAI disclosed that models undergoing an internal cybersecurity evaluation had escaped their testing environment and compromised part of Hugging Face’s production infrastructure. OpenAI characterized the event as an “unprecedented cyber incident.”The incident should put security leaders on alert, b
0
4 👁
8 Ways AI is Changing Threat Intelligence
The fundamentals haven't changed — the clock speed has. Defending everything is still the job, but adversaries can now move at machine-speed, which means the intelligence behind every decision has to move just as fast.
AI cuts both ways. The same automation that lets defenders orchestrate faster is available to attackers too, and whoever uses it more creatively will often hold the advantage at any given moment.
Trust in automation is being built one decision at a
0
3 👁
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
Executive Summary
The United States (US) will almost certainly remain at heightened threat from physical threat activities conducted by homegrown and domestic violent extremists (HVEs and DVEs, respectively) during the next twelve months. Since the last installation of this report in July 2025, there has been a substantial increase in mass-casualty attacks and attack plots by Islamic State (IS) supporters, assassinations and attempted assassinations of US government officials and high-pr
0
10 👁
Dealing with AI-Generated Extortion
Proving a Negative
How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files weren’t stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors?
0
8 👁
Ransomware is the Scoreboard
13,000.
That’s the number of ransomware victims Recorded Future has observed over the past two years.
Watching the near-real-time ransomware attacks on businesses, non-profits, and government agencies has left me, like many security professionals and board directors, pondering how and why cyber defense keeps losing this particular fight. Adversaries like Interlock and RansomHub have continued their successful march to riches over the past 18 months. The multi-billion-ruble questi
0
10 👁
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Executive Summary
Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families through ongoing tracking of the TAG-195 MaaS ecosystem. We named two of the families "TinyEgg" and “ChonkyChicken"; the third is a modularized variant of ChonkyChicken. The fourth family, which includes a modified browser credential theft helper, we named “ChromEggscalator". TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling Insikt Group has
0
9 👁
Modern Attack Vectors | Recorded Future
Key Takeaways
Modern threat actors have shifted from brute-forcing firewalls to compromising digital identities via stolen session cookies and credential stuffing to bypass MFA entirely
Adversaries increasingly target unpatched edge infrastructure like VPNs for zero-day access while exploiting open-source repositories to launch upstream supply chain attacks
Traditional internal security telemetry may miss critical pre-attack signals, making real-time, outsi
0
12 👁
Threat Hunting: A Guide | Recorded Future
Enterprise security architectures have never been more heavily funded, yet the perimeter is functionally obsolete. Despite multi-million dollar investments in next-generation firewalls and complex defense stacks, sophisticated adversaries slip past automated boundaries every day. They don't break in; they log in, embedding themselves silently into the background noise of normal business operations.
To survive in this environment, modern cyber defense teams must anchor their strategy to a
0
10 👁
Tracking Advanced Persistent Threat Groups | Recorded Future
Key takeaways
Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conducted by well-funded human adversaries (often nation-states) who target specific organizations for espionage, data theft, or critical infrastructure disruption.
Traditional security tools often fail because APT groups bypass signature-based defenses by using customized malware and Living-off-the-Land (LotL) tactics that mimic legitimate user activity inside the network.
0
10 👁
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Executive Summary
Between January and June 2026, Tehran survived unprecedented military, economic, and political pressure by relying on its longstanding hybrid warfare model: blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. Artificial intelligence (AI) enhanced these capabilities, acting as a force multiplier and almost certainly increasing the speed, scale, and effectiveness of Iranian operations. Ultimately, Iran
0
8 👁
The Shift: A New Era of AI Regulation
The export controls imposed on Anthropic’s Fable model mark a significant shift in United States (US) artificial intelligence (AI) policy. The controls set a precedent for treating frontier AI models as strategic assets rather than ordinary software products, creating uncertainty for enterprises adopting advanced AI. Security leaders should respond by investing in resilient, interoperable AI strategies rather than simply chasing the most powerful model available.
The
0
10 👁
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
A fast-growing scam impersonates city and county planning departments, sending property owners real-looking invoices for fake permit fees and pressuring them to wire payment on a deadline. Because the victim authorizes the transfer, payments commonly clear the behavioral checks built to catch fraud, making beneficiary accounts one of the most reliable signals to track this campaign. Research from CYBERA, the partner behind Recorded Future® Money Mule Intelligence, maps a single active ring down
0
10 👁
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intelligence and…
💬 0
👁 1
PurpleDelta's Fraudulent Employment Operations
Recorded Future · 6d ago
💬 0
👁 1
CopyCop Targets AI Investment in Armenia
Recorded Future · 6d ago
💬 0
👁 1
Malware Crypting Services and the Threat Actors Who Sell Them
Recorded Future · Aug 13, 2026
💬 0
👁 2

Mines, Minds, and Machines: The Journey of AI
Recorded Future · Aug 11, 2026

The Hugging Face Hack Was Cheap Persistence at Work
Recorded Future · Aug 10, 2026

July 2026 CVE Landscape
Recorded Future · Aug 7, 2026

Emerging Threats to Neurotechnology
Recorded Future · Aug 6, 2026
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
Agentic defense will be essential to countering agentic offense. However, defenders must actively mitigate the risk of autonomous …
💬 0
👁 4
8 Ways AI is Changing Threat Intelligence
Recorded Future · Aug 3, 2026
💬 0
👁 3
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
Recorded Future · Jul 30, 2026
💬 0
👁 10
Dealing with AI-Generated Extortion
Recorded Future · Jul 30, 2026
💬 0
👁 8

Ransomware is the Scoreboard
Recorded Future · Jul 24, 2026

TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Recorded Future · Jul 23, 2026

Modern Attack Vectors | Recorded Future
Recorded Future · Jul 22, 2026

Threat Hunting: A Guide | Recorded Future
Recorded Future · Jul 20, 2026
Tracking Advanced Persistent Threat Groups | Recorded Future
Key takeaways
Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conducted by well…
💬 0
👁 10
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Recorded Future · Jul 16, 2026
💬 0
👁 8
The Shift: A New Era of AI Regulation
Recorded Future · Jul 15, 2026
💬 0
👁 10
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
Recorded Future · Jul 14, 2026
💬 0
👁 10