DKDKCISSPSearch
AI SecurityDEVELOPING

The SOC Doesn't Need to Start Over with Every Alert

Security leaders keep debating whether AI will produce an entirely new class of cyberattack.

DKCISSP News DeskThe Hacker News25 Sept 2026, 5:00 pm
The SOC Doesn't Need to Start Over with Every Alert
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

It is in this spirit that we are launching Scan for Good , an initiative that uses AI - coupled with human security researchers - to uncover public exposures and complex attack paths across public services, critical infrastructure, and nonprofits.

Across all three incidents our SOC investigated, phishing opened the door to malicious remote access via the same trusted RMM tools your IT team likely uses to support your organization's devices.

Through our collaboration with the Google DeepMind team, Gemini 3.8 Flash Cyber’s frontier cybersecurity performance is helping uncover complex attack paths in foundational AI and cloud technology, and fueling Wiz as we work with public services, nonprofits, and other critical infrastructure providers to ensure they stay ahead of AI-powered adversaries.

According to NCC Group’s Cyber Threat Intelligence Report for August 2026 , published on September 23 , 1073 companies fell victim to ransomware attacks during the month.

An FBI spokesperson told 404 Media that the group exploited a zero-day vulnerability in Oracle PeopleSoft before pivoting to AWS GovCloud servers and downloading 2-3TB of data.

CyberXTron warned that organizations “should treat n0n as an active and credible double-extortion threat requiring prompt attention to credential hygiene, access monitoring, and backup isolation.” Reccommended actions for businesses to take to reduce the risk of attacks by n0n or other ransomware groups include:

Stolen refresh tokens give durable access to the victim's Microsoft 365 data from any machine, and the blast radius scales with the compromised user's privileges.

GTIG worked with the affected vendor on disclosure and disrupted the activity, and its own assessment is that the counter-discovery may have prevented the exploit from being used.

By late 2025, the same team was writing about malware samples that phoned a model mid-execution and about a maturing underground market for illicit AI tools, while Anthropic disclosed shutting down an extortion operation that leaned on AI at nearly every stage, from reconnaissance and credential harvesting through to setting ransom demands.

In May 2026, GTIG reported that cyber crime actors found a two-factor bypass in an open-source administration tool and built working exploits for it, and that based on the structure and content of those exploits it assessed with high confidence that an AI model supported both the discovery and the exploit development.

What happened

It is in this spirit that we are launching Scan for Good , an initiative that uses AI - coupled with human security researchers - to uncover public exposures and complex attack paths across public services, critical infrastructure, and nonprofits.

Across all three incidents our SOC investigated, phishing opened the door to malicious remote access via the same trusted RMM tools your IT team likely uses to support your organization's devices.

What changed

Through our collaboration with the Google DeepMind team, Gemini 3.8 Flash Cyber’s frontier cybersecurity performance is helping uncover complex attack paths in foundational AI and cloud technology, and fueling Wiz as we work with public services, nonprofits, and other critical infrastructure providers to ensure they stay ahead of AI-powered adversaries.

According to NCC Group’s Cyber Threat Intelligence Report for August 2026 , published on September 23 , 1073 companies fell victim to ransomware attacks during the month.

Who is affected

An FBI spokesperson told 404 Media that the group exploited a zero-day vulnerability in Oracle PeopleSoft before pivoting to AWS GovCloud servers and downloading 2-3TB of data.

CyberXTron warned that organizations “should treat n0n as an active and credible double-extortion threat requiring prompt attention to credential hygiene, access monitoring, and backup isolation.” Reccommended actions for businesses to take to reduce the risk of attacks by n0n or other ransomware groups include:

Why it matters

Stolen refresh tokens give durable access to the victim's Microsoft 365 data from any machine, and the blast radius scales with the compromised user's privileges.

GTIG worked with the affected vendor on disclosure and disrupted the activity, and its own assessment is that the counter-discovery may have prevented the exploit from being used.

Technical details

By late 2025, the same team was writing about malware samples that phoned a model mid-execution and about a maturing underground market for illicit AI tools, while Anthropic disclosed shutting down an extortion operation that leaned on AI at nearly every stage, from reconnaissance and credential harvesting through to setting ransom demands.

In May 2026, GTIG reported that cyber crime actors found a two-factor bypass in an open-source administration tool and built working exploits for it, and that based on the structure and content of those exploits it assessed with high confidence that an AI model supported both the discovery and the exploit development.

According to analysis of incidents by researchers, the n0n ransomware attacks begin by exploiting compromised credentials sourced from third-party infostealer malware .

Response

That points to a group systematically mining ERP platforms that hold HR, payroll, applicant, and health data.” PeopleSoft customers should assume compromise, ensure the fix for the previous zero day is applied and disable the Environment Management Hub or remove the PSEMHUB application, Povolny said.

The countdown timers associated with some of the victims – a psychological tactic designed to scare the compromised target into paying the ransom – have already reached zero and data stolen in the attacks has been released.

What security teams should do

Across these cases, a small public signal – be it a forgotten route, a missing permission check, or an exposed credential – quickly and autonomously escalated access to sensitive data, infrastructure, or administrative control.

Attribution

The Hacker News: Security leaders keep debating whether AI will produce an entirely new class of cyberattack.

Infosecurity Magazine: The trojan, named RemControl by its operator, has been observed targeting retail banking customers across Western Europe, the Middle East and Canada since July 2026.

Infosecurity Magazine: Named n0n, the emergence of the ransomware crew has been detailed by cybersecurity researchers at CyberXTron.

Wiz Research: As offensive AI capabilities improve, empowering defenders has become a global imperative.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am