Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

PAPERMILL: Tracking an Emerging China-Nexus Malware Factory

JUMPSEC’s DART (Detection & Response Team) raised an alert to the Threat Research team regarding a specific ticket that arrived in a clients’ inbox, passing SPF, DKIM, and DMARC. The email contained an attachment and a subject which spoke about Tax Audits, that attachment, named “Tax_Notice_45594.exe” is not actually an exe but instead an.ISO. On the surface this looks like a fairly typical phishing lure, but the delivery mechanism underneath is anything but.

Project Havoc: Breaking Identity Trust with Real-Time Synthetic Media

Under normal conditions, experiencing our digital reflection can feel surreal or even uncomfortable. So first off, we commend our participating execs for allowing us to use their publicly available personal data to create live audio/visual doppelgangers – as we found out just how advanced, believable, and potentially malicious our identity cloning tools currently are.

BlackToad: Network Manipulation in an AutoIt Payload

Recently, JUMPSEC’s DART (Detection and Response Team) detected a phishing email targeting a client environment. The email, written in Thai and containing a MediaFire download link, was identified as suspicious by an incident responder and we kicked off an investigation. Since then, we have established infrastructure to track the threat actor, analysed the novel payload in detail, and identified several IoCs below.

What's happening to DevOps Security?

As 2026 rolls on, our capacity to prompt ourselves silly appears to be limitless. We’ve already seen the financial, legal, and reputational damage to Deloitte as they partly refunded the Australian government for a 237-page audit report containing LLM-generated hallucinations like fabricated academic references, fake footnotes, and a false quote attributed to a judge.

Bugs & Betrayal - Vect Analysis

Vect is a newly observed RaaS operation that emerged in December of 2025, with affiliate recruitment and victim postings following shortly after in January 2026. Following the 19th of March 2026 Trivy/LiteLLM supply chain attack conducted by TeamPCP, in which ~340 GB uncompressed data was stolen, Vect announced on the dark web forum “Breached” that they would be partnering with TeamPCP.

How Much Does a Cyber Security Company Cost?

The cost of hiring an outsourced cyber security company can start from as little as £500 per month, or £10,000 or higher for large companies. For global multi nationals, it wouldn’t be unreasonable to spend millions on cyber security and to protect yourself against an attack of data breach. Companies have the option to use ongoing monthly services to detect potential threats, or the opportunity to do one-off tests to check for vulnerabilities such as penetration testing or red teaming.

How Are Cyber Security Companies Managing AI Attacks?

AI attacks pose real risks for companies because of their ability to scale and automate attacks like brute force attacks, smarter malware, deep fakes and advanced phishing. Attacks that were once slow, manual and easy to spot are now becoming faster, more sophisticated and harder to detect. UK government research shows that 32% of UK businesses have experienced a cyber attack in the last year, and experts warn that AI could make this number rise significantly.

What Can an Outsourced Cyber Security Company Do for Me?

Outsourcing cyber security is becoming increasingly common for UK organisations of all sizes. With cyber threats growing every year, many businesses simply do not have the in-house resources, staff, or specialist skills to stay protected. Recent UK government data shows that 48% of small businesses experienced a cyber breach in the last 12 months, and over 70% of companies say they lack the internal expertise needed to manage cyber risks effectively.