The cybersecurity field doesn’t slow down. New research surfaces constantly, and threat actors keep shifting their playbooks. Here are five topics that have the research community’s attention right now.
AI-generated malware that adapts. Not the theoretical kind. Researchers are seeing real samples where LLMs generate code that modifies itself to evade signature detection. It’s early, but it’s here.
Supply chain attacks on open-source AI dependencies. Everyone rushed to ship AI features. Few locked down their supply chains. Attackers are noticing and planting poisoned packages in ML toolchains.
Ransomware that exfiltrates before encrypting. This isn’t new, but the scale is. Groups now routinely steal terabytes before triggering encryption. The leverage is the data, not the files.
OT/ICS threats getting real. Critical infrastructure operators are reporting more scans and probes. The connection between IT and OT keeps expanding the attack surface. Air gaps are mostly a myth at this point.
The credential fatigue problem. MFA fatigue attacks worked so well that attackers barely bother with exploits anymore. They phish a password, spam MFA push notifications until the user accepts, and they’re in. Simple. Effective. Hard to stop.
Each of these areas had dedicated sessions at recent conferences. The research is progressing faster than the defenses.
