Organizations are facing heightened cybersecurity risks as employees increasingly use generative AI tools without IT oversight, a phenomenon known as shadow AI. This trend, highlighted by industry experts, exposes companies to data privacy, compliance, and security threats, with a significant portion of employees using unapproved AI applications on personal and work devices. CIOs are advised to implement clear policies categorizing AI tools as approved, restricted, or forbidden, and to provide secure environments for experimentation to balance innovation with data protection. In parallel, the healthcare sector is experiencing a surge in cyberattacks due to its rapid digital transformation, adoption of AI-powered diagnostics, and proliferation of Internet of Medical Things (IoMT) devices, making it a prime target for cybercriminals seeking valuable patient data.
The expansion of connected devices and AI-driven systems has also led to a rise in sophisticated malware campaigns targeting IoT environments. Notably, Mirai-based botnets such as ShadowV2 and RondoDox have exploited multiple vulnerabilities in IoT devices to build large-scale botnets for DDoS attacks. These developments underscore the urgent need for organizations across industries to strengthen their cybersecurity posture, particularly as attackers adapt to exploit the growing attack surface created by AI and IoT technologies. Security teams are urged to proactively manage shadow AI, secure IoT deployments, and prepare for increasingly complex threats leveraging both AI and IoT vectors.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
The U.S. Federal Communications Commission reversed telecom cybersecurity rules, marking a notable policy shift affecting the sector's regulatory environment. The change was cited as one of the week's major cybersecurity governance developments.
Microsoft and Kaspersky reported record-breaking levels of phishing and credential theft activity. Their findings indicated a significant escalation in the scale and effectiveness of social-engineering-driven attacks.
Russia-linked APT Water Gamayun was reported exploiting a newly identified MSC-related flaw to carry out stealthy infections. The disclosure added attribution and technical detail to an active espionage-related threat.
Security reporting highlighted the discovery of several advanced malware threats, including QuietEnvelope, Xillen Stealer, and new Android-focused malware. The findings added fresh technical detail on evolving criminal tooling and mobile threats.
Researchers reported a rise in phishing activity timed to the 2025 shopping season. The campaigns took advantage of seasonal consumer behavior to increase credential theft and fraud opportunities.
An upcoming encryption upgrade for Tor was disclosed as a notable technical development. The change was presented as an important improvement to the privacy network's security architecture.
Thailand banned the collection of iris biometric data by Worldcoin. The action represented a regulatory response to privacy and biometric data protection concerns.
UK authorities revealed a billion-dollar cryptocurrency laundering network allegedly linked to evasion of sanctions on Russia. The disclosure marked a significant law-enforcement and sanctions-related cybercrime development.
Singapore introduced a requirement for messaging applications to implement anti-spoofing measures. The move was part of a broader government response to fraud and impersonation risks in digital communications.
A resurgence of Mirai-derived botnets, including ShadowV2 and RondoDox, was reported targeting IoT devices worldwide by exploiting multiple vulnerabilities. The activity highlighted renewed large-scale abuse of exposed and weakly secured internet-connected devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cio.com
Open sourcesecuritysenses.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.