Cybersecurity leaders are increasingly investing in threat intelligence programs, with a focus on automation, high-fidelity indicators, and cross-functional collaboration to improve both detection and strategic decision-making. According to industry surveys, a significant majority of organizations are raising their threat intelligence budgets and aiming to mature their programs, leveraging AI to augment analyst workflows and address the challenge of information overload. Practitioners emphasize the importance of integrating intelligence into business strategy and risk communication, as well as the need for better tools to transform large data volumes into actionable insights.
Despite these advancements, fundamental security gaps such as the lack of enforced multi-factor authentication (MFA) continue to enable large-scale cloud data breaches. Security experts highlight that attackers are exploiting cloud collaboration services through information-stealing malware, and that many breaches could be prevented with basic controls like MFA. Additionally, the evolving landscape of AI in cybersecurity is prompting new defense strategies, such as poisoning knowledge graphs to protect sensitive data, and raising concerns about the risks associated with autonomous AI systems in critical infrastructure and public safety contexts.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Recorded Future published practitioner insights summarizing the 2025 State of Threat Intelligence Report and panel commentary from Adobe, Global Payments, and Superhuman on automation, tailored intelligence, leadership education, and third-party risk priorities.
The same ISMG discussion highlighted emerging AI-focused security ideas, including poisoning knowledge graphs with plausible false data to reduce the value of stolen information, and warned that autonomous AI robots in public spaces should be treated as safety-critical systems because compromise or failure could cause physical harm.
An ISMG editors' panel said major cloud data breaches continue to be enabled by organizations failing to enforce multifactor authentication, with attackers exploiting cloud collaboration services using credentials harvested by information-stealing malware.
The report found that 76% of organizations were already spending more than $250,000 annually on threat intelligence and 91% planned to increase that spending in 2026, reflecting broader treatment of threat intelligence as a strategic business function.
Recorded Future's 2025 State of Threat Intelligence Report was based on a survey of 615 cybersecurity executives and practitioners, capturing organizations' spending, maturity, and operational priorities for threat intelligence programs.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.