Archive for Sygnia

AI just turned a weeks-long hack into 72 hours

Posted in Commentary with tags on July 8, 2026 by itnerd

Sygnia researchers observed a lone threat actor use agentic AI to compress what would normally be a multi-week cloud intrusion into just 72 hours. According to their analysis, the attacker didn’t rely on novel malware or zero-day exploits; instead, an AI agent ran reconnaissance, credential abuse, and lateral movement using known, well-documented techniques, executing them in parallel at machine speed rather than sequentially by hand.

Roman Sannikov, VP, Threat Intelligence, iCOUNTER had this to say:

“This is the strategic inflection point we’ve been tracking: AI isn’t giving attackers new capabilities, it’s eliminating the human bottlenecks that used to slow them down. Reconnaissance, credential abuse, and lateral movement running in parallel rather than sequentially means the operational tempo of an intrusion is no longer bound by how fast a human operator can work.

That changes the defender’s decision timeline at the board level, not just the SOC level. When a cloud compromise that used to take weeks can now happen in 72 hours, the assumption that there’s time to detect, investigate, and respond before meaningful damage occurs no longer holds. Organizations need external visibility into adversary infrastructure and campaign activity before an intrusion reaches this speed, not after.

The technique here wasn’t novel; rather, that’s what makes it significant. Threat actors don’t need new tools when AI lets them run the tools they already have faster than any defender can react manually. Operational resilience now depends on intelligence-led defense that can match that tempo, not just harden the perimeter and wait.”

The fact that time to pwnage is shrinking dramatically shows that an organizations defences need to be up, active, and fluid. Otherwise that pwnage is going to happen.

Threat Actors “Luna Moth” Exposed By Cybersecurity Company

Posted in Commentary with tags on July 12, 2022 by itnerd

The Incident Response team at cybersecurity company Sygnia tracked a newer data extortion group called “Luna Moth’, which has been breaching companies’ info via fake subscription renewal phishing emails and threatening victims to make files publicly available unless they pay a ransom.

Chris Olson, CEO of The Media Trust had this comment:

  “Based on Sygnia’s report, Luna Moth actors are not using the most sophisticated phishing techniques available today – they reach out to victims through Gmail accounts, and use mass email campaigns rather than a targeted spear phishing approach. Aside from that, they do not even format their emails to mimic the brands they are impersonating. In spite of this, they have successfully compromised numerous organizations with ransomware in recent months.

Ultimately, this story reveals the need for increased cyber training and awareness of social engineering techniques, from email-based phishing attacks to malicious advertising (malvertising) and redirects. This year, both the cost and frequency of ransomware attacks are higher than ever – if organizations are not prepared to avoid basic phishing techniques, they will not be prepared to defend their users or revenue against more advanced cyber adversaries.”

Dr. Darren Williams, CEO and Founder, BlackFog adds this comment:

     “False subscription emails are the latest phishing trend and a great way to lure people into installing payloads for ransomware onto devices. We are seeing specific focus on sectors with the weakest security and investments such as Education, Government and Manufacturing with a 33%, 25% and 24% increase in attacks during June  (https://www.blackfog.com/the-state-of-ransomware-in-2022/).”

This highlights the fact that training and other means to stop phishing need to be done at companies to ensure that users don’t open up a Pandora’s box of problems via clicking on an email.