Skip to content Skip to footer

AI Security & Cybersecurity — September 24, 2026

Findings

  1. [1] 2026-09-24 Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

    In this article Who is Storm-2570?Storm-2570 attack chain: From initial foothold to impactWhat Storm-2570 activity means for defendersMitigation and protection guidanceMicrosoft Defender detectionsHunting queries Activity associated with Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, illustrates how tracking and… Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability. The threat actor rotates among commercially available RMM platforms, remote desktop components, and tunneling utilities, often deploying multiple tools during the same intrusion. For… Storm-2570’s use of Impacket and NetExec over Server Message Block (SMB) further supports their lateral movement pattern. Impacket is a collection of open-source Python classes designed for working with network protocols, and is popular with adversaries due to its ease… Tactic Observed activity Microsoft Defender coverage ExecutionStorm-2570 delivers tools such as PsExec, Impacket, NetExec, and RDP batch scripts, to carry out post-compromise activityMicrosoft Defender Antivirus– Behavior:Win32/PsexecRemoteMicrosoft Defender for Endpoint– Hands-on-keyboard attack involving multiple devices– Remote access software– Suspicious PowerShell command… let MeshAgentTerms = dynamic(["meshagent", "meshagent64", "meshcentral"]); union isfuzzy=true ( DeviceProcessEvents | where Timestamp > ago(30d) | where FileName has_any (MeshAgentTerms) or ProcessCommandLine has_any (MeshAgentTerms) or InitiatingProcessCommandLine has_any (MeshAgentTerms) | project Timestamp, DeviceName, ActionType, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, RegistryKey="",…

  2. [2] 2026-09-24 ​​​​​​​​What’s new in Microsoft Security: September 2026​​

    AI agents are now running on employee devices, cloud platforms, and across developer workflows. Security teams need to see those agents, govern what they can reach, and contain them when something goes wrong. This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen the security operations center (SOC) foundations that AI-era…

  3. [3] 2026-09-23 Reimagining the SOC for the agentic era in Microsoft Defender

    The physics of cybersecurity are changing. So must the security operations center (SOC). Cyberattackers are using agents to automate execution at unprecedented scale. What once required entire teams now requires a single operator and an agent framework. That shift has… ISOC changes their starting point. The capabilities practitioners need to investigate, hunt, automate, manage incidents, understand threats, and take action are brought together and available by default. Instead of organizing their work around the boundaries between tools, teams can organize…

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Security & Guardrails practice, or Request a Security Review.

Sources

  1. [1] Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
  2. [2] ​​​​​​​​What’s new in Microsoft Security: September 2026​​
  3. [3] Reimagining the SOC for the agentic era in Microsoft Defender

Leave a comment

0.0/5