Since the release of Flashpoint’s 𝗚𝗹𝗼𝗯𝗮𝗹 𝗧𝗵𝗿𝗲𝗮𝘁 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝗥𝗲𝗽𝗼𝗿𝘁: 𝟮𝟬𝟮𝟲 𝗠𝗶𝗱𝘆𝗲𝗮𝗿 𝗘𝗱𝗶𝘁𝗶𝗼𝗻 last week, its findings are already making headlines. Among the trends driving the conversation: 🔸 𝗔𝗜 𝗶𝘀 𝗺𝗼𝘃𝗶𝗻𝗴 𝗱𝗲𝗲𝗽𝗲𝗿 𝗶𝗻𝘁𝗼 𝘁𝗵𝗲 𝗰𝘆𝗯𝗲𝗿𝗰𝗿𝗶𝗺𝗶𝗻𝗮𝗹 𝗮𝘁𝘁𝗮𝗰𝗸 𝗹𝗶𝗳𝗲𝗰𝘆𝗰𝗹𝗲. Flashpoint tracked more than 22 million threat actor posts discussing, sharing, or advertising AI for criminal use in the first six months of 2026. Additionally, we’re seeing threat actors move beyond experimentation to deploy custom LLMs and automated tooling on private infrastructure. 🔸 𝗜𝗻𝗳𝗼𝘀𝘁𝗲𝗮𝗹𝗲𝗿𝘀 𝗮𝗿𝗲 𝗳𝗲𝗲𝗱𝗶𝗻𝗴 𝗮𝗻 𝗲𝗻𝗼𝗿𝗺𝗼𝘂𝘀 𝗶𝗱𝗲𝗻𝘁𝗶𝘁𝘆 𝗲𝗰𝗼𝗻𝗼𝗺𝘆. More than 7.4 million hosts and devices were infected in H1 2026, a 27% period-over-period increase, yielding more than 1.7 billion stolen credentials. 🔸 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗲𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝘁𝗶𝗼𝗻 𝗶𝘀 𝗮𝗰𝗰𝗲𝗹𝗲𝗿𝗮𝘁𝗶𝗻𝗴 𝗮𝗰𝗿𝗼𝘀𝘀 𝘁𝗵𝗲 𝗲𝗰𝗼𝘀𝘆𝘀𝘁𝗲𝗺. Flashpoint observed a sustained rise in the discussion and weaponization of newly disclosed vulnerabilities, with threat actors increasingly prioritizing speed-to-exploit over sophistication. In many cases, public proof-of-concept code is being operationalized within days, shrinking the window for defenders to respond. Thank you, Infosecurity Magazine, for highlighting some of the report's key findings: https://lnkd.in/ghCcevfD Want the full picture? Download the report for the latest intelligence on AI, infostealers, vulnerability exploitation, ransomware, and the convergence of cyber and geopolitical risk: https://lnkd.in/eG2UkvNJ Join us on August 25 for our 𝟮𝟬𝟮𝟲 𝗠𝗶𝗱𝘆𝗲𝗮𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝗕𝗿𝗶𝗲𝗳𝗶𝗻𝗴, where Flashpoint experts will unpack the findings and what they mean for security teams in the months ahead. 📅 August 25, 2026 | 1:00 PM ET Register for the webinar: https://lnkd.in/gq289qfv
About us
Flashpoint is the leader in threat data and intelligence. We empower mission-critical businesses and governments worldwide to decisively confront complex security challenges, reduce risk, and improve operational resilience amid fast-evolving threats. Through the Flashpoint Ignite platform, we deliver unparalleled depth, breadth and speed of data from highly relevant sources, enriched by human insights. Our solutions span cyber threat intelligence, vulnerability intelligence, geopolitical risk, physical security, fraud and brand protection. The result: our customers safeguard critical assets, avoid financial loss, and protect lives. Discover more at flashpoint.io.
- Website
-
https://www.flashpoint.io
External link for Flashpoint
- Industry
- Technology, Information and Internet
- Company size
- 201-500 employees
- Headquarters
- New York, NY
- Type
- Privately Held
- Specialties
- Deep Web, Dark Web, Intelligence, Business Risk Intelligence, Cybercrime, Open Source Analysis, Physical Security, Insider Threat Program, Brand Protection, M&A Diligence, Cybersecurity, Security Operations, Executive Protection, OSINT, Threat Intelligence, Vulnerability Intelligence, and Fraud
Locations
-
Primary
Get directions
25 W 39th St
New York, NY 10018, US
Employees at Flashpoint
Updates
-
Data centers are powering some of the most advanced technology in the world. But one of the emerging threats to that infrastructure costs less than $1,000. Flashpoint analysts are seeing growing hostility toward data center expansion across clearnet and Deep and Dark Web spaces, driven by concerns around energy and water consumption, local impacts, and backlash against AI. At the same time, low-cost FPV drone technology is changing what a physical attack can look like. Our latest research explores: 🔸 How online rhetoric around data centers is evolving 🔸 Why accessible, payload-capable drones are lowering the barrier to airborne threats 🔸 How protests could create cover for physical operations 🔸 Why traditional perimeter security may be insufficient against threats from above 🔸 How intelligence can help physical security teams identify emerging threats before they reach the perimeter Most data centers today aren’t equipped with the specialized C-UAS technology, training, or legal authority needed to respond effectively to an airborne incursion. And traditional foot patrols and perimeter access controls weren’t designed for threats coming from overhead. That makes early warning especially important. Understanding where hostility is building, how tactics are being discussed online, and whether specific facilities or executives are being targeted can give physical security teams more time to assess risk and harden critical assets. Learn more about what Flashpoint researchers are seeing and what it means for data center physical security teams: https://lnkd.in/gi4Uu5bD
-
Investigating online threats used to mean mastering complex search syntax, slowing down critical response times when every minute counts. With our latest update to Echosec, that barrier is removed. Analysts can now search and refine results using natural language. Describe a location, topic, or threat as if explaining it to a colleague, and let AI build the search strategy for you. 🔸 𝗔𝘀𝗸 𝗮 𝗾𝘂𝗲𝘀𝘁𝗶𝗼𝗻: State what you need to investigate in plain language, specifying locations, topics, or events. For example: “Show me threatening posts to my CEO.” 🔸 𝗥𝗲𝘃𝗶𝗲𝘄 𝘁𝗵𝗲 𝘀𝗲𝗮𝗿𝗰𝗵 𝗽𝗹𝗮𝗻: AI constructs an automated search strategy, identifying relevant terminology and key parameters. 🔸 𝗔𝗻𝗮𝗹𝘆𝘇𝗲 𝗿𝗮𝗻𝗸𝗲𝗱 𝗿𝗲𝘀𝘂𝗹𝘁𝘀: Posts and intelligence are ordered by relevance to your intent rather than chronologically. 🔸 𝗙𝗼𝗹𝗹𝗼𝘄 𝘂𝗽: Ask additional questions to drill deeper into the data without losing the original context. The full underlying dataset is preserved, giving teams the ability to leverage AI prioritization to accelerate analysis while retaining complete visibility into all retrieved data. The goal: spend less time managing complex search strings and more time gathering the intelligence needed to protect what matters most. 🔗 Learn more: https://lnkd.in/gwsNe9w8
-
𝗙𝗹𝗮𝘀𝗵𝗽𝗼𝗶𝗻𝘁'𝘀 𝗚𝗹𝗼𝗯𝗮𝗹 𝗧𝗵𝗿𝗲𝗮𝘁 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝗥𝗲𝗽𝗼𝗿𝘁: 𝟮𝟬𝟮𝟲 𝗠𝗶𝗱𝘆𝗲𝗮𝗿 𝗘𝗱𝗶𝘁𝗶𝗼𝗻 𝗶𝘀 𝗵𝗲𝗿𝗲. Serving as a companion to our annual Global Threat Intelligence Report, the 2026 Midyear Edition delivers a data-driven look at how cyber threats evolved during the first half of the year. Powered by Flashpoint's Primary Source Collection, it equips security, intelligence, fraud, and risk teams with the insights they need to understand what's changing, what's accelerating, and where to focus next. The report highlights five major developments shaping today's threat landscape: 🔸 𝗔𝗜 𝗶𝘀 𝗯𝗲𝗰𝗼𝗺𝗶𝗻𝗴 𝗮𝗻 𝗮𝘂𝘁𝗼𝗻𝗼𝗺𝗼𝘂𝘀 𝗳𝗼𝗿𝗰𝗲 𝗺𝘂𝗹𝘁𝗶𝗽𝗹𝗶𝗲𝗿 𝗳𝗼𝗿 𝗮𝘁𝘁𝗮𝗰𝗸𝗲𝗿𝘀. Flashpoint tracked more than 22 million threat actor posts discussing or advertising AI for criminal use in H1 2026, as adversaries increasingly deploy custom LLMs, automate phishing and malware development, and move malicious AI operations into private infrastructure. 🔸𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿𝘀 𝗮𝗿𝗲 𝗻𝗼 𝗹𝗼𝗻𝗴𝗲𝗿 𝗯𝗿𝗲𝗮𝗸𝗶𝗻𝗴 𝗶𝗻 — 𝘁𝗵𝗲𝘆'𝗿𝗲 𝗹𝗼𝗴𝗴𝗶𝗻𝗴 𝗶𝗻. Infostealers compromised 7.4 million devices and exposed more than 1.7 billion credentials during the first half of 2026, fueling an underground economy built on stolen identities rather than overreliance on technical exploits. 🔸 𝗧𝗵𝗲 𝘄𝗶𝗻𝗱𝗼𝘄 𝘁𝗼 𝗿𝗲𝗺𝗲𝗱𝗶𝗮𝘁𝗲 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 𝗰𝗼𝗻𝘁𝗶𝗻𝘂𝗲𝘀 𝘁𝗼 𝘀𝗵𝗿𝗶𝗻𝗸. More than 21,600 vulnerabilities were disclosed in H1 2026, with nearly one in five already possessing public or functional exploit code, making intelligence-driven prioritization more important than ever. 🔸 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗼𝗽𝗲𝗿𝗮𝘁𝗼𝗿𝘀 𝗮𝗿𝗲 𝗯𝗲𝗰𝗼𝗺𝗶𝗻𝗴 𝗳𝗮𝘀𝘁𝗲𝗿 𝗮𝗻𝗱 𝗺𝗼𝗿𝗲 𝗲𝗳𝗳𝗶𝗰𝗶𝗲𝗻𝘁. Ransomware activity increased 45% in H1 2026 compared to the same period last year, while AI-driven automation and lower barriers to entry continue to reshape the RaaS ecosystem. 🔸 𝗖𝘆𝗯𝗲𝗿 𝗮𝗻𝗱 𝗴𝗲𝗼𝗽𝗼𝗹𝗶𝘁𝗶𝗰𝗮𝗹 𝗿𝗶𝘀𝗸 𝗮𝗿𝗲 𝗶𝗻𝗰𝗿𝗲𝗮𝘀𝗶𝗻𝗴𝗹𝘆 𝗶𝗻𝘁𝗲𝗿𝗰𝗼𝗻𝗻𝗲𝗰𝘁𝗲𝗱. Organizations must account for the growing convergence of cyber operations, physical threats, fraud, and geopolitical instability when assessing enterprise risk. Download the report to gain: 📍 A comprehensive view of how the threat landscape evolved during the first half of 2026 📍 Intelligence on emerging attacker tactics across AI, identity, vulnerabilities, ransomware, and geopolitical risk 📍 Actionable insights to help security teams proactively reduce exposure and strengthen resilience Download the 2026 Midyear Edition: https://lnkd.in/eG2UkvNJ
-
CTI teams are being asked to cover more ground without a proportional increase in headcount. And increasingly, that ground extends well beyond the network. Physical security. Geopolitical risk. Protective intelligence. Executive travel. Facilities and events. The shift may sound like a major expansion of the CTI mandate, but the underlying methodology is surprisingly familiar: situational awareness, data aggregation, and predictive analysis. In fact, the earliest warning signs of physical risk are frequently digital, surfacing through social media sentiment, localized chatter, and open-source discussions. That makes physical security a natural extension of the work many CTI teams already do — and an opportunity to break down the operational silos that can leave threats sitting between disconnected cyber and physical security functions. Our latest blog explores what the data says about this shift, where CTI and physical security tradecraft overlap, and how Flashpoint helps teams extend existing intelligence workflows across both missions. 🔗 Read more: https://lnkd.in/ewgTdE7s
-
DoDIIS 2026 is underway in Tampa, bringing together the defense and intelligence community at a time when the information environment is becoming more complex, contested, and consequential to national security missions. Across today’s threat landscape, a few challenges are increasingly shaping how intelligence teams operate: 🔸 𝗖𝘆𝗯𝗲𝗿 𝗼𝗽𝗲𝗿𝗮𝘁𝗶𝗼𝗻𝘀 𝗮𝗿𝗲 𝗶𝗻𝗰𝗿𝗲𝗮𝘀𝗶𝗻𝗴𝗹𝘆 𝗶𝗻𝘁𝗲𝗿𝘁𝘄𝗶𝗻𝗲𝗱 𝘄𝗶𝘁𝗵 𝗴𝗲𝗼𝗽𝗼𝗹𝗶𝘁𝗶𝗰𝗮𝗹 𝗮𝗻𝗱 𝗸𝗶𝗻𝗲𝘁𝗶𝗰 𝗰𝗼𝗻𝗳𝗹𝗶𝗰𝘁: State-aligned actors and proxy networks are operating across digital and physical domains, expanding the range of organizations, infrastructure, and systems that can become part of a broader conflict. 🔸 𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗶𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲 𝗮𝗻𝗱 𝘀𝘂𝗽𝗽𝗹𝘆 𝗰𝗵𝗮𝗶𝗻𝘀 𝗮𝗿𝗲 𝗳𝗶𝗿𝗺𝗹𝘆 𝗶𝗻 𝘁𝗵𝗲 𝗰𝗿𝗼𝘀𝘀𝗵𝗮𝗶𝗿𝘀: Logistics, transportation, communications, operational technology, and other interconnected systems present opportunities for adversaries seeking to create disruption that extends well beyond a single target. 🔸 𝗔𝗜 𝗶𝘀 𝗮𝗰𝗰𝗲𝗹𝗲𝗿𝗮𝘁𝗶𝗻𝗴 𝗮𝗱𝘃𝗲𝗿𝘀𝗮𝗿𝘆 𝘁𝗿𝗮𝗱𝗲𝗰𝗿𝗮𝗳𝘁: Threat actors are using AI to automate and scale elements of their operations, from social engineering and target profiling to vulnerability exploitation, while increasingly moving activity into private environments that are harder for defenders to observe. 🔸 𝗦𝘁𝗮𝘁𝗲-𝗮𝗹𝗶𝗴𝗻𝗲𝗱 𝗮𝗰𝘁𝗶𝘃𝗶𝘁𝘆 𝗶𝘀 𝗯𝗲𝗰𝗼𝗺𝗶𝗻𝗴 𝗺𝗼𝗿𝗲 𝗱𝗶𝘀𝘁𝗿𝗶𝗯𝘂𝘁𝗲𝗱: The use of proxies, hacktivist personas, shared infrastructure, and other decentralized networks is complicating attribution and making it more important to connect activity across sources, actors, and environments. These are exactly the challenges Flashpoint is tackling this week at DoDIIS 2026. Stop by Booth #1823 to connect with our team and explore how Flashpoint Ignite helps government teams discover critical intelligence, investigate threats, and operationalize insights across national security missions. 📍 Tampa, FL | August 9–12 📌 Booth #1823 Learn more: https://lnkd.in/gVqU7bgZ #DoDIIS2026
-
-
When people think about cybercriminal infrastructure, they often picture dark web forums and hidden marketplaces. But much of today's illicit activity is happening in plain sight. Threat actors have been known to target mainstream platforms such as Discord, Telegram, and social networks to recruit, coordinate operations, distribute malware, and amplify extortion campaigns. The same platforms used for everyday communication have become part of the modern threat landscape. Understanding today's threat landscape requires looking beyond traditional underground forums. In a recent installment of our Understanding Illicit Ecosystems series, we explore: 🔸 How threat actors weaponize consumer platforms 🔸 Why public-to-private communication pipelines matter 🔸 How groups like "The Com" exploit social and gaming communities 🔸 Why monitoring the clearnet is critical for modern threat intelligence Read now: https://lnkd.in/eZh23QEq
-
Flashpoint’s annual user conference, FUSE, returns this September. Bringing together intelligence professionals from around the world, FUSE is where our customer community unites to share insights, sharpen skills, and collaborate on today’s toughest challenges. On 𝗦𝗲𝗽𝘁𝗲𝗺𝗯𝗲𝗿 𝟭𝟱–𝟭𝟲, attendees will take part in two high-impact days of virtual learning and connection at our 10th annual user conference. Why attend FUSE 2026? 🔸 𝗚𝗮𝗶𝗻 𝗦𝘁𝗿𝗮𝘁𝗲𝗴𝗶𝗰 𝗙𝗼𝗿𝗲𝘀𝗶𝗴𝗵𝘁: Understand how emerging threats, from agentic AI to identity-driven attacks, are reshaping the security landscape and what it means for your organization. 🔸 𝗢𝗽𝗲𝗿𝗮𝘁𝗶𝗼𝗻𝗮𝗹𝗶𝘇𝗲 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲: Learn how to connect intelligence directly to workflows, priorities, and decisions across your security program. 🔸 𝗟𝗲𝗮𝗿𝗻 𝗳𝗿𝗼𝗺 𝗥𝗲𝗮𝗹-𝗪𝗼𝗿𝗹𝗱 𝗟𝗲𝗮𝗱𝗲𝗿𝘀: Hear how leading organizations are tackling their most complex challenges and driving measurable outcomes with Flashpoint. 🔸 𝗔 𝗨𝗻𝗶𝗳𝗶𝗲𝗱 𝗙𝗿𝗼𝗻𝘁: Collaborate with fellow professionals who share your mission. Build connections, share strategies, spark new ideas, and align efforts for a more secure tomorrow. 📅 𝗦𝗲𝗽𝘁 𝟭𝟱 & 𝟭𝟲, 𝟮𝟬𝟮𝟲 | 11:00 AM–2:30 PM ET If you’re a Flashpoint customer and interested in attending, please reach out to your Flashpoint representative for details.
-
-
Black Hat USA 2026 is almost here, and our team is looking forward to meeting with security, intelligence, fraud, and resilience leaders throughout the week. The conversations this year are taking place against a rapidly evolving threat landscape. Across the first half of 2026, Flashpoint observed threat actors accelerating operations through AI, expanding identity-driven attacks, compressing vulnerability exploitation timelines, and capitalizing on increasingly interconnected cyber and geopolitical risks. Together, these developments are changing how security teams prioritize risk, allocate resources, and prepare for threats that move at machine speed. If you're attending Black Hat, we'd welcome the opportunity to discuss the challenges shaping your security priorities and share how Flashpoint helps organizations identify, prioritize, and respond to emerging threats with greater confidence. 🔗 Book a meeting: https://lnkd.in/gDtei_9c #BlackHat2026
-
-
Qilin ransomware has rapidly modernized its evasion techniques. Historically focused on file encryption, the ransomware-as-a-service (RaaS) group has expanded its operations to include aggressive, kernel-level defense evasion. Flashpoint has observed Qilin quietly deploying a previously unreported custom packer, alongside a sophisticated kernel-level EDR killer designed to blind and permanently disable endpoint security products before its ransomware payload is executed. In our new analysis, we break down: 🔸 How Qilin uses a custom Rust loader for reflective PE loading 🔸 How its new EDR killer blinds security products 🔸 Why the EDR killer market is transitioning from a niche capability into a standard prerequisite for high-impact ransomware operations Read the full analysis: https://lnkd.in/edGywQxf