Nothreat

Nothreat AI-enhanced cybersecurity system that self-improves with every attack in real time

On Thursday, OpenAI, Anthropic, AWS, Microsoft, Cisco and more than 140 other organisations published an open letter on ...
01/09/2026

On Thursday, OpenAI, Anthropic, AWS, Microsoft, Cisco and more than 140 other organisations published an open letter on collective cyber defence. Its warning: AI-enabled attacks are about to get far more capable, and the systems most exposed are the ones we all depend on — hospitals, water utilities, the infrastructure that keeps the internet running.

One idea in it is exactly what we built our platform around: when one organisation shares what it caught and fixed, everyone downstream should benefit from that too.

When Nothreat catches a new attack in one environment, the Crowd Immunity mechanism updates the defences of every connected system automatically – the same lesson, applied everywhere else, without anyone having to ask for it.

We've signed the letter, alongside Cisco, Fortinet, Palo Alto Networks, Tenable, IBM and Google. Not because it changes what we do – we agreed with the argument before it was written. But an idea like this only moves the industry if enough organisations are willing to say so publicly.

For more than forty days, attacks on Microsoft SharePoint ran with no CVE, no signature and no patch in existence. Nothi...
28/08/2026

For more than forty days, attacks on Microsoft SharePoint ran with no CVE, no signature and no patch in existence. Nothing on any threat list could recognise them.

One of our clients was protected the whole time.

Many organisations run SharePoint on their own servers — it holds their documents, contracts and internal records. Someone found a way in that no public advisory described and started using it quietly. The attack didn’t force its way in. It used ordinary SharePoint functions in an unusual order and faked where it was coming from.

So why did nobody catch it?

Almost every security tool works by recognition, comparing what is happening now against a list of things already known to be dangerous. That list gets written after the first victims. Until it exists, an attack like this looks like ordinary use — because technically it is ordinary use, just arranged in a way no real employee would ever produce.

Our client was a telecom operator running a nationwide private network. Their defence was the Nothreat™ Platform. It doesn’t wait for a list of known threats and doesn’t care where a request claims to come from. It reads the shape of the request itself — the order of the calls, the structure, what follows what. These requests didn’t behave like legitimate use, so the platform blocked them — every attempt, as it arrived, with no analyst involved.

The first probes landed on Nothreat CyberEcho — digital twins of the client’s IT services, deployed as decoys. Nothing legitimate ever touches them, so the attack had no noise to hide in.

More than forty days later, Microsoft published the flaw and shipped four separate patches. Within days, Eye Security confirmed 396 compromised systems across 145 organisations worldwide — almost a third in the government sector.

Our client lost no data and had no downtime. The attempts had been blocked as they arrived and logged as routine — so when the news broke, their security team went back through the records and found the attack sitting there, already stopped, more than forty days old.

That is what preemptive defence changes. Not a faster response. Nothing to respond to.

Reports this month describe a coordinated campaign against water and wastewater utilities across a dozen US states. Acco...
19/08/2026

Reports this month describe a coordinated campaign against water and wastewater utilities across a dozen US states. According to Axios and FBI reporting, this appears to be one of the broadest coordinated campaigns against US municipal water systems to date (axios.com/2026/08/04/water-cyberattacks-us-iran). The targets weren't billing systems or websites. They were the operational technology that controls pumps and treatment processes.

This is the pattern critical infrastructure operators have been warned about for years, now playing out at scale. OT environments are often treated as isolated in theory but bridged in practice, through vendor access, remote monitoring tools, or a single misconfigured connection.

Detection after the fact isn't a workable model here. A control system compromise isn't a data breach you disclose and remediate. It's a physical process someone else is now able to influence.

This is exactly the environment Nothreat is built for, including the parts of it that are genuinely isolated. Nothreat CyberEcho deploys digital twins of a client's OT devices, deployed as decoys, so reconnaissance against critical systems gets captured and analysed long before it reaches anything real. And where a network is fully air-gapped by design, Nothreat runs directly on OT and edge device hardware, with a footprint light enough for constrained infrastructure.

Critical infrastructure doesn't get a second chance to detect intrusion after impact. It needs to see attackers before they're anywhere near the real system, whether that system talks to the internet or not.

July 2026: almost one million medium- and high-level attacks detected in a set of clients.Most threat intelligence tells...
05/08/2026

July 2026: almost one million medium- and high-level attacks detected in a set of clients.

Most threat intelligence tells you what happened somewhere else, to someone else, at some point in the past. Intelligence generated from direct attacker interaction is different. It tells you what is happening right now, against your bespoke systems, from actors who are actively probing.

In July, Nothreat's Digital Twin layer recorded almost one million attack attempts across customer environments, filtered to medium and high severity only, excluding low-level noise, basic scanning, and automated bot traffic. What remained tells a clearer story.

Credential compromise was the dominant attack type. This wasn't broad scanning – it was focused, automated targeting of authentication endpoints across enterprise applications. Sustained campaigns using valid session tokens and pre-compiled credential sets suggest attackers are operating with data gathered from prior compromises, not conducting fresh reconnaissance.

The second largest category was Out-of-Band Callback Domain injection. These attacks don't look like attacks. They inject external domains into legitimate application flows to exfiltrate data or establish covert channels — exactly the kind of activity that bypasses signature-based detection.

Looking at MITRE ATT&CK mapping, Initial Access represented 35% of all tactics observed, followed by Credential Access at 16% (also partially included in Initial Access) and Command and Control at 11%. Attackers are focused on getting in through the window, not breaking through the front door.

One detail worth mentioning: a small number of LLM probe attempts were detected, specifically targeting AI inference endpoints and attempting to identify the underlying model and provider - a signal worth watching as AI infrastructure becomes a more common part of enterprise environments.

Every one of these signals came from attackers interacting with environments that looked real. The data reflects actual attacker behaviour, tooling, and intent, not simulated scenarios or aggregated feeds.

Signal quality determines decision quality. July's data makes that case clearly.

The breach rarely starts where you're looking. In 2025, third-party involvement in breaches doubled to 30% of all incide...
21/07/2026

The breach rarely starts where you're looking. In 2025, third-party involvement in breaches doubled to 30% of all incidents, the largest single-year shift ever recorded by Verizon's DBIR. A supply chain compromise now takes an average of 267 days to identify and contain. (IBM, 2025)

Attacks on mid-sized organisations have been increasing steadily. The common assumption is that smaller security teams or tighter budgets make them easier targets. In practice, the reason is simpler than that.

They're easier to model.

Shared tooling stacks, similar network architectures, recognisable exposure patterns. For an attacker, that predictability reduces the cost of each attempt. What works in one environment tends to work in the next. At scale, that efficiency matters more than any individual target's vulnerability.

There's a second layer that tends to get overlooked. Mid-market organisations rarely operate in isolation. They're connected to larger partners, vendors, and supply chains, and those connections are part of the attack surface whether they're mapped or not.

We saw this play out recently. A partner network connected to a large telecom operator was compromised. Nothreat detected the activity, blocked it before it could spread, and raised the alert. The telecom wasn't affected. But the margin was narrower than anyone would have liked.

That kind of exposure doesn't show up in a standard vulnerability scan. It lives in the relationships between organisations, not inside any single one of them.
Keeping track of third-party risk isn't a box to tick. It's one of the more practical things a security team can do right now.

(Verizon DBIR, 2025 / IBM Cost of a Data Breach, 2025)

Zero-day vulnerabilities are often described as unpredictable.But in practice, what's unpredictable is usually visibilit...
08/07/2026

Zero-day vulnerabilities are often described as unpredictable.
But in practice, what's unpredictable is usually visibility, and not the activity itself.

There is almost always a preceding phase before a vulnerability becomes public. Attackers probe behaviour, test access paths, interact with the environment in ways that don't quite match normal usage. Even if these signals don't look like exploitation, they are exploration.

Which is why they tend to get missed.

Most security environments are tuned to recognise known patterns (IOCs, e.g.).
Exploration that doesn't match a signature or a known technique passes through quietly. By the time the vulnerability is named and published, the groundwork has often already been laid.

This brings a gap - it's about the difference between activity that is recognised and activity that is understood.

Nothreat CyberEcho changes the gap - and any exploration itself becomes the preemptive signal.

The earlier that gap closes, the more resilient your company becomes.

Gartner named preemptive cybersecurity one of its top strategic technology trends for 2026. Their definition is precise:...
02/07/2026

Gartner named preemptive cybersecurity one of its top strategic technology trends for 2026. Their definition is precise: "acting before attackers strike using AI-powered SecOps, programmatic denial and deception."

Deception is not a footnote in that definition. It is one of three core pillars.

The logic is straightforward. If an attacker is interacting with a decoy, it is malicious by definition. No false positives, no noise, no waiting to see what develops. The alert is already the answer.

This is what Nothreat CyberEcho does. It creates autonomous digital twin clones of your real environment — servers, applications, IoT devices — that are indistinguishable from the genuine infrastructure. Attackers map what appears to be your real network. They move through what feels like your real systems. Every step they take inside the decoy environment is captured, analysed, and converted into automated protection before they ever reach the real one.

Gartner predicts preemptive cybersecurity will account for over 50% of IT security spending by 2030, up from less than 5% in 2024. The shift is structural, not incremental.

Nothreat CyberEcho is preemptive security in practice — not as a framework, but as a running system that requires no human intervention to operate.

Nothreat is expanding into Southeast Asia.We have signed a distribution partnership with IshanTech, a leading ICT securi...
24/06/2026

Nothreat is expanding into Southeast Asia.

We have signed a distribution partnership with IshanTech, a leading ICT security solutions provider based in Malaysia, to bring Nothreat's preemptive security products to the Malaysian market.

The timing reflects where the region is heading. Malaysia's cybersecurity market is forecast to reach $9.32 billion by 2031, driven by stricter compliance requirements, rapid cloud adoption, and growing demand from banking, telecoms, and the public sector. Malaysia also ranks among the most cyber-targeted countries in the Asia-Pacific region — making the case for preemptive security stronger, not weaker.

IshanTech brings deep local expertise, established enterprise relationships, and a strong track record across IT security and infrastructure. Together, we're making autonomous, self-learning defence available to organisations that need it most.

More to come.

On Friday, two of the world's most advanced AI models went dark overnight. Not because of a breach. Not because of a fai...
15/06/2026

On Friday, two of the world's most advanced AI models went dark overnight. Not because of a breach. Not because of a failure. Because of a policy decision.

For the first time, export controls were applied to a deployed commercial AI model rather than to chips or hardware.

But there's a broader shift this points to. Models at this capability level don't just assist analysts. They change the pace of everything. Vulnerability discovery, exploit development, and attack automation. As these capabilities become more powerful and more accessible, the gap between reactive security and preemptive security widens.

A defence that waits to see the attack before responding is already behind. At the speed these tools operate, detection after the fact is increasingly indistinguishable from no detection at all.

The organisations that stay ahead won't be the ones reacting faster. They'll be the ones who made the attacker's job harder before the attempt was even made through deception, autonomous response, and architectures that don't depend on a single external capability staying available.

This is the principle behind what we're building at Nothreat.

One of the quieter shifts in cybersecurity right now is how AI is changing attacker skill requirements.It's not that eve...
04/06/2026

One of the quieter shifts in cybersecurity right now is how AI is changing attacker skill requirements.

It's not that every attacker suddenly becomes highly sophisticated. It's that fewer steps now require deep expertise.

Tasks that once demanded real-world experience: scripting, payload adaptation, environment-specific tweaks — can now be assisted, generated, or fully automated. That changes who can run an attack. And more importantly, how often they can try.

When the barrier to entry drops, attempts increase. Techniques spread faster. Failure becomes less costly. Over time, average attackers start behaving like scalable ones.

But there's a second layer that gets less attention.

AI doesn't just lower the floor for opportunistic attacks. It also sharpens the ceiling for targeted ones. Sophisticated campaigns against specific organisations are now better informed and faster to execute. Reconnaissance that once took weeks gets compressed. Techniques that once required significant resources are increasingly within reach of smaller actors.

The result is pressure from both directions. More volume at the low end. More precision at the high end.

When attempts increase and targeting improves simultaneously, the question stops being whether something gets through. It becomes a question of whether you see the intent before the impact arrives.

That's where the gap between reactive and preemptive security becomes impossible to ignore.

Address

London

Alerts

Be the first to know and let us send you an email when Nothreat posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share