Articles published on Cyber threat intelligence
Authors
Select Authors
Journals
Select Journals
Duration
Select Duration
579 Search results
Sort by Recency
- Research Article
- 10.1038/s41597-026-07487-7
- May 25, 2026
- Scientific Data
- Lu Sun + 5 more
Advanced Persistent Threats(APTs) are characterized by persistence and complex attack chains. Information extraction techniques enable the identification of critical knowledge from unstructured Cyber Threat Intelligence (CTI), improving the detection of APT attacks. At present, high-quality information extraction Chinese datasets for APT scenarios remain scarce, particularly those covering multiple tasks such as entity, relation, and event extraction. This shortage limits the training and performance improvement of detection models. To address this issue, a multi-task information extraction Chinese dataset for APT Cyber Threat Intelligence is proposed. The dataset complies with the STIX 2.1 standard and is derived from 116 CTI reports. It covers three tasks: entity, relation, and event extraction. Specifically, it includes 2,574 entities, 1,506 relations, and 139 event instances across 808 sentences. Compared with existing APT threat intelligence datasets, our dataset offers significant advantages in task coverage, annotation granularity, and structural hierarchy. The dataset is further validated using several baseline models. This work provides strong support for APT intelligence modeling and cybersecurity research.
- Research Article
- 10.54254/2755-2721/2026.33193
- May 6, 2026
- Applied and Computational Engineering
- Ruofan Li
The situation of cyber threats is becoming increasingly complex and changeable. The traditional cyber threat intelligence system, due to its excessive reliance on closed data sources, has problems such as lagging updates and limited coverage. It is not only difficult to meet the real-time defense requirements but also unable to comprehensively capture new attack methods and potential threat trends. Open-source threat intelligence, with its advantage of multiple sources, can expose attack trends in advance and has become an important force to supplement the traditional intelligence system. However, the existing single machine learning algorithm has obvious shortcomings in the classification and evaluation of open-source threat intelligence and is difficult to take into account the multi-dimensional data features. To this end, this paper proposes the LSTM-KELM-Transformer classification algorithm. Firstly, data mining is carried out through correlation analysis and violin graph analysis, and then comparative experiments are conducted with multiple machine learning algorithms. The results show that this algorithm achieves 99% in accuracy, recall rate, precision rate and F1 score, with an AUC value of 99%. All evaluation indicators significantly outperform other algorithms, demonstrating excellent classification performance. This research provides a new technical solution for the efficient classification of open-source threat intelligence, which is of great practical significance for strengthening the real-time defense capability against network threats and improving the threat intelligence system construction.
- Research Article
- 10.1080/07366981.2026.2660226
- May 2, 2026
- EDPACS
- Richa Vijay + 2 more
ABSTRACT The quick pace of cyber threat has revealed important vulnerabilities in conventional antivirus tools, especially because of their centralized designs, poor visibility of threats, and slow reaction to new and polymorphic malware strains. To overcome such difficulties, this paper will propose a hybrid Blockchain-Based SDN-Cloud-IoT Collaborative Antivirus Network (BCAN), which uses the decentralized and transparent nature of blockchain technology to improve security and scalability in contemporary data management network structures. Contrary to other current blockchain-based systems of cyber threat intelligence (CTI), the proposed system suggests a single cross-layer approach to deploy Software Defined Networking (SDN), IoT-edge aggregation, cloud-based analytics, and smart-contract-based implementation of trust enforcement. In the proposed model, malware signatures, threat knowledge, and response plans are distributed among the antivirus engines, security scientists, IoT apparatus, and distributed nodes in close real time. Smart contracts can be used to authenticate devices, manage trust, and access (and) blockchain can be used to guarantee integrity, immutability, and auditability of shared intelligence. To minimize the blockchain overhead and enhance the scalability, an edge level aggregation mechanism is presented allowing to optimally record the transactions without the loss of security guarantees. Extensive experimental benchmarking, detection accuracy, false-positive rate, transactions analysis and gas consumption profiling show that detection performance, response time, and blockchain overhead are better regarding centralized antivirus solutions. The findings identify the feasibility of blockchain-based collaborating security designs of the next generation of decentralized cybersecurity infrastructures.
- Research Article
- 10.1016/j.asoc.2026.114911
- May 1, 2026
- Applied Soft Computing
- Shagufta Henna + 1 more
The rapid evolution of Domain Generation Algorithm (DGA)-driven attacks and obfuscated DNS traffic exposes fundamental weaknesses in conventional machine learning-based threat detection systems, particularly under adversarial manipulation. This study introduces FGM-GAN, a hybrid adversarial learning framework that synergistically combines gradient-based Fast Gradient Method (FGM) perturbations with adaptive Generative Adversarial Network (GAN)-based perturbations to improve both robustness and interpretability of deep neural networks for DNS threat classification. Unlike existing adversarial defenses that rely on model-specific perturbations, FGM-GAN explicitly learns class-conditional adversarial distributions for benign, phishing, and malware domains. This design enables the generation of realistic, feature-aligned perturbations that exhibit strong cross-model transferability. Experiments were conducted on the 32-feature CIC-BELL-DNS-2021 dataset (approximately 7000 labeled samples) using 5-fold cross-validation, hybrid perturbations with and , and evaluated against baseline DNN, SVM, Random Forest, KNN, and Decision Tree classifiers using accuracy and robustness metrics. Comprehensive evaluation demonstrates that FGM-GAN consistently improves robustness across diverse adversarial attacks (FGM, PGD, MIM, C&W) while maintaining stable performance across folds. Ablation studies and reduced-capacity variants confirm that gains arise from the hybrid adversarial mechanism rather than over-parameterization or hyperparameter tuning, and statistical significance tests verify the reproducibility of results. To enhance transparency and operational trust, the framework integrates multi-level explainable AI analyses spanning feature, neuron, and layer representations. These analyses consistently identify a compact set of high-impact DNS features and reveal structured adversarial propagation patterns, showing that robustness emerges from semantically meaningful representation learning. Collectively, these findings position FGM-GAN as a scalable and interpretable adversarial learning solution that jointly addresses robustness, transferability, and explainability in real-world DNS-based cybersecurity environments. • FGM-GAN hybrid improves neural network robustness against adversarial attacks • GANs produce realistic, class-specific adversarial perturbations for DNS data • Adversarial transferability validated across KNN, SVM, Decision Trees, RF • Gradient-XAI interprets feature, neuron, and layer-level model vulnerabilities • Combines robustness and explainability for actionable cyber threat intelligence
- Research Article
- 10.1016/j.comnet.2026.112203
- May 1, 2026
- Computer Networks
- Pedro Beltrán-López + 3 more
Reactive cyber deception: Stealth-based adaptive redirection to on-demand honeypots with AI-driven data generation
- Research Article
- 10.17752/guvenlikstrtj.1792238
- Apr 27, 2026
- Güvenlik Stratejileri Dergisi
- Hüseyin Parmaksız
This study introduces a framework for cyber threat intelligence aimed at enhancing Türkiye’s proactive cybersecurity capabilities, specifically addressing security vulnerabilities. A geographic analysis involving 11,911 malicious IP addresses and 6,927 malicious URLs from the National Cyber Incident Response Center (TR-CERT) facilitated the formation of intelligence-driven geographic blocking firewall policies, thus reinforcing proactive network defense strategies. The research correlated threat indicators from TR-CERT with exploit intelligence from the open-source Exploit-DB platform, establishing connections between Indicators of Compromise (IoCs) and security vulnerabilities. Risk calibration maps were developed to match these vulnerabilities with the Open Web Application Security Project (OWASP) Top 10 risk categories and validated against the National Vulnerability Database (NVD). This prioritization took into account vulnerability prevalence, Common Vulnerability Scoring System (CVSS) scores, exploitability levels, and potential impact. In addition, a dynamic risk scoring model based on Monte Carlo simulation was also used to estimate vulnerability risks, with exploitability serving as the probability parameter and CVSS scores as the impact parameter. The findings underscore that integrating exploit-focused vulnerability intelligence into national cyber threat intelligence processes can significantly enhance the development of more effective and intelligence-driven cyber defense architectures in rapidly evolving threat environments.
- Research Article
- 10.65725/jcise/2/2/003
- Apr 20, 2026
- RCHUB JOURNAL OF COMPUTATIONAL INTELLIGENCE SCIENCE AND ENGINEERING (JCISE)
- Spoorthi B S + 3 more
Abstract: Cybersecurity threats have grown more complex and frequent, creating serious risks for organizations, critical infrastructure, and individuals worldwide. Traditional signature-based security tools can no longer effectively identify and deal with advanced, evasive, and quickly changing cyber-attacks, such as zero-day exploits, ransomware, and multi-stage intrusion campaigns. As a result, there is a strong need for real-time cyber threat detection and response systems that adjust dynamically and offer timely, actionable information to security operations teams. This paper provides a detailed review of modern methods that combine machine learning (ML) and open-source intelligence (OSINT) gathered through automated web data scraping. Machine learning offers powerful analysis for spotting both known and unknown threats by recognizing patterns and detecting anomalies in various telemetry data, including network traffic, system logs, and endpoint activities. OSINT enhances these systems by supplying external insights into new vulnerabilities, threat actor tactics, techniques, and procedures (TTPs), as well as real-time cyber threat intelligence shared across open channels like social media, security forums, paste sites, and the dark web[1][2][3].By combining ML-based internal monitoring with continuously updated OSINT feeds, advanced systems improve threat classification accuracy, lower false alarms, and provide contextual information that aids proactive responses. This review looks into the key architectures, machine learning algorithms, and natural language processing techniques for analyzing OSINT, along with illustrative case studies in IoT, finance, and healthcare. It also highlights existing challenges, such as managing data quality, ensuring model robustness, and addressing privacy and compliance issues. It outlines future research directions, focusing on federated learning, explainability, and blockchain-enabled threat intelligence sharing. This paper aims to be a valuable resource for researchers and practitioners seeking more effective, adaptable, and integrated cyber security defence frameworks that can tackle the increasingly sophisticated threat landscape.
- Research Article
- 10.46507/jcgpp.v7i1.797
- Apr 19, 2026
- Journal of Contemporary Governance and Public Policy
- Suhirwan Suhirwan
The Straits of Malacca and Singapore are among the most strategically important maritime chokepoints in the global trading system. Although conventional threats such as piracy have been managed through regional cooperation, the rapid digitalisation of ports, vessel traffic systems, and naval command infrastructures has created new hybrid cyber-physical vulnerabilities. Despite recurring cyber incidents between 2020 and 2025, no institutionalised real-time cross-border Cyber Threat Intelligence (CTI) mechanism has emerged among Indonesia, Malaysia, and Singapore. This study examines the puzzle of institutional inertia under growing threat interdependence and its implications for SDG 9, Target 9.1 on resilient infrastructure, and SDG 17, Targets 17.16 and 17.17 on knowledge-sharing and effective public-private partnerships. Drawing on 18 semi-structured interviews and qualitative analysis of policy documents from 2020 to 2025, the study identifies three governance bottlenecks: legal-institutional ambiguity, sovereignty-related political constraints, and technical-operational interoperability gaps. Building on Regional Security Complex Theory and regime complexity scholarship, the article theorises Cooperative Sovereignty as a middle-ground governance modality between supranational integration and sovereignty-maximising bilateralism. It proposes the Malacca Cyber Intelligence Node (MCIN) as a federated, sovereignty-compatible mechanism for structured cyber threat signalling while preserving national control over data. The study contributes to governance scholarship and offers actionable pathways for strengthening maritime cyber resilience in sovereignty-sensitive regions.
- Research Article
- 10.1186/s42400-026-00588-1
- Apr 13, 2026
- Cybersecurity
- Yongwei Wang + 7 more
Abstract Extracting Chinese Cyber Threat Intelligence (CTI) under increasingly complex advanced persistent threat scenarios is crucial, yet challenging due to domain-specific term ambiguity and frequent long, nested entities. To address polysemy, nested-label conflicts, and cross-sentence semantic discontinuity, we propose an enhanced Transformer-based entity recognition method formulated as a pointer network. On the encoder side, we build a RoBERTa model with Rotary Positional Embeddings. To handle complex positions and boundaries of heterogeneous entity types, we introduce tokenization compensation and positional-parameter compression to sharpen boundary sensitivity. In the decoder, we refine GlobalPointer and model recognition as 2D head–tail span matching, enabling direct detection of overlapping and nested entities. To mitigate long-tail bias, we introduce an entity-frequency-aware dynamic threshold and a reweighted zero-boundary log-loss to improve recall for rare entities. Experiments demonstrate an overall F1 improvement of 6.32% over baselines on Chinese CTI datasets, with absolute gains reaching 19.7% specifically on nested and long entities. These results validate the model’s effectiveness in Chinese-specific named entity recognition and its utility for high-accuracy automated CTI analysis.
- Research Article
- 10.5171/2025.4540225
- Apr 13, 2026
- Journal of Eastern Europe Research in Business and Economics
- Selen Kayan Kilic + 1 more
In today’s digital world, Open-Source Intelligence (OSINT) is of critical importance in cyber threat analysis. However, when the studies in the current literature are examined, it has been realized that there is no comprehensive and automatic framework that allows the processing of visual and textual data obtained from social media platforms, especially Telegram, in an integrated manner with artificial intelligence. In order to fill this gap in literature, an AI-supported OSINT framework is proposed in this study, in which social media data is classified using GPT-based natural language processing models and configured for cyber threat intelligence. As a method, the text and images obtained from Telegram channels are collected automatically, classified according to categorical crime headings via GPT-based models, and the obtained outputs are configured in STIX 2.1 format and integrated into the OpenCTI platform. In addition, the System also provides pattern detection and relationship analysis by establishing correlations between different data types. The findings confirm that artificial intelligence-assisted classification provides superior performance compared to traditional methods in the accurate and rapid detection of threat contents. In addition, it has been observed that the data presented via visual panels and timelines with the OpenCTI platform accelerates the decision-making processes. This study not only provides a scalable and more easily applicable model for cybersecurity professionals but also makes an important contribution to the transformation of raw social media data into meaningful and actionable threat intelligence.
- Research Article
- 10.34133/research.1245
- Mar 23, 2026
- Research (Washington, D.C.)
- Jing Yang + 6 more
The dynamic metaverse paradigm integrates emerging technologies and offers transformative opportunities to enhance consumer healthcare applications through immersive, connected experiences. However, this paradigm faces substantial cybersecurity challenges, such as distributed denial-of-service attacks, probing, and port scanning. This undermines the trustworthiness and resilience of healthcare analytics frameworks. To address these threats, intrusion detection systems that support proactive anomaly detection are essential for securing metaverse-based healthcare applications. Conventional anomaly detection techniques face challenges such as low interpretability, suboptimal feature selection, class imbalance, and inefficient hyperparameter tuning. These challenges limit their reliability in practical cyber threat intelligence settings. To solve these challenges, this paper presents an anomaly-detection framework for Internet of Things-enabled metaverse healthcare environments. The proposed framework leverages an off-policy proximal policy optimization (PPO) algorithm that incorporates SHapley Additive exPlanations-based feature selection and class-specific reward adjustments to address imbalance. The reinforcement learning-based off-policy PPO enables adaptive, sample-efficient learning by leveraging prior experience during policy updates. The hyperparameters of the model are optimized using the Bayesian Optimization Hyperband algorithm to accelerate training and enhance performance. This optimization technique combines Bayesian search with the Hyperband method to improve efficiency and convergence during model tuning. The performance of our model is evaluated on NSL-KDD, MAWI, and CICIoT2023 datasets. The results depict that the model outperformed its contemporaries with state-of-the-art results where accuracy, F-measure, G-means, and area under the curve reached 88.005%, 87.271%, 87.986%, and 0.870; 92.184%, 88.992%, 89.738%, and 0.873; and 89.368%, 88.312%, 89.039%, and 0.836, respectively. The results confirm the effectiveness of the framework in cyber threat scenarios. They also show their potential for explainable, trustworthy intelligence in metaverse healthcare.
- Research Article
- 10.3390/fi18030173
- Mar 23, 2026
- Future Internet
- Md Moradul Siddique + 3 more
The sophistication of cyber attacks and privacy issues related to data sharing is improving and requires a decentralized approach. Conventional centralized approaches to IDS pose a threat to the privacy of data and data sovereignty. Contrarily, federated learning enables several clients to learn simultaneously without sharing their sensitive information, which is one of the most promising solutions to studying cyber threats in real time. This framework also adds value to IDS by using CTI, which is incorporated into the training process to make it more accurate in its detection while still maintaining privacy. Each client uses the local model, which is a random forest model that is trained on local datasets without sharing the raw data. Multiple aggregation methods, such as FedAvg, FedOPT, FedProx, and FedXGBoost, are then used to combine the local models into a global model. These techniques are judged with regard to accuracy and Cohen’s Kappa Score. The performance of various models in the NF-UNSW-NB15-v2 dataset experiments was tested. The local model took a value of 0.9941–0.9934 with Kappa scores of 0.8336–0.8088, showing strong performance in different configurations. The FedXGBoost aggregated global model was best in terms of its highest accuracy of 99.22 (Kappa score of 0.8417). More experiments were done on the DFedForest and DFedForest++ models. DFedForest++, incorporating diversity in local models alongside validation accuracy, achieved 99.76% accuracy, surpassing DFedForest (with 71% accuracy in local models). This framework operationalizes CTI through feature augmentation—appending three CTI-derived features (is_known_malicious_ip, is_suspicious_port, and ttp_match_score from MITRE ATT&CK v14 and AlienVault OTX) to each NetFlow record locally at each client before federated training begins. These results highlight the advantages of federated learning in providing collaborative, privacy-preserving solutions for cyber threat detection and emphasize the potential of CTI integration for improving the accuracy and robustness of IDS models across decentralized environments.
- Research Article
- 10.3390/electronics15061305
- Mar 20, 2026
- Electronics
- Nawal Almutairi
Security organizations increasingly rely on cyber threat intelligence (CTI) sharing to enhance their resilience against cyberattacks. Indicators of Compromise (IoCs) play a critical operational role in CTI by providing malicious artifacts that support threat detection, incident response, and facilitate proactive defense. However, the rapid growth of social media as CTI sources, characterized by short-text content, poses significant challenges to automated IoC extraction, contextual interpretation, operational integration, and reliable verification. To address these challenges, this study proposes a comprehensive framework that integrates Large Language Models (LLMs) across multiple stages of the CTI pipeline. The framework leverages LLM-driven data augmentation, a hybrid classification model, and contextual summarization to enhance short-text understanding while supporting expert-in-the-loop validation for operational reliability. Extensive experimental evaluations demonstrate that LLM-driven data augmentation substantially improves model robustness and generalization while reducing false-positive alerts, achieving a precision of 98.87%. Quantitative diversity analysis and expert-based human evaluation further confirm the linguistic quality and correctness of the generated augmented samples. In addition, IoC reports are validated using both reference-based and reference-free evaluation metrics that show strong alignment and high semantic adequacy. Moreover, a technology acceptance model was integrated with cybersecurity domain constructs to assess the acceptance factors of the proposed framework. Regression analysis showed that perceived usefulness, behavioral intention, trust in automation, and risk were the strongest predictors of actual use. These predictors are commonly interpreted as indicators of technology acceptance.
- Research Article
- 10.1038/s41598-025-34505-2
- Mar 2, 2026
- Scientific reports
- Shailendra Mishra + 2 more
Cyber-attacks pose a significant risk to digital infrastructure, resulting in losses at both individual and organizational levels, underscoring the need for proactive and intelligent defense mechanisms. This study proposes a hybrid Cyber Threat Intelligence (CTI) system integrating an immutable blockchain ledger, adaptive machine-learning models, and natural-language processing algorithms for timely detection, classification, and secure sharing of threat data. The system forecasts future attacks by analyzing aggregated data and recommending mitigation strategies. A BERT-based model, combined with spaCy and regular expressions for extracting Indicators of Compromise (IOCs) from unstructured data, achieved 95% accuracy and a 95.7% F1-score, with a 55% latency reduction (from 120ms to 54ms for 200 reports). Validation used 10-fold cross-validation with paired t-tests across 10,000 Monte Carlo simulations (t = 3.45, p < 0.001, Cohen’s d ranging 0.76–1.12 from heatmaps) on CIC-IDS2017 and UNSW-NB15 datasets. The Cross-Dataset Robustness Index (CRI) confirmed strong generalization, with BERT at 0.999, slightly outperforming LSTM (0.998), SVM (0.95), and Naïve Bayes (0.92). The system excels in high-volume data processing, event correlation, and threat detection/response rates. This scalable solution suits Security Operations Centers (SOCs), IoT environments, and financial cybersecurity, providing robust unstructured data handling and adaptability to evolving threats.
- Research Article
- 10.3390/e28030261
- Feb 27, 2026
- Entropy
- Yong Li + 6 more
Cyber threat intelligence (CTI) has been explored to strengthen system security via taking raw threat data from various data sources and transforming it into actionable insights that enable organizations to predict, detect, and respond to cyber threats. Named entity recognition (NER) and relation extraction (RE) are the key tasks of CTI data mining. However, current CTI NER and/or RE research is mainly focused on English CTI, which is not directly transferable to Chinese CTI due to fundamental linguistic and terminological differences. Moreover, the existing limited studies on Chinese CTI do not effectively address uncertainty in predictions in low-resource scenarios where entities and relations are sparse. This work aims to improve the performance of NER and RE tasks in low-resource Chinese CTI scenarios, and we make two major contributions. The first is that we construct a Chinese CTI dataset, which includes 16 types of entities and 9 types of relations—more than those of the existing open-source dataset on Chinese CTI. The second is that we propose an entropy-driven approach for entity and relation (EDAER) extraction. EDAER is the first to combine the techniques of RoBERTa_wwm, Mamba, RDCNN and CRF to perform NER tasks. In addition, EDAER is the first to apply entropy to quantify the uncertainty of the model’s predictions in NER and RE tasks in Chinese CTI scenarios. Moreover, EDAER is the first to apply contrastive learning techniques in Chinese CTI scenarios to learn meaningful features by maximizing the similarity between positive samples and minimizing the similarity between negative samples. Extensive experimental results on public and our built datasets demonstrate that our proposed approach performs the best. These results show that (1) RoBERTa_wwwm significantly outperforms BERT on both NER and RE tasks; (2) Mamba outperforms BiLSTM on the NER task; (3) the entropy-based dynamic gating mechanism contributes to performance improvements in both NER and RE tasks; and (4) the uncertainty-guided contrastive learning mechanism is helpful for performance improvement in the NER task.
- Research Article
- 10.1108/jsit-05-2025-0223
- Feb 20, 2026
- Journal of Systems and Information Technology
- Joshua T Lavoie + 1 more
Purpose Cyber threat intelligence (CTI) and risk management (RM) remain fragmented across tools, formats and governance processes, limiting interoperability and consistent decision-making. This study aims to develop unified risk and intelligence messaging (URIM), a governance-oriented artifact that standardizes risk and intelligence communication across heterogeneous organizational contexts. Design/methodology/approach Following design science research (DSR), the authors elicited requirements from cybersecurity professionals. A pilot study refined the survey instrument, followed by a qualitative survey using purposive and snowball sampling. Thematic analysis informed the URIM artifact specification, which was appraised through a qualitative ex ante expert review, with recommendations registered for subsequent cycles. Findings Three recurring barriers to effective cyber risk governance emerged: fragmented toolchains, limited data interoperability and inconsistent governance practices. Participants highlighted vendor lock-in, incompatible protocols and weak standardization as constraints on intelligence sharing. They supported a vendor-neutral approach combining canonical governance messages, semantic alignment and modular compliance features. Originality/value URIM extends cybersecurity governance research by providing a user-informed, model-level DSR artifact that links CTI and RM through standardized governance messaging and explicit interface specifications. It makes interoperability requirements explicit by defining canonical messages and semantic alignment rules that existing CTI-sharing and RM approaches often leave implicit.
- Research Article
- 10.34190/iccws.21.1.4482
- Feb 19, 2026
- International Conference on Cyber Warfare and Security
- Jani Siivola + 6 more
The NIS2 Directive introduces stricter requirements for how essential entities, including energy-sector operators, must manage cybersecurity risks and report incidents. In practice, many organisations face difficulties in transforming these legal obligations into concrete, daily security operations, especially in operational technology (OT) environments where visibility, logging, and coordinated responses are often limited. This paper examines how SecureAI, an AI-based anomaly detection and enrichment tool within the Cyber Threat Intelligence (CTI) ecosystem, can help energy operators meet key NIS2 obligations. The study is based on a qualitative desk-research approach, a comparative mapping of SecureAI capabilities against NIS2 Articles 20-26, and a realistic OT case scenario based on recent intrusion patterns. Prior research shows that AI can detect industrial anomalies faster and more accurately than rule-based systems, and that automated CTI processing can turn raw alerts into structured and shareable intelligence. At the same time, NIS2 requires accountable use of such tools, meaning that human oversight, transparency of analysis, and reliable evidence generation must be part of AI-supported workflows. These requirements guided the assessment. The analysis shows that SecureAI supports several key NIS2-related tasks. It identifies unusual behaviour in network and host telemetry, enriches findings with asset information and event relationships, and produces structured alert objects that support operator decision-making. The CTI Framework then converts these enriched alerts into STIX/TAXII objects suitable for reporting, documentation, and intelligence exchange. The case scenario–an unauthorised remote-access intrusion followed by suspicious HMI-PLC activity–demonstrates how SecureAI can highlight the anomaly, provide context for understanding its impact, and supply material for reporting and further investigation.
- Research Article
- 10.34190/iccws.21.1.4481
- Feb 19, 2026
- International Conference on Cyber Warfare and Security
- Ilkka Tikanmäki + 4 more
The importance of robust cybersecurity frameworks has been raised by the digitalisation of critical infrastructure, particularly in the energy sector. The European Union (EU) launched the Cyber Resilience Act (CRA) in 2022, establishing uniform cybersecurity standards for products with digital elements at all lifecycle stages to address this issue. CRA describes requirements for software and hardware products with digital elements placed on the EU market. This study examines the CRA's effects on the energy sector and evaluates how the DYNAMO platform can support compliance and enhance sectoral resilience. The platform's key element is a dynamic resilience assessment methodology, which combines business continuity management (BCM) and cyber threat intelligence (CTI). Significant cybersecurity vulnerabilities in the energy sector are identified in the study, which include a growing attack surface, complex supply chains, and convergence of operational technology (OT) and information technology (IT) systems. CRA's inability to address OT-specific challenges, particularly in legacy systems like SCADA, is highlighted in the study through a literature review and case study analysis. The gap analysis shows that although CRA follows standards like NIST and ISO 27001, it doesn't have provisions for real-time monitoring, adaptive risk management, and OT-specific protections. To resolve those gaps, the research suggests that DYNAMO include 24-hour incident reporting to the European Union Agency for Cybersecurity (ENISA), structured vulnerability disclosure protocols, and post-market surveillance mechanisms. Additionally, DYNAMO must develop customised plans for OT environments, which involve retrofitting outdated systems and improving threat detection abilities. The findings show that cybersecurity in the energy industry requires a more dynamic and functionally integrated approach. Aligning DYNAMO and CRA will support regulatory compliance and strengthen the industry's resilience to evolving cyber threats. The next stage of research should be to validate these recommendations via empirical testing and explore cross-sector applications of the DYNAMO framework.
- Research Article
- 10.36418/syntax-literate.v11i2.63770
- Feb 9, 2026
- Syntax Literate ; Jurnal Ilmiah Indonesia
- Dewi Holilah
Credential leaks pose a major threat to cybersecurity because they often lead to follow-up attacks such as credential stuffing and account takeovers. Beyond dark web forums, Telegram has emerged as a prominent platform for the open distribution of leaked credentials. However, existing studies largely focus on descriptive analysis or threat detection, providing limited support for transparent and measurable post-compromise risk assessment. This study proposes an Explainable Platform Risk Scoring (XPRS) framework to support post-compromise decision-making in Cyber Threat Intelligence (CTI). Credential leak data are collected from public Telegram channels and processed through preprocessing stages to mitigate duplication and remove irrelevant records. Technical vulnerability is quantified using Shannon entropy, while platform risk is estimated by integrating platform impact and leak characteristics. Explainable Artificial Intelligence (XAI) employs SHapley Additive exPlanations (SHAP) to clarify risk indicators. The evaluation utilizes rank-based statistical analysis to examine the correlation between platform frequency and associated risk scores. The results indicate that XPRS consistently generates and interprets platform-level risk prioritization, offering practical support for transparent cybersecurity in post-compromise contexts. The findings demonstrate that the frequency of leaks is not the primary determinant of risk; instead, platforms in critical sectors such as Identity & Access Management (IAM), government, and financial services consistently exhibit the highest risk scores despite lower leak volumes. This underscores that systemic impact and credential quality are more significant in post-compromise risk assessment than the sheer quantity of leaks.
- Research Article
- 10.3390/app16031668
- Feb 6, 2026
- Applied Sciences
- Mateo Barrios-González + 3 more
The increasing complexity and scale of cyber threats have pushed Cyber Threat Intelligence (CTI) beyond the capabilities of traditional rule-based systems. This article explores how Artificial Intelligence (AI), particularly Machine Learning (ML), Deep Learning (DL), Natural Language Processing (NLP), and graph-based analytics, is reshaping the CTI landscape. By automating threat data processing, enhancing attribution, and enabling predictive capabilities, AI is transforming CTI into a proactive and scalable discipline. By analysing CTI architectures, real-world use cases, platform comparisons, and current limitations, this study highlights the emerging opportunities and challenges at the intersection of cybersecurity and AI. This analysis concludes that the future of CTI lies in hybrid systems that seamlessly combine human expertise with intelligent automation.