<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Threat-Attribution on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/threat-attribution/</link><description>Recent content in Threat-Attribution on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 16 Jun 2024 11:30:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/threat-attribution/index.xml" rel="self" type="application/rss+xml"/><item><title>94% of Security Incidents Use Anonymised Infrastructure</title><link>https://zxcloudsecurity.co.uk/posts/94-percent-incidents-anonymised-infrastructure-threat-intelligence-reactive/</link><pubDate>Tue, 16 Jun 2026 11:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/94-percent-incidents-anonymised-infrastructure-threat-intelligence-reactive/</guid><description>New survey finds 94% of security incidents involve anonymised infrastructure. Learn why threat intelligence teams remain reactive and what to do about it.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/survey-94-of-incidents-involve.html">The Hacker News</a></p>
<hr>
<p>A new survey reveals that 94% of security incidents involve anonymised infrastructure such as VPNs, proxies, and hosting services, making it difficult to attribute attacks to real threat actors. Despite access to large volumes of IP enrichment and threat intelligence data, most security teams remain reactive rather than proactive. The core problem is signal-to-noise ratio — too much data, too little actionable context.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your threat intelligence pipeline for coverage of anonymising infrastructure (e.g. Tor exit nodes, residential proxies, bulletproof hosting ASNs) and ensure your SIEM or SOAR rules treat traffic from these sources with elevated suspicion by default. Consider integrating purpose-built IP context providers that specialise in anonymisation detection rather than relying solely on generic reputation feeds.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/survey-94-of-incidents-involve.html">Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive</a></p>
]]></content:encoded></item></channel></rss>