JUMPSEC’s cover photo
JUMPSEC

JUMPSEC

Computer and Network Security

Acton, London 3,864 followers

Futureproof your cyber defences, realise genuine improvement with JUMPSEC managed services and consultancy solutions.

About us

Adaptive Cyber Security JUMPSEC operates on a core principle: real attack insight drives stronger defence. As a specialist cyber‑security organisation, we deliver deep technical expertise, advanced capabilities, and tailored solutions that strengthen resilience and support secure organisational transformation.

Website
http://www.jumpsec.com
Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
Acton, London
Type
Privately Held
Founded
2012
Specialties
Cyber Incident Response, Security Architecture Consultancy, Application and Mobile penetration testing, Social Engineering, Security Assessments, Managed Vulnerability Scanning, Security Operations Centre, SOC-as-a-service, Threat Intelligence, Security awareness workshops & training, Threat Modelling, Cyber Incident Response capability review, Incident detection and capability review, Cyber Security Consultancy, ransomware, Cyber Security, Penetration Testing, managed services, Red Teaming, and MXDR

Locations

Employees at JUMPSEC

Updates

  • How much of a campaign can be assembled from pre-built components before reliable attribution starts to break down? We've decided to call this one PAPERMILL. The designation refers to an emerging, Silver Fox-like activity cluster identified during our investigation of a tax-themed phishing campaign. Beneath a layered chain of trusted software abuse, sideloaded DLLs, and multiple loader stages sat a familiar objective: delivering VenomRAT to establish remote access to the victim system. While the activity exhibits characteristics associated with broader China-nexus operations, the evidence does not currently support confident attribution to a specific threat actor. For now, PAPERMILL provides a working designation for a cluster that appears defined less by bespoke malware and more by the industrialised assembly of existing components. Read the full research: PAPERMILL: https://lnkd.in/eni74trK

  • View organization page for JUMPSEC

    3,864 followers

    Today marks another important milestone for JUMPSEC. We are pleased to confirm that JUMPSEC has successfully secured a place on G-Cloud 15 under Lot 3 - Cloud Support. Over the last few years, JUMPSEC's capability has expanded significantly beyond traditional testing services, and in G-Cloud 15, we've included this wider capability, grounded in the reality that resilience is built through informed decisions, continuous improvement, and a clear understanding of risk. Today, our clients engage us across five core areas: ●   Offensive: understand how an attacker could compromise your organisation. ●   Defensive: strengthen resilience before incidents occur. ●   MXDR: improve the speed and effectiveness of threat detection and response. ●   Continuous Reconnaissance: understand what a motivated attacker can see, learn and exploit today. ●   AI Assurance: adopt AI securely, responsibly and with confidence. Our team includes specialists who help organisations understand not only where risk exists, but what to do about it next. Whether you're a central government department, local authority, NHS organisation, university, emergency service, housing association or wider public sector body, G-Cloud 15 now provides a straightforward route to access JUMPSEC's expertise. We're looking forward to supporting organisations that want to move beyond compliance exercises and make genuine improvements to their cyber resilience. If you'd like to discuss an upcoming requirement or simply sense-check your current strategy, we'd be delighted to talk. #GCloud15 #CyberSecurity #CyberResilience #PublicSector #Microsoft #ManagedDetectionAndResponse #ThreatLedSecurity #SocialValue #GCloud15

    • JUMSEC is a provider on G Cloud 15 Lot 3
  • Trust is becoming an ever greater part of an organisation's attack surface. Our Threat Researcher Jack L. recently analysed the source code behind an active BlueNoroff phishing operation impersonating Zoom and Microsoft Teams. What he uncovered wasn't just another #phishing kit; the reverse engineering revealed a particularly effective victim acquisition platform. Compromised Telegram accounts, fake meetings, AI-generated participants, wallet profiling and malware delivery. The attack spreads through genuine business relationships. Read the blog post: https://lnkd.in/gFfhJ2Dk The research has already been picked up by The Hacker News: Read the coverage here: https://lnkd.in/gFbN3eZi When a real account belonging to someone you know becomes the attack vector, traditional anti-phishing advice breaks down. BlueNoroff's model works because the sender isn't a stranger. #teams #zoom #BlueNoroff #clickfix

    • No alternative text description for this image
  • Many security controls implicitly rely on visual and vocal trust, from supplier payment approvals to HR requests and password resets. But what happens when seeing and hearing someone is no longer reliable evidence of identity? In our latest research, "Project Havoc," JUMPSEC's team built live, interactive video/audio clones using nothing but free open-source tools, then used them on internal video calls to see how convincing our synthetic identities were. Interestingly, our real-time face re-enactment and voice conversion was good enough to make colleagues believe they were talking to a genuine exec and act on it – under certain conditions. It's effective but not flawless, and instances where it doesn't work are arguably just as interesting. We break down: ▶️ Exactly how the framework works (and how accessible it is) ▶️ How real-world precedent informs the three attack paths we assess as most viable right now (Finance, IT/SecOps, and HR) ▶️ Why it works in some scenarios and falls flat in others ▶️ How sophisticated the tooling currently is (via a demo video) ▶️ Why "seeing is believing" no longer holds up as a security control, and what needs to replace it. As many organisations have hardened phishing defences and MFA, attackers have pushed harder into the human layer. IT helpdesk vishing, MFA fatigue, and voice-based pretexting are exactly where attackers are finding repeated success. Synthetic media is a natural next step in that arms race and it's already proving effective, as we have used it ourselves to strengthen recent vishing simulations. If someone appeared on a Teams call looking and sounding exactly like your CEO, which of your controls would still verify who they are? If the answer is "not many", this research is worth 10 minutes of your time. Read the full research here: https://lnkd.in/eT4TzYaj #CyberSecurity #SocialEngineering #Vishing #DeepfakeFraud #IdentityVerification #RedTeaming #AdversarySimulation

  • We’re proud to share that JUMPSEC is a founding signatory of the CREST AI Charter — reinforcing our commitment to using AI responsibly across cybersecurity. As AI adoption accelerates, trust, transparency, and human oversight matter more than ever. By backing CREST’s nine AI principles, we’re ensuring that innovation never comes at the expense of accountability. For our clients, this means clarity on where AI is used, confidence in how it’s governed, and assurance that expert judgement remains at the core of every service. ➡️ Read more: https://lnkd.in/ezXVYh-m #CyberSecurity #AI #ResponsibleAI #CREST #Trust #Innovation

    • JUMPSEC is a founding signatory of the CREST AI Charter, backing responsible AI use across cybersecurity – with transparency and human oversight built in.

JUMPSEC has become a founding signatory of the CREST AI Charter, a public commitment to using artificial intelligence responsibly across cybersecurity services. We’re among the first group of CREST members worldwide to put our name to it.

The Charter is the work of CREST, the global not-for-profit that accredits providers and sets professional standards across the cybersecurity industry. It asks signatories to support CREST’s nine AI Principles and to help shape AI-enabled security services that customers can trust. More than one in ten CREST members signed up in the founding group, spanning Europe, North America, the Middle East, and Asia-Pacific.
  • View organization page for JUMPSEC

    3,864 followers

    Yesterday, we hosted our annual JUMPSEC Industry Briefing, and one thing is clear: the threat landscape is shifting faster than most organisations are structured to respond. Across the sessions, a few key themes emerged: - The attack surface has moved upstream. Modern attackers aren’t breaking into your product; they’re compromising the systems that build it. CI/CD pipelines, dependencies, and software supply chains are now prime targets, with attackers exploiting implicit trust at scale. - AI is accelerating both sides — but especially the attacker. Agentic AI is already operating inside pipelines, acting with speed, autonomy, and often excessive privilege. The challenge isn’t just capability; it’s control. These agents behave like developers, but without intuition or skepticism. - Threat actor behaviour is evolving (and blurring). From geopolitical spill over impacting private organizations to the convergence of financially motivated and state-backed tactics — attribution is getting harder and less useful as a defensive anchor. - Identity is now the primary battleground. Whether it’s credential abuse, synthetic identities, or AI-driven impersonation, attackers are increasingly logging in rather than breaking in. That shift underpins many of the most impactful incidents we’re seeing today. And perhaps the most provocative takeaway: "Security Operations is DEAD" — not the people, but the model. Alert queues and SLAs don’t measure whether you’ve stopped an attack; only that you’ve processed activity. Modern defence needs to move toward understanding behaviour, not just handling alerts. A huge thank you to our speakers and clients who joined us for such an open and thought-provoking discussion. The takeaway? Cybersecurity isn’t failing — but the way we organise around it needs to evolve quickly. If you'd like to continue the conversation or dive deeper into any of these topics, feel free to reach out. #CyberSecurity #ThreatIntelligence #AI #SupplyChainSecurity #SecOps #IdentitySecurity

    • Yesterday we hosted our JUMPSEC Industry Briefing — and one thing is clear: the threat landscape is shifting faster than most organisations are structured to respond.
Across the sessions, a few key themes emerged:
The attack surface has moved upstream
Modern attackers aren’t breaking into your product — they’re compromising the systems that build it.
CI/CD pipelines, dependencies, and software supply chains are now prime targets, with attackers exploiting implicit trust at scale. 
AI is accelerating both sides — but especially the attacker
Agentic AI is already operating inside pipelines, acting with speed, autonomy, and often excessive privilege.
The challenge isn’t just capability — it’s control. These agents behave like developers, but without intuition or scepticism. 
Threat actor behaviour is evolving (and blurring)
From geopolitical spillover impacting private organisations, to the convergence of financially motivated and state-backed tactics — attribution is getting harder, and
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
      +1
  • What can malware really do once it’s inside your environment? In our latest threat intelligence write-up, we break down how the BlackToad campaign uses an AutoIt-based payload to manipulate network activity in subtle but impactful ways. Rather than relying on obvious or noisy techniques, this approach demonstrates how attackers can quietly control communications and evade detection using relatively simple tooling—something defenders shouldn’t underestimate. This post walks through: ➡️ How the payload works in practice ➡️ The techniques used to interfere with network behaviour ➡️ Why these methods are effective against traditional detection ➡️ What defenders should be looking out for If you're interested in how real-world threats actually operate under the hood—and what that means for detection and response—this one’s worth a read. 👉 https://lnkd.in/gsiYsW6p #ThreatIntelligence #CyberSecurity #DetectionEngineering #MalwareAnalysis #BlueTeam

    • What can malware really do once it’s inside your environment?
In our latest threat intelligence write-up, we break down how the BlackToad campaign uses an AutoIt-based payload to manipulate network activity in subtle but impactful ways.
Rather than relying on obvious or noisy techniques, this approach demonstrates how attackers can quietly control communications and evade detection using relatively simple tooling—something defenders shouldn’t underestimate.
This post walks through:

How the payload works in practice
The techniques used to interfere with network behaviour
Why these methods are effective against traditional detection
What defenders should be looking out for

If you're interested in how real-world threats actually operate under the hood—and what that means for detection and response—this one’s worth a read.
👉 www.jumpsec.com/guides/blacktoad-network-manipulation-in-an-autoit-payload/
#ThreatIntelligence #CyberSecurity #DetectionEngineering #MalwareAnalysis #BlueTeam
  • It’s well established that attackers make use of legitimate system tooling to blend into normal activity. But the more important shift is how these tools are now being used to structure entire intrusion chains designed for stealth, persistence, and post-compromise control. In our new research piece, ‘BlackToad: Network Manipulation via AutoIt Payloads’, we examine how threat actors are abusing legitimate Windows scripting environments, in this case AutoIt, as part of a multi-stage payload designed for stealth and network manipulation. Key takeaways: 🔹 AutoIt remains attractive to attackers due to its legitimacy and low detection footprint 🔹 Execution chains are increasingly focused on post-compromise network manipulation, not just initial access 🔹 Obfuscation and layered scripting significantly reduce the effectiveness of static detection methods 🔹 Behavioural detection and investigative analysis remain critical for uncovering this type of activity Full write-up here: https://lnkd.in/gsiYsW6p

Similar pages

Browse jobs