- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,693
The usual rules of protection were officially recognized as outdated.

MITRE has released ATT&CK v19 is a major update of the framework used by security teams to describe tactics and techniques of intruders. The new version significantly changes the usual structure: the developers have divided the too broad category of Defense Evasion, added more details for industrial systems and expanded the coverage of attacks using AI, social engineering and mobile threats.
The main change affected the tactics of Defense Evasion. Previously, there were attempts by intruders to hide in the infrastructure, and actions aimed at disabling protective equipment. In ATT&CK v19, the previous category is replaced by two directions:
ATT&CK v19 expands the description of attacks where attackers use AI. The new T1682 Query Public Aviation equipment describes requests for public AI services for reconnaissance purposes and operations planning. T1683 Generate Content covers the preparation of text, audio and visual content, including materials created manually, through contractors or with AI. Social engineering is now put into a separate parental technique T1684, where they have moved the identity swing and e-mail spider.
The matrix for industrial systems has become more accurate. MITRE has added subtechnics to change the firmware, block the communication via Serial COM, Ethernet and Wi-Fi, remote system detection, download programs to controllers and abuse of unsafe account. This level of detail helps to more accurately link the behavior of attackers with telemetry and integrity checks.
The mobile direction also received a noticeable update. Detection strategies now cover part of the techniques for Mobile and provide practical guidelines for Android and iOS. VajraSpy, DocSwap and Crocodilus are added to the matrix, and the Phishing technique is updated to take into account voice phishing, where attackers cloned voices using AI.
In the cyber reconnaissance block, MITRE added new information about Iranian and Chinese groups, malware for attacks on network devices, campaigns with vipes, compromising the npm ecosystem and tools used in extortion operations. The Anthropic AI-orchestrated Campaign and LAMEHUG are classified, associated with the use of a large language model in real-life operations.
The update of ATT&CK shows that it is not enough for the defenders to simply know the set of techniques of attackers: you have to more accurately understand their goal, the context of actions and traces in different environments, otherwise even familiar technology may go unnoticed.

MITRE has released ATT&CK v19 is a major update of the framework used by security teams to describe tactics and techniques of intruders. The new version significantly changes the usual structure: the developers have divided the too broad category of Defense Evasion, added more details for industrial systems and expanded the coverage of attacks using AI, social engineering and mobile threats.
The main change affected the tactics of Defense Evasion. Previously, there were attempts by intruders to hide in the infrastructure, and actions aimed at disabling protective equipment. In ATT&CK v19, the previous category is replaced by two directions:
- Stealth describes the disguise of behavior, the launch of legitimate utility for malicious purposes, obfuscation of the payload and the issuance of processes for trustees.
- Defense Impressment covers EDR shutdown, log interference, bypassing trusted mechanisms, and other activities that break the defense.
ATT&CK v19 expands the description of attacks where attackers use AI. The new T1682 Query Public Aviation equipment describes requests for public AI services for reconnaissance purposes and operations planning. T1683 Generate Content covers the preparation of text, audio and visual content, including materials created manually, through contractors or with AI. Social engineering is now put into a separate parental technique T1684, where they have moved the identity swing and e-mail spider.
The matrix for industrial systems has become more accurate. MITRE has added subtechnics to change the firmware, block the communication via Serial COM, Ethernet and Wi-Fi, remote system detection, download programs to controllers and abuse of unsafe account. This level of detail helps to more accurately link the behavior of attackers with telemetry and integrity checks.
The mobile direction also received a noticeable update. Detection strategies now cover part of the techniques for Mobile and provide practical guidelines for Android and iOS. VajraSpy, DocSwap and Crocodilus are added to the matrix, and the Phishing technique is updated to take into account voice phishing, where attackers cloned voices using AI.
In the cyber reconnaissance block, MITRE added new information about Iranian and Chinese groups, malware for attacks on network devices, campaigns with vipes, compromising the npm ecosystem and tools used in extortion operations. The Anthropic AI-orchestrated Campaign and LAMEHUG are classified, associated with the use of a large language model in real-life operations.
The update of ATT&CK shows that it is not enough for the defenders to simply know the set of techniques of attackers: you have to more accurately understand their goal, the context of actions and traces in different environments, otherwise even familiar technology may go unnoticed.