Latest Articles

Adversaries are skipping passwords: OAuth consent phishing & token theft are now top initial-access paths

Adversaries are skipping passwords: OAuth consent phishing & token theft are now top initial-access paths

Across recent incident response cases, the dominant initial-access vector is no longer password spray or basic phishing. Instead, adversaries are abusing OAuth application consent and token theft to...

Apple patches actively exploited ImageIO zero-day (CVE-2025-43300): update iOS/iPadOS/macOS now

Apple patches actively exploited ImageIO zero-day (CVE-2025-43300): update iOS/iPadOS/macOS now

Apple has shipped urgent security updates to address CVE-2025-43300, an out-of-bounds write in the ImageIO framework that can be triggered by a maliciously crafted image. Apple says it is aware of...

Google Patches Actively Exploited Chrome 0-Day (CVE-2025-10585) — Update Now

Google Patches Actively Exploited Chrome 0-Day (CVE-2025-10585) — Update Now

Google has shipped an emergency update for Chrome to fix CVE-2025-10585, a high-severity type confusion flaw in the V8 JavaScript engine that is already being exploited in the wild. The issue was...

SEO-Poisoned GitHub Pages Impersonate Popular Apps to Push macOS Atomic Stealer

SEO-Poisoned GitHub Pages Impersonate Popular Apps to Push macOS Atomic Stealer

Summary: A new campaign is abusing GitHub Pages and search-engine poisoning to rank high for queries like “Install on Mac.” The pages impersonate well-known software vendors and redirect...

Surge in Malvertising Delivers Infostealers via Fake Software Installers

Surge in Malvertising Delivers Infostealers via Fake Software Installers

News • Expert Insights Threat actors are abusing paid search ads and SEO-poisoned pages to distribute trojanized installers for popular tools (e.g., editors, media apps,...

Wave of “QR Phishing” Emails Targets Microsoft 365 Users

Wave of “QR Phishing” Emails Targets Microsoft 365 Users

News • Expert Insights Attackers embed QR codes in PNG images to evade text/URL scanning and redirect victims to credential-harvesting pages. Emails contain PNG...