Latest Articles

Passkeys won’t save you (unless you fix identity sprawl and recovery loopholes)

Passkeys won’t save you (unless you fix identity sprawl and recovery loopholes)

Opinion: Passkeys are the best mainstream step we’ve taken against credential phishing. But enterprises rolling out “passwordless” are discovering an uncomfortable truth: you can remove passwords...

Supply-chain reality check: package-squatting + CI/OIDC abuse are the fastest routes into your cloud

Supply-chain reality check: package-squatting + CI/OIDC abuse are the fastest routes into your cloud

Package squatting / dependency confusion: Adversaries publish near-name or higher-version packages to public registries (npm/PyPI). CI/dev machines resolve to the malicious package, executing...

Search malvertising is back: signed installers + cloned brands are delivering loaders at scale

Search malvertising is back: signed installers + cloned brands are delivering loaders at scale

Malvertising/SEO-poisoning campaigns are impersonating popular software (VPNs, IDEs, archivers, wallets). The flow is consistent: paid search ad → look-alike domain → signed MSI/EXE that side-loads a...

Stop buying more EDR until you’ve fixed identity and SaaS: a pragmatic 90-day plan

Stop buying more EDR until you’ve fixed identity and SaaS: a pragmatic 90-day plan

Most incidents we triage in 2025 do not begin with a kernel exploit on an endpoints; they begin with identity and SaaS: consent grants, token theft, weak conditional access, and sprawling...

Adversaries are skipping passwords: OAuth consent phishing & token theft are now top initial-access paths

Adversaries are skipping passwords: OAuth consent phishing & token theft are now top initial-access paths

Across recent incident response cases, the dominant initial-access vector is no longer password spray or basic phishing. Instead, adversaries are abusing OAuth application consent and token theft to...

Apple patches actively exploited ImageIO zero-day (CVE-2025-43300): update iOS/iPadOS/macOS now

Apple patches actively exploited ImageIO zero-day (CVE-2025-43300): update iOS/iPadOS/macOS now

Apple has shipped urgent security updates to address CVE-2025-43300, an out-of-bounds write in the ImageIO framework that can be triggered by a maliciously crafted image. Apple says it is aware of...

Google Patches Actively Exploited Chrome 0-Day (CVE-2025-10585) — Update Now

Google Patches Actively Exploited Chrome 0-Day (CVE-2025-10585) — Update Now

Google has shipped an emergency update for Chrome to fix CVE-2025-10585, a high-severity type confusion flaw in the V8 JavaScript engine that is already being exploited in the wild. The issue was...

SEO-Poisoned GitHub Pages Impersonate Popular Apps to Push macOS Atomic Stealer

SEO-Poisoned GitHub Pages Impersonate Popular Apps to Push macOS Atomic Stealer

Summary: A new campaign is abusing GitHub Pages and search-engine poisoning to rank high for queries like “Install on Mac.” The pages impersonate well-known software vendors and redirect...

Surge in Malvertising Delivers Infostealers via Fake Software Installers

Surge in Malvertising Delivers Infostealers via Fake Software Installers

News • Expert Insights Threat actors are abusing paid search ads and SEO-poisoned pages to distribute trojanized installers for popular tools (e.g., editors, media apps,...

Wave of “QR Phishing” Emails Targets Microsoft 365 Users

Wave of “QR Phishing” Emails Targets Microsoft 365 Users

News • Expert Insights Attackers embed QR codes in PNG images to evade text/URL scanning and redirect victims to credential-harvesting pages. Emails contain PNG...