Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Identity resilience in the age of advanced AI attacks
13+ hour, 22+ min ago (234+ words) Tomer Bar, Associate VP of Security Research at Semperis | Published 14 Sept 2026 GUEST OPINION: Identity Resilience: A Holistic Strategy Modern enterprises rarely operate on a single ecosystem. A resilient defence requires a clear understanding of the entire identity environment and how…...
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
22+ hour, 39+ min ago (25+ words) An engineering breakdown of AitM authentication relays, Device Code phishing, post-compromise MFA registration …...
The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines
1+ day, 7+ hour ago (129+ words) CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first…...
Solana Mobile warns users of phishing risks after Brevo breach
2+ day, 9+ hour ago (387+ words) A SAML SSO vulnerability gave attackers access to 138 customer accounts, with phishing emails reaching hundreds of thousands of crypto users Email marketing platforms are the quiet infrastructure of the internet, the unglamorous pipes that move newsletters and alerts from companies…...
The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
4+ day, 7+ hour ago (1610+ words) Our research shows how an attacker with root can spoof the Linux control group (cgroup) information the SPIRE agent uses during workload attestation. This tricks the agent into issuing a co-located workload's SVID to an attacker-controlled process. As part of…...
Defending Non-Human Identities: Why Machine Credentials Demand a New Security Playbook
4+ day, 19+ hour ago (513+ words) Modern cyberattacks no longer rely solely on stolen passwords and hijacked session cookies. As engineering workflows migrate to automated pipelines....
New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs
5+ day, 1+ hour ago (850+ words) What makes N0va especially relevant for SOC leaders is how it spreads the attack across different layers. Legitimate authentication, trusted brand lures, compromised websites, and cloud infrastructure can leave security teams with only part of the picture, making it easier to…...
Cyberattacks increasingly carried out through identity compromise
5+ day, 10+ hour ago (402+ words) An increasing number of cyberattacks are now being carried out using compromised user identities rather than through traditional system breaches. Data from Nordlo’s Security Operations Centre (SOC) shows that the number of incidents in Sweden has tripled in just eight…...
BigBear 2.0: Microsoft 365 AiTM Phishing and Session Theft
5+ day, 18+ hour ago (1471+ words) 1. Basic Information Report Title: Tracking BigBear 2.0 Evilginx2 phishing campaign Source: CloudSEK Date Published: 2026-09-07 Original Source: CloudSEK Related Source: BleepingComputer: BigBear Microsoft 365 phishing service bypassed MFA Related Source: Microsoft Learn: Authentication strengths Associated Malware / Threat Groups / CVEs / Products: BigBear 2.0, Evilginx2, BigBear affiliates, Microsoft…...
Microsoft Exposes New Phishing Attack: Hiding Within Words
6+ day, 10+ hour ago (248+ words) Microsoft specialists have identified a large-scale phishing campaign utilizing a method experts call “ASCII smuggling.” Attackers insert invisible Unicode characters into email text to confuse automated security and content filtering systems. The core of the attack lies in inserting invisible…...