CISA Red Team Compromises Two Critical Infrastructure Orgs; One SOC Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
Mollema found that low-privilege processes in a compromised Windows session can use the Windows Hello for Business key without a fresh PIN…
Group-IB has discovered a new espionage implant named HollowGraph that hijacks Microsoft 365 calendars for command-and-control (C2) and data exfiltration. The malware,…
Identity lifecycle management (ILM) was architected around human principals with employment records, managers, and departure dates. AI agents have none of these,…
The red team abused Entra ID applications with elevated permissions to read the security team's email, demonstrating the risk of over-permissioned applications…