BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
On July 24, 2026, researchers H0j3n and Aniq Fakhrul published a working exploit for a Microsoft Active Directory Certificate Services (AD CS)…
Most organizations focus on protecting Non-Human Identities (NHIs) from theft, but a more insidious threat is emerging: fabricated machine identities. Unlike stolen…
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on July…
Proofpoint has uncovered a novel evasion technique called OAuth client ID spoofing, exploited by at least two threat actors to validate stolen…
Microsoft Entra ID is a cloud-based identity and access management service. The article describes a blind spot in its sign-in telemetry that…
A sophisticated threat actor tracked as O-UNC-066 by Okta is targeting organizations across multiple sectors with a voice-based phishing (vishing) scheme that…
New research from Carnegie Mellon University PhD student Jacob Ginesin, also a cryptographic auditor at Cure53, reveals that GitHub's 'Verified' commit badge…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
Orchid Security is a company that identifies 'identity dark matter'—the mass of identity activity invisible to traditional governance tools. It is referenced…