Phishing & social engineering
Credential theft, business email compromise, and the human-targeted attacks that open the door for everything else.
ShinyHunters beat MFA at ReliaQuest. Device trust stopped it.
ShinyHunters vished a ReliaQuest employee and got the MFA push approved, but device-trust rules blocked the theft.
A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands
A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.
Fake IT help-desk calls are stealing Microsoft 365 and Okta data
A vishing crew posing as IT help desk on personal phones steals Microsoft 365 and Okta sessions, then renames to dodge IOC lists. Here is how to detect it.
Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA
Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.
Scattered Spider keeps winning because your help desk, not a CVE, is the way in
An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.
AI keeps inventing web addresses that do not exist. Attackers now buy them first.
Unit 42 found attackers registering the fake web domains AI models hallucinate, turning a chatbot's answer into a phishing and supply chain threat.
Hotels are running malware on a legitimate Node.js runtime, and that beats allowlisting
TonRAT runs on a genuine Node.js runtime on hotel front-desk machines, hides its C2 on the TON blockchain, and slips past allowlists. Here is what to hunt.
A rigged 7-Zip archive can erase the Windows warning on downloaded files, and there is no fix yet
A crafted RAR5 archive lets 7-Zip 26.02 strip the Mark-of-the-Web, defeating Windows SmartScreen warnings. No patch exists yet.
Signal's recovery key never expires, and Russian intelligence is now phishing for it
Russian intelligence is phishing Signal users for the Backup Recovery Key, a secret that decrypts a whole message history and that no reset or new account can
ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect
Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.