Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Help Desk Vishing + AitM Token Theft: Defending Microsoft 365 Against Executive-Targeted Data Theft and Extortion
The Threat: Voice-Based Social Engineering Meets Token Theft Threat hunters have disclosed a widespread data theft and extortion threat clus...
UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack
UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack Threat Summary Live OTX pulse dat...
Token Research Exposes 39 Passkey Attack Methods: A Defender's Guide to Hardening FIDO2 Deployments
Introduction Passkeys were supposed to end the phishing era. For credential replay and password theft, they largely have — FIDO2's origin-bo...
Knight Office AiTM Phishing Kit: M365 Session Token Theft Campaign — OTX Pulse Analysis & Detection Pack
Threat Summary A single but high-fidelity OTX pulse from AlienVault (TLP:WHITE, modified 2026-09-02) details Knight Office, a newly document...
Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack
Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack Exc...
Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack
Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack Two live OTX pulses ...
Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack
Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack Threat Summary The five pulses describe one...
NovaCookies AitM Phishing Kit Abuses DocuSign to Steal Microsoft 365 Sessions — Detection and Hardening Guide
Introduction Security researchers at Island have disclosed a new subscription-based adversary-in-the-middle (AitM) social engineering toolki...
The MFA Identity Trap: How Attackers Pass Authentication and What Defenders Must Detect Instead
When "Authenticated" Doesn't Mean "Trusted" A hard truth is circulating through the security community, crystallized in a recent SecurityWee...