Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Mantax Otax Android Malware: Detecting File Encryption, Data Theft, and Harassment Campaigns
Mantax Otax Android Malware: Detecting File Encryption, Data Theft, and Harassment Campaigns A newly reported Android malicious software str...
Shadow AI in the Enterprise: Detecting and Governing AI Agent Alerts Flooding Your SOC
Introduction Over the past year, a new class of alert has appeared in enterprise security operations centers — and it is growing faster than...
AI-Assisted Secrets Harvesting: How Threat Groups Abused Claude to Extract Credentials from 1.8M Android Apps — Defense Playbook
AI Is Now a Force Multiplier for Secrets Harvesting — and Your Mobile Apps Are the Target Anthropic has disclosed that multiple threat group...
Anthropic Claude Weaponized by 'Generative Threat Groups': Detecting and Defending Against AI-Automated Exploitation and Data Theft
AI-Accelerated Attacks Are No Longer Theoretical Anthropic has publicly confirmed what many of us in the IR community have been seeing in ca...
The Fragmenting Fraud Ecosystem: Detection and Monitoring Strategies for a Post-Marketplace Threat Landscape
Introduction A recent analysis from Rapid7's threat research team confirms what many of us have been watching unfold on the ground: the cybe...
CVE-2026-87020: Orthanc DICOM Server Heap Overflow DoS — Healthcare Detection and Remediation Guide
Why this Orthanc advisory matters now CISA ICS Medical Advisory ICSMA-26-253-02 flags a high-severity flaw in Orthanc DICOM Server < 1.13.0,...
JFrog Artifactory Chained Exploit Grants Admin Access: Detection, Hunting, and Remediation for Self-Hosted Servers
Chained JFrog Artifactory Flaws Hand Attackers the Keys to Your Build Pipeline Between August 15 and September 8, researchers at Wiz observe...
ThreatsDay Roundup: 200 Android Flaws, Malicious Browser Extensions, and 119K Scam Shops — A Defender's Playbook
This week's ThreatsDay roundup reads less like a collection of separate incidents and more like an indictment of a single defensive failure:...
Identity Attacks Drove Half of All Confirmed Intrusions in Q2 2026: Detection and Hardening Guide for the Top 4 Attack Patterns
Introduction Between May and July 2026, Prophet Security investigated every alert across its customer environments — not a sampled subset, n...