Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
ARToken PhaaS & EvilTokens M365 Toolkit: Detection and Defense Strategies
ARToken PhaaS & EvilTokens M365 Toolkit: Detection and Defense Strategies Introduction Security researchers have exposed a new Social Engine...
SearchLeak: Microsoft 365 Copilot Enterprise Data Exfiltration — Defense and Detection
Introduction A critical vulnerability chain, dubbed SearchLeak, has been identified in Microsoft 365 Copilot Enterprise, posing a severe ris...
UNC5221 APT: Detecting Brickstorm, Plenet, and AgentPSD in Microsoft 365
Introduction A Chinese espionage cluster tracked as UNC5221 is actively conducting targeted intrusions against Microsoft 365 environments. T...
FBI Alert: Kali365 Phishing-as-a-Service Hijacks M365 OAuth Tokens — Detection and Defense
The FBI has issued a warning regarding 'Kali365,' a sophisticated social engineering-as-a-service (SEaaS) platform specifically designed to ...
Storm-2949: Cloud-Wide Identity Breach Detection and Hardening Guide
Introduction Storm-2949 has redefined the scope of cloud intrusions, proving that a single compromised identity can serve as a master key fo...
Tycoon2FA: Microsoft 365 Device Code Phishing and Trustifi Abuse — Detection and Hardening
Introduction The Phishing-as-a-Service (PhaaS) ecosystem has evolved again with the Tycoon2FA kit, which now integrates device-code social e...