Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
JadeProx PlugX/TriBack Campaign, Void Blizzard Zimbra Zero-Click Espionage & Helix SharePoint Extortion: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Three concurrent OTX pulses paint a picture of a threat landscape dominated by espionage-grade tradecraft migrating into crim...
Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack
Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack Three concur...
CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack
Threat Summary Two concurrent OTX pulses reveal a coordinated surge in identity-centric attacks against Microsoft 365 and enterprise cloud e...
Defending Against Device Code Phishing: The 2026 OAuth Bypass Threat
Defending Against Device Code Phishing: The 2026 OAuth Bypass Threat Device code phishing has emerged as the fastest-growing social engineer...
Tycoon2FA: Microsoft 365 Device Code Phishing and Trustifi Abuse — Detection and Hardening
Introduction The Phishing-as-a-Service (PhaaS) ecosystem has evolved again with the Tycoon2FA kit, which now integrates device-code social e...