Security Insights

Latest threat analysis, industry news, and security best practices from our expert team.

Has:
device-code-phishing5 articles
Aug 22, 2026

JadeProx PlugX/TriBack Campaign, Void Blizzard Zimbra Zero-Click Espionage & Helix SharePoint Extortion: OTX Pulse Analysis — Enterprise Detection Pack

Threat Summary Three concurrent OTX pulses paint a picture of a threat landscape dominated by espionage-grade tradecraft migrating into crim...

darkwebotx-pulsedarkweb-apt
Darkweb AptRead Now
Aug 12, 2026

Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack

Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack Three concur...

darkwebotx-pulsedarkweb-apt
Darkweb AptRead Now
Aug 12, 2026

CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack

Threat Summary Two concurrent OTX pulses reveal a coordinated surge in identity-centric attacks against Microsoft 365 and enterprise cloud e...

darkwebotx-pulsedarkweb-credentials
Darkweb CredentialsRead Now
Aug 1, 2026

Defending Against Device Code Phishing: The 2026 OAuth Bypass Threat

Defending Against Device Code Phishing: The 2026 OAuth Bypass Threat Device code phishing has emerged as the fastest-growing social engineer...

sigma-rulekql-detectionthreat-hunting
Incident ResponseRead Now
May 17, 2026

Tycoon2FA: Microsoft 365 Device Code Phishing and Trustifi Abuse — Detection and Hardening

Introduction The Phishing-as-a-Service (PhaaS) ecosystem has evolved again with the Tycoon2FA kit, which now integrates device-code social e...

healthcare-cybersecurityhipaa-compliancehealthcare-ransomware
Incident ResponseRead Now