Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Malicious "Twitch Enhanced Viewer" Extension Leaks OAuth Tokens From 31,000 Users — Detection, Token Revocation, and Browser Hardening Guide
Introduction Nearly 31,000 Twitch users have had their OAuth access tokens silently siphoned to proxy infrastructure operated by a Russian c...
Passkey Phishing Attacks on Microsoft Entra ID: Detection and Hardening Guide for Cloud Account Takeover
Introduction Microsoft has disclosed two active campaigns that should be on every cloud defender's radar right now. The first is a high-volu...
CVE-2026-51990: Tencent Sogou Input Method Exploited to Deploy GrayRabbit Malware — Detection and Remediation Guide
Introduction Threat actors linked to a China-aligned espionage group are actively exploiting a critical vulnerability tracked as CVE-2026-51...
AI-Driven Social Engineering: How Frontier Models Manipulate Humans and How to Defend Your Organization
Introduction In a recent interview with the Dark Reading News Desk, Fred Heiding of Menlo Park Intelligence laid out research findings that ...
Weaponized Claude Artifacts and ClickFix Lures: Detecting AI Platform Abuse in Your Environment
The Trusted Platform Problem Has Reached AI Security teams have spent years conditioning users to trust well-known domains: microsoft.com, g...
Shadow AI in the Enterprise: Detecting and Governing AI Agent Alerts Flooding Your SOC
Introduction Over the past year, a new class of alert has appeared in enterprise security operations centers — and it is growing faster than...
AI-Assisted Secrets Harvesting: How Threat Groups Abused Claude to Extract Credentials from 1.8M Android Apps — Defense Playbook
AI Is Now a Force Multiplier for Secrets Harvesting — and Your Mobile Apps Are the Target Anthropic has disclosed that multiple threat group...
Anthropic Claude Weaponized by 'Generative Threat Groups': Detecting and Defending Against AI-Automated Exploitation and Data Theft
AI-Accelerated Attacks Are No Longer Theoretical Anthropic has publicly confirmed what many of us in the IR community have been seeing in ca...
The Fragmenting Fraud Ecosystem: Detection and Monitoring Strategies for a Post-Marketplace Threat Landscape
Introduction A recent analysis from Rapid7's threat research team confirms what many of us have been watching unfold on the ground: the cybe...