Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Cisco SD-WAN Zero-Day & GitHub Actions Abuse: Supply Chain Credential Theft
Intelligence Briefing: Multi-Vector Supply Chain & Credential Theft Campaign Threat Summary Recent OTX pulses indicate a coordinated surge i...
Icarus Threat Group: Klue Supply Chain Attack & OAuth Token Theft — Detection Engineering
Threat Summary The Icarus threat group has launched a sophisticated supply chain attack targeting Klue, a market intelligence platform used ...
Icarus Supply Chain Attack via Klue: OAuth Abuse & Salesforce CRM Data Exfiltration — OTX Pulse Analysis
Threat Summary A critical supply chain attack has been identified targeting enterprise CRM environments. On June 11, 2026, the Icarus threat...
Klue-Salesforce Supply Chain Attack: Detecting and Containing Third-Party OAuth Abuse
Introduction A supply chain compromise involving Klue, a competitive intelligence platform, has resulted in unauthorized access to Salesforc...
Klue OAuth Breach: Detecting Icarus Group Salesforce Token Theft
Introduction Klue, a market intelligence platform, has confirmed a significant security incident involving the theft of OAuth tokens used to...
Anatomy of the 2026 Attack Surface: Defending Against AI Abuse, NastyC2, and OAuth Device Codes
Introduction The internet didn't break this week; it simply functioned exactly as threat actors designed it to. The latest ThreatsDay Bullet...
Supply Chain Assault & Credential Harvesting: ClickFix, LofyStealer, JINX-0164, Kali365, and Shai-Hulud Campaigns — Enterprise Detection Pack
Supply Chain Assault & Credential Harvesting: ClickFix, LofyStealer, JINX-0164, Kali365, and Shai-Hulud Campaigns Threat Summary Recent OTX ...
Vercel Breach Analysis: Third-Party AI Supply Chain Attack via Compromised Context.ai
Introduction Vercel recently disclosed a security breach stemming from a compromised third-party AI tool, Context.ai. This incident highligh...
AI-Enabled Device Code Phishing: Detecting Automated OAuth Abuse (April 2026 Campaign)
AI-Enabled Device Code Phishing: Detecting Automated OAuth Abuse On April 6, 2026, the Microsoft Security Blog published a critical analysis...