Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
N0va Phishkit AiTM Campaigns Target US and EU Enterprises: Detection and Identity Hardening Guide
Introduction A new phishing kit tracked as N0va is actively targeting organizations across North America and Europe, and it represents the l...
KREMLIN Banking Malware (REF9334): Detecting and Removing Malicious Chrome and Edge Extensions Stealing Session Tokens
Introduction Elastic Security Labs has disclosed a previously undocumented Brazilian banking malware operation, tracked as REF9334, that del...
Infostealer Logs Expose Replayable AI Session Tokens: Detecting and Remediating Stolen Google, Anthropic, and LLM API Credentials
Introduction A growing volume of infostealer logs circulating on criminal marketplaces contains something defenders haven't traditionally pr...
Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack
Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack Exc...
Infostealers Targeting Claude Accounts: Session Token Theft Detection and Response Guide
Infostealers Are Harvesting Claude Sessions — Your AI Accounts Are Now Part of the Attack Surface A threat actor has been caught using multi...
The MFA Identity Trap: How Attackers Pass Authentication and What Defenders Must Detect Instead
When "Authenticated" Doesn't Mean "Trusted" A hard truth is circulating through the security community, crystallized in a recent SecurityWee...
Passkey Attacks Can Expose Synced FIDO2 Keys and Bypass Phishing-Resistant MFA: Detection and Hardening Guide
Overview Security researchers are describing a new class of attacks against passkeys that undermine two assumptions many organizations made ...