Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
OAuth Consent Abuse: Why MFA Isn't Enough — Detection and Remediation Guide for Entra ID
Introduction Multi-factor authentication has become the default answer to identity attacks — and for password-based credential theft, it rem...
Help Desk Vishing + AitM Token Theft: Defending Microsoft 365 Against Executive-Targeted Data Theft and Extortion
The Threat: Voice-Based Social Engineering Meets Token Theft Threat hunters have disclosed a widespread data theft and extortion threat clus...
Kali365 Phishing Kit Weaponizes Microsoft Authentication: AiTM Detection and Defense Guide for Microsoft 365
Kali365 Weaponizes Microsoft Authentication: What Defenders Need to Know Now The emergence of the Kali365 phishing kit marks another escalat...
Storm-2945 'CaptiveCrunch': Hotel Wi-Fi DNS Hijacking and M365 Token Theft Defense
Storm-2945 'CaptiveCrunch': Hotel Wi-Fi DNS Hijacking and M365 Token Theft Defense Introduction Since early May 2026, a sophisticated cyber-...
VS Code Zero-Day: Detecting and Blocking GitHub Token Theft via Malicious Links
Introduction A critical security vulnerability has been disclosed in Visual Studio Code (VS Code) that allows attackers to steal GitHub auth...
Grafana GitHub Token Breach: Detecting Source Code Exfiltration and Extortion Vectors
Introduction Grafana has confirmed a significant security incident involving the compromise of a GitHub access token, which allowed an unaut...