Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology, consulting, and healthcare.
What makes N0va especially relevant for SOC leaders is how it spreads the attack across different layers.
Legitimate authentication, trusted brand lures,...
Phishing remains one of the most effective ways for attackers to gain access to corporate environments. From 2013-2023, the FBI recorded 158,436 US victims of Business Email Compromise (BEC), with over $20 billion in reported losses.
The FBI specifically warns that phishing is used to...
Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States and stolen session cookies accounting for more than half of all outcomes.
A phishing-as-a-service (PhaaS) toolkit tracked as...
A trusted supplier can become an attack path overnight.
Large US and EU enterprises often rely on hundreds of vendors, giving attackers plenty of opportunities to hide malicious activity inside legitimate emails, files, and business workflows.
The window to react is...
Threat intelligence (TI) feeds are expected to close visibility gaps that inevitably emerge in enterprise SOCs and make investigations faster and more effective.
This promise sounds particularly attractive to leaders of growing SOC teams that need to face an increasing alert...
US SOC teams are dealing with a growing volume of alerts, while analyst time and security budgets remain limited.
Too much of that time is spent checking signals that turn out to be low-risk, which slows investigations and makes it easier for...
Phishing is the primary initial access vector, driving 16% of breaches at an average cost of $4.8 million. Attackers now leverage Generative AI and AiTM kits to easily bypass MFA and traditional Secure Email Gateways.
Because users click malicious links in a median of just 21...
A Formula 1 pit crew doesn't wait until every sensor, camera, and engineer agrees that a tire needs changing. They have a few seconds to make a decision using the best evidence available. Wait for perfect certainty, and the...
Destiny Stealer activity is rising across Europe and the US, putting corporate accounts, remote access, email data, and sensitive business information at risk.
A single infected endpoint can expose passwords, session cookies, VPN details, Outlook data, cryptocurrency wallets, Wi-Fi...
Security Operations Centers (SOCs) face overwhelming challenges not due to a lack of alerts but because each alert requires a new investigation.
Analysts must validate indicators, identify malicious behavior, assess the scope of threats, and determine whether to contain or...