Saturday, September 5, 2026
Follow on LinkedIn

Cyber Security Guide

VPN Is the Biggest Backdoor Into Your Plant — Here’s What Should Replace It on Your OT Network   

Every industrial organisation now lets someone in from the outside — OEM vendors, system integrators, remote engineers. How they get in determines whether a plant’s biggest convenience becomes its biggest breach path.  Remote Access Has Become OT’s Biggest Front Door  Operational technology (OT) environments were designed to be isolated....

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States and stolen session cookies accounting for more than half of all outcomes. A phishing-as-a-service (PhaaS) toolkit tracked as...

Trusted Vendors Are Becoming Attack Paths: How US and EU Enterprises Can Reduce the Risk 

A trusted supplier can become an attack path overnight.  Large US and EU enterprises often rely on hundreds of vendors, giving attackers plenty of opportunities to hide malicious activity inside legitimate emails, files, and business workflows.  The window to react is...

Why Threat Intelligence Feeds Often Fail to Meet SOC Expectations 

Threat intelligence (TI) feeds are expected to close visibility gaps that inevitably emerge in enterprise SOCs and make investigations faster and more effective. This promise sounds particularly attractive to leaders of growing SOC teams that need to face an increasing alert...

The Endpoint-to-Cloud Privilege Security Checklist: 21 Controls to Eliminate Standing Access 

PAM secured the endpoint; privilege moved on. Work through these 21 controls to find out where standing access is accumulating in your cloud, SaaS, and AI estate — and how to shut it down without slowing anyone.  For twenty years,...

Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge

Global malware activity climbed sharply over the past week, with remote access trojans (RATs), information stealers, and loaders all posting significant week-over-week gains, according to threat sample uploads tracked by ANY.RUN. AsyncRAT topped the chart with 211 uploads, edging out...

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections. Each kit uses a fundamentally different technical approach: Adversary-in-the-Middle (AiTM) session...

How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways 

Phishing is the primary initial access vector, driving 16% of breaches at an average cost of $4.8 million. Attackers now leverage Generative AI and AiTM kits to easily bypass MFA and traditional Secure Email Gateways.  Because users click malicious links in a median of just 21...

Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)

Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth device-code flow abuse and adversary-in-the-middle (AiTM) kits targeting Microsoft 365 identities. Cybercriminal group Storm-1747, the operator behind Tycoon2FA, logged 50...

An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response 

A Formula 1 pit crew doesn't wait until every sensor, camera, and engineer agrees that a tire needs changing. They have a few seconds to make a decision using the best evidence available. Wait for perfect certainty, and the...

Latest News

Latest News