Passkey Lures, Stolen Sessions, and the Microsoft 365 Data Trail
Microsoft describes intrusions that start with fake passkey support calls and continue through new MFA methods, Graph reconnaissance, and cloud data access.
In-depth red team tactics, blue team strategy — and privacy-first security tools that run entirely in your browser. No accounts. No telemetry. No data leaves your machine.
Microsoft describes intrusions that start with fake passkey support calls and continue through new MFA methods, Graph reconnaissance, and cloud data access.
An actively exploited VeloCloud Orchestrator flaw needs no admin login. Check certificate-based exposure, fixed releases, and evidence of compromise.
Researchers demonstrated five ways a malicious extension could cross into browser AI features. The impact varies by product, but extension governance is the shared control.
Picus Labs found evasion, persistence and command-and-control techniques in eight of its 2026 top ten malware behaviors. What defenders can take from the data.
How attackers turn GitHub Actions' shared build cache into a supply chain weapon — real cases, attack mechanics, detection logic, and mitigations.
GitHub says an employee device was compromised through a poisoned third-party VS Code extension and internal repositories were exfiltrated. Here is the fact-checked breakdown for defenders.
A pre-authentication SQL injection in Roundcube's virtuser_query plugin has been reported in active use. Check whether your installation is exposed, update it, and investigate suspicious activity.