Cloud SecurityFancy Bear attacks abuse Office macros, legitimate cloud servicesLaura FrenchSeptember 17, 2025The Russia-backed campaign uses the Covenant framework and BeardShell backdoor.
Attack surface managementWhy proximity-based threats are the weakest link in enterprise securityShmulik YehezkelSeptember 16, 2025Proximity-based threats turn physical presence into digital compromise, exposing the weakest link in security.
IdentityVoidProxy phishing operation targets Microsoft 365, Google accountsSteve ZurierSeptember 16, 2025The new PhaaS uses adversary-in-the-middle techniques to steal credentials, MFA codes, and session tokens.
Network SecurityMalicious Exchange inbox rules hidden with ‘Inboxfuscation’ techniqueLaura FrenchSeptember 12, 2025The method, developed by Permiso, hides suspicious keywords with Unicode.
Vulnerability ManagementDELMIA Apriso flaw added to CISA list of exploited vulnerabilitiesSteve ZurierSeptember 12, 2025DELMIA Apriso software is heavily used on manufacturing shop floors.
Critical Infrastructure SecurityCISA flags critical flaws in Rockwell Automation, ABB productsSteve ZurierSeptember 11, 2025Experts say OT teams and CISOs must prioritize patching the ICS flaws right away.
IdentityFour lessons from the Salesloft OAuth hackDanny Brickman September 11, 2025Here’s why teams have to refine their defenses for non-human identities, or face the consequences.