A 25-year-old wiki sat forgotten for years, then quietly became AI agent infrastructure: 18,000 posts in 52 days, unnoticed. Abandoned digital assets stay accessible and unmonitored while still carrying your organization’s name.
Category: Blog
No Vulnerability Was Exploited: Inside the SaaS Extortion Wave That Breaks In Through Consent, Not Code
OAuth consent phishing let a single extortion group breach 1,000+ organizations without exploiting a CVE. See how attackers weaponize legitimate consent grants — and why MFA and firewalls never see it happen.
Continuous Monitoring vs. Annual Audit: Why the TPRM Calendar Is Broken
Annual vendor audits produce a snapshot; vendor risk is a movie. See why the 364 days between formal assessments is where 48% of third-party breaches actually happen, and how continuous vendor monitoring closes that gap for DORA and NIS2 compliance.
AI Gateway Exploitation: How Attackers Are Targeting LiteLLM, RAGFlow, and Kestra to Steal Your Model Provider Keys
Three actively exploited AI orchestration platforms — LiteLLM, RAGFlow, and Kestra — are giving attackers a single entry point to every model provider credential an organization holds. See the CVE chains, IOCs, and detection rules from Brandefense’s INT-2608-e7a5 campaign analysis.
Phishing-as-a-Service 2.0: The Kits That Bypass MFA Without a Fake Login Page
Phishing-as-a-service kits like EvilTokens and Kali365 no longer need a fake login page. See how AiTM proxies and OAuth device code abuse bypass MFA, and what actually stops them.
CRA Reporting Obligations: The 24-Hour Clock Starts When You Find Out
From 11 September 2026, CRA reporting obligations require manufacturers to file an early warning within 24 hours of becoming aware that a product is being actively exploited. The regulation measures awareness, not exploitation — and for most organisations, awareness is the part that’s not ready.
CVE Volume Is Exploding, But Is Your Risk? Making Sense of 2026’s Vulnpocalypse
CVE volume in 2026 is set to double the 2023 figure, yet only about two percent of published vulnerabilities are ever confirmed exploited. See which CVEs actually mattered this year, and the four filters that replace volume-based triage.
No Patch Exists Yet: Who Owns the Pre-Disclosure Window?
Our H1 2026 analysis found that 32.1% of exploited vulnerabilities were attacked before a fix even existed. Patch velocity cannot close that window. See who should own it, and which controls actually work when there is no patch to install.
API Sprawl: The Attack Surface Nobody Put On the Inventory
API sprawl is not a documentation problem, it is a structural one. Shadow APIs, zombie APIs and inherited endpoints grow every week through normal engineering work, and only 15 percent of organisations trust their inventory. See why continuous, outside-in discovery is the only fix that keeps pace.
Device-Code Phishing Jumped 1,380%: The MFA Bypass Method Nobody’s Training Employees On
Device code phishing defeats even hardware security keys and passkeys by hijacking OAuth’s device authorization flow instead of stealing a password. It passes every awareness-training check because nothing about the login page is fake.