A documented ransomware operation completed reconnaissance, credential theft, lateral movement, and encryption with no human operator at any stage. This…
A 25-year-old wiki sat forgotten for years, then quietly became AI agent infrastructure: 18,000 posts in 52 days, unnoticed. Abandoned…
OAuth consent phishing let a single extortion group breach 1,000+ organizations without exploiting a CVE. See how attackers weaponize legitimate…
Annual vendor audits produce a snapshot; vendor risk is a movie. See why the 364 days between formal assessments is…
Three actively exploited AI orchestration platforms — LiteLLM, RAGFlow, and Kestra — are giving attackers a single entry point to…
Phishing-as-a-service kits like EvilTokens and Kali365 no longer need a fake login page. See how AiTM proxies and OAuth device…
From 11 September 2026, CRA reporting obligations require manufacturers to file an early warning within 24 hours of becoming aware…
CVE volume in 2026 is set to double the 2023 figure, yet only about two percent of published vulnerabilities are…
Our H1 2026 analysis found that 32.1% of exploited vulnerabilities were attacked before a fix even existed. Patch velocity cannot…
Take control of your digital security with an exclusive demo of our powerful threat management platform.