Search

Agentic Ransomware: What Happens When Malware Doesn’t Need a Human Operator to Decide Who to Hit Next?

A documented ransomware operation completed reconnaissance, credential theft, lateral movement, and encryption with no human operator at any stage. This…

When Abandoned Digital Assets Become Someone Else’s Infrastructure

A 25-year-old wiki sat forgotten for years, then quietly became AI agent infrastructure: 18,000 posts in 52 days, unnoticed. Abandoned…

No Vulnerability Was Exploited: Inside the SaaS Extortion Wave That Breaks In Through Consent, Not Code

OAuth consent phishing let a single extortion group breach 1,000+ organizations without exploiting a CVE. See how attackers weaponize legitimate…

Continuous Monitoring vs. Annual Audit: Why the TPRM Calendar Is Broken

Annual vendor audits produce a snapshot; vendor risk is a movie. See why the 364 days between formal assessments is…

AI Gateway Exploitation: How Attackers Are Targeting LiteLLM, RAGFlow, and Kestra to Steal Your Model Provider Keys

Three actively exploited AI orchestration platforms — LiteLLM, RAGFlow, and Kestra — are giving attackers a single entry point to…

Phishing-as-a-Service 2.0: The Kits That Bypass MFA Without a Fake Login Page

Phishing-as-a-service kits like EvilTokens and Kali365 no longer need a fake login page. See how AiTM proxies and OAuth device…

CRA Reporting Obligations: The 24-Hour Clock Starts When You Find Out

From 11 September 2026, CRA reporting obligations require manufacturers to file an early warning within 24 hours of becoming aware…

CVE Volume Is Exploding, But Is Your Risk? Making Sense of 2026’s Vulnpocalypse

CVE volume in 2026 is set to double the 2023 figure, yet only about two percent of published vulnerabilities are…

No Patch Exists Yet: Who Owns the Pre-Disclosure Window?

Our H1 2026 analysis found that 32.1% of exploited vulnerabilities were attacked before a fix even existed. Patch velocity cannot…