Search

Phishing-as-a-Service 2.0: The Kits That Bypass MFA Without a Fake Login Page

Phishing-as-a-service kits like EvilTokens and Kali365 no longer need a fake login page. See how AiTM proxies and OAuth device…

CRA Reporting Obligations: The 24-Hour Clock Starts When You Find Out

From 11 September 2026, CRA reporting obligations require manufacturers to file an early warning within 24 hours of becoming aware…

CVE Volume Is Exploding, But Is Your Risk? Making Sense of 2026’s Vulnpocalypse

CVE volume in 2026 is set to double the 2023 figure, yet only about two percent of published vulnerabilities are…

No Patch Exists Yet: Who Owns the Pre-Disclosure Window?

Our H1 2026 analysis found that 32.1% of exploited vulnerabilities were attacked before a fix even existed. Patch velocity cannot…

API Sprawl: The Attack Surface Nobody Put On the Inventory

API sprawl is not a documentation problem, it is a structural one. Shadow APIs, zombie APIs and inherited endpoints grow…

Device-Code Phishing Jumped 1,380%: The MFA Bypass Method Nobody’s Training Employees On

Device code phishing defeats even hardware security keys and passkeys by hijacking OAuth's device authorization flow instead of stealing a…

The Board Meeting That Never Happened: Deepfake Video Calls and the New Wire Fraud

A finance employee joined a video call with his CFO and colleagues — every face was synthetic. The deepfake video…

One Vendor, Eleven Crises: Why Your TPRM Program Has a People Data Blind Spot

A single HR assessment vendor breach exposed psychometric profiles and interview recordings for executives across eleven organizations. See why people…

146 Active Groups and Counting: Why Ransomware Fragmentation Makes Attribution Harder Than Ever

The ransomware ecosystem has fragmented past the point where group-based playbooks work: 146 active groups, 61 new since April 2025,…