Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft ...
A new analysis reveals how cybercriminals are exploiting blob URLs in email phishing attacks, generating malicious pages ...
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners ...
Once you start using generative AI within a company, there is almost always a specific set of concerns that arises.“I’m ...
Microsoft revealed updates to its bug bounty program for Dynamics 365 and Power Platform with a new structure and new awards. Researchers are eligible for bounty awards between $1,250 and $60,000.
Barracuda says device code phishing became a large-scale threat in 2026. The scam abuses the OAuth 2.0 device flow used by TVs and similar devices, an ...
A phishing campaign abuses Microsoft OAuth and Teams to redirect victims to fake login pages generated inside their browsers.
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
An agentic cybersecurity incident in July impacted OpenAI, Google, Anthropic and Meta; everyone reported it except Google.
Tech leaders warn that weak authentication, security backlogs, and slow remediation are leaving enterprises exposed as AI expands attackers’ capabilities.
In today's update of our weekly series, we'll walk you through the actively exploited bug at Cisco, updates by OpenAI and Anthropic and more.
Discover how to build a customized Microsoft document management system for your business with the workflows, security and ...