No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
Acknowledgments: Special thanks to Dave Kleinatland, Matt Kiely, Jamin Becker, Bryan Masters, Justin Allen, and Arnelle French for their contributions to this investigation. UPDATE @…
Acknowledgments: Special thanks to Dave Kleinatland, Matt Kiely, Jamin Becker, Bryan Masters, Justin Allen, and Arnelle French for their contributions to this investigation. UPDATE @…
When most people hear the word “disruption,” they think about business growth, new markets, or a competitor making a bold move. Ransomware crews have their…
We hope all of our Canadian readers had a happy Canada Day! As you settle back in from what was hopefully a relaxing day off,…
Beginning late last year, an unknown threat actor took advantage of a service offered by Meta meant to connect businesses who use Facebook or Instagram…
At 5:47 p.m. on a Friday, someone runs PowerShell in your environment. Maybe it’s a tired admin finishing one last task before signing off. But…
AI-augmented tradecraft is changing the threat landscape that defenders have operated in. For years, defenders have relied on identifying the signatures and behaviors of off-the-shelf…
Key Takeaways CISA BOD 26–04 mandates remediation of the publicly exposed, highest-risk, known-exploited vulnerabilities within 3 days. The directive applies a risk-based model evaluating exposure,…
In March 2026, our SOC caught a surge of anomalous Microsoft 365 logins across dozens of organizations simultaneously. The source: a handful of IP addresses…
Why Qualys joined the Athena coalition, and what it means for how you prioritize risk. Qualys is proud to have joined Athena, the industry coalition…
Key Takeaways Most AppSec programs treat API-layer coverage as a DAST extension, but BOLA, BFLA, and SSRF require authenticated multi-role testing that traditional scanners weren’t…
We spent three months assessing how Microsoft 365 environments actually get compromised. What we found should change how you think about identity hardening. In front…
We’ve already established that artificial intelligence is raising the bar for adversaries. This is especially the case when it comes to crafting phishing messages. These…