AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration
AI-augmented tradecraft is changing the threat landscape that defenders have operated in. For years, defenders have relied on identifying the signatures and behaviors of off-the-shelf…
AI-augmented tradecraft is changing the threat landscape that defenders have operated in. For years, defenders have relied on identifying the signatures and behaviors of off-the-shelf…
Key Takeaways CISA BOD 26–04 mandates remediation of the publicly exposed, highest-risk, known-exploited vulnerabilities within 3 days. The directive applies a risk-based model evaluating exposure,…
In March 2026, our SOC caught a surge of anomalous Microsoft 365 logins across dozens of organizations simultaneously. The source: a handful of IP addresses…
Why Qualys joined the Athena coalition, and what it means for how you prioritize risk. Qualys is proud to have joined Athena, the industry coalition…
Key Takeaways Most AppSec programs treat API-layer coverage as a DAST extension, but BOLA, BFLA, and SSRF require authenticated multi-role testing that traditional scanners weren’t…
We spent three months assessing how Microsoft 365 environments actually get compromised. What we found should change how you think about identity hardening. In front…
We’ve already established that artificial intelligence is raising the bar for adversaries. This is especially the case when it comes to crafting phishing messages. These…
Sometimes it starts with something as simple as dragging a link into your browser. Three seconds later, a cybercriminal has the tokens they need to…
Detect case variation in command execution: Hunt for mixed-case command invocations like Cmd.eXE, CmD.Exe which may indicate evasion attempts Behavioral Correlation Rules Hunt for FileZilla installation on servers…
“ Acknowledgments: Special thanks to the efforts of Michael Tigges, Anna Pham, Adam Mooney, and Samantha Shaw for their contributions to this investigation. On May…
Microsoft 365 gaps rarely announce themselves. Risk builds quietly in the background. An admin account accumulates more access than it needs. A Conditional Access policy…
For years, standard Security Awareness Training (SAT) has conditioned users to look for the same old red flags: a misspelled domain name, a sketchy sender…