OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The…
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The…
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open…
Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against…
A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered “HollowByte,” a Denial of…
The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 –…
Ravie LakshmananJul 17, 2026Social Engineering / Malware North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image…
Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network Pierluigi Paganini July 18, 2026 Researchers found China’s Daxin rootkit and a new Stupig backdoor…
The limits of a detection-first model When we gather for industry forums like the RSAC Conference, the topics include automation, AI-driven response and operational resilience.…
At Wiz, our vision for cloud security has always been a unified, collaborative platform that empowers teams across the organization. That’s why we’re excited about…
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.…
A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the…
Hours of San Francisco Police Department drone video footage exposed on the open web illustrates a new era of incredibly granular—and consequential—urban surveillance. Meanwhile, the…