Brevo is a French SaaS company that provides a digital marketing and customer communication platform for businesses. It was ...
Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data.
FedEx Corp. recently announced its new premium delivery option for residential and commercial shipments. The Memphis-based ...
Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat ...
Sentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access ...
Learn how TrustSink abuses rogue Entra external authentication providers to capture passwords and why removing the provider matters after a reset.
Sentire's Threat Response Unit (TRU) has uncovered a previously undocumented device-code phishing kit, dubbed "GhostCode," that abuses Microsoft's OAuth 2.0 device authorization grant flow to hijack ...
Elastic Security Labs has uncovered a long-running malware operation that plants fake browser extensions inside Chrome and ...
Threat actors have been chaining three JFrog Artifactory vulnerabilities to gain admin privileges and deploy backdoors.
Western product designers love to build for high-end smartphones connected to uncapped home fiber. It is an easy trap to fall into when working out of offices in London or San Francisco where gigabit ...
Critical ArangoDB flaws let attackers bypass authentication, access data, and gain root-level code execution on vulnerable hosts.