Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
One Click Away from Account Compromise: What a Recent Microsoft 365 Phishing Campaign Teaches Us
10+ hour, 40+ min ago (352+ words) Phishing is still one of the simplest ways to target an employee. A message does not always look …...
From Domain Admin to Enterprise Admin: How Weak LDAP Signing Enabled Forest-Level Privilege…
12+ hour, 18+ min ago (614+ words) From Domain Admin to Enterprise Admin: How Weak LDAP Signing Enabled Forest-Level Privilege Escalation Introduction Active Directory privilege escalation is rarely caused by a single vulnerability …...
Passwords Have Worked for Decades. So Why Is the whole industry switching to passkeys?
17+ hour, 54+ min ago (546+ words) Passwords have been protecting our accounts for decades. We all know how they work: Enter your username → enter your password → you’re logged in. So why is the tech industry now moving toward passkeys? The answer isn’t that passwords suddenly stopped…...
Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
2+ day, 18+ hour ago (707+ words) Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single…...
Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
2+ day, 22+ hour ago (444+ words) Microsoft Security Research said it has observed the cloud-focused intrusions since May 2026. The campaign begins with a phone call or SMS sent to an employee’s personal device. Posing as IT support, the caller claims the target must urgently update a…...
Passkey Phishing Hijacks Microsoft 365 Accounts for Cloud Data Theft
2+ day, 23+ hour ago (417+ words) The activity, observed since May 2026, relies heavily on social engineering. Victims may receive a phone call, SMS message, or Microsoft Teams message from someone impersonating the organization’s IT helpdesk. The attacker claims that the user must urgently update a passkey,…...
Cybersecurity: Why Legacy Telnet and Zero Trust Flaws Persist
2+ day, 20+ hour ago (605+ words) Any strategy, regulatory framework, or management system is going to tell us how important encryption is, and it will require us to implement it, whether in transit or at rest. But the most relevant factor is how basic this control…...
The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
2+ day, 21+ hour ago (1610+ words) Our research shows how an attacker with root can spoof the Linux control group (cgroup) information the SPIRE agent uses during workload attestation. This tricks the agent into issuing a co-located workload's SVID to an attacker-controlled process. As part of…...
VPN Infrastructure Is Now the Authentication Gap’s Final Frontier
2+ day, 22+ hour ago (66+ words) Previdian recorded 10 exploitation attempts from six attacker IPs within 24 hours of a public PoC release. The 15-day patch-to-exploitation window shows threat actors weaponizing Citrix disclosures faster than enterprises can deploy fixes. Heath Callahan Trust, Identity & Security All stories by Heath…...
Citrix NetScaler Authentication Bypass Under Active Exploitation – VPN Infrastructure Joins the Authentication Gap
3+ day, 7+ hour ago (66+ words) Previdian recorded 10 exploitation attempts from six attacker IPs within 24 hours of a public PoC release. The 15-day patch-to-exploitation window shows threat actors weaponizing Citrix disclosures faster than enterprises can deploy fixes. Heath Callahan Trust, Identity & Security All stories by Heath…...