Latest Briefings
Azure CLI Password Spray Campaign Hits 78+ Microsoft Accounts in 81M Attempts
A large-scale, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 accounts across a two-week window, researchers at Huntress…
Google Patches 382 Vulnerabilities in Chrome 151, 15 Rated Critical
The Chrome 151 release addresses a record-setting batch of security flaws, with 358 of them discovered internally, likely aided by AI-assisted vulnerability…
81 Million Login Attempts Hit Azure CLI in Massive Password Spray Campaign
Huntress tracked over 81 million credential spray attempts against Microsoft 365 environments between June 12 and 21, with attackers abusing the OAuth…
Apple Patches 37 Flaws in iOS, macOS, and Safari, 26 in WebKit Alone
Apple's latest round of security updates addresses dozens of vulnerabilities across its platform, with the majority concentrated in WebKit and exploitable through…
Amazon Fined $2.25M for Blocking Identity Theft Victims’ Transaction Records
The FTC says Amazon repeatedly denied fraud victims and law enforcement access to transaction records required by federal law, citing bogus privacy…
Six Questions to Pressure-Test Vendor Claims Around Frontier AI
As security vendors race to tout Frontier AI capabilities, enterprises need a sharper framework for separating genuine investment from marketing noise. A…
ARToken: Inside the EvilTokens Affiliate Panel Targeting Microsoft 365
Cisco Talos has dissected ARToken, a phishing-as-a-service panel linked to EvilTokens that abuses Microsoft OAuth device code flows to bypass MFA and…
Hardening AI-Generated Code Before It Ships
AI can write code faster than most humans can review it. This guide gives you a practical checklist for auditing, testing, and…
Fake Perplexity AI Extension Intercepted Search Queries via Chrome Web Store
A malicious Chrome extension impersonating Perplexity AI quietly rerouted all browser search queries through attacker-controlled infrastructure, Microsoft Threat Intelligence researchers found.
Langflow RCE Flaw Exploited to Drop Monero Miner on AI Endpoints
Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero cryptocurrency mining malware on exposed AI…
Poisoned MCP Tool Descriptions Can Turn AI Agents Into Data Exfiltration Tools
New Microsoft research demonstrates how attackers can manipulate AI agents into leaking sensitive company data by embedding malicious instructions inside tool descriptions,…
CIA Director Ratcliffe Outlines Aggressive Tech Overhaul at AWS Summit
CIA Director John Ratcliffe described sweeping organizational and procurement changes at the agency, framing frontier AI as a strategic imperative comparable in…