July 24, 2026

Email threat landscape: Q2 2026 trends and insights

In this article Tycoon2FA Q2 disruption impact QR code phishing attacks CAPTCHA-gated phishing tactics Malicious payloads Business email compromise Microsoft Teams threats Notable phishing campaigns Mitigation […]
July 17, 2026

ACR Stealer: Two observed intrusion chains amid increased threat activity

In this article Campaign 1: WebDAV-based ClickFix with Python loaders and blockchain C2 Campaign 2: MSHTA-initiated PowerShell chain with steganographic payload delivery Mitigation and protection guidance […]
July 16, 2026

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

In this article Attack chain overview How the attack started: GitHub Actions pwn request Mitigation and protection guidance Learn more On July 14, 2026, Microsoft Threat […]
July 14, 2026

Defending SaaS-based applications against ShinyHunters OAuth abuse

In this article Attack chain overview Improving visibility into Salesforce OAuth abuse Mitigation and protection guidance Learn more In a series of campaigns observed between mid-2025 […]