IAM / Zero Trust

The New Phishing Click: How OAuth Consent Bypasses MFA IAM / ZERO TRUST

The New Phishing Click: How OAuth Consent Bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340...

22. Mai 2026 Keine Kommentare
Agent AI is Coming. Are You Ready? IAM / ZERO TRUST

Agent AI is Coming. Are You Ready?

New Industry Data Just Released Suggests Not. On May 19th, 2026, Orchid Security released the results of our Identity Gap:...

22. Mai 2026 Keine Kommentare
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet IAM / ZERO TRUST

Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet

Modern crypto drainers don't hack wallets. They trick users into approving malicious transactions. Flare explores how the Lucifer DaaS platform...

22. Mai 2026 Keine Kommentare
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike IAM / ZERO TRUST

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in...

22. Mai 2026 Keine Kommentare
How to Reduce Phishing Exposure Before It Turns into Business Disruption IAM / ZERO TRUST

How to Reduce Phishing Exposure Before It Turns into Business Disruption

What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business...

21. Mai 2026 Keine Kommentare
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account IAM / ZERO TRUST

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the...

21. Mai 2026 Keine Kommentare
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials IAM / ZERO TRUST

Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious...

21. Mai 2026 Keine Kommentare
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer IAM / ZERO TRUST

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio...

21. Mai 2026 Keine Kommentare
The New Phishing Click: How OAuth Consent Bypasses MFA IAM / ZERO TRUST

The New Phishing Click: How OAuth Consent Bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340...

21. Mai 2026 Keine Kommentare
Agent AI is Coming. Are You Ready? IAM / ZERO TRUST

Agent AI is Coming. Are You Ready?

New Industry Data Just Released Suggests Not. On May 19th, 2026, Orchid Security released the results of our Identity Gap:...

21. Mai 2026 Keine Kommentare