Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.” OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.

Survey: Companies Cite Phishing as their Top AI-Enabled Fraud Concern

A recent survey from Experian found that 60% of companies report fraud losses that are “somewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern. “Businesses identify AI-generated phishing as the most common AI-enabled fraud risk at 53%,” the report says.

13 essential cybersecurity frameworks, standards, and regulations explained

Security teams rarely work from a single rulebook. They may use the NIST Cybersecurity Framework to organize the program, ISO/IEC 27001 to build a formal management system, SOC 2 reports to assess vendors, and laws such as HIPAA, GDPR, DORA, or NIS2 to meet legal obligations. Those names are often grouped together, even though they serve different purposes. Some provide guidance. Some can be certified or independently assessed. Others are contractual requirements, laws, or mandatory sector standards.

Why Buy a Mobile AppSec Platform Instead of Building With AI?

AI has lowered the cost of building mobile security tooling to near zero. However, it has not lowered the cost of operating it. Building a scanner is now a weekend project, while sustaining detection accuracy, threat research, real-device infrastructure, and developer trust across years remains a full organizational commitment. That distinction is the entire build-versus-buy question in 2026, and most evaluations get it wrong by measuring the wrong thing.

When the fuzzers come knocking on port 389: Hunting injection canaries in LDAP

It's easy to think of core infrastructure protocols like LDAP, Kerberos, DNS, SMB, and NTP as furniture. They're so old, so ubiquitous, and normally so quietly reliable that we almost stop seeing them. However, history teaches us that Infrastructure protocols can and do have serious vulnerabilities. They say when you kick a rock over, dozens of bugs crawl out from under it. In this vein, this blog delves into how I went looking for one security issue and uncovered 6 other ones.

Why do I need a cloud risk assessment?

Your business almost certainly runs on cloud services. From document storage, email and finance software to your customer data and internal systems, the chances are that most of what keeps your business operational lives, at least in part, in the cloud. And yet, for many businesses, the question of whether that cloud environment is secure rarely gets asked. It tends to be presumed. After all, you’ve got bigger things to worry about. You’re with a reputable provider.

Dark Web Monitoring Vendors Compared

According to the 2026 Context Gap research, 79% of organizations first learn about active threats from outsiders rather than their own tooling. You've watched another headline roll past of a Fortune 500 company exposed on the dark web. Each story ends the same way: with a breach notification and inevitable board questions. You decide your company won't be the next case study. You need a tool that'll find your exposures before an attacker does.

How to Improve AI Search Visibility Without Exposing Sensitive Data

AI search visibility creates a useful tension for security and marketing teams. A company wants its expertise, products, and evidence to be easy for search engines and AI systems to find. At the same time, it cannot afford to expose customer data, internal documents, credentials, or operational details simply to make its content more "machine readable." The right goal is not maximum crawlability. It is controlled public visibility: publish enough reliable information for a search system to understand and cite the company while keeping private information behind real access controls.

LinkedIn to CRM Extensions: A Security Checklist (2026)

Browser extensions that copy LinkedIn profiles and conversations into a CRM are now standard in most sales teams. They are useful, and they are also a data security decision that usually never reaches the security team. Each one runs inside the rep's authenticated browser session, reads personal data from LinkedIn, and moves it into a second system under the rep's own credentials. This article sets out the questions a security or IT function should ask before allowing one, and how the common tools answer them.

Beyond the Login Screen: Why Qualified Electronic Signatures Belong in Identity Security

For years, identity security was mostly discussed as an access problem. Can the right person log in? Is multi-factor authentication enabled? Are privileged accounts protected? Can stolen credentials be used from an unknown device? Those questions still matter. But they describe only the beginning of a digital transaction.

What is a backdoor attack?

A backdoor attack is hard to detect. Since they bypass standard security measures, backdoor attacks can enter your system and go unnoticed for a long time. While some cyberattacks tend to be smash-and-grab, backdoor attacks are stealthier. They allow hackers to enter secretly, gather more secure data than typical attacks, and can cause significant damage. Because they can be so difficult to detect and cause so much damage, you need to know the signs of a backdoor attack and learn how to mitigate it.