In business, calling something a dinosaur is meant to suggest it is slow, outdated and overdue for extinction. Which is unfair to dinosaurs, who enjoyed one of the most successful runs in the history of life.
![]()
In business, calling something a dinosaur is meant to suggest it is slow, outdated and overdue for extinction. Which is unfair to dinosaurs, who enjoyed one of the most successful runs in the history of life.
![]()
Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal
The lure email has been received. This is a fabricated iCloud sign-in alert designed to feel like an official security notification, complete with a fake reference number and a display link that resolves to Apple’s own domain.”
Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens dynamically, per device, in milliseconds, without the victim ever knowing a decision was made.
![]()
Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake. Just over half of this impersonation activity took place on social media platforms using fake profiles, followed by video platforms.
![]()
The recent developments surrounding vulnerabilities in major AI repositories like Hugging Face serve as a critical wake-up call for the cybersecurity community. As we accelerate toward an agentic future, the platforms we rely on for innovation are increasingly becoming the primary vectors for systemic risk.
![]()
When it comes to outbound email security, every organization operates under different operational constraints and security requirements. Some security teams prioritize in-app nudges and coaching to catch risky behavior the moment an email is drafted. Others want to avoid friction, particularly for executives, sales teams or mobile-first employees who rarely interact with desktop add-ins.
![]()
Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.
![]()
Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called “Jalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.
![]()