The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.
SSO Vishing And SaaS Data Theft: Domain Monitoring Before The Helpdesk Call
ShinyHunters-style SSO vishing shows how fake login domains, MFA enrollment abuse, and SaaS access can become data theft. Domain monitoring gives defenders early warning.

AI-Enabled Device Code Phishing: How OAuth Tokens Became the New Credential Theft Target
Device code phishing turns a legitimate OAuth flow into a token theft path. Learn how AI-assisted lures, Entra ID abuse, and session token replay change phishing detection in 2026.

LLMjacking Explained: How Attackers Abuse Cloud Credentials to Steal AI Compute
LLMjacking combines cloud credential theft with expensive AI workloads. Learn how attackers find exposed keys, abuse model APIs, hide compute costs, and how defenders can detect the pattern.

Non-Human Identity Security: API Keys, Service Accounts, and Workload Credentials in 2026
Non-human identities now outnumber users in most environments. Learn how API keys, service accounts, CI tokens, and workload credentials become attack paths and how to govern them.

OAuth Consent Phishing: Detecting Malicious App Grants Before Data Exfiltration
OAuth consent phishing tricks users into granting access instead of giving up passwords. Learn how malicious app grants work, which permissions matter, and how to detect abuse early.

Session Token Theft: Why Infostealers Bypass MFA and How Defenders Respond
Infostealers increasingly target browser cookies, session tokens, and refresh tokens. Learn why MFA is not enough, what token theft looks like, and how to detect replay.