Topic: identity compromise
-
Why Attackers Now Target Cloud and SaaS First
Cybercrime in 2026 has shifted from malware and vulnerability exploitation to targeting identities and trust in cloud/SaaS environments, with a single compromised account enabling multi-layered attacks across email, SaaS, and networks. Attackers are increasingly infiltrating supply chains (e.g., ...
Read More » -
Druva Restores Access by Linking Identity Data to User Behavior
Identity-driven attacks are a major security threat, and Druva's new Identity Resilience solution provides a unified SaaS platform to protect, detect, and recover from identity compromises across providers like Okta and Microsoft. The platform uses an identity-aware methodology, modeling identiti...
Read More » -
Why Hackers Keep Exploiting the Same Security Gaps
The majority of successful breaches stem from fundamental failures in identity management, third-party access controls, and perimeter device security, with stolen credentials being a primary gateway. Attackers frequently exploit trusted tools and workflows, such as remote management software and ...
Read More » -
Ransomware Strikes Most After Hours
Attackers strategically time their most damaging actions, like ransomware encryption and data theft, for outside standard business hours when defenses are weakest, occurring in 88% and 79% of incidents respectively. Identity theft, through stolen credentials or phishing, is the primary entry poin...
Read More » -
Enterprise GenAI boosts ransomware risk: How to contain it
Generative AI amplifies existing ransomware threats by accelerating attacker operations (e.g., phishing, code writing) and introducing new risks when enterprise AI assistants and agents are compromised, expanding the attack surface. The primary risk from enterprise AI is delegated authority: comp...
Read More » -
Software Vulnerabilities Now Top Cloud Attack Vector
Software vulnerabilities have become the primary attack vector for cloud environments, surpassing compromised credentials, as attackers rapidly exploit disclosed flaws in third-party applications. Identity-based attacks remain prevalent, with voice phishing (vishing) emerging as a key tactic to m...
Read More » -
Darktrace: 32 Million Phishing Emails Targeted Identities in 2025
Identity-based cyber attacks surged in 2025, with 32 million high-confidence phishing emails detected, marking a shift from breaching defenses to credential theft as the primary threat. Identity compromise has overtaken vulnerability exploitation as the main attack entry point, with adversaries u...
Read More » -
Salesforce Trust Exploited by Cyberattackers
Salesforce environments saw a twenty-fold surge in malicious activity in Q1 2025, as cybercriminals increasingly exploit trusted business platforms for sophisticated attacks. Malicious Word documents and QR code-laden image files are common attack vectors, leveraging user trust in routine communi...
Read More » -
Top 6 Cyber Threats to Watch in 2026
The cybersecurity landscape is defined by a dangerous synergy between AI and human ingenuity, creating adaptive, automated threats that require a proactive, intelligence-driven security posture beyond traditional defenses. Key emerging threats include autonomous agentic AI exploits, weaponized de...
Read More » -
Microsoft Fights 100 Trillion AI Attacks Daily
Microsoft processes over 100 trillion security signals daily, indicating a massive surge in AI-powered cyberattacks that threaten economic stability and personal safety. AI is dual-use, enabling both advanced cyberattacks like autonomous malware and faster defenses, with identity-based attacks an...
Read More »