Topic: identity compromise

  • Why Attackers Now Target Cloud and SaaS First

    Why Attackers Now Target Cloud and SaaS First

    Cybercrime in 2026 has shifted from malware and vulnerability exploitation to targeting identities and trust in cloud/SaaS environments, with a single compromised account enabling multi-layered attacks across email, SaaS, and networks. Attackers are increasingly infiltrating supply chains (e.g., ...

    Read More »
  • Druva Restores Access by Linking Identity Data to User Behavior

    Druva Restores Access by Linking Identity Data to User Behavior

    Identity-driven attacks are a major security threat, and Druva's new Identity Resilience solution provides a unified SaaS platform to protect, detect, and recover from identity compromises across providers like Okta and Microsoft. The platform uses an identity-aware methodology, modeling identiti...

    Read More »
  • Why Hackers Keep Exploiting the Same Security Gaps

    Why Hackers Keep Exploiting the Same Security Gaps

    The majority of successful breaches stem from fundamental failures in identity management, third-party access controls, and perimeter device security, with stolen credentials being a primary gateway. Attackers frequently exploit trusted tools and workflows, such as remote management software and ...

    Read More »
  • Ransomware Strikes Most After Hours

    Ransomware Strikes Most After Hours

    Attackers strategically time their most damaging actions, like ransomware encryption and data theft, for outside standard business hours when defenses are weakest, occurring in 88% and 79% of incidents respectively. Identity theft, through stolen credentials or phishing, is the primary entry poin...

    Read More »
  • Enterprise GenAI boosts ransomware risk: How to contain it

    Enterprise GenAI boosts ransomware risk: How to contain it

    Generative AI amplifies existing ransomware threats by accelerating attacker operations (e.g., phishing, code writing) and introducing new risks when enterprise AI assistants and agents are compromised, expanding the attack surface. The primary risk from enterprise AI is delegated authority: comp...

    Read More »
  • Software Vulnerabilities Now Top Cloud Attack Vector

    Software Vulnerabilities Now Top Cloud Attack Vector

    Software vulnerabilities have become the primary attack vector for cloud environments, surpassing compromised credentials, as attackers rapidly exploit disclosed flaws in third-party applications. Identity-based attacks remain prevalent, with voice phishing (vishing) emerging as a key tactic to m...

    Read More »
  • Darktrace: 32 Million Phishing Emails Targeted Identities in 2025

    Darktrace: 32 Million Phishing Emails Targeted Identities in 2025

    Identity-based cyber attacks surged in 2025, with 32 million high-confidence phishing emails detected, marking a shift from breaching defenses to credential theft as the primary threat. Identity compromise has overtaken vulnerability exploitation as the main attack entry point, with adversaries u...

    Read More »
  • Salesforce Trust Exploited by Cyberattackers

    Salesforce Trust Exploited by Cyberattackers

    Salesforce environments saw a twenty-fold surge in malicious activity in Q1 2025, as cybercriminals increasingly exploit trusted business platforms for sophisticated attacks. Malicious Word documents and QR code-laden image files are common attack vectors, leveraging user trust in routine communi...

    Read More »
  • Top 6 Cyber Threats to Watch in 2026

    Top 6 Cyber Threats to Watch in 2026

    The cybersecurity landscape is defined by a dangerous synergy between AI and human ingenuity, creating adaptive, automated threats that require a proactive, intelligence-driven security posture beyond traditional defenses. Key emerging threats include autonomous agentic AI exploits, weaponized de...

    Read More »
  • Microsoft Fights 100 Trillion AI Attacks Daily

    Microsoft Fights 100 Trillion AI Attacks Daily

    Microsoft processes over 100 trillion security signals daily, indicating a massive surge in AI-powered cyberattacks that threaten economic stability and personal safety. AI is dual-use, enabling both advanced cyberattacks like autonomous malware and faster defenses, with identity-based attacks an...

    Read More »