Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Threat Actors Abuse Trusted Accounts and Internal Tools to Launch Convincing BEC Attacks

Attackers are continually finding new ways to refine business email compromise (BEC) attacks, according to Douglas McKee, Director of Vulnerability Intelligence at Rapid7. When attackers compromise trusted tools and accounts, they can manipulate victims’ view of reality. One way attackers can achieve this is through what McKee calls “calendar warfare,” in which attackers use calendar meetings to trick users into falling for attacks.

The cyberattack your security team has no framework for

At the opening bell, your stock drops fifteen percent due to a data breach that never actually happened. Fake screenshots, a fake CEO statement, no actual hack. Your security team looks into it, but finds nothing because there's nothing to find. And the damage is already done. Gartner is calling disinformation attacks like this a top threat, and most companies aren’t prepared to handle it. For more insightful videos, visit ManageEngine Insights.

Supply Chain Attacks in the SaaS Era: Unpacking the Drift Breach | Cloudflare x The CISO Signal

It was just a little chat window in the corner of the screen. But behind it was a web of trusted connections reaching deep inside the enterprise. Here’s how attackers turned a trusted integration into a massive supply chain breach. Expand for more details and resources In August 2025, attackers tracked as UNC6395 compromised OAuth tokens associated with Salesloft’s Drift integration. This turned trusted connections to Salesforce environments into an attack path reaching hundreds of companies, including top-tier cybersecurity organizations.

The first 72 hours of a ransomware attack: Why restored isn't recovered

You start the day with reports that your employees cannot access critical systems. A ransom note soon explains why: attackers have encrypted them and demand $2 million in bitcoin for a decryption key. Your team contains the attack and confirms that the backups are safe, yet this is only the beginning. Restoring your servers can take weeks, but recovering the business can take much longer.

Zero-Day Attack Prevention: Catching Unknown Vulnerabilities Before Threat Actors Do

On September 1, 2026, OpenAI announced that its Astra model had reached the Critical tier for cyber capability under the company’s Preparedness Framework, a first for its systems. While working through an internal benchmark of 20 recently disclosed vulnerabilities in Google’s V8 engine, the model found two zero-days that no one had asked it to look for and used them in a working exploit chain. OpenAI is disclosing both flaws and restricting the capability to vetted testers.

PoSA v1.11: Turning Fragmented Attack Signals Into Actionable Risk

With PoSA v1.11, we focused on a practical problem: detecting more attack activity does not necessarily help fraud and security teams make better decisions. PoSA already identifies activity across digital impersonation, credential theft, attacker devices and account access. The challenge is making the connections between that activity easier to understand, identifying which users and devices require attention, and making that intelligence available to the systems and teams responsible for responding.

The New Rules of Patching: When a Fix Becomes a Blueprint for Attackers

TL;DR: Frontier AI has collapsed the vulnerability exploit window from weeks to mere hours. Attackers now use advanced AI models to reverse-engineer published fixes and generate working exploits faster than human security teams can deploy updates. In the AI era, publishing a patch creates a blueprint for attackers. Surviving this threat requires vendors to tier sensitive disclosures and customers to treat patch application speed as a critical security metric.

Phone Numbers as an Attack Surface: What SIM Swap and Data Leaks Actually Expose

The majority of security teams' work time is devoted to passive mitigation, password rotation, enabling multifactor authentication, or making authentication more complex and giving much more attention to the phone number in recovery than to other factors. Not a communication channel, but rather an identifier, as said, it's used in many aspects of tools, banking, and also e-mail, and when all thieves discover the methods of using it, that's when trouble arrives.

Kiteworks recommends server shutdown pending possible attack

On September 25, 2026, reports emerged that Kiteworks (formerly Acellion) emailed customers that law enforcement alerted them about an “imminent” cyberattack on Kiteworks systems, possibly caused by exploitation of a zero-day vulnerability. Kiteworks reportedly advised customers to shut down servers between 02:00 and 08:00 UTC on September 26, if not sooner, as a “precautionary” measure.

The water system attacks were simple. Securing OT isn't.

Recent cyberattacks against U.S. water and wastewater systems have put some familiar operational technology (OT) security problems back in the headlines. Federal agencies have warned about malicious actors targeting internet-facing programmable logic controllers (PLCs), changing device configurations, and disrupting operations at utilities across multiple states.