A password-spraying campaign aimed at AWS root user accounts across more than 150 organizations shows how cloud attackers keep pressing on the most privileged identity in the stack.
A sustained attempt against AWS root accounts shows how low-rate credential attacks still matter when the target is the one identity that can reach everything.
A sharp rise in automated login attempts shows how attackers can still press through identity systems when legacy authentication or incomplete MFA coverage leaves even one sign-in path exposed.
A use-case guide turns into a sharper lesson: identity security tools only work when they match the way an organization actually authenticates, escalates privilege, and moves trust around.
A two-week burst of automated sign-in attempts shows how password spraying can strain cloud defenses even when the full extent of account impact is still unclear.
A massive credential campaign against Microsoft 365 shows how distributed password spraying can turn identity controls into the real front line of cloud defense.
A ransomware listing naming Dadolighting and claiming 17 extracted email addresses shows how even limited identifier exposure can expand phishing, impersonation, and extortion risk.
A two-week wave of password spraying against Microsoft 365 shows how weak credentials and permissive sign-in controls can turn identity into the softest layer of cloud security.
A ransomware label tied to "Refinery-Hotel" is best read as an intelligence lead, while Akira's known tradecraft explains why defenders should pay attention even before any breach is confirmed.
A huge password-spray wave against Microsoft’s command-line cloud tooling shows why authentication, not code, is often the real battleground in modern cloud attacks.
A high-volume spray campaign against Azure CLI sign-ins shows how cloud attackers often hunt for weak identity settings instead of breaking software.
A federal appearance in Boston has turned a cross-border cyberespionage case into a reminder that stolen identities, not flashy malware, are often the real engine of modern intrusions.
The GRU debate is not just about attribution; it is about how state power, identity abuse, and edge-device targeting fit into a long-running cyber strategy.
Iranian cyber operatives ramp up sophisticated password-spraying campaigns targeting critical infrastructure across the Middle East, blending digital and physical conflict.
Automated attacks flood enterprise VPN gateways, exposing the persistent risks of weak credentials and cloud-hosted threats.