- AI Assistants Need a Different Threat Model: Why AI Security Doesn't End With Permissions
- The Intercept on the Interceptors: Inside Salt Typhoon
- The Minimum-Viable Threat Actor: AI and the New Floor for Offensive Operations
- Inside JadePuffer, the First Documented Agentic Ransomware Attack
- Attackers Have Negotiation Playbooks. Why Don’t Defenders?
- AI Phishing-as-a-Service Is a Marketing Operation
- The Gentlemen's Second Payday: Turning One Victim Against Another
- MCP’s CVE Trail Points to a Deeper SDK Problem
- One Credential, Multiple Doors: Breaking Down the Klue OAuth Breach
- Borrowing Trust From Microsoft: Breaking Down the DragonForce Teams Relay Campaign
- CISA’s New Directive Takes Aim at the CVSS Priority Queue
- Medium Severity, Maximum Impact: How Attackers Learned to Game CVSS
- A Security Tool as the Weapon: Breaking Down the FortiClient EMS Campaign
- The Psychology Behind Vishing — and Why Most Defenses Miss It
- When the Lock Is Disabled: Breaking Down the CISA GovCloud Credential Exposure
- An AI Ingredients List Assumes You Know What the Ingredients Are
- The Exploit With a Hallucinated CVSS Score: Breaking Down the First Confirmed AI-Developed Zero-Day
- The LPE AI Found and Fumbled: Breaking Down “Copy Fail” (CVE-2026-31431)
- Most Security Controls Were Built on Assumptions Agentic AI Violates
- The Attack That Started as Paperwork: Breaking Down the Freight Theft Surge