Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has unveiled NatJack, a novel attack methodology that exploits network address translation (NAT) vulnerabilities to hijack TCP sessions, manipulate DNS responses, and compromise network infrastructure. The techniques, demonstrated at Black Hat USA 2026, enable attackers to expose victim IP addresses, exhaust NAT tables, and gain unauthorized access across various
AIDevice Code Phishing Up 1,500% in 2026; Vishing Doubles
Social engineering attacks are experiencing dramatic growth, with device code phishing surging 1,500% in 2026 and vishing incidents doubling. These evolving attack techniques enable threat actors to circumvent established security controls while minimizing their digital footprint, presenting significant challenges for enterprise security teams.
AIHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have identified a sophisticated spear-phishing campaign targeting a law firm using two previously undocumented malware tools: HollowFrame, a Go-based loader framework, and Matryoshka, a Rust-based backdoor. The attack begins with a phishing email containing a link to an encrypted archive with a malicious Windows Shortcut file that initiates a multi-stage infection chain.
AI6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly escalated from a specialized red-team tactic to a widespread enterprise threat in less than six months. Originally designed for input-limited devices like smart TVs and printers, the device authorization flow has been adopted across numerous applications beyond its intended scope, crea
AIAgentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
Cybersecurity researchers at Tenet Security have identified a new attack vector called 'Agentjacking' that exploits AI coding agents to execute malicious code on developer systems. The attack leverages fake error reports through platforms like Sentry, an open-source error-tracking tool, to trick AI agents into running arbitrary code.
AIWho Runs the Ransomware Group ‘The Gentlemen?’
The Gentlemen ransomware group has become the second most active ransomware operation by victim count, attracting affiliates with an unprecedented 90/10 revenue split. Security researchers have traced the group's administrator, known as Hastalamuerte/Zeta88, to Alexander Andreevich Yapaev, a 36-year-old from Izhevsk, Russia, who also works in B2B marketing for an electrical products company. The i
AIFake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
Cybersecurity researchers have identified a large-scale malicious campaign using fake websites that impersonate legitimate open-source and freeware projects. These fraudulent sites, which rank highly on Google search results, redirect users through a Traffic Distribution System (TDS) to deliver malware including Remus Stealer, AnimateClipper, and SessionGate framework. The sites are professionally
