DEAD#VAX Campaign Uses IPFS-Hosted VHD Files to Deploy AsyncRAT via Fileless Execution
Securonix researchers document a sophisticated malware campaign that chains IPFS hosting, virtual hard disk abuse, and in-memory shellcode injection to deliver AsyncRAT while evading traditional detection.
Building an Effective Security Awareness Training Program
A comprehensive guide to developing security awareness training that changes behavior, not just checks compliance boxes. Covers program design, phishing simulations, metrics, and building a security culture.
Top Security Awareness Training Platforms 2026
Ranking the leading security awareness training and human risk management platforms based on content quality, phishing simulation, behavioral analytics, and effectiveness at reducing human risk.
PDF Phishing Campaign Harvests Dropbox Credentials via Trusted Cloud Infrastructure
A phishing campaign uses clean PDF attachments hosted on Vercel to redirect victims to fake Dropbox login pages, bypassing email security by avoiding traditional malware or suspicious links.
Top Email Security Solutions for 2026
Ranking the best email security platforms based on the 2025 Forrester Wave results, AI-powered detection, and defense against phishing, BEC, and multi-channel social engineering.
Top Secure Email Gateways & Email Security Platforms for 2026
Comprehensive ranking of email security solutions covering secure email gateways, API-based protection, and AI-driven phishing and BEC defense for the modern enterprise.
Proofpoint
The leading email security and human-centric cybersecurity company, protecting organizations from phishing, business email compromise, and data loss through email, cloud, and security awareness solutions.
Abnormal Security
AI-native email security platform using behavioral AI to detect and prevent business email compromise, phishing, account takeover, and other advanced email attacks.
Email Security and Phishing Defense Guide
A comprehensive guide to protecting your organization from email-based threats including phishing, business email compromise, and malware delivery through layered technical controls and user awareness.
Microsoft Disrupts RedVDS Cybercrime Service Behind $40 Million in Fraud
Coordinated action with UK, German authorities, and Europol takes down subscription service that operated 2,600 VMs sending over 1 million phishing emails daily. Microsoft's 35th civil action against cybercrime.
Russia's Fancy Bear APT Runs Low-Cost Credential Harvesting Campaign Against Global Targets
APT28 targets energy, defense, and policy organizations in Turkey, the Balkans, and Central Asia with phishing campaigns using legitimate PDFs from real think tanks and free hosting infrastructure.
Ledger Customer Data Exposed After Third-Party Breach at Global-e
Crypto hardware wallet maker Ledger disclosed that customer names, addresses, and order data were exposed after hackers breached e-commerce partner Global-e. No wallet keys or recovery phrases were compromised.
KnowBe4
World's largest security awareness training platform providing phishing simulations, security education, and human risk management. Co-founded with Kevin Mitnick.