Social EngineeringMalwareFake CAPTCHA, Real Business: Traffic Distribution for HireAugust 4, 2026·8 min read
PhishingCloudMalicious Bing Ads Lead to Widespread Azure Tech Support ScamsFebruary 5, 2026·2 min read
MalwareCredential TheftPython NodeStealer Targets Facebook Ads Manager with New TechniquesNovember 20, 2024·5 min read
MalwareCloudGitHub Comments from Legitimate Repositories Exploited to Deliver Remcos RATOctober 21, 2024·2 min read
CloudMalwareCloud Threats Memo: Iranian Threat Actors Continue to Exploit AzureSeptember 11, 2024·3 min read
CloudMalwareCloud Threats Memo: CloudSorcerer, a Recently Discovered APT, is Exploiting Multiple Legitimate Cloud ServicesJuly 12, 2024·2 min read
CloudMalwareTwo Recent Campaigns from Brazil and Korea Exploiting Legitimate Cloud ServicesJune 13, 2024·3 min read
CloudPhishingCloud Threats Memo: Multiple Legitimate Cloud Storage Services Exploited to Target Israeli OrganizationsApril 2, 2024·3 min read
MalwarePhishingCloud Threats Memo: Google Drive Abused to Target Organizations in Asian CountriesMarch 6, 2024·2 min read
MalwareCloudCloud Threats Memo: Back to the Basics: New DarkGate Campaign Exploiting Microsoft TeamsFebruary 9, 2024·3 min read
MalwarePhishingThreat Actors Distributing Screenshotter Malware from OneDriveJanuary 26, 2024·2 min read
MalwareCredential TheftCloud Threats Memo: A Parasite Exploiting Legitimate Cloud ServicesDecember 1, 2023·3 min read
MalwareCloudCloud Threats Memo: Multiple DarkGate Loader Campaigns Exploiting Legitimate Cloud ServicesOctober 30, 2023·3 min read
PhishingCloudAmazon-themed PDF Phishing, Abusing LinkedIn and Twitter, Targets Microsoft Live Outlook UsersOctober 26, 2023·4 min read
CloudCredential TheftCloud Threats Memo: Mitigating the Risk of Third-party AppsSeptember 15, 2023·2 min read
MalwareCredential TheftNew Python NodeStealer Goes Beyond Facebook Credentials, Now Stealing All Browser Cookies and Login CredentialsSeptember 14, 2023·6 min read
PhishingCredential TheftEvasive Phishing Campaign Steals Cloud Credentials Using Cloudflare R2 and TurnstileAugust 14, 2023·5 min read
MalwareCloudCloud Threats Memo: Russian State-sponsored Threat Actors Increasingly Exploiting Legitimate Cloud ServicesAugust 4, 2023·2 min read
VulnerabilityPhishingMitigating the Latest Microsoft Teams Vulnerability with NetskopeJuly 24, 2023·3 min read
MalwarePhishingCloud Threats Memo: Another State-Sponsored Actor Exploiting DropboxJuly 17, 2023·2 min read
PhishingCredential TheftAWS Amplify Hosted Phishing Campaigns Abusing Telegram, Static FormsJuly 14, 2023·5 min read
MalwareCloudCloud Threats Memo: A Recent Campaign Exploiting Digital Trust Through GithubJune 26, 2023·3 min read
PhishingCloud.Zip and .Mov Top Level Domain Abuse: One Month After Being Made PublicJune 12, 2023·5 min read
MalwarePhishingCloud Threats Memo: Threat Actors Continue to Exploit the Flexibility of GitHub for Malicious PurposesJune 5, 2023·3 min read
CloudMalwareCloud Threats Memo: More Details on Long-Lasting Campaigns Targeting Eastern EuropeMay 19, 2023·2 min read
PhishingCredential TheftInterPlanetary File System: A Decentralized Place to Host Phishing ContentMay 16, 2023·6 min read
CloudMalwareCloud Threats Memo: North-Korean State-Sponsored Threat Actors Continue to Exploit Legitimate Cloud ServicesMay 4, 2023·3 min read
CloudMalwareCloud Threats Memo: Threat Actors Increasingly Exploiting Google DriveApril 21, 2023·3 min read
CloudEspionageNetskope Cloud Threats Memo: Cyber Espionage Campaign Abusing OneDrive and DropboxMarch 29, 2023·2 min read
MalwareEspionageCloud Threats Memo: Cyber Espionage Campaign Using Remote Access ToolsMarch 14, 2023·2 min read
MalwareEspionageCloud Threats Memo: Multiple Different Cloud Apps Abused in a Single Cyber Espionage CampaignMarch 3, 2023·3 min read
PhishingCloudCloud Threats Memo: Understanding the Growing Risk of Consent PhishingFebruary 2, 2023·3 min read
MalwareCloudCloud Threats Memo: Threat Actors Continue to Abuse Cloud Services to Deliver Malware in 2023January 19, 2023·3 min read
EspionageCloudCloud Threats Memo: State-sponsored Threat Actors Continue to Abuse Legitimate Cloud ServicesDecember 19, 2022·2 min read
MalwareCloudCloud Threats Memo: Understanding the Dead Drop Resolver TechniqueDecember 13, 2022·2 min read
MalwareCloudCloud Threats Memo: Cyber Espionage Exploiting Google Drive for C2 InfrastructureDecember 6, 2022·2 min read
MalwarePhishingCloud Threats Memo: Yet Another Cyber Espionage Campaign Exploiting Cloud ServicesNovember 30, 2022·2 min read
PhishingCloudCloud Abuse: New Technique Using Adobe Acrobat to Host PhishingNovember 16, 2022·3 min read
PhishingCloudCloud Threats Memo: Exploiting Google Forms for Phishing CampaignsNovember 3, 2022·2 min read
PhishingCredential TheftAttackers Continue to Abuse Google Sites and Microsoft Azure to Host Cryptocurrency PhishingSeptember 15, 2022·6 min read
MalwareCloudCloud Threats Memo: Lampion Exploiting WeTransfer to Deliver MalwareSeptember 13, 2022·2 min read
VulnerabilityRansomwareCloud Threats Memo: The Growing Risk of Misconfigured Internet-facing ServersAugust 18, 2022·2 min read
PhishingCredential TheftAbusing Google Sites and Microsoft Azure for Crypto PhishingAugust 9, 2022·4 min read
PhishingCloudCloud Threats Memo: Cloud Storage Services are Increasingly Exploited to Deliver MalwareAugust 2, 2022·2 min read
MalwareCloudCloud Threats Memo: Dropbox: Flexible Cloud Storage Increasingly Exploited by AttackersJuly 26, 2022·2 min read
CloudCredential TheftBreaking Down the 2022 Verizon Data Breach Investigations Report (DBIR)June 28, 2022·4 min read
Credential TheftCloudCloud Threats Memo: Analyzing the Top 10 Initial Access VectorsMay 19, 2022·3 min read
VulnerabilityCloudCloud Threats Memo: What We Can Learn From the Top 15 Routinely Exploited Threats of 2021May 5, 2022·2 min read
PhishingCredential TheftCloud Threats Memo: Protecting Yourself from Static Web App Phishing CampaignsApril 5, 2022·2 min read
MalwarePhishingOffice Documents and Cloud Apps: Perfect for Malware DeliveryMarch 22, 2022·5 min read
Credential TheftCloudCloud Threats Memo: Why Multi-Factor Authentication is a Must-HaveFebruary 10, 2022·2 min read
PhishingCloudCloud Threats Memo: New Malicious Campaign Using GitHub for Command and ControlFebruary 2, 2022·2 min read
CloudCommand and ControlCloud Threats Memo: Exploiting Legitimate Cloud Services for Command and ControlJanuary 14, 2022·2 min read
Cloud CryptoCloud Threats Memo: Hard Statistics About Poorly Secured Cloud AccountsDecember 8, 2021·2 min read
CloudCredential TheftOver-Privileged Service Accounts Create Escalation of Privileges and Lateral Movement in Google CloudDecember 2, 2021·13 min read
PhishingRansomwareCloud Threats Memo: Scary Examples of Weaponizing Google DriveNovember 18, 2021·3 min read
CloudCloud Threats Memo: Misconfigurations as a Threat Vector Continue to RiseNovember 8, 2021·2 min read
MalwareCloudCloud Threats Memo: BazarLoader Exploiting Popular Cloud ServicesOctober 25, 2021·2 min read
PhishingCloudCloud Threats Memo: Adding to the List of Exploited Cloud ServicesSeptember 28, 2021·2 min read
AuthCredential TheftWho Do You Trust? Challenges with OAuth Application IdentitySeptember 14, 2021·12 min read
CloudCloud Threats Memo: Learning From Recent Cloud Storage Misconfiguration IncidentsJuly 30, 2021·2 min read
MalwarePhishingCloud Threats Memo: Hancitor Continues Exploiting DocuSign and Google Docs TemplatesJuly 15, 2021·1 min read
MalwareCloudCloud Threats Memo: Preventing the Exploitation of Dropbox as a Command and ControlJuly 8, 2021·1 min read
PhishingCloudCloud Threats Memo: Takeaways From the Q1 2021 Phishing Activity Trend ReportJune 15, 2021·2 min read
CloudCredential TheftA Real-World Look at AWS Best Practices: Password PoliciesJune 3, 2021·5 min read
CloudCloud Threats Memo: How Contact Tracing and Personal Cloud Apps Led to a Huge PII ExposureMay 21, 2021·2 min read
CloudCredential TheftA Real-World Look at AWS Best Practices: IAM User AccountsMay 6, 2021·9 min read
CloudRansomwareCloud Threats Memo: Staggering Statistics About Recent Cloud MisconfigurationsMay 6, 2021·2 min read
CloudCloud Threats Memo: Keeping Protected Health Information Safe From Leaky AppsApril 7, 2021·1 min read
CloudCloud Threats Memo: Keeping Sensitive Data Safe From Personal InstancesMarch 24, 2021·2 min read
MalwareCloudCloud Threats Memo: Hard Times for ARM-based Mac M1 ProcessorsFebruary 23, 2021·2 min read
PhishingCloudCloud Threats Memo: Surprising Findings from Q4 2020 Phishing Trends ReportFebruary 17, 2021·2 min read
Credential TheftMalwareHere Comes TroubleGrabber: Stealing Credentials Through DiscordNovember 13, 2020·9 min read
CloudMalwareLeaky Chats: Accidental Exposure and Malware in Discord AttachmentsNovember 4, 2020·5 min read
CloudRemote AccessIt's All About Access: Remote Access Statistics for Public Cloud WorkloadsOctober 6, 2020·6 min read
MalwareCloudDangerous Docs: Surge in Cloud-delivered Malicious Office DocumentsSeptember 30, 2020·3 min read
CloudMalwareLeaky Images: Accidental Exposure and Malware in Google Photos and HangoutsSeptember 29, 2020·5 min read
CloudTracking COVID-19's Effect on Remote Working by Industry and GeographyAugust 19, 2020·3 min read
PhishingCredential TheftA Big Catch: Cloud Phishing from Google App Engine and Azure App ServiceAugust 12, 2020·4 min read
MalwareVulnerabilityTelegramRAT evades traditional defenses via the cloudDecember 18, 2017·7 min read
CryptoCloudThe modern Gold Mine Rush - Office 365 as a crypto miner’s paradiseNovember 7, 2017·5 min read
MalwareCloudNetskope Threat Research Labs analysis of ongoing cloud aware data theft attackJuly 25, 2017·4 min read
CloudVulnerabilityTargeted Attack Campaigns with Multi-Variate Malware Observed in the CloudMarch 8, 2017·6 min read
CloudMalwareVirlock’s resurgence poses bigger threat to file syncing over the cloudJanuary 30, 2017·2 min read
CloudManually Deobfuscating Strings Obfuscated in Malicious JavaScript CodeNovember 7, 2016·9 min read
CloudMalwareNitol Botnet makes a resurgence with evasive sandbox analysis techniqueOctober 14, 2016·4 min read
CloudMalwareNetskope Threat Research Labs Technical Analysis: CloudSquirrel MalwareJuly 27, 2016·8 min read
CloudMalwareZepto variant of Locky ransomware delivered via popular Cloud Storage appsJuly 19, 2016·5 min read
CloudMalwareCloudSquirrel Malware Squirrels Away Sensitive User Data Using Popular Cloud AppsJuly 15, 2016·2 min read
CloudMalwareAnatomy of a Ransomware Attack: Cerber Uses Steganography to “Hide in Plain Sight”June 30, 2016·6 min read
CloudVulnerabilitySurprise! Nine “Must-Dos” to Protect Against Malware in Remote Support AppsMarch 24, 2016·4 min read
CloudVulnerabilityManage the Android Stagefright vulnerability without getting in the way of businessAugust 5, 2015·1 min read
CloudVulnerabilityShellshock and Your Enterprise Cloud Apps – Watch Out for Half-baked PatchesSeptember 25, 2014·1 min read
CloudVulnerabilityOpenSSL ChangeCipherSpec Injection Vulnerability (CVE-2014-0224)June 6, 2014·3 min read
CloudVulnerabilityThe Tie Between Cloud App Enterprise-Readiness Score and Heartbleed Remediation: 7 Steps You Need to Take NowApril 16, 2014·3 min read