-

A Domain’s History Doesn’t Tell You What It’s Doing Today
A domain can be legitimate for years. It can belong to a trusted service, have a clean reputation, and appear in security databases as safe. And then, one day, everything changes. A legitimate domain can be compromised, redirected, or abused as part of a phishing campaign. A previously trusted website can become the delivery point…
-

A Cyberattack Doesn’t Stay in IT
It is easy to think of a cyberattack as a technology problem: a compromised system, a breached server, or a locked account. But once an attack succeeds, its impact rarely stays within the IT department. A phishing attack can start with a single click by one employee. But that click can lead to disrupted operations,…
-

When MFA Isn’t Enough: The New Face of Microsoft 365 Phishing
Multi-factor authentication has made it much harder for attackers to take over corporate accounts. But phishing attacks are evolving, and attackers are finding ways to bypass the protection MFA provides. A recent FBI warning about Kali365, a phishing-as-a-service platform targeting Microsoft 365 users, highlights this shift. Attackers Don’t Always Need Your Password Traditional phishing attacks…
-

It Took Three Employees to Get Inside: The Levi Strauss Case
When a major company suffers a cyberattack, we often look for the sophisticated part of the story. Was there a zero-day vulnerability? Was ransomware involved? Did attackers exploit a complex technical weakness? Sometimes, the answer is much simpler. Levi Strauss recently disclosed a cybersecurity incident in which an unauthorized third party gained access to its…
-

The Rise of Personalized Phishing: When Every Employee Becomes a Target
For years, phishing attacks were largely based on volume. Attackers sent thousands or even millions of generic messages, hoping that a small percentage of recipients would click, respond, or share sensitive information. But the nature of phishing has changed. Today, many attacks are no longer built around reaching as many people as possible. They are…
-

Zero-Day Isn’t Just About Software
When people hear the term Zero-Day, they usually think of a newly discovered software vulnerability – one that has not yet been patched or even identified by the vendor. But the same concept exists in the world of phishing. Here too, there is a “day zero.” The moment a phishing campaign appears for the very…
-

Cybersecurity Is Moving Closer to the User
A few years ago, if you had asked where an organization’s first line of defense was, most people would have pointed to the firewall, the servers, or the corporate network. But the workplace has changed. Today, employees begin their workday in the browser. They open Microsoft 365, collaborate in Teams, join Zoom meetings, communicate through…
-

Phishing Has Left the Inbox
For years, most anti-phishing efforts focused on email. Filtering technologies improved, employees received security awareness training, and organizations invested heavily in detecting suspicious messages before they reached users’ inboxes. But while everyone was focused on email, attackers started looking for other ways to reach their targets. Today, more and more attacks begin through everyday platforms…
-

Why Do BEC Attacks Keep Increasing?
According to a recent study, 74% of organizations reported Business Email Compromise (BEC) attempts in 2025, up from 63% the previous year. In addition, 85% reported receiving messages impersonating trusted entities, while more than half encountered lookalike domains designed to mimic legitimate organizations. At first glance, these numbers seem surprising. Organizations are investing more than…