Ransomware-as-a-Service
Affiliate operators are packaging ransomware campaigns so less-skilled attackers can launch high-impact extortion quickly.
Stat: $1.54M avg demand
Read Full BriefThreat index
A plain-language index of active cyber threats, why they matter, who they target, and which vendor categories can help reduce exposure.
Affiliate operators are packaging ransomware campaigns so less-skilled attackers can launch high-impact extortion quickly.
Stat: $1.54M avg demand
Read Full BriefEmail compromise and impersonation attacks are targeting payment approvals, invoice changes, and executive requests.
Stat: $2.9B lost in 2023 (FBI IC3)
Read Full BriefMalicious scripts are intercepting wallet approvals and draining assets from compromised sites and fake interfaces.
Stat: New JS injection targeting Web3 sites
Read Full BriefAttackers are impersonating vendors and resubmitting believable invoices to reroute payment flows.
Stat: Targeting AP departments at 50–500 employee companies
Read Full BriefAttackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.
Stat: 24B credentials available on dark web
Read Full BriefPhone number takeover still enables account resets, MFA interception, and financial fraud when carriers are socially engineered.
Stat: Mobile carriers still vulnerable
Read Full BriefModern phishing kits mirror brand experiences, proxy live sessions, and capture one-time codes in real time.
Stat: Microsoft 365 impersonation + real-time OTP bypass
Read Full BriefSynthetic voice and video are being used to impersonate executives, bypass trust checks, and trigger sensitive actions.
Stat: Voice + video cloning now used in fraud
Read Full BriefCompromised vendors, dependencies, and software update paths are allowing attackers to reach many targets at once.
Stat: 62% of breaches trace to a vendor
Read Full BriefNewly disclosed vulnerabilities are being exploited before many organizations can inventory, prioritize, and patch.
Stat: 97-day avg discovery-to-patch window
Read Full BriefOpen storage, permissive IAM, and weak environment controls remain one of the most common root causes of cloud data exposure.
Stat: #1 cause of cloud data breaches
Read Full BriefAI-generated code is accelerating delivery, but unreviewed output is also introducing authentication, data exposure, and dependency risk.
Stat: New: AI-generated code with unreviewed security gaps
Read Full BriefLLMs are enabling more targeted, more fluent, and more personalized phishing at industrial scale.
Stat: LLMs used to generate hyper-personalized attacks
Read Full BriefAI agents are being used to probe environments, enumerate weaknesses, and chain attack paths with less human direction.
Stat: AI agents that probe vulnerabilities without human direction
Read Full BriefSynthetic video is being used to reinforce business fraud, fake authority, and bypass trust-based verification.
Stat: Corporate impersonation via video call
Read Full BriefAdversaries are manipulating data inputs and training sets to skew AI outputs, trust signals, and downstream decisions.
Stat: Corrupting AI training data to manipulate outputs
Read Full Brief