top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Fake Hires Are Getting Corporate Credentials Before Companies Detect Them
Fraudulent job candidates are slipping through remote hiring systems and gaining legitimate access to corporate networks, exposing a growing identity security gap that conventional screening tools are failing to close. New research from HYPR found that 98% of surveyed HR executives have encountered candidate fraud. Yet 68% of fraudulent hires were ultimately exposed through human observation or intuition, rather than automated security controls. The findings suggest generativ
Sep 16


AI Agents Emerge as the Top Insider Security Risk for Enterprises
AI agents are quickly gaining access to sensitive corporate systems, and security leaders increasingly see that autonomy as a bigger threat than traditional hackers or malicious employees. New research from Exabeam found that 48% of security leaders consider AI agents operating with excessive, compromised, or unintended access their organization’s greatest current threat. By comparison, 28% selected external attackers, while compromised and malicious insiders each received 12
Sep 16


CISA Warns of 17 Active Directory Attack Techniques as AI Expands Identity Risk
The US Cybersecurity and Infrastructure Security Agency and five international cybersecurity agencies have released new guidance on securing Microsoft Active Directory, detailing 17 techniques attackers commonly use to compromise enterprise identity systems. The threat list includes Kerberoasting, AS-REP Roasting, password spraying, DCSync, Golden Ticket attacks, certificate abuse and the exploitation of insecure delegation settings. None of these techniques is particularly n
Sep 16


GhostCode Phishing Kit Targets Microsoft Accounts Through OAuth Device Codes
A new phishing campaign is exploiting Microsoft’s device authentication process to hijack accounts, giving attackers a way to bypass traditional multifactor authentication protections. Researchers at eSentire have named the phishing kit “GhostCode.” The campaign begins when attackers submit messages through corporate website contact forms while impersonating procurement representatives from legitimate organizations. These messages are designed to establish trust and steer emp
Sep 16


Authentication Has a Session Trust Problem
This guest article was contributed by Alastair Parr, CTO at Spur Organizations have made significant progress in strengthening authentication and securing workforce and customer access. Identity verification, multifactor authentication, device intelligence, behavioral analytics, fraud scoring, bot management, and conditional access policies have all made it harder for attackers to gain access using stolen credentials alone. Identity remains a valuable target, though, and atta
Sep 13


ShieldCrash Exploit Reportedly Bypasses Microsoft’s Windows Defender ShieldBreak Fix
A newly released proof-of-concept exploit suggests Microsoft’s September 2026 security update may not have fully resolved ShieldBreak, a Windows Defender vulnerability that can allow attackers to access sensitive files with SYSTEM privileges. Security researcher Nightmare Eclipse published the new exploit, called ShieldCrash, on GitHub only days after Microsoft issued its ShieldBreak fix. According to the researcher, the proof of concept can read arbitrary files with the high
Sep 13
bottom of page