All posts
I used GLM 5.2 to attack my own company. It worked.
AI Threats
June 30, 20267 min read

I used GLM 5.2 to attack my own company. It worked.

China's new open-weight model just topped every leaderboard, and anyone can download it for free. So I pointed it at my own company to see what it would actually do for an attacker. The answer took about five minutes and one sentence.

Read article
How a real Intuit link ended on a fake login page
Threat Research
June 22, 20265 min read

How a real Intuit link ended on a fake login page

A remittance notice passed every check. The link pointed at intuit.com, the hover test passed, the domain looked clean. Three redirects later it ended on a page built to steal logins. Here is how the attacker borrowed Intuit's trust.

Read article
API vs. SEG: Why the Future of Email Security is API-First
Architecture
September 1, 20256 min read

API vs. SEG: Why the Future of Email Security is API-First

Secure email gateways reroute your mail flow and hope their signatures catch what's new. API-based security reads every email in place, without touching your MX records. Here's why that matters.

Read article
How Cambrient Gives MSPs Their Time Back
MSP
October 7, 20255 min read

How Cambrient Gives MSPs Their Time Back

MSP analysts spend hours triaging phishing reports, fielding 'is this safe?' tickets, and manually remediating threats across clients. Here's how agentic AI changes that equation entirely.

Read article
What Proofpoint, Mimecast, and Abnormal Miss. Two Real Phishes That Prove It
Threat Research
September 23, 20258 min read

What Proofpoint, Mimecast, and Abnormal Miss. Two Real Phishes That Prove It

We ran two real phishing campaigns through the industry's top tools. Here's exactly what they missed, why they missed it, and what an agentic agent found instead.

Read article
Newsletter

Get the latest insights.

New attacks, new research, and product updates, delivered when it matters.