
I used GLM 5.2 to attack my own company. It worked.
China's new open-weight model just topped every leaderboard, and anyone can download it for free. So I pointed it at my own company to see what it would actually do for an attacker. The answer took about five minutes and one sentence.

How a real Intuit link ended on a fake login page
A remittance notice passed every check. The link pointed at intuit.com, the hover test passed, the domain looked clean. Three redirects later it ended on a page built to steal logins. Here is how the attacker borrowed Intuit's trust.

API vs. SEG: Why the Future of Email Security is API-First
Secure email gateways reroute your mail flow and hope their signatures catch what's new. API-based security reads every email in place, without touching your MX records. Here's why that matters.

How Cambrient Gives MSPs Their Time Back
MSP analysts spend hours triaging phishing reports, fielding 'is this safe?' tickets, and manually remediating threats across clients. Here's how agentic AI changes that equation entirely.

What Proofpoint, Mimecast, and Abnormal Miss. Two Real Phishes That Prove It
We ran two real phishing campaigns through the industry's top tools. Here's exactly what they missed, why they missed it, and what an agentic agent found instead.
Get the latest insights.
New attacks, new research, and product updates, delivered when it matters.