Latest in Insights

Research

Infostealers Have Found a New Target: Your AI Agent

Malware operators are expanding beyond browser passwords and crypto wallets to collect access tokens, MCP configurations, prompt histories and project data stored by AI tools.

Jan Rubín's photo
Jan Rubín

10 min read

Leadership Perspectives

The Cyber Defense Window Must Include Consumers

Why consumer Cyber Safety must be a central part of the collective defense against AI-powered attacks

Howie Xu's photo
Howie Xu

6 min read

Research

The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign

Attackers posed as executives, moved conversations to WhatsApp and personal email, and forged acquisition documents to set up international wire transfers. When they targeted Gen, researchers played along, exposing a wider M&A scam.

Martin Chlumecký's photo
+1
Martin Chlumecký & 1 others

14 min read

Research

 WordlistLoader Delivering Amatera via ClearFake Campaigns

New Loader Hiding Shellcode in Plain English Words

Vojtěch Krejsa's photo
Vojtěch Krejsa

25 min read

Research

A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

A hand-written Windows backdoor stored its command-and-control domain as the number of trailing spaces in a fake desktop.ini, and we found it on exactly one machine.

Milánek's photo
Milánek

2 min read

Research

The phishing link that died on purpose

A single expired URL exposed a phishing campaign built around Mailer-Go, Cloudflare Workers and an EvilTokens OneDrive lure.

Jan Kořínek's photo
Jan Kořínek

10 min read

Reports

Threat Report H1 2026

Attackers spent the first half of 2026 abusing trust that already exists: hotel workflows, messaging sessions, browser data, developer tools, AI agents, payment habits and identity signals.

Threat Research Team's photo
Threat Research Team

1 min read

Research

Fake invoices are moving from inboxes to shopping apps

Scammers are using order-tracking apps to place fake receipts where users expect to see real purchases, then pushing them to call fake support numbers.

Luis Corrons's photo
+1
Luis Corrons & 1 others

9 min read

Research

Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections

A Technical Walkthrough of How Vidar Defeats Application-Bound Encryption

Vojtěch Krejsa's photo
Vojtěch Krejsa

13 min read

Explore Insights Topics

Research

Infostealers Have Found a New Target: Your AI Agent

Jan Rubín's photo
Jan Rubín

10 min read

Leadership Perspectives

The Cyber Defense Window Must Include Consumers

Howie Xu's photo
Howie Xu

6 min read

Research

The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign

Martin Chlumecký's photo
+1
Martin Chlumecký & 1 others

14 min read

Research

 WordlistLoader Delivering Amatera via ClearFake Campaigns

Vojtěch Krejsa's photo
Vojtěch Krejsa

25 min read

Research

A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

Milánek's photo
Milánek

2 min read

Research

The phishing link that died on purpose

Jan Kořínek's photo
Jan Kořínek

10 min read

Reports

Threat Report H1 2026

Threat Research Team's photo
Threat Research Team

1 min read

Research

Fake invoices are moving from inboxes to shopping apps

Luis Corrons's photo
+1
Luis Corrons & 1 others

9 min read

Research

Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections

Vojtěch Krejsa's photo
Vojtěch Krejsa

13 min read