Latest in Insights

Leadership Perspectives

The Most Dangerous Part of AI Is Still Human

Why malicious use worries me more than machines acting alone

Luis Corrons's photo
Luis Corrons

• 11 min read

Research

Is Your Home Internet Feeding the AI Data Race?

Residential proxy providers sell household IP access for AI data collection, but many users do not understand what that access involves.

Luis Corrons's photo
Luis Corrons

• 9 min read

Research

Free AI, at the Price of Your Prompt

You choose a model, ask a question and get an answer. Behind that familiar exchange is a less familiar journey involving prompt logs, shifting model identities and servers whose role is never explained to users.

Vojtěch Moravec's photo
Vojtěch Moravec

• 12 min read

Research

Gray Rabbits and the Tale of a One-Click Backdoor

One click. Three critical failures. One backdoor.

Alexandru-Cristian Bardaș's photo
Alexandru-Cristian Bardaș

• 26 min read

Research

Infostealers Have Found a New Target: Your AI Agent

Malware operators are expanding beyond browser passwords and crypto wallets to collect access tokens, MCP configurations, prompt histories and project data stored by AI tools.

Jan Rubín's photo
Jan Rubín

• 10 min read

Leadership Perspectives

The Cyber Defense Window Must Include Consumers

Why consumer Cyber Safety must be a central part of the collective defense against AI-powered attacks

Howie Xu's photo
Howie Xu

• 6 min read

Research

The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign

Attackers posed as executives, moved conversations to WhatsApp and personal email, and forged acquisition documents to set up international wire transfers. When they targeted Gen, researchers played along, exposing a wider M&A scam.

Martin Chlumecký's photo
+1
Martin Chlumecký & 1 others

• 14 min read

Research

 WordlistLoader Delivering Amatera via ClearFake Campaigns

New Loader Hiding Shellcode in Plain English Words

Vojtěch Krejsa's photo
Vojtěch Krejsa

• 25 min read

Research

A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

A hand-written Windows backdoor stored its command-and-control domain as the number of trailing spaces in a fake desktop.ini, and we found it on exactly one machine.

Milánek's photo
Milánek

• 2 min read

Explore Insights Topics

Leadership Perspectives

The Most Dangerous Part of AI Is Still Human

Luis Corrons's photo
Luis Corrons

• 11 min read

Research

Is Your Home Internet Feeding the AI Data Race?

Luis Corrons's photo
Luis Corrons

• 9 min read

Research

Free AI, at the Price of Your Prompt

Vojtěch Moravec's photo
Vojtěch Moravec

• 12 min read

Research

Gray Rabbits and the Tale of a One-Click Backdoor

Alexandru-Cristian Bardaș's photo
Alexandru-Cristian Bardaș

• 26 min read

Research

Infostealers Have Found a New Target: Your AI Agent

Jan Rubín's photo
Jan Rubín

• 10 min read

Leadership Perspectives

The Cyber Defense Window Must Include Consumers

Howie Xu's photo
Howie Xu

• 6 min read

Research

The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign

Martin Chlumecký's photo
+1
Martin Chlumecký & 1 others

• 14 min read

Research

 WordlistLoader Delivering Amatera via ClearFake Campaigns

Vojtěch Krejsa's photo
Vojtěch Krejsa

• 25 min read

Research

A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

Milánek's photo
Milánek

• 2 min read