logo

Vectra AI Blog

ID: 2609a75c-8514-5187-8adf-6f21e01b7b0d

STIX ID: identity--2609a75c-8514-5187-8adf-6f21e01b7b0d

Feed Type: rss

Earliest post: 2022-09-20

Latest post: 2026-06-02

The Vectra AI Blog delivers expert insights on emerging cyber threats, attacker tactics, and AI-driven defense strategies to help security teams stay ahead of modern attacks.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Azure’s Hidden Operators: A Threat Model for Platform-Level Managed Identities by Kat Traxler2026-06-01TrueTrue
Shai-Hulud Part 2: When the Worm Forged Its Own Security Certificate by Lucie Cardiet2026-05-13TrueTrue
ShinyHunters isn’t a group. It’s a pattern. by Lucie Cardiet2026-05-06TrueTrue
Azure Logging just Changed - Your Detections May be Missing it by Alex Groyz2026-04-20TrueTrue
When the Defender Becomes the Door: BlueHammer, RedSun, and UnDefend in the Wild by Justin Howe2026-04-20TrueTrue
The rise of supply chain-driven data theft in SaaS environments by Lucie Cardiet2026-04-14TrueTrue
FortiClient EMS Zero-Day: When the Control Plane Becomes Initial Access by Lucie Cardiet2026-04-08TrueTrue
The axios Breach: A Wake-Up Call for Software Supply Chain Security by Yusri Mohd Yusop2026-04-03TrueTrue
Breaking down the axios supply chain incident by Lucie Cardiet2026-04-01TrueTrue
Detecting Sliver C2: When Advanced Beaconing Tries to Hide in Plain Sight by Lucie Cardiet2026-03-23TrueTrue
How Attackers Establish Persistence in Hybrid Environments by Lucie Cardiet2026-03-16TrueTrue
What the Stryker Incident Reveals About Handala’s Attack Playbook by Lucie Cardiet2026-03-13TrueTrue
5-Minute Hunt: Six Queries to Detect Iranian APT Activity by Lucie Cardiet2026-03-06TrueTrue
AWS Compromised by AI Agents in Minutes by Alex Groyz2026-02-10TrueTrue
Moltbook and the Illusion of “Harmless” AI-Agent Communities by Lucie Cardiet2026-02-03TrueTrue
From Clawdbot to OpenClaw: When Automation Becomes a Digital Backdoor by Lucie Cardiet2026-01-29TrueTrue
OPSEC Failures: How Threat Actor Mistakes Help Defenders by Lucie Cardiet2026-01-09TrueTrue
How Threat Actors Turned AI Into a Weapon by Mauro Paredes2026-01-05TrueTrue
CVE-2025-14847 MongoBleed in the Wild: Identifying MongoDB Exposure and Exploitation with Network Metadata by Fabien Guillot2025-12-29TrueTrue
Shai-Hulud: When a Supply-Chain Incident Turns Into a Worm by Lucie Cardiet2025-11-26TrueTrue
How Typhoon APTs Infiltrate Infrastructure Without Leaving a Trace by Lucie Cardiet2025-11-20TrueTrue
Think Your Microsoft Environment Is Resilient to Attacks? Think Again by Tiffany Nip2025-11-19TrueTrue
Operation ENDGAME and the Battle for Initial Access by Lucie Cardiet2025-11-14TrueTrue
How Attackers Gain Initial Access in Hybrid Environments by Lucie Cardiet2025-11-12TrueTrue
From Conti to Black Basta to DevMan: The Endless Ransomware Rebrand by Lucie Cardiet2025-10-17TrueTrue
Could the F5 Breach Expose a New Edge Security Gap? by Lucie Cardiet2025-10-16TrueTrue
Qilin’s 2025 Playbook, and the Security Gap it Exposes by Lucie Cardiet2025-10-15TrueTrue
Seeing Beneath the Surface: What Crimson Collective Reveals About Cloud Detection Depth by Lucie Cardiet2025-10-09TrueTrue
Cl0p Is Back, Exploiting Supply Chains Again. by Lucie Cardiet2025-10-07TrueTrue
Red Hat GitLab Breach Shows Why Consulting Data is a Goldmine for Attackers by Lucie Cardiet2025-10-03TrueTrue
When GoAnywhere Lets Attackers Go Everywhere by Lucie Cardiet2025-10-02TrueTrue
Beyond Endpoints: How BRICKSTORM Exposed Security Blind Spots by Lucie Cardiet2025-10-01TrueTrue
Scattered Lapsus$ Hunters Announce They Are Going Dark but the Threat Remains by Lucie Cardiet2025-09-17TrueTrue
LockBit is Back: What’s New in Version 5.0 by Lucie Cardiet2025-09-12TrueTrue
The Npm Exploit Is The Entry Point, What Follows Is Just As Critical. by Lucie Cardiet2025-09-11TrueTrue
How AI is Fueling Cybercrime and Why Security Gaps Are Growing by Lucie Cardiet2025-09-10TrueTrue
5-Minute Hunt: Detecting Risky Multi-Tenant Apps in Microsoft 365 by Lucie Cardiet2025-09-09TrueTrue
GLOBAL RaaS: Dissecting a Modern Ransomware Franchise by Lucie Cardiet2025-09-08TrueTrue
CISA’s August Advisory: Why You Need Post-Compromise Detection by Lucie Cardiet2025-08-28TrueTrue
New Technologies bring new risks: MCP-Powered Swarm C2 by Strahinja Janjusevic2025-08-27TrueTrue
4 Real-World Attacks That Show Why SOCs Need NDR by Lucie Cardiet2025-08-21TrueTrue
CVE-2025-53770: A 9.8/10 Critical Exploit Targeting SharePoint by Lucie Cardiet2025-07-23TrueTrue
Are Iranian APTs Already inside Your Hybrid Network? by Lucie Cardiet2025-07-10TrueTrue
Sanofi Uses Vectra to Stop Cyberattack in Real Time by Hitesh Sheth2025-06-30TrueTrue
How Black Basta Turned Public Data into a Breach Playbook by Lucie Cardiet2025-06-25TrueTrue
Play’s New Tactics Bypass Traditional Defenses. Are You Ready? by Lucie Cardiet2025-06-12TrueTrue
How attackers use Brute Ratel (BRC4) by Lucie Cardiet2025-05-14TrueTrue
Identity-Centric Attacks: The New Reality for UK Retail by Caren Havelock2025-05-06TrueTrue
How Attackers Use Shodan & FOFA by Lucie Cardiet2025-04-24TrueTrue
How Threat Actors Weaponize EV Certificates by Lucie Cardiet2025-04-01TrueTrue

1–50 of 84