ReliaQuest stories
Phishing emails can still slip into Microsoft 365 mailboxes when attackers leave the SMTP envelope sender blank, ReliaQuest has found.
ReliaQuest has appointed Krish Venkataraman as Chief Financial Officer, bringing more than 20 years of technology and finance experience.
ReliaQuest says a single operator may have used a commercial AI coding agent to build malware, a console and update pipeline across 324 hosts.
Manufacturers face credential theft and engineering-data loss after a tailored Windchill web shell tied to Clop exploited CVE-2026-12569.
GreyMatter users will gain wider access to Anthropic's Claude models as ReliaQuest brings them deeper into its threat response platform.
Corporate travellers at hotels and conference centres were quietly sent to fake Microsoft 365 pages after attackers took over guest Wi-Fi gateways.
Ransomware activity stayed elevated in Q2, with 2,252 named victims and The Gentlemen overtaking Qilin to top the rankings.
Account takeovers are becoming harder to stop as attackers use real-time code theft and fake login pages to bypass Microsoft 365 MFA.
Businesses face a fresh wave of identity theft-driven extortion as Helix is linked to BlackFile and ShinyHunters through shared infrastructure.
The tactic now reaches Mac users, as attackers turn to trusted tools and social engineering to evade defences and steal credentials.
Existing phishing and fraud tactics are becoming faster, cheaper and harder to detect, raising the risk for large organisations, ReliaQuest said.
Trusted third-party access has let attackers quietly pull large volumes of Salesforce records from enterprise systems via a Klue integration.
Older, internet-facing IIS servers are being singled out by China-linked hackers, with one new cluster able to persist despite partial containment.
Patching alone has left some older SonicWall devices exposed to VPN attacks, with reliaQuest finding the first known in-the-wild use of CVE-2024-12802.
Corporate users can be compromised in under five minutes when attackers pose as help-desk staff in external Microsoft Teams chats, researchers say.
The attack kept retrying for hours after network blocks, as a scheduled task and Python proxy preserved access on the host.
Leak-site noise is making it harder for firms to tell real breaches from extortion theatre, as active sites hit 91 in the first quarter of 2026.
Senior staff are increasingly in the crosshairs as suspected former Black Basta affiliates use Teams impersonation to seize remote access.
Security teams could cut storage and response delays as ReliaQuest's new platform detects threats before telemetry is indexed or centralised.
Florida State University will expand AI cyber training and research after a USD $1.5 million gift from ReliaQuest to fund new student and faculty programmes.