buildOne report1 publisher Just 474 of the 1,000 most popular websites set DMARC to reject spoofed mail, a dev.to survey of their DNS found. Thirty-two months after Google and Yahoo began requiring DMARC from bulk senders, 84.5% of the sites publish a record, but only 69.4% apply an enforcing policy to all their mail.
Reality
- Evidence62
- Adoption68
- Hype gap0
- Incentives
- Insufficient
- Confidence60
Yubico and Okta's survey of 1,890 tech and security professionals found 23% work where multifactor login is not required on every application. With 88% still rating their company secure, at least one respondent in nine gave both answers.
Reality
- Evidence45
- Adoption55
- Hype gap+15
- Incentives75
- Confidence50
Proofpoint says China-aligned TA419 has posed as a former White House official and an Anthropic employee to phish AI policy experts since at least April 2025. The first approach asks for nothing; the credential-stealing link follows only after a target replies.
Perspective Coverage
7 publishers
- Builder
- Builder 28%
- Operator
- Operator 59%
- Investor
- Investor 13%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
buildOne report1 publisher Proofpoint says China-aligned TA419 has phished US AI policy experts since April 2025 with a proxy that captures Microsoft session cookies and bypasses MFA. Its fix is passkeys plus out-of-band checks on unsolicited expert outreach.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Microsoft says Star Blizzard has sent fake event invitations to more than 100 organizations since January, many from hacked WordPress and cPanel sites. The group, long known for stealing email passwords, now uses the messages to install a Windows backdoor.
Perspective Coverage
8 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence66
- Adoption35
- Hype gap+18
- Incentives35
- Confidence70
Proofpoint says China-aligned TA419 posed as two former US officials and an Anthropic employee to phish AI policy experts' Microsoft accounts. Two recipients flagged the Parker emails by checking with her through another channel, a habit teams fielding advisory requests can adopt.
Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 53%
- Investor
- Investor 27%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
buildOne report1 publisher Microsoft says Russia's FSB-linked Star Blizzard sent fake event invitations to more than 100 organizations since January 2026. The lures pose as Chatham House and Atlantic Council events and carry a new Python backdoor, CosmicPulse, aimed at people working on Ukraine.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence62
buildOne report1 publisher Microsoft's record September release fixed up to 997 CVEs, including two local escalations to SYSTEM that attackers used before the patch shipped. A 7.8 score understates the step that turns a phishing foothold into control of the machine, so both go ahead of the 9.8 remote flaws.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence42
Recorded Future says filtering, verification and training still blunt most AI phishing, with deepfaked voice and video the exception. Its advice is to stop treating a familiar face or voice on a call as proof of identity.
Reality
- Evidence45
- Adoption40
- Hype gap0
- Incentives45
- Confidence50
Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives
- Insufficient
- Confidence60
Proofpoint says at least four China-linked espionage groups fired the same BlueMoon code at different victims during the four weeks a Chromium fix took to reach stable Chrome, and two more groups probably did too.
Perspective Coverage
9 publishers
- Builder
- Builder 31%
- Operator
- Operator 60%
- Investor
- Investor 9%
Reality
- Evidence80
- Adoption30
- Hype gap+10
- Incentives40
- Confidence76
Volexity attributes September 1 spear-phishing at multiple NGOs to the Chinese cluster UTA0560. The chain used two Chrome flaws and one in Windows ALPC, and a second China-nexus actor ran the same chain.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence62
LastPass traced a fake Authenticator hosted on GitHub to a months-long impersonation campaign that spoofed at least 40 organizations, including its own brand. The server steering victims to the download was still being updated in September.
Perspective Coverage
4 publishers
- Builder
- Builder 27%
- Operator
- Operator 64%
- Investor
- Investor 9%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence70
Proofpoint says an unknown actor sprayed over 5,700 M365 accounts in Chile and breached only seven, all dormant service accounts at one retailer. Employee logins held, and those seven unused accounts still gave the attacker mail, Teams chats, OneDrive files and, in one case, the Azure portal.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence50
Have I Been Squatted found Corp MDM, a small Android implant that takes newly arriving SMS and switches on call forwarding, sharing one hard-coded address with the credential phishing and Windows malware aimed at the same sector.
Publishers:haveibeensquatted.com · thehackernews.com Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence66
Rapid7's research with Zimbra turned up more than 50 vulnerabilities, several of which let an attacker send mail as another user with no password involved. The operational item today is CVE-2026-73570, the SNMP command injection CISA gave federal agencies three days to fix.
Reality
- Evidence55
- Adoption60
- Hype gap+25
- Incentives78
- Confidence55
Proofpoint tracked three waves of TeamFiltration password spraying against Microsoft 365 tenants in Chile between July 21 and August 16. The seven accounts that opened were all functional identities carrying provisioned passwords with no MFA.
Reality
- Evidence50
- Adoption60
- Hype gap+10
- Incentives65
- Confidence55
Writing for the Forbes Technology Council, Proofpoint's Sumit uses three incidents since 2023 to argue that access control answers whether an action is allowed while agents need a check on whether it should happen at all.
Reality
- Evidence24
- Adoption
- Insufficient
- Hype gap+34
- Incentives82
- Confidence58
LastPass and Delphos Labs say a single malware-as-a-service kit impersonated at least 40 companies on GitHub, and the kernel driver it delivered was Microsoft-attested and undetected by every engine on VirusTotal.
Publishers:blog.lastpass.com
Reality
- Evidence62
- Adoption48
- Hype gap+12
- Incentives68
- Confidence55
Volexity dates UTA0565's exploitation to September 3 and 4, five to six days before it first reported the chain publicly, delivered from typosquats of China Digital Times and the Center for American Progress and ending in a new implant it calls CLEANGULP.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives52
- Confidence64
Earlier coverage
- Okta puts an enforcement point between AI agents and the tools they call
Product · September 22, 2026 · One report1 publisher
- Crosspoint pays about 30 times run rate to lead MIND's $72M Series B
Invest · September 19, 2026 · Confirmed3 publishers
- Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0
Security · September 18, 2026 · One report1 publisher
- A third bypass of the same Defender flaw landed hours after Microsoft's second fix shipped
Build · September 15, 2026 · Confirmed2 publishers
- Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source
Leadership · September 15, 2026 · One report1 publisher
- Four espionage crews picked up the same Chrome and Windows exploit chain within days
Product · September 11, 2026 · One report1 publisher
- Proofpoint absorbs Acuvity to see which AI services staff and machines are calling
Security · September 11, 2026 · One report1 publisher
- AI governance lands on 79% of CISOs without a matching increase in resources
Security · September 9, 2026 · One report1 publisher
- Cloudflare turns OpenAI's cyber model into WAF rules that wait on human approval
Product · September 3, 2026 · One report1 publisher
- NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail
Security · August 26, 2026 · Confirmed2 publishers