Unit 42 reports endpoint alerts tied to collaboration tools more than quadrupled in 12 months, with 99% linked to chat phishing. Most controls still watch email and logins, not authenticated sessions.
Publishers:unit42.paloaltonetworks.com
Reality
- Evidence44
- Adoption38
- Hype gap+22
- Incentives78
- Confidence48
Wiz says rogue device registrations are drifting toward benign names, while nearly one in seven Entra tenants saw such an attack in 90 days. Naming strings were never the signal.
Publishers:wiz.io
Reality
- Evidence42
- Adoption55
TheHatman's claimed Entra haul and the FortiBleed spraying wave share one detectable seam: a successful authentication landing just behind a spike of failures.
Publishers:unit42.paloaltonetworks.com
Reality
- Evidence46
- Adoption58
build1 distinct publisher Unit 42's three techniques all assume malware is already running on the box. That makes this an endpoint and browser-profile problem, not a reason to stall a passkey deployment.
Publishers:dev.to
Reality
- Evidence44
- Adoption24
Unit 42 says the Android TV box botnet now floods over HTTP/2 with full Chrome fingerprints and resolves its command server through the Ethereum Name Service, with Tor as a fallback.
Publishers:cyberscoop.com
Reality
- Evidence55
- Adoption45
Broadcom's Threat Hunter Team says the same small team, the same infrastructure and one control panel serve both Chinese state espionage and a crypto-fraud sideline. Actor-type triage does not survive that.
Publishers:infosecurity-magazine.com
Reality
- Evidence58
- Adoption68
Unit 42 says the C++ loader reads encrypted commands from immutable smart contracts over public RPC endpoints, which turns takedown work into traffic monitoring.
Publishers:unit42.paloaltonetworks.com
Reality
- Evidence62
- Adoption28