What the 2025 Elastic Global Threat Report reveals about the evolving threat landscape
The 2025 Elastic Global Threat Report provides current insights on adversary trends and defender strategies derived from real-world telemetry.
20 articles
The 2025 Elastic Global Threat Report provides current insights on adversary trends and defender strategies derived from real-world telemetry.
A year later: Elastic Security Labs re-examines the WARMCOOKIE backdoor.
FlipSwitch offers a fresh look at bypassing Linux kernel defenses, revealing a new technique in the ongoing battle between cyber attackers and defenders.
Elastic shares results of the 2025 AV Comparatives EPR test
This research examines how Model Context Protocol (MCP) tools expand the attack surface for autonomous agents, detailing exploit vectors such as tool poisoni...
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis.
An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies.
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes!
Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining.
Agentic systems require security teams to balance autonomy with alignment, ensuring that AI agents can act independently while remaining goal-consistent and ...
Abstract Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover.
NOVABLIGHT is a NodeJS infostealer developed and sold as a MaaS offering; it is used primarily to steal credentials and compromise cryptowallets.
Manual testing doesn't have to be repetitive.
Elastic Security Labs detected the recent emergence of infostealers using an illicitly acquired version of the commercial evasion framework, SHELLTER, to dep...
Contextual search brings clarity, speed, and insight to defence security teams
This article explores OAuth phishing and token-based abuse in Microsoft Entra ID. Through emulation and analysis of tokens, scope, and device behavior during...
Elastic Security Labs detected a surge in ClickFix campaigns, using GHOSTPULSE to deploy Remote Access Trojans and data-stealing malware.
We explore the immense value that call stacks bring to malware detection and why Elastic considers them to be vital Windows endpoint telemetry despite the ar...
Elastic Security nailed it with a perfect score of 100% in the most recent AV-Comparatives Business Security Test.