Heroes, have a great Labor Day. This is the fresh-off-the-BBQ look at the cybersecurity landscape for September 1, 2025.
Critical Threats
High Severity
Executive Briefing
Recent data indicates that supply chain attacks have doubled, a trend exemplified by the recent third-party breach affecting Google. This trend requires executives to re-evaluate third-party risk management programs, as adversaries increasingly target smaller, less secure partners to gain access to larger, high-value targets.
With over 80% of security incidents originating from web applications, the browser has become the new enterprise perimeter and a primary attack surface. Threat actors like Scattered Spider are exploiting this shift, forcing security leaders to rethink security strategies and implement browser-centric security controls to protect against modern threats.
Vendor Spotlight
Spotlight Rationale: Selected to address the identity-based attack vector used by APT29 in their latest campaign targeting Microsoft credentials.
Threat Context: Russian-Linked APT29 Targets Microsoft Credentials in Watering Hole Campaign
Platform Focus: MojoAuth - Risk-Based Authentication (RBA)
MojoAuth's Risk-Based Authentication (RBA) provides a direct defense against credential theft campaigns like the one waged by APT29. Instead of relying solely on static credentials, RBA dynamically assesses the risk of each login attempt by analyzing signals such as user location, device fingerprint, time of day, and IP reputation. This allows the system to automatically challenge high-risk authentication attempts—like those originating from an APT29-controlled watering hole—with step-up authentication (MFA) or block them entirely, preventing unauthorized access even if the initial authentication flow is manipulated.
Actionable Platform Guidance: Implement a risk-based authentication policy to detect and mitigate anomalous access patterns. Define risk signals (e.g., new device, impossible travel, known malicious IP), establish risk tiers (low, medium, high), and configure adaptive access policies. For example, a login attempt using the device code flow from a previously unseen geographic location should automatically trigger a mandatory MFA challenge or be blocked.
Source: mojoauth.com