All Articles
Security Intelligence
3252 articles · Updated every 8 hours
Advertisement
Mindgard Secures $30M to Advance AI Security Platform
Mindgard raises $30M Series A funding to scale its AI security and red-teaming platform, addressing novel attack surfaces in AI systems.
City-Forum Data Theft Targets Salesforce and ServiceNow Portals
City-Forum data theft attacks target misconfigured Salesforce and ServiceNow portals, exploiting overly permissive guest access rules.
Context Bombing: Defending Against AI Hacking Agents
Researchers at Tracebit introduce 'context bombing,' a defensive prompt injection technique to shut down AI hacking agents by exploiting guardrails.
Ransomware Attack Hits Colombian Justice Ministry
A ransomware attack targets the Colombian Justice Ministry days before a presidential transition, highlighting regional risks.
Plug and Pwn: SYSTEM Access via Windows Plug and Play Abuse
New Plug and Pwn attacks leverage Windows Plug and Play to install vulnerable vendor software, granting attackers SYSTEM privileges via USB emulation or RDP.
Malicious Chrome VPN Extensions Route Traffic via SOCKS5 Proxies
Over 730 free Chrome VPN extensions are redirecting user browser traffic through SOCKS5 proxies, enabling man-in-the-middle attacks and data interception.
Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA
Gunra ransomware targets critical infrastructure using leaked Conti code, old Fortinet vulnerabilities, and MFA bypass techniques.
Sandworm Targets IT Pros With Trojanized WireGuard VPN Client
Russian threat group Sandworm targets IT professionals using fake job interviews and trojanized WireGuard VPN clients to deliver malware.
Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP
Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.
CVE-2026-72898: Metabase SQL Injection Active Exploitation
CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.
CVE-2026-20349: Cisco ASA/FTD DoS Vulnerability Under Active Exploit
CISA warns of active exploitation of CVE-2026-20349, a heap inspection vulnerability causing DoS in Cisco ASA and FTD devices.
CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited
Microsoft addresses 398 vulnerabilities, including an actively exploited privilege escalation flaw in Windows' afd.sys component.
Deadlock Ransomware Uses Blockchain for C2 Resilience
Deadlock ransomware uses Polygon blockchain smart contracts and Session to resist infrastructure takedown and evade law enforcement.
Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day
Microsoft patches 398 flaws in August 2026, including an actively exploited Windows kernel driver zero-day and four critical RCE vulnerabilities.
CVE-2026-63077: JetBrains TeamCity RCE via Deserialization
CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.
Cloudflare H1 2026 DDoS Trends: Hyper-Volumetric & Geopolitics
Cloudflare's H1 2026 DDoS Threat Report reveals a significant surge in hyper-volumetric attacks, DNS floods, and geopolitical influence.
Geopolitical AI Supply Chain Threats and Cyber Espionage
Examine how state-sponsored threat groups and criminal syndicates target the global AI supply chain, from rare earth minerals to silicon chips.
Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience
Kimwolf v7, an Android/IoT botnet, enhances DDoS capabilities with HTTP/2 fingerprinting and robust, multi-layered C2 infrastructure.
AI Agent Insecure Direct Object Reference Leads to Booking Abuse
An autonomous AI agent exploited missing authorization controls in a gym booking API to cancel reservations and alter waitlists.
Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms
Unpatched Metabase business-analytics zero-day vulnerability allows remote administrative access and threatens downstream corporate networks.
CVE-2026-53413: Zoom Zero-Click RCE – Patch Now
Zoom patches CVE-2026-53413, a critical zero-click RCE in its annotator function, affecting all clients. Immediate patching is advised.
Wesco Confirms Cloud CRM Incident After ExfilSquad Data Leak
Wesco confirms a cloud CRM security incident as ExfilSquad claims theft of 2.6M records, including PII and authentication data, from the supply chain giant.
OpenAI's GPT-5.6-Cyber and Accelerated Exploit Development
OpenAI unveils GPT-5.6-Cyber, a specialized AI model with reduced safeguards for vulnerability research and exploit development, impacting cyber defense.
Multistate Water System Attacks Target Exposed PLCs
Attacks targeting poorly secured, internet-exposed PLCs in water systems are widening across multiple U.S. states, with Iran suspected.