All Articles
Security Intelligence
3458 articles · Updated every 8 hours
Advertisement
Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws
Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.
Dark Web Service Nexus Sells 153M+ Driver Licenses
A new dark web service, Nexus, is selling over 153 million drivers' licenses from North America, likely sourced from an identity verification company.
Palo Alto Networks Acquires AI Agent Platform Console
Palo Alto Networks acquires AI agent platform Console to enhance Cortex with natural language automation and agentic workflows.
Faronics Deploy Abused by Phishing Actors to Install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint management tool to gain remote access and install ScreenConnect via malicious installers.
The Agentic SOC: From AI Theater to Real Defense
Explore the Agentic SOC transition, focusing on measurable AI ROI, new risks like indirect prompt injection, and redefining analyst roles for autonomous defense.
Leaked Russian Cyber-Ops Training Exposes Institutional Pathways
Leaked materials reveal Russia's institutional system for generating cyber capabilities, linking university recruitment to GRU and Sandworm units for diverse operations.
Advertisement
AI-Generated Email Praise: A New Pre-Scam Tactic Emerges
Analysts observe AI-generated "thank you" emails from suspicious accounts, potentially an early stage of sophisticated social engineering scams.
ClickFix Campaign Exploits Polygon Blockchain for C2 Evasion
The ClickFix campaign compromises 31 organizations, dynamically updating its C2 server via EtherHiding and the Polygon blockchain.
Sevii's AI Module: Autonomous Defense Against AI-Speed Attacks
Sevii extends its Autonomous Defense & Remediation (ADR) platform with a new AI security module, enabling real-time, autonomous response to AI-driven cyber attacks.
CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens
Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.
BREEZE COMET Exploits Brazilian Financial Systems
BREEZE COMET, a financially motivated threat actor, targets Brazilian financial services for fraudulent transfers, leveraging custom malware and AI for development.
AI Baby Monitors & Privacy Risks: The Nanit Surveillance Trend
AI-powered baby monitors like Nanit collect vast child data, raising significant long-term privacy and surveillance concerns for families.
TerminalFix: PowerShell Weaponization in Enterprise Attacks
Analysis of 'TerminalFix' campaign, detailing PowerShell weaponization, multistage attack chain, and reverse tunnels into enterprise networks.
AI-Assisted PLC Exploit Porting: WAGO RCE via Claude
Forescout researchers used Anthropic's Claude to port a WAGO PLC RCE exploit, demonstrating AI's potential in offensive security but highlighting current challenges.
CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack
Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.
Threat Actors Prefer Repeatable Playbooks Over Novel Exploits
Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.
CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data
CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.
CVE-2026-66384: JFrog Artifactory Path Traversal Exploit
CISA warns of active exploitation of CVE-2026-66384 in JFrog Artifactory, allowing authenticated users to write data outside intended paths. Patch immediately.
CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation
CISA adds CVE-2026-53362 to KEV, confirming active exploitation of a Linux Kernel privilege escalation vulnerability via IPv6. Patch now.
CVE-2023-49105: ownCloud Improper Auth Leads to Data Compromise
CVE-2023-49105 in ownCloud allows unauthenticated file access, modification, or deletion, actively exploited in the wild.
CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Exploit
CISA adds CVE-2026-82078 in PaperCut NG/MF to its KEV catalog following active exploitation. Review technical details and patch now.
Cloudflare Adaptive Intelligence: Reversing Bot Attack Economics
Cloudflare introduces Adaptive Intelligence, a new bot detection engine designed to increase the economic cost for attackers and continuously adapt defenses.
AI's Impact on Threat Intelligence & Business Risk Management
Discover how AI is intensifying vulnerability volumes and enabling faster threat actor operations, necessitating a strategic shift to risk-based threat intelligence.
Recorded Future Launches AI Alert Filtering for Analysts
Recorded Future introduces AI Alert Filtering, an agent designed to automatically reduce security alert volume by 63% for threat analysts.