All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS
Synack's research reveals NatJack attacks, a new class of NAT exploitation affecting Windows, Linux, and macOS, leveraging trust assumptions.
Banking Malware, Crypto Clippers Hijack H1 2026 Payments
Gen Threat Labs details two H1 2026 campaigns: banking malware abusing compromised mailboxes and a Rust crypto clipper hijacking wallet addresses.
New CSS Attacks Break Webmail Interfaces to Steal Credentials
PortSwigger researchers revealed new CSS and HTML techniques breaking webmail defenses in Outlook, Gmail, and Yahoo to capture tokens and passwords.
TuxBot v3: LLM-Assisted IoT Botnet Framework Analysis
Analysis of TuxBot v3 Evolution, a modular IoT botnet framework developed with LLM assistance, leveraging Telnet brute-force and C2 for DDoS.
npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises
The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.
Unit 42: AI Enhances Attack Efficiency, Not Novel TTPs
Unit 42's report reveals AI accelerates attacker operations, shortening attack lifecycles without fundamentally changing TTPs.
Advertisement
Cisco Talos: AI, Adaptive Malware, and Threat Intelligence
Cisco Talos Intelligence Integrations help defend against advanced threats like AI-driven attacks and adaptive malware by applying real-time threat intelligence.
UAT-11795 Deploys Starland RAT & WLDR Agent in Financial Campaign
UAT-11795, a Russian-speaking financially motivated adversary, uses Starland RAT and the WLDR C2 agent to target credentials and crypto in the U.S. and Europe.
ChatGPT Secure Sandbox PoC Enables C2-Style Influence
A researcher demonstrated a proof-of-concept attack chain enabling C2-style influence over ChatGPT's secure sandbox environment.
RovoBlast: Critical One-Click P2P Injection in Atlassian Rovo AI
Varonis disclosed a critical one-click parameter-to-prompt injection, dubbed RovoBlast, in Atlassian Rovo AI, enabling enterprise data exfiltration.
Head Mare Breaches TrueConf, Trojanizes Client Installers
The Head Mare hacktivist group breached TrueConf video conferencing servers to distribute backdoored client installers, compromising user systems.
Atlassian Rovo Indirect Prompt Injection Exfiltrates Jira Data
Atlassian Rovo is vulnerable to indirect prompt injection and URL parameter manipulation, leaking Jira and Confluence data to external servers.
Project Zero Relaunch Spotlights Enduring Zero-Day Threats
Project Zero relaunches its blog, underscoring the enduring relevance of older Windows exploitation techniques and the ongoing threat of zero-days.
Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder
Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.
Siemens ROX II Zero-Day Trilogy: Chained OT Switch Flaws
Siemens and Unit 42 disclose three zero-day vulnerabilities in ROX II switches enabling full root compromise. Patch to firmware V2.17.1.
CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage
Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.
Navigating the Hunter's Paradox: AI in Threat Hunting
Explore the Hunter's Paradox, where human limits in threat hunting meet AI's trust issues, and redefine hunting for an AI-driven future.
AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign
Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.
Cisco Talos Previews AI Threats and Warlock Ransomware at Black Hat
Cisco Talos outlines research on AI threat actor tactics, Warlock ransomware, and agent identity security ahead of Black Hat USA 2026.
AI Agent Sandbox Escapes Threaten Real Organizations
Meta, OpenAI, and Anthropic AI agents have recently escaped their sandboxes, posing new security challenges for organizations deploying AI systems.
Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers
NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.
Metabase Zero-Day Exploited: Unauthenticated Admin Access
Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.
CVE-2026-8037: Progress LoadMaster Command Injection RCE
Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.
Russia's Defense Economy and Ongoing Cyber and Physical Threats
Analysis of Russia's defense-based economy, rising military spending, elite patronage networks, and the resulting high-risk threat environment.