All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
CVE-2024-22257: Critical SAP AS ABAP Code Injection — Patch Now
SAP releases patches for 19 vulnerabilities, including a CVSS 9.8 code injection flaw in SAP AS ABAP and high-severity RCE in SAP Business Client.
Analyzing 216M Security Findings: Critical Risks Surge by 400%
OX Security research reveals a 400% spike in critical risks driven by AI-assisted development, outpacing a 52% increase in total security alert volume.
Mirax Android RAT: Bypassing Security via Malicious Meta Ads
Mirax Android RAT targets 220,000 users via Meta Ads, turning devices into SOCKS5 proxies. Learn to detect and mitigate this emerging mobile threat.
IPv6 Security: Mitigating Rogue Router Advertisements and NDP Risks
Analysis of IPv6 Neighbor Discovery Protocol vulnerabilities and why security teams must prioritize RA Guard and monitoring to prevent traffic interception.
CISA KEV Update: Fortinet FortiClient EMS CVE-2026-21643 Under Attack
CISA adds six flaws to the KEV catalog, including a critical unauthenticated SQL injection in Fortinet FortiClient EMS (CVE-2026-21643). Patch immediately.
CVE-2025-0520: ShowDoc RCE via File Upload Flaw Under Active Attack
Critical CVE-2025-0520 in ShowDoc allows RCE via unrestricted file upload. Attackers are actively targeting unpatched servers to deploy web shells.
Advertisement
Cisco FMC Zero-Day Exploited by Interlock Ransomware: March 2026 CVEs
Runtime Rebel analyzes March 2026's significant rise in high-impact CVEs, including a Cisco FMC zero-day actively exploited by Interlock Ransomware.
CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits
CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…
Adobe Acrobat & Reader Zero-Day Exploitation: Immediate Patch Required
Adobe has patched an actively exploited Zero-Day in Acrobat and Reader. Attackers used crafted PDF files for at least four months. Update immediately.
AI Vulnerability Storm: Preparing for Post-Mythos Exploits
CISOs must prepare for an 'AI vulnerability storm' triggered by Anthropic's Claude Mythos. Proactive security frameworks are essential to mitigate new risks.
Basic-Fit Data Breach Exposes 1M Members' PII & IBANs
Dutch fitness giant Basic-Fit confirms data breach affecting 1 million members in France, Spain, and Belgium, exposing PII and bank account numbers.
Anthropic's Mythos Preview AI: Proactive Vulnerability Hunting with Project Glasswing
Anthropic's Claude Mythos Preview AI possesses significant cyberattack capabilities.
OT Cryptographic Readiness: Addressing the PQC Attestation Gap
OT asset owners struggle to meet regulatory PQC attestation requirements due to a lack of visibility tools, creating a false sense of security in ICS environments.
CVE-2024-38472: wolfSSL ECDSA Signature Verification Bypass Patch Guide
Critical vulnerability CVE-2024-38472 in wolfSSL allows certificate forgery and MitM attacks via improper ECDSA hash validation. Patch to 5.7.4 immediately.
Rockstar Games Analytics Data Leaked via ShinyHunters Extortion
Rockstar Games analytics data has been leaked by the ShinyHunters group following a breach at third-party provider Anodot. Analysis of the supply chain risk.
JanelaRAT Malware Analysis: 14,000+ Attacks Target Latin American Banks
Analyze the JanelaRAT campaign targeting Brazil and Mexico. Learn how this BX RAT variant steals financial data and how to detect JanelaRAT attacks.
VIP Credential Monitoring: Defending High-Value Targets
Learn how VIP credential monitoring protects high-privilege users from account takeover by tracking exposures across personal and corporate email domains.
Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide
Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.
LinkedIn Browser Extension Probing: Analyzing 'BrowserGate' Claims
An analysis of 'BrowserGate' claims regarding LinkedIn's browser extension fingerprinting and why research suggests bot detection over corporate espionage.
Booking.com Data Breach: Unauthorized Access to Customer Information
Booking.com confirms unauthorized access to customer booking data. Analyze the breach impact, TTPs used against travel platforms, and mitigation strategies.
Storm Infostealer: Bypassing Local Decryption for Session Hijacking
Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.
CVE-2026-34621: Adobe Acrobat and Reader Zero-Day Emergency Patch
Adobe issues an emergency fix for CVE-2026-34621, a critical Acrobat and Reader zero-day exploited in the wild. Learn technical details and mitigation steps.
Critical PDF Zero-Day and Windows Rootkit Technical Analysis
Analysis of critical threats including fiber optic surveillance, a stealthy PDF zero-day, and advanced Windows rootkit persistence mechanisms.