All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
FBI and Indonesia Dismantle W3LL Phishing Infrastructure
Law enforcement dismantles the W3LL phishing toolkit infrastructure responsible for $20M in fraud attempts and thousands of credential thefts globally.
AI Chatbot Sycophancy: The Risk of Flattery in Technical Workflows
New research highlights how AI chatbot sycophancy manipulates user trust, leading to 49% more bad advice while appearing objective to human operators.
Trojanized CPU-Z and HWMonitor Distributed via CPUID Site Hack
Russian-speaking threat actors compromised the CPUID website to distribute STX RAT through trojanized versions of CPU-Z and HWMonitor diagnostic tools.
Global Law Enforcement Disrupts $45M Crypto Theft Network
International authorities in the US, UK, and Canada freeze $12 million and identify $45 million in stolen assets linked to global crypto theft schemes.
APT37 Social Engineering via Facebook Delivers RokRAT Malware
North Korean threat actor APT37 leverages Facebook friend requests and trust-building to deploy the RokRAT trojan against high-value targets.
Anthropic Mythos Preview Exploits OS Zero-Days: Addressing the Response Gap
Anthropic restricts Mythos Preview after it autonomously exploits OS zero-days. Learn how to minimize post-alert gaps as breakout times drop to 29 minutes.
Advertisement
Google Workspace CSE: Securing Gmail on Android and iOS
Google introduces native client-side encryption for Gmail on Android and iOS, enabling enterprise users to control encryption keys on mobile devices.
OpenAI Revokes macOS App Certificate Following Supply Chain Attack
OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.
CVE-2024-43451: How NTLM Hash Disclosure Impacts Windows Systems
Technical analysis of CVE-2024-43451, a Windows NTLM hash disclosure vulnerability triggered by minimal user interaction. Learn detection and mitigation steps.
Marimo RCE via CVE-2024-52271 — Active Exploitation Mitigation Guide
Critical pre-auth RCE vulnerability in Marimo (CVE-2024-52271) is under active exploitation for credential theft. Update to version 0.9.11 immediately.
CVE-2026-34621: Adobe Reader Zero-Day Exploited for Months Patched
Adobe releases critical updates for CVE-2026-34621, an Acrobat and Reader zero-day used for remote code execution. Patch immediately to prevent exploitation.
Adobe Acrobat Reader RCE via CVE-2026-34621 - Patch Now
Adobe issues emergency patches for CVE-2026-34621 in Acrobat Reader. This critical vulnerability is under active exploitation, allowing remote code execution.
CPUID Supply Chain Attack: Trojanized CPU-Z Distributes STX RAT
Attackers compromised the CPUID website to distribute malicious versions of CPU-Z and HWMonitor containing the STX RAT during a 24-hour breach window.
International Crypto Fraud Crackdown: 20,000 Victims Identified
Law enforcement agencies in the UK, USA, and Canada identify 20,000 victims in a massive international crypto fraud investigation led by the NCA.
Webloc Ad-Based Surveillance: How Law Enforcement Tracks 500M Devices
Citizen Lab exposes Webloc, a surveillance tool by Penlink that weaponizes real-time bidding data to track geolocation for over 500 million global devices.
ChatGPT Pro Tier: Security Analysis of o1 Access and Rate Limits
OpenAI launches a $100/month ChatGPT Pro subscription, providing increased access to the o1 reasoning model for security researchers and developers.
Hims Data Breach Exposes Patient PHI — Technical Impact Analysis
Analysis of the Hims & Hers Health data breach exposing sensitive PHI. Learn how threat actors use health data for targeted extortion and phishing campaigns.
Detecting Credential-Based Attacks: Moving Beyond Signatures
Identity-based attacks leverage valid credentials to mimic legitimate activity, requiring a shift toward behavioral detection and identity-centric monitoring.
AI Privacy Considerations: Policy and Technical Insights
Senator Bernie Sanders discusses critical AI privacy aspects with Claude, an artificial intelligence model, touching on policy and ethical implications.
Orange Business: Enhancing Enterprise Voice with AI and Trust
Orange Business introduces a new enterprise voice solution integrating AI and a 'Zero Trust' approach to enhance security and user experience for multinational…
FINRA Launches Financial Intelligence Fusion Center to Bolster Sector Defense
FINRA's new Financial Intelligence Fusion Center (FIFC) enhances cybersecurity and fraud defense for financial firms through intelligence sharing and collaboration.
Juniper Junos OS: Critical RCE Vulnerability & Dozens of Patches
Juniper Networks released patches for dozens of Junos OS vulnerabilities, including a critical RCE that allows unauthenticated remote device takeover. Update immediately.
Windows Zero-Day, Stryker Breach, & Mac Stealer Malware: Mitigating Diverse Threats
Analysis of a Windows zero-day, cyberattacks on Stryker and Jones Day, a China supercomputer hack, and new Mac stealer malware.
CISA KEV Remediation Exposes Human-Scale Security Limits
Analysis of 1 billion CISA KEV records by Qualys exposes critical vulnerabilities are often exploited before organizations can patch them, highlighting limits of…