All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Adobe Reader Zero-Day Exploited via Malicious PDF Documents
Researchers reveal a sophisticated Adobe Reader zero-day exploit used in the wild since late 2025, involving malicious PDF invoices to compromise systems.
Managing Enterprise Risks of Shadow AI and Unauthorized LLMs
Shadow AI bypasses security controls, leading to data leakage. Learn how to identify and mitigate risks from unauthorized AI tools in the enterprise.
Venezuela Geopolitical Risk: Navigating Post-Maduro Transition
Analysis of the Venezuelan political landscape following the 2026 US operation, focusing on Delcy Rodríguez’s strategy and PSUV internal rivalries.
Honeypot Data Analysis: Predictable Year and Season Password Patterns
SANS ISC research reveals how attackers exploit predictable password patterns, such as years and seasons, driven by outdated rotation policies.
Bitcoin Depot Credential Theft: $3.6M Stolen from Hot Wallets
Bitcoin Depot reports a $3.6 million loss after attackers compromised administrative credentials to drain corporate hot wallets. Analyze the breach and TTPs.
Eurail Data Breach: 300,000 Travelers' Passport Data Stolen
Eurail discloses a data breach impacting 300,000 individuals. Stolen names and passport numbers pose significant risks for identity theft and phishing.
Advertisement
Microsoft Developer Account Suspensions Block OSS Security Patches
Microsoft's suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.
Bitcoin Depot Breach: $3.6M Exfiltrated from Crypto Wallet Systems
Bitcoin Depot reports a $3.6 million theft following a breach of internal systems. Analyze the impact and learn how to mitigate cryptocurrency ATM breaches.
APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers
Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…
Iran-Linked Cyber Attacks Persist Despite Israel-Hezbollah Ceasefire
Iran-affiliated threat actors maintain operational tempo against US critical infrastructure, disregarding kinetic pauses in Middle East regional conflicts.
TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity
Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.
CVE-2026-1340: Ivanti EPMM Code Injection — Patch Now
CISA adds CVE-2026-1340, a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM), to its KEV Catalog due to active exploitation.
AI-Led Remediation Crisis: HackerOne Halts Bug Bounties
HackerOne pauses bug bounties due to an AI-driven remediation crisis, highlighting how automated vulnerability discovery overwhelms open-source project capacity to fix…
Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics
Threat actors are increasingly using emojis for covert Command and Control communications to evade security filters. Learn how to detect these obfuscated TTPs.
Apache ActiveMQ Classic RCE via Jolokia API: Patch Now
An unauthenticated Remote Code Execution flaw, present for 13 years, impacts Apache ActiveMQ Classic, allowing full system compromise. Immediate patching is critical.
OpenSSL: Data Leakage & DoS Vulnerabilities Patched
OpenSSL patches seven vulnerabilities, including a data leakage flaw and multiple denial-of-service risks. Update immediately to secure cryptographic communications.
UNC6783 Leverages BPOs to Steal Corporate Zendesk Tickets
New threat actor UNC6783 targets Business Process Outsourcing (BPO) providers to gain access to client Zendesk support tickets, risking sensitive data.
Magecart Skimmer Hides in Pixel-Sized SVG on Magento Stores
A sophisticated Magecart campaign targets nearly 100 Magento stores, concealing credit card-stealing JavaScript within tiny, pixel-sized SVG images.
Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns
The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.
Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy
A new variant of Chaos malware targets misconfigured cloud deployments, leveraging SOCKS proxy capabilities to expand botnet infrastructure beyond edge devices.
Consumer GPUs vs Enterprise Hardware for Password Cracking
Analysis of research comparing the NVIDIA H100 and RTX 4090 for password cracking, highlighting why attackers favor consumer-grade hardware for brute-force.
APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware
APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.
litellm 1.82.8 Supply Chain Compromise via Malicious .pth File
Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.
Ninja Forms RCE via Arbitrary File Upload: Mitigation Guide
Hackers are actively exploiting a critical Ninja Forms vulnerability to upload arbitrary files and achieve RCE. Learn how to secure your WordPress site now.