All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Managing Shadow AI Risks in Healthcare: Security Governance Guide
Healthcare organizations face rising risks from unsanctioned AI usage. Learn how to secure patient data and implement governance to prevent data leakage.
UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script
Threat actor UAT-10608 is leveraging an automated script to exploit a Next.js SSRF flaw, exfiltrating credentials and environment secrets from web applications.
Google DeepMind Research: Six Web Attack Vectors Against AI Agents
DeepMind researchers reveal how malicious web content can manipulate AI agents, highlighting risks like indirect prompt injection and data exfiltration.
Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers
Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.
FortiClient EMS RCE via CVE-2023-48788 — Patch Guidance
CISA mandates federal agencies patch the critical FortiClient EMS SQL injection flaw, CVE-2023-48788, which allows unauthenticated remote code execution.
Chrome Zero-Day and Fortinet Exploits: Weekly Threat Intelligence
Intelligence analysis of the latest Chrome zero-day, Fortinet vulnerabilities, and the Axios security breach, including technical remediation for SOC teams.
Advertisement
Multi-OS Attack Defense: Unifying SOC Workflows Across Platforms
Learn how modern threat actors exploit fragmented security silos to move across Windows, Linux, and macOS, and how SOCs can implement unified defenses.
Analyzing the Frequency of Open Redirects in Phishing Campaigns
Examine the technical drivers behind the use of open redirects in phishing delivery and learn strategies for detection and vulnerability remediation.
Google Accelerates Post-Quantum Cryptography Transition for 2029
Google announces a full migration to post-quantum cryptography by 2029 to ensure crypto-agility and defend against future quantum computing threats.
North Korean Social Engineering Targets Node.js Maintainers
North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.
Guardarian Users Targeted via 36 Malicious Strapi npm Packages
Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.
BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks
Germany's BKA unmasks the leadership of the REvil (Sodinokibi) ransomware group, including the representative UNKN, following a major threat intel investigation.
CVE-2024-32113: Apache OFBiz RCE Exploited for Mirai Botnet
Technical analysis of CVE-2024-32113 exploitation in Apache OFBiz. Learn how attackers use path traversal to deploy Mirai botnet malware and how to patch.
Germany Doxes UNKN: Identity of REvil and GandCrab Leader Revealed
German authorities identify Daniil Maksimovich Shchukin as UNKN, the lead operator behind the notorious GandCrab and REvil ransomware operations.
FortiClient EMS RCE via CVE-2026-35616 — Mitigation Guide
Fortinet releases emergency patches for CVE-2026-35616, a critical SQL injection flaw in FortiClient EMS exploited to achieve unauthenticated RCE.
QR Code Phishing: SMS Traffic Violation Scams Bypass Mobile Filters
Scammers are using QR codes in SMS traffic violation scams to bypass security filters and steal financial data. Learn how to identify and block quishing.
DPRK Social Engineering Behind $285 Million Drift Hack: Analysis
A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.
CVE-2025-55182: Hackers Exploit React2Shell in Next.js Applications
Security researchers observe automated credential theft campaigns exploiting the React2Shell vulnerability (CVE-2025-55182) in vulnerable Next.js frameworks.
CVE-2026-35616: Critical FortiClient EMS API Bypass Exploited
Fortinet releases out-of-band patches for CVE-2026-35616, a critical API access bypass in FortiClient EMS enabling unauthenticated privilege escalation.
36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL
36 malicious npm packages disguised as Strapi CMS plugins target Redis and PostgreSQL environments to deploy persistent implants and reverse shells.
Axios npm Hijack Attempt: Detecting Social Engineering Tactics
North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.
LinkedIn Browser Fingerprinting: Privacy Risks of Extension Scanning
LinkedIn is reportedly scanning users for over 6,000 Chrome extensions using browser fingerprinting techniques, raising significant privacy concerns.
OAuth 2.0 Device Code Phishing Surge: Protecting M365 and Google
Device code phishing attacks have surged 37x this year. Learn how adversaries abuse the OAuth 2.0 Device Authorization Grant to bypass MFA and hijack accounts.