Skip to main content

All Articles

Security Intelligence

3410 articles · Updated every 8 hours

Severity (this page):

Advertisement

HIGH
Supply Chain

European Commission AWS Breach: Trivy Supply Chain Attack Analysis

The European Commission confirms a 300GB data breach in its AWS environment linked to a Trivy supply chain attack. Learn about the impact and mitigations.

Runtime Rebel Intel
4 min read · Apr 4, 2026
Apple Patches DarkSword for iOS 18 — Security Analysis
HIGH
Vulnerabilities

Apple Patches DarkSword for iOS 18 — Security Analysis

Apple breaks precedent by patching the DarkSword mobile exploitation framework for iOS 18, addressing critical kernel-level risks and RCE vulnerabilities.

Runtime Rebel Intel
3 min read · Apr 4, 2026
HIGH
Data Breach

Hims & Hers Data Breach via Zendesk: Support Ticket Compromise

Telehealth provider Hims & Hers discloses a data breach impacting customer support tickets, stemming from a compromise of their Zendesk platform.

Runtime Rebel Intel
5 min read · Apr 4, 2026
MEDIUM
Threat Intel

BrowserGate: LinkedIn's Stealthy Chrome Extension Scanning and Data Collection

Analysis of 'BrowserGate' reveals LinkedIn's hidden JavaScript scanning over 6,000 Chrome extensions and collecting user device data. Understand the privacy implications.

Runtime Rebel Intel
4 min read · Apr 4, 2026
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
HIGH
Threat Intel

Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers

Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.

Runtime Rebel Intel
3 min read · Apr 4, 2026
TA416 Targets European Govts with PlugX & OAuth Phishing
HIGH
Threat Intel

TA416 Targets European Govts with PlugX & OAuth Phishing

China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.

Runtime Rebel Intel
4 min read · Apr 3, 2026

Advertisement

HIGH
Supply Chain

TeamPCP Supply Chain: CERT-EU Confirms Cloud Breach, 1000+ SaaS Environments Affected

CERT-EU confirms European Commission cloud breach via TeamPCP supply chain campaign. Mandiant identifies over 1,000 compromised SaaS environments.

Runtime Rebel Intel
5 min read · Apr 3, 2026
Emerging XR Authentication: Skull Vibrations for Identity
INFO
Threat Intel

Emerging XR Authentication: Skull Vibrations for Identity

Emerging research suggests skull vibration harmonics from vital signs could serve as a novel authentication method for VR, AR, and MR headsets, offering unique identity…

Runtime Rebel Intel
5 min read · Apr 3, 2026
TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting
HIGH
Threat Intel

TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting

Runtime Rebel details how TeamPCP's supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos.

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Threat Intel

Recent Cyber Threats: Data Leaks, Android Malware, Critical Infra Ransomware

Analysis of a ChatGPT data leak, the emergence of an Android rootkit, and a ransomware attack impacting a water facility. Essential insights for defenders.

Runtime Rebel Intel
4 min read · Apr 3, 2026
CRITICAL
Threat Intel

TrueConf Zero-Day: Exploitation Against Asian Governments

A Chinese threat actor is actively exploiting a TrueConf video conferencing zero-day to conduct reconnaissance and achieve privilege escalation against Asian government…

Runtime Rebel Intel
4 min read · Apr 3, 2026
INFO
Threat Intel

Multi-Extortion Ransomware Tactics: A Deeper Dive

Analyze the evolution of multi-extortion ransomware, its reliance on data leaks, and strategies for mitigating the impact of exfiltrated data.

Runtime Rebel Intel
4 min read · Apr 3, 2026
Third-Party Risk: The Growing Supply Chain Security Gap
HIGH
Supply Chain

Third-Party Risk: The Growing Supply Chain Security Gap

Organizations face increasing breach risks through trusted vendors, SaaS tools, and subcontractors.

Runtime Rebel Intel
5 min read · Apr 3, 2026
UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise
HIGH
Supply Chain

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise

Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…

Runtime Rebel Intel
4 min read · Apr 3, 2026
INFO
Threat Intel

WebinarTV Secretly Records Public Zoom Meetings: Privacy Risks

WebinarTV records and publishes public Zoom meetings without consent. Understand the privacy risks and implement immediate mitigations for sensitive data exposure.

Runtime Rebel Intel
4 min read · Apr 3, 2026
INFO
Threat Intel

Shadow AI & Zero-Click Exploits Expand Enterprise Mobile Attack Surface

Enterprises face a growing mobile attack surface from shadow AI in apps, outdated devices, and zero-click exploits, leading to unseen risks for corporate data.

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Vulnerabilities

CVE-2023-24489: Citrix ShareFile StorageZones Controller Unauthenticated RCE

Critical unauthenticated RCE in Citrix ShareFile StorageZones Controller (CVE-2023-24489) enables arbitrary file upload and full system compromise. Patch immediately.

Runtime Rebel Intel
4 min read · Apr 3, 2026
MEDIUM
Identity & Access

Insider Threat: Former Engineer Locks 254 Windows Servers in Extortion

A former infrastructure engineer pleaded guilty to a $750,000 extortion plot after locking administrators out of 254 Windows servers and deleting backups.

Runtime Rebel Intel
3 min read · Apr 3, 2026
INFO
Cloud Security

Exchange Online Mailbox Access Issues Persist for Outlook Users

Microsoft Exchange Online users on Outlook mobile and macOS are experiencing intermittent mailbox access issues for weeks; investigation ongoing.

Runtime Rebel Intel
4 min read · Apr 3, 2026
Drift Protocol Hacked for $285M via Durable Nonce Attack
HIGH
Data Breach

Drift Protocol Hacked for $285M via Durable Nonce Attack

Solana-based DEX Drift Protocol lost $285 million due to a social engineering and durable nonce attack, leading to Security Council takeover.

Runtime Rebel Intel
4 min read · Apr 3, 2026
SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases
HIGH
Malware

SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases

A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.

Runtime Rebel Intel
6 min read · Apr 3, 2026
LAC Cybercrime Trends 2025: Banking Trojans and Ransomware Shifts
MEDIUM
Threat Intel

LAC Cybercrime Trends 2025: Banking Trojans and Ransomware Shifts

Analysis of the 2025 Latin America and Caribbean cybercrime landscape, highlighting banking trojan evolution and regional ransomware operation trends.

Runtime Rebel Intel
3 min read · Apr 3, 2026
CRITICAL
Vulnerabilities

Ivanti Connect Secure RCE: Internal Network Vulnerability Detection

Analyze the impact of Ivanti Connect Secure vulnerabilities and learn how to conduct internal network vulnerability scanning for Ivanti appliances to detect flaws.

Runtime Rebel Intel
3 min read · Apr 3, 2026
MEDIUM
Vulnerabilities

Yokogawa CENTUM VP CVE-2025-7741 Hardcoded Password Patch Guidance

CISA identifies a hardcoded password in Yokogawa CENTUM VP (CVE-2025-7741). Learn how to secure the PROG account and apply the R7.01.10 patch now.

Runtime Rebel Intel
4 min read · Apr 3, 2026