All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
CVE-2024-20359: Cisco IMC Auth Bypass Grants Admin Access
Cisco IMC critical authentication bypass (CVE-2024-20359) allows unauthenticated attackers admin access. Learn about the vulnerability and urgent patch guidance.
Open Source Security: Key Findings from 2025 Trust Report
Analysis of the 2025 State of Trusted Open Source Report, detailing prevalent vulnerabilities and consumption patterns in container images and language libraries.
REF1695 Operation: ISO Lures Deploy RATs and Crypto Miners
Financially motivated REF1695 operation uses fake ISO installers to distribute RATs and crypto miners, monetizing infections via cryptojacking and CPA fraud since…
Quantum Geopolitics: Cyber Threats in an Era of Iran Conflict
Analyze how the shift toward quantum geopolitics and Iranian proxy conflicts impact global cyber stability and critical infrastructure protection.
Defeating Industrialized Fraud: Identifying Standardized Attack Patterns
Analysis of the industrialized fraud ecosystem and how standardized attack infrastructure allows financial institutions to detect patterns before losses occur.
Ivanti Connect Secure RCE via CVE-2024-21887 — Mitigation Guide
Critical Ivanti Connect Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 continue to be exploited. Learn detection strategies and mitigation steps.
Advertisement
CVE-2026-5281: Google Dawn RCE via Use-After-Free — Mitigation Guide
CISA adds CVE-2026-5281 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in Google Dawn's WebGPU implementation.
2026 US Cyber Strategy: Implications of Private Sector Hackback
An analysis of the 2026 US Cyber Strategy for America and its provisions for private sector offensive cyber operations and adversary network disruption.
Cyberattacks Target Latin American Government and Health Sectors
Recent disruptive cyberattacks and ransomware probes are targeting government infrastructure and health services across Latin America and the Caribbean.
LatAm Cybersecurity: Hiring Self-Taught Talent to Combat Cyberattacks
Research reveals Latin America's self-taught cybersecurity talent remains overlooked despite a massive surge in regional cyberattacks and labor demands.
Variance Secures $21.5M for AI-Driven Compliance Investigation Platform
Variance raises $21.5M to scale its AI agent platform designed to automate complex compliance investigations for financial institutions and regulated sectors.
CVE-2023-46747: 14,000 F5 BIG-IP APM Instances Exposed to RCE
Over 14,000 F5 BIG-IP APM instances remain vulnerable to critical RCE flaws. Learn about CVE-2023-46747 exploitation risks and how to secure your perimeter.
iOS 18.7.7 Update Expanded to Mitigate DarkSword Exploit Kit Risks
Apple expands iOS 18.7.7 and iPadOS 18.7.7 availability to additional devices to mitigate risks from the recently disclosed DarkSword exploit kit.
Linx Security Boosts Identity Governance Solutions with $50M Funding
Linx Security secures $50M funding, accelerating product development and global reach for its identity security and governance platform, underscoring identity…
Apple iOS 18 Security Updates: Mitigating DarkSword Exploit Chain
Apple expands iOS 18 security patches to protect more iPhone models against the DarkSword exploit kit targeting WebKit and JavaScriptCore vulnerabilities.
CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware
CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…
Depthfirst's $80M Funding: Advancing AI in Threat Detection
Depthfirst secured $80M in Series B funding to advance AI research, develop security models, and scale enterprise adoption.
NoVoice Android Malware on Google Play: 2.3 Million Devices Infected
NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.
EvilTokens Fuels Microsoft Device Code Phishing & BEC
New EvilTokens service automates Microsoft device code phishing, enabling account takeover and sophisticated business email compromise (BEC) attacks. Learn how to defend.
UAC-0255 Impersonates CERT-UA to Distribute AGEWHEEZE Malware
UAC-0255 targeted 1 million emails with a phishing campaign impersonating CERT-UA to deploy the AGEWHEEZE RAT. Learn about the TTPs and mitigation steps.
TeamPCP Supply Chain Campaign: First Victim, Cloud Enumeration, Ransomware
Detailed analysis of TeamPCP supply chain campaign, covering the first confirmed victim, post-compromise cloud enumeration tactics, and dual ransomware operations.
Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks
Analyze Venom Stealer MaaS, a new cybercrime platform enabling automated, persistent information-stealing through social engineering 'ClickFix' attacks.
DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation
DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.
Hasbro Cyberattack: Investigating Scope and Data Compromise
Toy giant Hasbro is investigating a cyberattack, assessing the incident's full scope and potential data compromise. Learn defense strategies.