All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Recorded Future's Engine: Unifying Threat Intelligence Sources
Explore Recorded Future's unique collection engine, integrating technical, underground, and community intelligence for proactive threat defense and deeper insights.
Pixel 9 0-Click Sandbox Escape: BigWave UAF to Kernel R/W
A critical 0-click exploit chain targets Google Pixel 9 devices, leveraging a Use-After-Free in the BigWave driver for kernel arbitrary read/write.
Project Zero Uncovers Android 0-Click Exploit Chain Ecosystem Weaknesses
Project Zero details findings from a Pixel 9 0-click exploit chain, highlighting critical Android ecosystem issues and proposing security enhancements.
Bypassing Windows Administrator Protection: Security Research
Analysis of Windows 11 25H2 Administrator Protection, detailing security research into UAC flaws and local privilege escalation vectors.
XCSSET v40 Malware Targets macOS Developers via Xcode
Discover how XCSSET v40 targets macOS developers using fileless persistence, memory execution, and Xcode project supply chain attacks.
Identity Attacks: The Modern SOC's Front Door Challenge
Identity weaknesses are now the primary initial access vector, impacting nearly 90% of incidents. Learn how to detect and mitigate identity-driven attacks.
Advertisement
msaRAT: Chaos Ransomware's Covert Browser-Based C2
Cisco Talos uncovers msaRAT, a new Rust-based RAT used by Chaos ransomware for covert C2 via Chrome DevTools Protocol, evading detection.
Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse
Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.
Adversarial Clothing and Facial Recognition Security Theater
An analysis of adversarial clothing designed to evade facial recognition systems, examining effectiveness, security theater, and surveillance risks.
Friday Squid Blogging: Exploring Wider Cybersecurity Dialogues
An analysis of a unique blog post leveraging non-security content to foster community discussion on unaddressed cybersecurity news and topics.
AI-Generated Patches: High Failure Rate & New Vulnerabilities
A recent study reveals that AI-generated software patches fail in approximately half of all cases, often introducing new bugs or bypass vulnerabilities.
Metabase SQLi Zero-Day Exploited: Data Theft Attacks Confirmed
A critical Metabase SQL injection zero-day vulnerability (versions 1.58+) has been exploited in data theft attacks affecting customers like Framework and Tally.
Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer
Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.
Critical Backdoors & Supply Chain Attacks: Zbtlink Routers & QuickFox VPN Compromised
Urgent warning: Zbtlink routers ship with unauthenticated root backdoors, while QuickFox VPN delivers FDMTP implant via supply chain compromise.
Levi Strauss & Co. Corporate Data Stolen via Social Engineering
Levi Strauss & Co. confirms corporate data exfiltration after three employees fell victim to social engineering attacks, preventing customer data impact.
CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE
A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.
Linux Shell Forensics: Investigating Atuin History in Incident Response
Forensic analysis of Linux shell history using Atuin, a tool that enhances command logging.
Unlimited Technology Systems Data Breach Exposes 3.8M Records
Unlimited Technology Systems disclosed a data breach exposing PII and PHI of 3.8 million individuals, including Social Security numbers.
TeamPCP's Evolving Threat: Redis, Cloud Native & Supply Chain Attacks
TeamPCP, active since 2020, now targets Redis, Docker, Kubernetes, and supply chains, deploying wipers and backdoors.
AI's Transformative Impact on Threat Intelligence and Defenses
AI is rapidly accelerating the threat landscape, enabling machine-speed attacks and increasing defender challenges. Prioritizing intelligence is key.
Emerging Cyber Threats and Espionage Risks in Neurotechnology
Examine growing security threats to neurotechnology and brain-computer interfaces, focusing on IP theft, biometric data collection, and state-sponsored espionage.
ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat
Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.
Adversaries Weaponize AI: New Threat Landscape & Defensive Strategies
An analysis of how adversaries weaponize AI to generate malicious code, scale fraud, and accelerate zero-day discovery, shortening response times for defenders.
UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion
Google Threat Intelligence Group tracks UNC6671 shifting through Redact, Pink, Helix, and Falcon extortion brands while targeting cloud environments.