All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Cowrie Honeypot Analysis: Detecting Automated Session Disconnects
Analyze DShield Cowrie honeypot data to distinguish between automated bot traffic and manual actor activity through session duration and exit commands.
Iranian-Linked Handala Group Breaches Kash Patel's Personal Email
FBI confirms Iranian-linked Handala hackers breached Director nominee Kash Patel's personal email, leaking documents and highlighting spear-phishing risks.
Smart Slider 3 Vulnerability: Patch CVE-2024-11116 File Read Flaw
A file read vulnerability in Smart Slider 3 affects over 800,000 WordPress sites. Authenticated users can access sensitive server files via CVE-2024-11116.
Iran-Linked Handala Hackers Breach FBI Director, Target Stryker
Handala Hack Team compromised FBI Director Kash Patel's personal email and deployed destructive wiper malware against medical giant Stryker.
TeamPCP Supply Chain Campaign: Weaponized Scanners and PyPI Compromise
Analysis of the TeamPCP campaign transition to monetization following the Telnyx PyPI compromise and Vect ransomware partnership affecting security tools.
Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads
Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.
Advertisement
ClickFix Social Engineering Drops Infiniti Stealer on macOS
Attackers use fake Cloudflare CAPTCHA pages and ClickFix tactics to deliver the Python-based Infiniti Stealer to macOS systems via terminal commands.
Citrix NetScaler CVE-2026-3055 Memory Overread — Mitigation Guide
Attackers are actively scanning for CVE-2026-3055, a CVSS 9.3 memory overread flaw in Citrix NetScaler ADC and Gateway. Patch vulnerable instances immediately.
CVE-2025-53521: CISA Warns of Active F5 BIG-IP APM RCE Exploitation
CISA adds CVE-2025-53521 to its KEV catalog following active exploitation of F5 BIG-IP APM. The critical RCE flaw carries a CVSS v4 score of 9.3.
TA446 Deploys Leaked DarkSword iOS Exploit Kit — Technical Analysis
Russian threat actor TA446 (Callisto) is targeting iOS users with the leaked DarkSword exploit kit. Learn how to detect and defend against this campaign.
Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware
Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.
Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos
Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.
Pro-Iranian Group Claims Hack of FBI Director's Personal Account
A pro-Iranian hacking group claims to have compromised the personal account of FBI Director Kash Patel, exfiltrating emails and documents.
GitHub Malware Campaign: Fake VS Code Alerts Target Developers
Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.
Telnyx PyPI Package Compromised by TeamPCP via Steganography
TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.
Apple iOS Lock Screen Alerts Warn of Active Web-Based Exploits
Apple is now issuing direct Lock Screen notifications to warn users on outdated iOS versions about active web-based attacks and the need for urgent updates.
TeamPCP Supply Chain Attack: Telnyx PyPI Compromise and Vect Ransomware
TeamPCP campaign escalates with Telnyx PyPI compromise and Vect Ransomware mass affiliate program. Critical update for software developers and SOC teams.
Industrial OT Attacks With Physical Consequences Decline 25%
Physical-impact cyberattacks on operational technology fell 25% in 2023, driven by a ransomware lull and complex technical barriers in OT environments.
Geopolitical Exploitation of Compromised IP Cameras
Nation-states including Russia and Iran are weaponizing compromised IP cameras for battlefield intelligence and critical infrastructure surveillance.
OpenAI Model Behavior Bug Bounty: Reporting AI Safety Risks
OpenAI launches a bug bounty program targeting model abuse and safety risks. Learn how to report jailbreaks and bypasses to improve enterprise AI security.
Palo Alto Networks Recruiter Scam and Quantum Security Outlook
Threat actors are impersonating Palo Alto Networks recruiters to target security professionals, while Google sets a 2029 deadline for quantum computing.
EC Investigates Breach After IntelBroker Claims AWS Account Hack
The European Commission is investigating a security breach of its AWS infrastructure after threat actor IntelBroker claimed to have stolen user database records.
Agentic GRC Implementation: Scaling Security Compliance with AI Agents
Explore how agentic GRC transforms compliance from manual evidence collection to automated risk leadership, requiring a shift in security team operations.
AitM Phishing Campaign Targets TikTok Business via Turnstile Evasion
Security researchers have identified a sophisticated AitM phishing campaign using Cloudflare Turnstile to hijack TikTok for Business accounts for malvertising.