All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
TikTok for Business Phishing Campaign Evades Security Bots
A new TikTok for Business phishing campaign uses sophisticated bot-evasion techniques to steal corporate credentials and hijack advertising assets.
UK Sanctions Xinbi Marketplace Over Southeast Asian Scam Network Ties
UK sanctions the Xinbi marketplace for enabling Southeast Asian scam centers to conduct pig butchering fraud using stolen data and satellite equipment.
Claude Chrome Extension Zero-Click Prompt Injection Vulnerability
A critical flaw in Anthropic's Claude Chrome extension allowed websites to silently inject malicious prompts using zero-click XSS techniques.
AI Regulation Rollbacks and the 2026 US Midterm Election Threat Landscape
Analysis of the US executive order restricting state AI regulation and its impact on cybersecurity, election integrity, and emerging adversary TTPs.
Intermediaries and Brokers Fuel Global Spyware Market Expansion
Research reveals how third-party resellers and brokers bypass government restrictions to expand the global reach of commercial spyware operations.
HP and Dell Launch Quantum-Resistant PC and AI Security Protections
HP and Dell introduce quantum-resistant hardware and AI-driven security tools to protect firmware and data against future decryption threats and exploits.
Advertisement
Alleged RedLine Infostealer Admin Extradited to US
US extradites Hambardzum Minasyan, suspected administrator of RedLine Malware, following Operation Magnus. Analysis of RedLine MaaS and defense strategies.
RedLine Infostealer Admin Extradited: Strategic Impact on MaaS
An Armenian national has been extradited to the US for allegedly managing RedLine Infostealer, a pivotal development in the ongoing Operation Magnus.
Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code
Kaspersky researchers reveal that the Coruna iOS exploit kit reuses sophisticated kernel exploit code from the 2023 Operation Triangulation campaign.
CVE-2024-38077: RCE in Windows Remote Desktop Licensing — Patch Now
Technical analysis of CVE-2024-38077, a critical heap overflow vulnerability in Windows Remote Desktop Licensing Service allowing unauthenticated RCE.
Apple Addresses 85 Vulnerabilities in Recent OS Updates
Apple released significant security updates patching 85 vulnerabilities across macOS, iOS, iPadOS, tvOS, watchOS, and visionOS, with no active exploitation reported.
EU Leadership in Cybersecurity Dialogue at RSA Conference 2024
At RSAC 2024, EU officials are leading critical discussions on cybersecurity challenges, signaling a shift in global cyber policy influence.
CVE-2024-34102: PolyShell Exploits Target 56% of Magento Stores
Attackers are aggressively exploiting the CosmicSting vulnerability (CVE-2024-34102) in Magento and Adobe Commerce stores using PolyShell polyglot web shells.
GitHub Copilot Autofix: AI-Driven Vulnerability Remediation in GHAS
GitHub integrates AI-powered scanning into Advanced Security to detect and remediate vulnerabilities across more languages using Copilot Autofix.
CVE-2026-33017: Langflow Code Injection - Patch Immediately
CISA adds actively exploited Langflow Code Injection Vulnerability (CVE-2026-33017) to KEV catalog. Critical patch urged for all organizations.
Risks of Public Cyber Attribution: Strategic Considerations
Publicly attributing cyberattacks carries significant risks, from diplomatic fallout to escalating aggression.
Torg Grabber Infostealer: Threat to 728 Crypto Wallets
Analysis of Torg Grabber infostealer, detailing its methods for exfiltrating sensitive data from 728 cryptocurrency wallets and 850 browser extensions.
Bubble Platform Abuse: Credential Phishing Targets Microsoft Accounts
Threat actors are abusing the Bubble no-code platform to host sophisticated phishing campaigns, bypassing traditional detection and targeting Microsoft account…
Russian Authorities Arrest LeakBase Admin for Stolen Data Sales
Russian law enforcement arrested the alleged administrator of LeakBase, a major marketplace for stolen credentials, disrupting a key cybercrime resource.
Palo Alto Networks Recruitment Fraud: Analysis of Phishing Tactics
Phishing campaigns posing as Palo Alto Networks recruiters leverage LinkedIn data and psychological tactics to defraud job seekers in the security industry.
Russian TA551 Cybercriminal Ilya Angelov Sentenced to 2 Years
Ilya Angelov, a member of the TA551 (Shathak) cybercrime group, was sentenced to two years in prison for his involvement in malware and phishing operations.
Onit Security Raises $11M for Continuous Exposure Management
Israeli startup Onit Security secures $11 million in seed funding to scale its platform for identifying and prioritizing exploitable enterprise exposures.
Underground Markets Pivot to Premium AI Account Trading
Cybercriminals are increasingly trading stolen premium AI accounts to enhance social engineering, automate malware creation, and bypass safety filters.
Citrix NetScaler Info Disclosure: CVE-2024-8069 Patch Guide
Citrix urges immediate patching of two NetScaler ADC and Gateway vulnerabilities, including a flaw similar to the high-impact CitrixBleed exploit.