All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.
ClickFix Social Engineering Clusters Target Windows and macOS Systems
Insikt Group identifies five ClickFix clusters using obfuscated commands to exploit native system tools via fake browser error overlays on Windows and macOS.
Section 702 Surveillance Abuse: Senator Wyden Warns of Secret NSA Law
Senator Ron Wyden issues a warning regarding undisclosed abuses of Section 702 surveillance authorities and the privacy implications for US citizens.
CSA Launches CSAI: New Standards for Autonomous AI Agent Security
The Cloud Security Alliance (CSA) has launched the CSAI foundation to address security gaps in autonomous AI agents through new standards and certifications.
TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code
TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.
RSAC 2026 Day 2: Advanced AI Automation and Cloud Security Updates
An analysis of key announcements from RSAC 2026 Day 2, focusing on AI-driven incident response, cloud security platforms, and identity-centric defense.
Advertisement
Silnikau Sentenced: BitPaymer Ransomware Botnet Operator Receives 2 Years
Russian national Maksim Silnikau sentenced for managing a botnet used in BitPaymer ransomware attacks targeting 72 U.S. companies and demanding $100 million.
Archer NX200 and NX510v Auth Bypass: CVE-2024-5035 Patch Guidance
TP-Link patches critical auth bypass CVE-2024-5035 and command injection in Archer NX routers, preventing unauthorized firmware uploads and remote code execution.
TA551 Botnet Operator Sentenced: Analyzing Shathak Ransomware Tactics
Russian national Ilya Angelov sentenced for managing the TA551 botnet, a major facilitator of ransomware attacks via sophisticated phishing campaigns.
AI Agent Autonomy: Analyzing the Machine-Speed Espionage Threat
Anthropic details a state-sponsored campaign where AI agents automated 90% of tactical operations, requiring new strategies for autonomous threat detection.
Iranian Hacktivists Target Infrastructure: Reality vs. Rhetoric
Analysis of Iran-aligned hacktivist groups, their limited technical impact on Gulf infrastructure, and the role of psychological operations in cyber warfare.
Navia Benefit Solutions Breach Exposes HackerOne Employee PII
HackerOne confirms 519 employees' PII was exposed in a third-party breach at Navia Benefit Solutions. Analysis of supply chain risks and mitigation steps.
FCC Bans Foreign-Made Routers Over National Security Concerns
The FCC has prohibited the importation of new foreign-made routers to mitigate supply chain risks and protect critical communication infrastructure from adversaries.
SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives
Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.
SVG-Based Phishing: Using Scalable Vector Graphics for Credential Theft
Discover how threat actors leverage SVG files to bypass email filters and execute credential theft through embedded JavaScript and HTML forms.
AI Coding Tools: New Challenges for Endpoint Security Defenses
A security researcher demonstrates how AI coding tools can bypass traditional endpoint security measures, prompting a reevaluation of defense strategies.
Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack
TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.
LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials
TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.
PTC Windchill RCE via CVE-2024-38472 — Mitigation and Patch Guide
PTC warns of imminent RCE threats against Windchill and FlexPLM systems. Learn how to secure your PLM environment and apply critical security updates now.
Schneider Electric Plant iT/Brewmaxx RCE via Multiple Redis Vulnerabilities
Multiple critical and high-severity vulnerabilities in Schneider Electric Plant iT/Brewmaxx 9.60+ (Redis component) enable RCE and privilege escalation, affecting…
CVE-2026-2417: Pharos Controls RCE via Missing Authentication
Critical vulnerability (CVE-2026-2417) in Pharos Controls Mosaic Show Controller firmware 2.15.3 allows unauthenticated root RCE. Upgrade to 2.16+ immediately.
Governing Agentic AI: Security Risks and Governance Lessons from OpenClaw
Explore the security implications of agentic AI systems like OpenClaw. Learn about the shift to autonomous AI actions and the need for robust governance.
US Department of Energy Unveils Project Armor Energy Security Plan
The DOE's CESER launches Project Armor, a five-year initiative to harden critical US energy infrastructure against physical hazards and cyber threats.
Firefox 149 Integrated VPN: Analysis of Privacy and Security Features
Mozilla introduces a built-in VPN in Firefox 149 with a 50GB monthly data cap, enhancing user privacy while creating new visibility challenges for SOC teams.