All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
TeamPCP Targets Kubernetes Clusters with Iran-Specific Wiper Malware
TeamPCP is targeting misconfigured Kubernetes clusters to deploy a data-wiping script that specifically triggers on Iranian system configurations and locales.
WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware
North Korean threat actor WaterPlum leverages VS Code tasks.json to automate StoatWaffle malware deployment during fraudulent developer recruitment campaigns.
M-Trends 2026: Evolving Ransomware, Persistence, and SaaS Attack Vectors
M-Trends 2026 reveals critical shifts in adversary TTPs: destructive ransomware, zero-day exploitation for persistence, and voice phishing for SaaS access.
RSAC 2024: AI Security Startups Lead Innovation Sandbox Finalists
Analyze how AI-driven cybersecurity startup trends dominated the 2024 RSAC Innovation Sandbox, signaling a shift toward securing large language models.
Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys
Phishing campaign targets healthcare and government sectors with copyright infringement decoys to deliver Lumma Stealer via legitimate cloud services.
CanisterWorm Wiper Attacks Target Iran via Cloud Misconfigurations
Analysis of the CanisterWorm wiper targeting Iranian systems through cloud service vulnerabilities, shifting from financial extortion to destructive operations.
Advertisement
Mandiant M-Trends 2026: Handoff Time Shrinks to 22 Seconds
Mandiant's M-Trends 2026 report reveals a drastic reduction in initial access handoff times to 22 seconds, demanding faster detection and response.
RSAC 2026: Analyzing Pre-Event Cybersecurity Vendor Announcements
Analysis of pre-event announcements for RSAC 2026, detailing the shift toward AI-driven security operations and unified identity-centric defense strategies.
Varonis Atlas: Securing AI Data Exposure via DSPM Strategies
Varonis Atlas addresses the security risks of AI agents by providing visibility and control over sensitive data exposure in AI environments and LLM tools.
AWS Bedrock AI Agent Security: Analysis of Eight Attack Vectors
Research identifies eight critical attack vectors in AWS Bedrock, focusing on risks to integrated enterprise data and automated Lambda function execution.
CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks
Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.
Microsoft Xbox One Hardware Security Defeated via Bliss Exploit
Security researchers have bypassed Microsoft Xbox One hardware security using the Bliss voltage glitching exploit, enabling unsigned code execution.
Tycoon 2FA PaaS Recovery: Detecting AitM Phishing Infrastructure
Tycoon 2FA Phishing-as-a-Service has recovered from law enforcement disruption. Learn how this AitM platform bypasses MFA and how to protect your organization.
QNAP Patches Four Pwn2Own Vulnerabilities in QTS and QuTS hero
QNAP releases security updates for four vulnerabilities, including CVE-2024-50387 and CVE-2024-50388, exploited during the Pwn2Own Ireland 2024 competition.
Iranian Handala Group Leverages Telegram for Malware Delivery and C2
FBI alerts organizations to Handala, an Iranian MOIS-linked group using Telegram APIs for data exfiltration, ransomware, and wiper attacks across sectors.
Exchange Online Service Change: Solving Outlook for Mac Access Issues
Microsoft addresses a service disruption in Exchange Online caused by virtual account updates affecting Outlook for Mac and mobile device connectivity.
Trivy Supply Chain Attack: Malicious Docker Hub Images Identified
Attackers hijacked Trivy Docker Hub images (v0.69.4-0.69.6) to distribute infostealers and Kubernetes wipers. Learn how to detect and remediate this threat.
IRS Phishing Campaign Targets 29,000 Users with RMM Malware
Microsoft warns of a widespread IRS phishing campaign targeting 29,000 users with tax-themed lures to deploy RMM malware and steal enterprise credentials.
CVE-2021-35587: Critical RCE in Oracle Identity Manager Patched
Oracle issues emergency patches for CVE-2021-35587, a critical RCE flaw in Identity Manager with a 9.8 CVSS score. Immediate mitigation is required.
KB5085516 Emergency Update: Fix for Microsoft Account Sign-in Failures
Microsoft releases emergency KB5085516 update to resolve widespread authentication failures affecting OneDrive, Teams, and other cloud-integrated services.
Quest KACE SMA CVE-2025-32975 Exploited — Critical Patch Guidance
Threat actors are exploiting a critical CVSS 10.0 vulnerability, CVE-2025-32975, in Quest KACE Systems Management Appliances exposed to the internet.
PHP 8.1 End-of-Life: Security Risks and Upgrade Path Analysis
PHP 8.1 has reached its end-of-life status. Learn about the security implications of running unsupported software and the technical steps for remediation.
VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol
VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.
Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub
Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.