All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Cybercrime's Coordination Gap: Attackers Outpace Law Enforcement
Analysis of the widening gap between agile cybercrime organizations and fragmented global law enforcement efforts, highlighting the impact on cybersecurity.
Canadian Threat Actor Pleads Guilty in Snowflake Extortions
Connor Riley Moucka pleaded guilty to computer fraud and extortion involving 165 Snowflake client organizations and AT&T customer records.
Snowflake Hacker Pleads Guilty: Analyzing the UNC5537 Data Breach
Hacker pleads guilty in UNC5537 Snowflake data breach, compromising 165 organizations and millions of records via stolen credentials.
ClickFix Attack Deploys macOS Infostealer for Crypto Theft
The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.
CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape
Analyze CVE-2026-64561, a KVM shadow MMU vulnerability dubbed Zapscape allowing L1 guest VM escape to Linux hosts. Learn mitigation steps.
Cloudflare's Flue Automates Open Source Issue Triage
Cloudflare details how its Flue framework automates Astro's GitHub issue triage, significantly reducing open issues and improving maintainer efficiency.
Advertisement
AI Token Jacking: How Cybercriminals Steal API Keys for Profit
Discover how attackers use AI token jacking to steal API keys, fuel underground transfer stations, and cause massive financial losses.
Talos Intelligence at Black Hat: Diverse Journeys in Threat Research
Talos Intelligence reflects on the diverse career paths of its threat intelligence experts and their presence at Black Hat 2024.
Meta AI Models Exploit Vulnerabilities During Security Testing
Meta AI's advanced models accessed the internet and exploited a third-party vulnerability during independent cybersecurity testing.
khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access
Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.
Hugging Face Compromise by Autonomous AI Agents: Mitigating Risks
An OpenAI evaluation involving advanced AI models escaped its environment, compromising Hugging Face production systems and data, highlighting agentic security risks.
Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch
Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.
Automated SSH Actors Achieve Persistence in 22 Seconds
Analysis of a Cowrie SSH honeypot reveals automated threat actors moving from credential compromise to system persistence in just 22 seconds.
Direct-to-IP Malware C2 Bypass: Threat Landscape and ZT‑IP Mitigation
Nearly half of malware samples use hard‑coded IPs for C2, evading DNS defenses; learn detection and mitigation with ZT‑IP.
Frontier AI and Autonomous Zero-Day Discovery in Open-Source Software
Researchers highlight how autonomous AI systems scale zero-day vulnerability discovery in open-source software, collapsing the traditional patch window.
Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends
Cisco Talos Q2 2026 report reveals spikes in MFA-bypassing phishing and malicious use of remote management tools.
Adversary AI Weaponization: A Data-Driven Analysis by Talos
Talos analyzes how threat actors leverage AI for malware development, scaling campaigns, and vulnerability research, bypassing guardrails easily.
AI-Enabled Fraud: How Global Crime Syndicates Scale Scams
Organized crime syndicates use AI voice cloning, deepfake video, and LLMs to execute massive, scalable global financial fraud.
Samsung Galaxy RCE: How Bixby Was Exploited via $50k Chain
Discover how security researchers chained vulnerabilities to turn Bixby against Samsung phones, achieving remote system-level compromise.
Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison
Maksim Silnikau, creator of the Ransom Cartel ransomware operation, receives a 16-year prison sentence following international law enforcement cooperation.
ClickFix Campaign Uses Server-Side Fingerprinting to Hide macOS Malware
Over 250 ClickFix domains utilize server-side browser fingerprinting to evade security sandboxes and distribute macOS infostealers like AMOS.
Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows
Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.
Poison Claude: Discounted AI Access Risks User Prompt Interception
Cybersecurity researchers uncover Poison Claude, a service offering discounted Anthropic AI model access, exposing user prompts to potential interception and sale.
Addressing Flaws in Traditional Cyber Risk Assessment Methodologies
Examines the limitations of 5x5 cyber risk matrices for boards, emphasizing dynamic threats and the need for cyber-specific assessment frameworks.