All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit
Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.
FBI Seizes Handala Infrastructure Following Stryker Cyberattack
The FBI dismantled Handala hacktivist infrastructure after a destructive attack on Stryker wiped 80,000 devices. Learn about these wiping TTPs.
Perseus Android Banking Malware Targets Notes Apps for Data Theft
Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.
FortiGate RaaS and Citrix Exploits: Defensive Analysis of New TTPs
An analysis of the latest ThreatsDay bulletin covering FortiGate RaaS, Citrix exploits, and LiveChat phishing lures targeting perimeter security.
DJI Romo Remote Camera Access via MQTT Vulnerability
An MQTT misconfiguration in DJI Romo vacuums allows unauthorized remote control and camera access for 7,000 devices. Learn the risks and mitigation steps.
CVE-2024-38094: SharePoint RCE Exploited in the Wild — Patch Now
CISA adds CVE-2024-38094 to its KEV catalog after active exploitation of a SharePoint RCE vulnerability. Learn how to detect and remediate this threat.
Advertisement
Raven Emerges From Stealth with $20M for Runtime Security
Raven secures $20M in funding to launch a runtime application security platform designed to detect anomalous behavior and block sophisticated cyberattacks.
Perseus Android Malware: Technical Analysis of Note-Stealing Tactics
Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.
Secure Microsoft Intune Systems Against Wipe Attacks - CISA Warning
CISA urges organizations to secure Microsoft Intune following a breach at Stryker where attackers used the management tool to wipe corporate systems.
DarkSword iOS Exploit Kit: Full Takeover via 6 Flaws and 3 Zero-Days
Analysis of DarkSword, a sophisticated iOS exploit kit using six vulnerabilities, including three zero-days, for state-sponsored surveillance and data theft.
Securing Claude Code: Managing AI Agent Risk with Ceros Visibility
Discover how Claude Code creates new security challenges for engineering teams and how Ceros provides the visibility needed to govern autonomous AI agents.
EU Sanctions China and Iran Entities Over APT31 Cyber Operations
The European Union imposes sanctions on Chinese and Iranian entities linked to APT31 and state-sponsored cyber espionage targeting democratic institutions.
CISA KEV Update: CVE-2025-66376 Zimbra and SharePoint Exploits
CISA warns of active exploitation for Zimbra CVE-2025-66376, SharePoint flaws, and Cisco zero-days used in ransomware attacks. Secure your systems now.
Analysis of 'iranbot' Message in Cowrie Honeypot Logs
A peculiar 'iranbot_was_here' message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.
Ivanti Connect Secure RCE via CVE-2025-0551 — Mitigation Guide
Unauthenticated RCE vulnerabilities CVE-2025-0551 and CVE-2025-0552 impact Ivanti Connect Secure gateways. Learn how to detect and patch these critical flaws.
Hardening Endpoint Management Systems: CISA Alert on Intune Attacks
CISA warns of active cyberattacks targeting endpoint management systems, specifically Microsoft Intune.
DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users
DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.
Aura Marketing Database Breach: Impact on 900,000 Customer Contacts
Identity protection firm Aura confirms a data breach exposing nearly 900,000 marketing records. Learn about the risks of phishing and social engineering.
CVE-2025-66376: ZCS Cross-Site Scripting Actively Exploited
CISA adds CVE-2025-66376, a Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting vulnerability, to its KEV Catalog due to active exploitation.
CVE-2026-20963: Microsoft SharePoint Deserialization Exploit — Patch Now
CISA adds CVE-2026-20963, a Microsoft SharePoint deserialization vulnerability, to its KEV catalog due to active exploitation.
XBOW: AI-Powered Offensive Security Reshapes Vulnerability Discovery
XBOW, an autonomous offensive security firm, secured $120M, reaching a $1B+ valuation. Explore its AI-powered platform for vulnerability discovery and validation.
Machine-Speed Attacks: The Failure of Predictive Security Models
Analysis of why predictive security models fail against machine-speed attacks and the technical shift toward preemptive security strategies for defenders.
ConnectWise ScreenConnect Flaw Allows Unauthorized Access
ConnectWise ScreenConnect users must patch a critical cryptographic signature verification flaw enabling unauthorized access and privilege escalation.