All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
CVE-2024-4510: Zimbra Collaboration Suite XSS Exploitation Guide
CISA adds CVE-2024-4510 to the KEV catalog following active exploitation of a Zimbra Collaboration Suite XSS vulnerability. Patch ZCS version 9.0.0 today.
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs
US Treasury sanctions North Korea's IT worker network used to fund WMD programs. Learn how these actors use fake identities and how to secure remote hiring.
Adminer & phpMyAdmin: Attacker Scans Target Database Management Tools
Runtime Rebel observes increased honeypot scans targeting Adminer and phpMyAdmin.
DarkSword iOS Exploit Chain: Analyzing Multi-Actor Zero-Day Campaigns
Analysis of the DarkSword iOS exploit chain, used by multiple actors to deploy GHOSTBLADE and GHOSTKNIFE malware via zero-day vulnerabilities in iOS 18.7.
SideWinder APT Expands Southeast Asia Espionage Campaign
SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.
Claudy Day: Prompt Injection and XSS Flaws Target Claude AI Users
Researchers uncover 'Claudy Day', a trio of vulnerabilities in Anthropic's Claude AI that allow data theft through malicious Google search results.
Advertisement
DarkSword iOS Exploit Kit: Analysis of State-Sponsored Spyware Chains
Analysis of the DarkSword exploit kit targeting six iOS vulnerabilities for state-sponsored surveillance and full device compromise via WebKit exploits.
Native Exits Stealth with $42M to Tackle Cloud Infrastructure Risks
Cloud security startup Native raises $42M to improve infrastructure resilience. Phil Venables joins the board to guide its cloud-native security strategy.
Professional Refund Fraud Economy Targets Major E-Commerce Retailers
An analysis of the professional refund-as-a-service economy, detailing TTPs used by fraudsters to exploit retailer return policies and payment platforms.
Marquis Ransomware Attack Impacts 74 Banks and 672,000 Individuals
Marquis financial services reports a massive 2025 data breach affecting 74 US banks and 672,000 customers following a ransomware incident in August.
CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now
Interlock ransomware actors are exploiting CVE-2026-20131, a critical 10.0 CVSS zero-day in Cisco FMC, to gain unauthenticated root access and deploy malware.
Ivanti vTM Authentication Bypass: CVE-2024-7593 Mitigation Guide
Ivanti patches a critical authentication bypass in Virtual Traffic Manager. Learn how CVE-2024-7593 allows unauthenticated administrative access.
Privacy Risks of Meta AI Glasses: Bluetooth Detection Strategies
Meta's AI-enabled glasses raise significant privacy concerns. Learn how Bluetooth-based detection apps identify nearby hardware to mitigate surveillance risks.
WhatsApp View Once Bypass via Modified Clients - Meta Won't Patch
A new WhatsApp View Once bypass allows recipients to persist media via modified clients. Meta declines patching, citing client-side enforcement limits.
Ubuntu CVE-2026-3888: Privilege Escalation via systemd Timing Flaw
A high-severity flaw in Ubuntu 24.04+ allows local attackers to gain root access via a systemd cleanup timing exploit tracked as CVE-2026-3888.
Unifying Context: Breaking Attack Paths via Cybersecurity Mesh
Security teams struggle to prioritize vulnerabilities without context. Discover how CSMA identifies and disrupts complex attack paths to sensitive crown jewels.
CVE-2026-32746: GNU InetUtils Telnetd RCE Mitigation Guide
Unauthenticated root RCE discovered in GNU InetUtils telnetd (CVE-2026-32746). Learn how to detect CVE-2026-32746 exploit attempts and secure port 23.
CVE-2026-20643: Apple Patches WebKit Same-Origin Policy Bypass
Apple addresses CVE-2026-20643, a critical WebKit Navigation API flaw allowing Same-Origin Policy bypass on iOS and macOS. Deploy updates immediately.
Apple CVE-2026-20643: WebKit Flaw Fixed via Background Update
Apple deploys the first Background Security Improvements update to address a critical WebKit vulnerability (CVE-2026-20643) across iOS and macOS platforms.
Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges
Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.
Credential Theft Surge: Understanding Infostealer & AI Social Engineering
Credential theft surged in late 2025, driven by sophisticated infostealer malware and AI-enhanced social engineering.
GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified
The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.
CVE-2025-13957: Hard-coded Credentials in Schneider EcoStruxure DCE
Hard-coded credentials in Schneider Electric EcoStruxure Data Center Expert v9.0 and prior (CVE-2025-13957) allow information disclosure and RCE if SOCKS Proxy is…
Siemens SICAM SIAPP SDK RCE and DoS Vulnerabilities: Patch Guide
Siemens releases security updates for SICAM SIAPP SDK versions prior to 2.1.7 to address high-severity RCE, command injection, and buffer overflow flaws.