All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
7-Stage Phishing Chain Targets Outpost24 C-Suite via Redirects
Security researchers identify a sophisticated 7-stage phishing attack targeting Outpost24 executives using legitimate domains to evade email gateways.
EU Sanctions China and Iran Entities for Critical Infrastructure Attacks
The EU Council imposes sanctions on Chinese and Iranian entities for cyberattacks targeting critical infrastructure and intellectual property theft.
Amazon Bedrock and SGLang AI Flaws Enable RCE and Data Exfiltration
Researchers reveal DNS-based exfiltration and RCE vulnerabilities in Amazon Bedrock and SGLang AI frameworks, highlighting critical sandbox escape risks.
Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis
The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.
UK Companies House Vulnerability: API Flaw Exposed Millions of Firms
A broken access control vulnerability at UK Companies House allowed unauthorized access to sensitive records and potential modification of corporate filings.
Tech Giants Pledge $12.5M to Bolster Open Source Software Security
Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.
Advertisement
Hiding Malicious Commands from AI via Font-Rendering Manipulation
Learn how attackers use font-rendering tricks to bypass AI safety filters and execute prompt injection attacks against LLM-powered assistants.
Securing Autonomous AI Agents: Identity and Access Management
Enterprises must address the security risks of autonomous AI agents by treating them as non-human identities with granular access controls and monitoring.
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.
Exploiting IPv4-Mapped IPv6 Addresses to Obfuscate Web Scanning
Attackers leverage RFC 4038 IPv4-mapped IPv6 addresses to bypass security filters and obfuscate scanning activities targeting proxy-related URLs.
Tracebit Raises $20M to Scale Cloud-Native Deception Technology
Tracebit secures $20M in Series A funding to expand its cloud-native deception platform, helping SOC teams detect lateral movement and credential theft.
Tech Giants Sign Industry Pact to Combat Online Scams and Fraud
Leading tech firms including Google, Meta, and Microsoft sign a collaborative pact to enhance cross-platform intelligence sharing and fight online scams.
Windows 11 24H2 Samsung Galaxy Book C: Drive Access Fix
Microsoft releases technical guidance to resolve C: drive access denied errors and application failures on Samsung Galaxy Book devices running Windows 11.
LeakNet Ransomware: Stealthy Exploitation via Deno and ClickFix
LeakNet ransomware adopts ClickFix social engineering and the Deno runtime for stealthy initial access and loader deployment in corporate environments.
Konni Group Deploys EndRAT via Phishing and KakaoTalk Hijacking
North Korean threat actor Konni leverages spear-phishing and KakaoTalk desktop exploitation to distribute EndRAT malware and facilitate lateral movement.
Securing AI Infrastructure: Addressing the Skills Gap in Adversarial Testing
Pentera's 2026 report reveals significant gaps in AI security, highlighting how CISOs struggle with outdated tools and a lack of specialized skill sets.
CVE-2025-47813: CISA Warns of Wing FTP Server Path Leakage Exploitation
CISA adds CVE-2025-47813 to its KEV catalog, highlighting active exploitation of a Wing FTP Server information disclosure flaw that leaks internal server paths.
Earth Kaluu Cyberespionage Campaign Targets SE Asian Military Orgs
An investigation into the China-nexus Earth Kaluu campaign reveals long-term persistence in Southeast Asian military networks using custom backdoors.
GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions
Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.
CVE-2025-47813: Wing FTP Server Information Disclosure Added to KEV
CISA adds CVE-2025-47813 to the Known Exploited Vulnerabilities catalog, signaling active exploitation of Wing FTP Server. Immediate patching is required.
Olympic Cybersecurity: Lessons from Paris 2024 to Milan 2026
Analyze the cybersecurity strategies from Paris 2024 used to protect global events and how they inform preparations for the Milan Cortina 2026 Winter Games.
CVE-2024-50498: Wing FTP Server Exploited in RCE Chains — Patch Now
CISA adds CVE-2024-50498 to its KEV catalog after reports of active exploitation. Learn how to secure Wing FTP Server versions prior to 7.5.0 from RCE chains.
Remote Device Wiping Attack Hits Stryker via Microsoft Environment
An attack on medical technology firm Stryker resulted in the remote wiping of tens of thousands of devices by leveraging internal management tools and identity.
GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection
The GlassWorm campaign uses stolen GitHub tokens to inject malicious code into Python repositories, including Django and machine learning projects.