All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
OAuth Exploitation and EDR Termination: New Bulletin Analysis
Analysis of current threats including OAuth token theft, EDR termination techniques, Signal phishing, and 'Zombie ZIP' archive evasion strategies.
Scaling Enterprise Phishing Detection: 3 Strategies for CISOs
Discover how to scale phishing detection within your SOC by leveraging automated triage, behavioral analysis, and integrated threat intelligence feeds.
Cisco IOS XR Software Vulnerabilities: CVE-2024-20320 Patch Guide
Cisco addresses high-severity vulnerabilities in IOS XR Software, including SSH privilege escalation and DoS flaws. Essential mitigation steps for network admins.
Zoom and Splunk Patch Critical RCE and PE Vulnerabilities
Security updates for Splunk Enterprise and Zoom Desktop Client address critical vulnerabilities, including a 9.6-rated RCE and high-severity privilege escalation.
DOJ Charges Second Insider for Aiding BlackCat Ransomware Operations
The US DOJ charges a second DigitalMint employee for collaborating with BlackCat ransomware, revealing insider threats in incident response and negotiation.
Apple Patches CVE-2023-43010 WebKit Vulnerability in Older Devices
Apple backports fixes for CVE-2023-43010 in older iOS and macOS versions to defend against the Coruna exploit kit targeting WebKit memory corruption.
Advertisement
Weaponizing SOC Workloads: How Modern Phishing Exhausts Analysts
Attackers are shifting from employee deception to operational disruption by weaponizing phishing investigation workloads to overwhelm SOC analysts.
n8n RCE via CVE-2025-68613 — CISA Flags Active Exploitation
CISA adds CVE-2025-68613 to its KEV catalog after reports of active exploitation against n8n workflow automation instances. Patch now to prevent RCE.
IoT Default Credentials: Preventing Unauthorized Admin Access
The SANS ISC highlights the persistent threat of IoT devices compromised by default admin credentials. Learn critical steps to secure your smart devices.
CVE-2024-21410: Protect Microsoft Exchange from NTLM Relay Attacks
Deep dive into CVE-2024-21410, a critical privilege escalation vulnerability in Microsoft Exchange. Learn how to detect exploits and implement EPA mitigations.
Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active
Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.
INC Ransomware Oceania: Healthcare and Government Sectors Under Siege
INC Ransomware has launched a series of attacks against healthcare and government agencies in Oceania, using double extortion to compromise sensitive data.
CVE-2025-68613: n8n Improper Code Control — Actively Exploited
CISA adds CVE-2025-68613, an n8n vulnerability involving improper control of dynamically-managed code, to its KEV Catalog due to active exploitation.
Joshua Rudd Confirmed: Implications for NSA and US Cyber Command Leadership
General Joshua Rudd's confirmation to lead both NSA and US Cyber Command under the 'dual-hat' arrangement signals unified cybersecurity strategy.
Elementor Ally Plugin SQLi: Unauthenticated Data Theft Risk
An unauthenticated SQL injection vulnerability in the Elementor Ally WordPress plugin affects over 400,000 sites, risking sensitive data exposure.
WhatsApp Introduces Parent-Managed Accounts for Pre-Teens
WhatsApp rolls out new parent-managed accounts, enabling guardians to control contact lists and group access for pre-teen users, enhancing digital safety.
Manipulating Perplexity Comet AI via Reasoning-Based Phishing
Researchers from Guardio demonstrate a rapid attack vector against Perplexity’s Comet AI browser, tricking it into executing malicious phishing tasks.
Chinese Nexus Actors Pivot to Qatar: Geopolitical Espionage
Analysis of Chinese Nexus actors' shift to targeting Qatari entities amid Iranian conflict. Understand their adaptable TTPs and fortify defenses.
Stryker Wiper Attack: Iran-Backed Group Targets Medtech Operations
Analysis of a destructive wiper attack claimed by an Iran-backed hacktivist group against medical technology firm Stryker, disrupting global operations.
Wiz Joins Google Cloud: Strategic Implications for Cloud Security
Analyzes Google Cloud's landmark acquisition of Wiz, exploring the strategic impacts on cloud security posture, multi-cloud defense, and compliance for enterprises.
Handala Group Attack on Stryker: MedTech Device Wiping Incident
Iranian-linked Handala group claims wiping over 200,000 devices at medtech giant Stryker. Analysis of TTPs and mitigation for critical infrastructure.
Meta Anti-Scam Tools: Facial Recognition and WhatsApp Protection
Meta implements facial recognition and enhanced messaging warnings to combat celeb-bait ads and account takeovers across WhatsApp, Facebook, and Messenger.
Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers
Meta disrupts a global fraud network by disabling 150,000 accounts tied to Southeast Asian scam centers in coordination with international law enforcement.
n8n RCE Vulnerabilities CVE-2026-27577 and CVE-2026-27493 - Patch Now
Critical vulnerabilities in the n8n workflow automation platform allow unauthenticated remote code execution and sandbox escapes. Update instances immediately.