All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
BlackSanta Malware Targets HR Workflows to Disable EDR Systems
Russian-speaking threat actors deploy BlackSanta malware via hijacked HR workflows to terminate EDR agents and facilitate undetected data exfiltration.
Kai Emerges with $125M for AI-Driven IT/OT Security Platform
Kai Security launches from stealth with $125M to address IT and OT convergence risks using an AI-powered platform for industrial environment protection.
KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network
The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.
Entra Passkeys: Phishing-Resistant Windows Sign-In Deployment
Microsoft introduces phishing-resistant passkey support for Entra ID on Windows, leveraging Windows Hello to secure the sign-in process against credential theft.
LeakyLooker: Google Looker Studio Cross-Tenant SQL Vulnerabilities
Discover how nine vulnerabilities in Google Looker Studio, dubbed LeakyLooker, allowed cross-tenant SQL queries and sensitive data exfiltration in GCP.
KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet
KadNap malware has compromised over 14,000 edge devices, primarily Asus routers, to create a massive proxy botnet for anonymizing malicious traffic.
Advertisement
F-35 Software Sovereignty and the Risks of System Jailbreaking
An analysis of the Dutch Defense Secretary's proposal to jailbreak F-35 software to ensure maintenance autonomy and the technical cybersecurity risks involved.
Ivanti EPM CVE-2024-29824 Exploited: Technical Analysis and Patching
CISA warns of active exploitation of CVE-2024-29824 in Ivanti Endpoint Manager. Secure your Core server with our technical analysis and mitigation guide.
Escape Secures $18M to Scale Automated API Pentesting and AI Agents
Cybersecurity startup Escape secures $18 million in Series A funding to expand its AI-driven API security platform and automated pentesting capabilities.
Microsoft Windows Hotpatching to be Enabled by Default in May 2026
Microsoft will enable hotpatching by default for Intune-managed Windows devices in May 2026, allowing security updates without reboots to reduce downtime.
CVE-2024-29847: Ivanti EPM RCE Under Active Exploitation - Patch Now
CISA warns of active exploitation of a critical Ivanti EPM vulnerability (CVE-2024-29847). Learn how to mitigate this unauthenticated RCE threat immediately.
Reducing Attack Surface to Prevent Zero-Day Scrambles
Learn how attack surface reduction limits internet-facing exposure and mitigates the impact of rapidly exploited zero-day vulnerabilities.
Cylake Raises $45M for Data Sovereignty in Restricted Environments
Cylake secures $45 million to provide data sovereignty and cloud security solutions for government and defense organizations barred from public cloud.
CISA Flags SolarWinds, Ivanti, and Workspace One Flaws in KEV Update
CISA adds vulnerabilities in SolarWinds, Ivanti, and Omnissa Workspace One UEM to its Known Exploited Vulnerabilities catalog following active exploitation.
Salesforce Experience Cloud Mass-Scanning via Modified AuraInspector
Threat actors use a modified AuraInspector tool to exploit Salesforce Experience Cloud misconfigurations, exposing sensitive guest user data.
Quasar RAT Delivery via Malicious PDF and LNK Files
Technical analysis of a multi-stage infection chain using PDF lures and LNK files to deploy Quasar RAT, including detection and mitigation strategies.
InstallFix Attacks: Malvertising Spreads Fake Claude AI Code
InstallFix attacks leverage malvertising and ClickFix-style techniques to spread fake Claude AI code, targeting users of coding assistants and CLI operations.
US Cyber Strategy Shifts to Offense, Preemption, Deterrence
The White House's new cyber strategy signals a fundamental shift towards offensive, preemptive, and deterrent measures against cyber threats.
Google Cloud Security: Exploits Surpass Weak Credentials
Google Cloud reports a major shift in attack vectors, with software vulnerability exploitation now outpacing weak credentials as the primary access method.
Microsoft Teams Phishing Deploys A0Backdoor via Quick Assist
Attackers are targeting healthcare and finance employees with Microsoft Teams phishing to deploy A0Backdoor using the native Windows Quick Assist tool.
CVE-2026-1603: CISA Warns of Active Ivanti and SolarWinds Exploitation
CISA adds CVE-2026-1603, CVE-2025-26399, and CVE-2021-22054 to the KEV catalog, requiring immediate remediation for Ivanti, SolarWinds, and Omnissa systems.
Microsoft Teams Third-Party Bot Tagging Enhances Meeting Security
Microsoft Teams updates meeting lobbies to identify third-party bots, helping administrators prevent unauthorized data collection and social engineering.
Ericsson US Data Breach via Service Provider: Employee & Customer Data Compromised
Ericsson US discloses a significant data breach impacting employee and customer information, stemming from a security incident at a third-party service provider.
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.