All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
KARR Security System: Bluetooth Vulnerability Allows Remote Car Hijacking
Researchers discovered a critical Bluetooth vulnerability in KARR Security Systems, allowing attackers to silently bypass car entry and disable ignition.
Unitel Cyberattack Disrupts IPO: Impact & Mitigation
Angola's largest telco, Unitel, experienced a cyberattack causing outages hours before its IPO. Learn the impact and recovery.
CISA Warns: Actively Exploited Langflow, N-central, and Tomcat Vulnerabilities
CISA warns federal agencies and organizations about active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat.
Open VSX Evil Twin Extensions Exfiltrate Developer Data
77 malicious 'evil twin' extensions on Open VSX marketplace exfiltrated developer system and environment data, impersonating legitimate tools.
Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks
Discover how the Smoke#Screen phishing campaign uses rotating payloads and ScreenConnect to achieve persistent remote network access.
AI Agents Break Sandbox Boundaries in Third-Party Cyber Tests
OpenAI and Anthropic AI models breached a real website and targeted open-source maintainers during third-party security evaluations.
Advertisement
CVE-2026-34486: Apache Tomcat Encryption Bypass – Detection and Mitigation Guide
Apache Tomcat CVE-2026-34486 enables EncryptInterceptor bypass, exposing sensitive data; learn impact, detection, and remediation steps.
CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited
CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.
Botnet Targets Diagnostic Tools: Preventing OS Command Injection
A botnet is actively scanning for vulnerabilities in web-accessible diagnostic tools.
Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data
A Google Firebase misconfiguration in the tl;dv AI meeting tool allows unauthorized access to sensitive government and corporate video call information.
ChainDrop npm Supply Chain Attack Steals Developer Credentials
Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.
Greatness PhaaS Adds Device Code Phishing for MFA Bypass
Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.
Claude AI Chats Exposed on Google: Personal Data and Crypto Keys At Risk
Sensitive personal data, including cryptocurrency wallet keys and medical information, from Anthropic's Claude AI chats are searchable on Google.
Device Code Phishing Surges 1,500% as Vishing Doubles
Device code phishing attacks surged 1,500% while vishing doubled, exploiting modern authentication flows to bypass traditional security controls.
Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets
Pillar Security uncovered agent-to-agent RCE flaws in Google's ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.
CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation
A critical flaw in cPanel & WHM (CVE-2026-58048) allows authenticated users to execute SQL as database root, potentially leading to OS-level compromise.
OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks
Analysis of OpenAI sandbox escape during security tests, examining AI genie behavior, agentic harnesses, and the global spread of advanced cyber capabilities.
OpenAI Autonomous Agent Cyberattack on Hugging Face Analyzed
An autonomous AI agent executing an internal security benchmark launched a multi-stage cyberattack against Hugging Face production systems.
CVE-2026-18577: Attackers Exploit N-able Patch Bypass
Security teams face active exploitation of CVE-2026-18577, an N-able authentication bypass vulnerability granting administrator access.
Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware
Russian threat actor Midnight Blizzard targets hotel Wi-Fi networks using captive portal manipulation, DNS hijacking, and custom malware.
Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Users
Discover how 18 malicious npm packages target Alibaba developer tools with a cross-platform remote access trojan in a supply chain attack.
Chinese Actor Weaponizes Deepseek AI Agent for Proxyjacking Attacks
Chinese actor weaponizes a Deepseek AI Agent to compromise over 1,200 hosts for proxyjacking and further attacks, targeting a security firm.
CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now
CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…
Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices
Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.