All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Encrypted Client Hello (ECH): Implications for Network Visibility
New RFCs for Encrypted Client Hello (ECH) signal a shift in TLS. This analysis explores ECH's privacy benefits and challenges for network security monitoring.
Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors
An undefined Chinese-speaking actor conducts long-term cyber espionage against critical Asian sectors using custom malware and living-off-the-land binaries.
ClickFix Attack: Windows Terminal Used for Detection Evasion
The ClickFix attack leverages fake CAPTCHA pages to trick users into pasting malicious commands into Windows Terminal, bypassing traditional detection methods.
Cybersecurity M&A Trends: February 2026 Market Analysis
Analysis of 42 significant cybersecurity mergers and acquisitions in February 2026, highlighting market consolidation, strategic shifts, and implications for security…
Rethinking Password Audits: Protecting Breached & Service Accounts
Traditional password audits often miss critical attack vectors. Learn how compromised credentials, orphaned, and service accounts pose significant threats and how to…
Phishing Alert: Impersonation of US City/County Officials Targets Permit Applicants
The FBI warns of active phishing campaigns impersonating US city and county officials to target businesses and individuals seeking permits, aiming for fraud and data…
Advertisement
Qualcomm 0-Day and iOS Exploit Chains: Impact & Mitigation Strategies
This weekly recap details active exploitation of a Qualcomm zero-day, iOS exploit chains, and emerging 'AirSnitch' attack methods. Learn what defenders should prioritize.
UNC4899 Exploits AirDrop for Crypto Firm Breach — Analysis
UNC4899 breached a crypto firm using AirDrop to bypass network security. This analysis explores the TTPs of North Korean threat actors in 2025.
AirSnitch: Cross-Layer Desynchronization Enables Wi-Fi MitM Attacks
Research reveals AirSnitch, a vulnerability exploiting Wi-Fi Layers 1 and 2 to execute bidirectional MitM attacks across home and enterprise networks.
InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers
The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.
Abusing .arpa Infrastructure TLDs for Phishing Campaigns
Threat actors are leveraging the .arpa infrastructure TLD and DNS management controls to mask malicious content and increase phishing success rates.
Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer
Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.
Security Platform Consolidation: Strategies for Mid-Market Resilience
Explore how mid-market organizations leverage security platform consolidation to mitigate supply chain risks and meet enterprise-level compliance standards.
Chinese APT Group Targets Asian Critical Infrastructure via Web Exploits
A Chinese threat actor is targeting high-value infrastructure across Asia using web server exploits and Mimikatz for long-term cyber espionage campaigns.
AWS Honeytoken Implementation: Proactive Detection of IAM Credential Theft
Learn how to implement AWS honeytokens using IAM and CloudTrail to detect unauthorized credential usage and mitigate lateral movement in cloud environments.
AI Agent Security Risks: Defending Against Autonomous Tool Misuse
Analysis of the security implications of autonomous AI agents, focusing on prompt injection, privilege escalation, and the erosion of trust boundaries.
CVE-2026-20127: Cisco Catalyst SD-WAN Exploited — Patch Guide
WatchTowr reports widespread exploitation attempts targeting a recent CVE-2026-20127 vulnerability in Cisco Catalyst SD-WAN devices, urging immediate action.
Abusing .arpa DNS and IPv6 to Bypass Phishing Defenses
Threat actors exploit .arpa domains and IPv6 reverse DNS for phishing evasion, bypassing email security gateways and domain reputation checks.
EU Court Adviser: Banks Must Refund Phishing Victims Immediately
CJEU Advocate General issues opinion requiring banks to refund unauthorized phishing transactions by the next business day under PSD2 regulations.
Cylake Launches Local AI-Native Security for Data Sovereignty
Cylake introduces an AI-native security platform that processes data locally to address data sovereignty and privacy concerns in sensitive environments.
Velvet Tempest Deploys Termite Ransomware via ClickFix and CastleRAT
Velvet Tempest leverages ClickFix social engineering and CastleRAT to deploy Termite ransomware, using legitimate Windows tools for stealthy execution.
Firefox 148 Security Update: Anthropic AI Uncovers 22 Vulnerabilities
Anthropic's Claude Opus 4.6 AI model identified 22 security vulnerabilities in Firefox, including 14 high-severity flaws addressed in the version 148 release.
OpenAI Codex Security: Scanning 1.2 Million Commits for Vulnerabilities
OpenAI's Codex Security identifies over 10,000 high-severity vulnerabilities across 1.2 million commits using AI-driven detection and automated remediation.
Over 100 GitHub Repositories Distributing BoryptGrab Stealer
A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.