All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
LastPass Phishing Campaign Targets Master Passwords via Fake Alerts
LastPass warns of a new phishing campaign using fraudulent security alerts to steal master passwords. Learn how to identify and mitigate these vault threats.
APT41-Linked Silver Dragon Targets Governments via Google Drive C2
APT41 sub-group Silver Dragon targets European and Southeast Asian governments using public-facing server exploits and Google Drive for C2 operations.
Malicious Laravel Packagist Packages Deploy Cross-Platform RAT
Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.
CVE-2025-22719: VMware Aria Operations RCE Exploited in the Wild
CVE-2025-22719 is a critical remote code execution vulnerability in VMware Aria Operations for Networks currently being exploited by unauthenticated attackers.
VMware Aria Operations CVE-2026-22719 Exploited - Mitigation Guide
CISA adds CVE-2026-22719, a VMware Aria Operations command injection flaw, to the KEV catalog following active exploitation. Secure your systems now.
LATAM Cyber Threat Evolution: Proactive Intelligence Imperative
Latin America's cybersecurity landscape demands a shift from reactive defense to proactive threat intelligence to counter escalating PIX fraud, ransomware, and targeted…
Advertisement
CVE-2025-0282: Ivanti Connect Secure Heap Overflow — Mitigation Guide
Technical analysis of the Ivanti Connect Secure heap overflow (CVE-2025-0282) allowing unauthenticated RCE. Includes detection steps and patch guidance.
Hitachi Energy RTU500 CMU Firmware Vulnerabilities: Patch Guidance
Hitachi Energy issues critical patches for RTU500 series CMU firmware addressing high-severity DoS and information disclosure risks (CVE-2026-1773, CVE-2024-8176).
TPMS Data Leakage: Silent Vehicle Tracking via RF Sensors
Unencrypted Tire Pressure Monitoring System signals allow for passive vehicle tracking. Learn how attackers exploit unique sensor IDs to monitor movement.
Intelligence-Led Takedown of African Cybercrime Syndicate
Runtime Rebel details how a threat intelligence team supported Interpol in dismantling a major African cybercrime syndicate, leading to 574 arrests and $3M+ recovered.
AkzoNobel Cyberattack: 8Base Ransomware Targets Michigan Site
Dutch paint giant AkzoNobel confirms a network breach at its Troy facility. Analyze the impact on manufacturing and the 8Base ransomware claims in this brief.
CVE-2023-20887: VMware Aria Operations for Networks RCE Exploit Guide
CISA adds CVE-2023-20887 to its KEV catalog. Learn how to detect and patch this critical RCE flaw in VMware Aria Operations for Networks.
Mobiliti e-mobi.hu EV Chargers: Critical Auth Bypass & DoS Vulnerabilities
Critical vulnerabilities in Mobiliti e-mobi.hu EV charging stations (all versions) allow unauthenticated attackers to gain administrative control or disrupt services.
Moltbook's 'AI Theater': Unmasking Human Control in Autonomous Platforms
Runtime Rebel investigates Moltbook's 'AI-only' facade, revealing extensive human involvement.
Mitigating Shadow AI Risks: Data Leaks from AI Browsers
Banning AI browsers leads to 'Shadow AI' and uncontrolled data exposure. Learn to implement controlled enablement and robust governance to prevent data leakage.
Geopolitical Strikes on AWS Data Centers: Mitigating Physical Disaster Risk
Iranian drone strikes damaged AWS data centers in UAE and Bahrain, highlighting critical vulnerabilities to physical disasters and the urgent need for geo-redundancy.
Google Chrome Two-Week Release Cycle: Reducing the Patch Gap
Google transitions Chrome to a two-week stable release cycle to accelerate security patching and minimize the window for n-day vulnerability exploitation.
Fake IT Support Campaigns Deploy Customized Havoc C2 Payloads
Huntress identifies a new campaign using fake IT support lures and vishing to deploy Havoc C2 for data exfiltration and ransomware delivery.
CrushFTP Bruteforce Scans: Protecting Against RCE & Auth Bypass
Ongoing bruteforce scans are targeting CrushFTP servers, likely attempting to exploit past critical vulnerabilities like CVE-2024-4040 (RCE) and CVE-2025-31161 (auth…
Coruna Exploit Kit: iOS 13-17.2.1 Targeted by Multiple APTs
Google Threat Intelligence Group details Coruna, a powerful iOS exploit kit targeting versions 13.0 to 17.2.1, used by commercial vendors and nation-state actors for…
Pro-Iranian Cyber Operations Escalate Amidst Middle East Conflict
Analysis of escalating pro-Iranian cyberattacks targeting economic and physical infrastructure in retaliation for US-Israeli military actions.
Addressing the Cloud AI Agent Workload Identity Crisis
Examine the challenges of securing AI agent workloads in complex cloud environments, focusing on identity management, least privilege, and critical mitigation strategies.
Honeywell IQ4 Vulnerability: Assessing Internet Exposure & Impact
A researcher claims thousands of internet-exposed Honeywell IQ4 building controllers are vulnerable. Understand the potential impact and mitigation strategies.
SecOps Resilience: Addressing Critical Security Operations Challenges
Fig Security launches with $38M to enhance SecOps resilience. This analysis details modern security operations challenges and strategies for improving security posture.