All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Google’s Path to Quantum-Safe Chrome HTTPS via Merkle Tree Certificates
Google is developing Merkle Tree Certificates (MTCs) for Chrome to transition the web toward post-quantum cryptography and enhance HTTPS certificate security.
North Korean APT Bridges Air Gaps with New Malware Suite
North Korean threat actors utilize malicious LNK files and specialized USB propagation tools to compromise air-gapped networks. Analysis and defense guide.
North Korean Malicious npm Packages: Detecting Contagious Interview
North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.
APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence
Akamai reports Russia-linked APT28 exploited CVE-2026-21513 in the MSHTML Framework as a zero-day before Microsoft's February 2026 security patch updates.
CVE-2025-24036: Critical RCE in Ivanti Connect Secure — Patch Now
Exploit analysis of CVE-2025-24036 in Ivanti Connect Secure and Policy Secure. Learn to detect unauthenticated RCE attempts and apply mitigation strategies.
ClawJacked Vulnerability in OpenClaw AI Agent Enables Data Hijacking
Analysis of the ClawJacked attack where malicious websites can hijack local OpenClaw instances to steal sensitive LLM API keys and private conversation data.
Advertisement
Claude Code Weaponized in Mexican Government Cyberattack
Analysis of how threat actors leveraged Anthropic’s Claude Code to automate exploitation and exfiltrate 150GB of data from Mexico's infrastructure ministry.
Samsung Settles Texas Privacy Dispute Over Smart TV Data Collection
Samsung settles with Texas over unauthorized smart TV data collection, mandating explicit consent for ACR features and highlighting regional privacy risks.
QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware
Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.
ClawJacked: Hijacking Local OpenClaw AI Agents via WebSocket
A high-severity vulnerability in the OpenClaw AI gateway allows malicious websites to take control of local AI agents by exploiting WebSocket flaws.
Korean Tax Agency Leak Leads to $4.8M Cryptocurrency Theft
South Korea's National Tax Service accidentally leaked a wallet's mnemonic seed phrase in a press release, allowing hackers to drain $4.8 million.
Analysis of the Kimwolf Botnet and Threat Actor 'Dort'
An analysis of the Kimwolf botnet operator 'Dort', including retaliatory TTPs like DDoS, swatting, and the exploitation of undisclosed vulnerabilities.
Canadian Tire Data Breach Impacts 38 Million Accounts
Canadian Tire confirms a massive data breach affecting 38 million customer accounts, exposing PII and encrypted passwords. Analysis of security risks.
Google Cloud API Keys Exposed via Public Gemini Access
Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.
Pentagon Designates Anthropic as AI Supply Chain Risk
The Pentagon designated Anthropic a supply chain risk following disputes over Claude AI usage policies regarding autonomous weapons and mass surveillance.
Enhancing Wireless & Drone Defense for Major Urban Events
As cities host major events, security posture must extend beyond traditional physical and cyber defenses to address complex wireless and drone threats.
Ransomware Realities: Singing River Health and Healthcare Resilience
Analysis of the ransomware attack on Singing River Health System, focusing on the Rhysida threat group and the technical impact of EHR downtime on patient care.
Federal Directive Mandates Phase-Out of Anthropic AI from U.S. Agencies
All U.S. federal agencies must discontinue Anthropic technology, impacting AI supply chains while OpenAI, Google, and xAI maintain their government contracts.
The Impact of Opaque Breach Transparency on Cybersecurity Defense
An analysis of how minimal data breach disclosure hinders threat intelligence sharing and why technical transparency is vital for collective defense.
APT37 Deploys SHROUDEDVUE Malware to Target Air-Gapped Networks
North Korean threat actor APT37 utilizes new malware families like SHROUDEDVUE and WASHSYNC to infiltrate air-gapped systems via removable USB drives.
Windows 11 Hardens Batch File Execution to Counter Script Attacks
Microsoft tests security enhancements for batch and CMD files in Windows 11 Insider Build 27723 to mitigate Living-off-the-Land (LotL) script abuse.
900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation
Over 900 Sangoma FreePBX instances are currently infected with web shells following a command injection campaign first observed in late 2025.
DOJ Seizes $61M in Tether Linked to Global Pig Butchering Scams
The U.S. Department of Justice seized $61 million in Tether (USDT) tied to pig butchering investment fraud, marking a major blow to criminal laundering networks.
Phishing Campaign Leverages Donut Loader via Spoofed FedEx Alerts
Analysis of a phishing campaign using fake FedEx delivery notifications to deliver the Donut loader framework for in-memory shellcode execution.