All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Aeternum C2 Leverages Polygon Blockchain for Command-and-Control
Aeternum C2 loader uses the Polygon blockchain to store encrypted instructions, creating a decentralized infrastructure resilient to traditional takedowns.
Recorded Future Integrates CYBERA Data to Combat Money Mule Networks
Recorded Future partners with CYBERA to integrate verified scam-linked bank account data, enhancing payment fraud detection and money mule mitigation efforts.
Gambit Security Raises $61M to Converge Physical and Cyber Security
Gambit Security exits stealth with $61M in funding to integrate physical access control and video surveillance into modern enterprise IT security stacks.
Anthropic Patches Claude Code Vulnerabilities Enabling Silent Hacking
Anthropic addressed flaws in Claude Code that allowed attackers to execute arbitrary commands on developer devices via malicious repository configurations.
Ransomware Payment Rates Hit All-Time Low Despite Surge in Attacks
Ransomware payment rates dropped to a record 28% in 2023 as organizations improve recovery and face increasing legal pressure against paying threat actors.
Olympique Marseille Confirms Data Leak Following Heller Cyberattack
French football club Olympique de Marseille investigates a data breach after the Heller extortion group leaked 3.5 GB of sensitive player and staff records.
Advertisement
Threat Intelligence Analysis: Kali Linux AI Integration and Browser Crash Traps
Analysis of Kali Linux Claude AI integration, Chrome browser crash traps, and the ongoing exploitation of WinRAR vulnerabilities by LockBit affiliates.
UAT-10027 Deploys Dohdoor Backdoor via DNS-over-HTTPS
UAT-10027 targets U.S. healthcare and education sectors using the novel Dohdoor backdoor, leveraging DNS-over-HTTPS for stealthy C2 communication.
Entropy Deficiencies in LLM-Generated Passwords
Research indicates that Large Language Models produce predictable passwords with biased character distributions, increasing vulnerability to targeted attacks.
US Sanctions Russian Exploit Broker Operation Zero
US Treasury sanctions Russian exploit broker Operation Zero and its owner Sergey Zaytsev for facilitating zero-day trades with Russian intelligence agencies.
Zyxel Fixes Critical RCE Vulnerability in UPnP Implementation
Zyxel releases patches for CVE-2024-42057, a command injection flaw in the UPnP function of several VMG and fiber router models, allowing unauthenticated RCE.
New York Sues Valve Over Alleged Illegal Gambling in Loot Boxes
The New York Attorney General sues Valve Corporation, alleging that loot boxes and skin trading ecosystems facilitate illegal gambling targeting minors.
Malicious StripeApi.Net NuGet Package Targets Financial API Tokens
Researchers identify a typosquatting NuGet package, StripeApi.Net, designed to mimic official Stripe libraries and exfiltrate sensitive financial API keys.
Microsoft Warns of Fake Next.js Repos Delivering In-Memory Malware
Microsoft warns developers of a coordinated campaign using malicious Next.js repositories disguised as job assessments to deliver in-memory malware.
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited for Admin Access
CVE-2026-20127 is a critical CVSS 10.0 flaw in Cisco SD-WAN controllers exploited since 2023, allowing unauthenticated remote administrative access.
Hypervisor-Based Persistence: Abusing Virtual Machines for Stealth
Analysis of how threat actors leverage virtualization platforms to host malicious guest OSs, bypassing host-level EDR and maintaining persistent access.
Optimizing Honeypot Log Analysis Using AI and LLM Orchestration
An analysis of how AI-assisted log processing reduces noise in DShield and Cowrie honeypot data, enabling analysts to identify sophisticated threat patterns.
CLAIR Model: Mapping Critical Infrastructure Interdependencies
The CLAIR Model is a conceptual framework designed to map complex interdependencies within critical infrastructure, enhancing resilience and risk assessment.
AI Code Generation Poses Supply Chain Risk to Developer Machines
Learn how AI-generated code, like from Anthropic's Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…
Chinese Police Use ChatGPT in Influence Operations Against Japan
Chinese police reportedly used ChatGPT for politically motivated influence operations to smear Japan's PM Takaichi, highlighting AI's role in disinformation campaigns.
Fake Next.js Job Interview Tests Backdoor Developers
Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.
UFP Technologies Data Breach Exposes Sensitive Personal Information
Medical device manufacturer UFP Technologies confirms a February 2024 cyberattack led to the theft of Social Security numbers and personal data.
Cisco SD-WAN Exploitation: Critical Authentication Bypass & Escalation
CISA alerts on active global exploitation of Cisco SD-WAN, leveraging CVE-2026-20127 for initial access and CVE-2022-20775 for privilege escalation.
CISA Adds Two Cisco SD-WAN Exploits to KEV Catalog
CISA adds CVE-2022-20775 (Path Traversal) and CVE-2026-20127 (Auth Bypass) affecting Cisco SD-WAN to its Known Exploited Vulnerabilities Catalog.