Skip to main content

All Articles

Security Intelligence

3410 articles · Updated every 8 hours

Severity (this page):

Advertisement

Next.js Supply Chain Attacks: North Korean Actors Target Developers
HIGH
Supply Chain

Next.js Supply Chain Attacks: North Korean Actors Target Developers

North Korean state-sponsored actors leverage malicious Next.js repositories and fake job interviews to compromise developers' systems for persistent access and espionage.

Runtime Rebel Intel
4 min read · Feb 25, 2026
HIGH
Threat Intel

Chinese Cyberspies Exploit SaaS APIs in Global Espionage Campaign

A suspected Chinese threat actor breached dozens of telecom firms and government agencies, using SaaS API calls to evade detection in a global espionage campaign.

Runtime Rebel Intel
5 min read · Feb 25, 2026
CRITICAL
Vulnerabilities

Critical Cisco SD-WAN Zero-Day Exploited Since 2023

Cisco Catalyst SD-WAN critical authentication bypass (CVE-2026-20127) actively exploited since 2023, enabling remote compromise and rogue peer addition.

Runtime Rebel Intel
4 min read · Feb 25, 2026
Claude Code Flaws Enable RCE & API Key Exfiltration
HIGH
Vulnerabilities

Claude Code Flaws Enable RCE & API Key Exfiltration

Multiple security flaws in Anthropic's Claude Code AI coding assistant allow remote code execution and API credential theft via configuration mechanisms.

Runtime Rebel Intel
5 min read · Feb 25, 2026
Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches
MEDIUM
Threat Intel

Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches

Google disrupts infrastructure of China-nexus threat actor UNC2814 (GRIDTIDE) after 53 breaches across 42 countries targeting government and telecom sectors.

Runtime Rebel Intel
3 min read · Feb 25, 2026
HIGH
Threat Intel

GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally

Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.

Runtime Rebel Intel
5 min read · Feb 25, 2026

Advertisement

TOAD Emails: The 'Call This Number' Gateway Bypass Threat
MEDIUM
Threat Intel

TOAD Emails: The 'Call This Number' Gateway Bypass Threat

Attackers use Telephone-Oriented Attack Delivery (TOAD) with 'call this number' emails to bypass gateways, relying on social engineering post-call.

Runtime Rebel Intel
4 min read · Feb 25, 2026
HIGH
Threat Intel

Google Disrupts Chinese Espionage Actor UNC2814 Targeting Telecoms

Google and Mandiant disrupt UNC2814, a Chinese state-sponsored actor active since 2017, targeting 42 countries across telecom and government sectors.

Runtime Rebel Intel
4 min read · Feb 25, 2026
HIGH
Threat Intel

Stolen Credentials and the Escalation of Agentic AI Attacks

IBM X-Force reports 56% of 2025 vulnerabilities require no authentication, enabling agentic AI to weaponize stolen credentials and expand attack blast radius.

Runtime Rebel Intel
4 min read · Feb 25, 2026
MEDIUM
Threat Intel

OpenClaw Underground Trends: Assessing Hype vs. Operational Risk

Flare telemetry reveals a gap between high OpenClaw chatter on Telegram and actual exploitation, highlighting the need to distinguish hype from threat.

Runtime Rebel Intel
4 min read · Feb 25, 2026
HIGH
Data Breach

Marquis Sues SonicWall Over Ransomware Breach Impacting 74 Banks

Marquis Software Solutions alleges SonicWall's gross negligence in securing cloud backups led to a ransomware attack affecting 74 U.S. financial institutions.

Runtime Rebel Intel
4 min read · Feb 25, 2026
Optimizing Incident Triage to Mitigate Enterprise Business Risk
INFO
Threat Intel

Optimizing Incident Triage to Mitigate Enterprise Business Risk

Examine how inefficient security incident triage increases business risk, escalates operational costs, and leads to missed SLAs in the modern SOC.

Runtime Rebel Intel
4 min read · Feb 25, 2026
SLH Recruits Women for $1,000 IT Help Desk Vishing Attacks
HIGH
Threat Intel

SLH Recruits Women for $1,000 IT Help Desk Vishing Attacks

Scattered LAPSUS$ Hunters (SLH) are offering financial incentives to recruit women for vishing campaigns targeting corporate IT help desks and IAM systems.

Runtime Rebel Intel
4 min read · Feb 25, 2026
MEDIUM
Threat Intel

Data Poisoning Risks in Real-Time AI Search and Ingestion

A recent experiment highlights how rapid web scraping for AI models like Gemini and ChatGPT enables data poisoning attacks through unverified web content.

Runtime Rebel Intel
4 min read · Feb 25, 2026
Quantitative Scoring for OT Incidents: The Richter Scale Model
INFO
Threat Intel

Quantitative Scoring for OT Incidents: The Richter Scale Model

Analysis of a new logarithmic scoring system designed to quantify the physical magnitude and technical severity of operational technology (OT) cyberattacks.

Runtime Rebel Intel
4 min read · Feb 25, 2026
MEDIUM
Data Breach

Wynn Resorts Confirms Employee Data Breach Linked to ShinyHunters

Wynn Resorts confirms a data breach affecting employee information after the ShinyHunters group removed stolen records from a dark web leak site.

Runtime Rebel Intel
4 min read · Feb 25, 2026
INFO
Threat Intel

Cybersecurity M&A Trends 2025: Analysis of 426 Industry Deals

SecurityWeek reports 426 cybersecurity M&A deals in 2025, highlighting a disciplined market shift toward GRC, data protection, and identity management.

Runtime Rebel Intel
4 min read · Feb 25, 2026
HIGH
Threat Intel

Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia

Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.

Runtime Rebel Intel
4 min read · Feb 25, 2026
INFO
Threat Intel

US Treasury Sanctions Russian Broker for Stolen Zero-Day Exploits

The US sanctions Artem Kruglov and associated firms for brokering stolen hacking tools and zero-day exploits for Russian intelligence services.

Runtime Rebel Intel
4 min read · Feb 25, 2026
L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker
HIGH
Threat Intel

L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker

Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.

Runtime Rebel Intel
4 min read · Feb 25, 2026
National Security Risks of Manual Data Transfer Processes
INFO
Threat Intel

National Security Risks of Manual Data Transfer Processes

Report reveals 50% of national security organizations rely on manual data transfers, creating systemic risks and critical intelligence latency.

Runtime Rebel Intel
4 min read · Feb 25, 2026
Interpol’s Operation Red Card 2.0: 651 Arrests Targeting Cybercrime
MEDIUM
Threat Intel

Interpol’s Operation Red Card 2.0: 651 Arrests Targeting Cybercrime

INTERPOL and AFRIPOL's Operation Red Card 2.0 disrupts West African cybercrime syndicates, leading to 651 arrests and $4.3 million in seized funds.

Runtime Rebel Intel
4 min read · Feb 25, 2026
INFO
Threat Intel

Windows 11 KB5077241: Native Sysmon Integration and BitLocker Updates

Microsoft integrates native Sysmon and enhances BitLocker management in the Windows 11 KB5077241 optional update, providing advanced telemetry for defenders.

Runtime Rebel Intel
4 min read · Feb 25, 2026
CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog
HIGH
Vulnerabilities

CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog

CISA confirms active exploitation of FileZen CVE-2026-25108, an OS command injection flaw. Organizations must patch immediately to prevent command execution.

Runtime Rebel Intel
4 min read · Feb 25, 2026