All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now
CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.
CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw
CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…
Coldcard Firmware Flaw Enables $70M Bitcoin Theft
A critical firmware flaw in Coldcard hardware wallets, specifically a March 2021 integration error affecting seed generation, led to over $70 million in Bitcoin theft.
Rails Active Storage RCE via Critical Flaw — Patch Now
A critical flaw in Rails Active Storage permits unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.
Balance Theory Secures $19M to Advance Cybersecurity Investment Management
Balance Theory raises $19 million in funding to help enterprises optimize and manage their cybersecurity investments, addressing critical budget allocation challenges.
Phishing Targets AI Service Users: Guard Your ChatGPT Accounts
Recent phishing campaigns impersonate popular AI services like ChatGPT to trick users into divulging credentials. Learn how to protect your accounts and data.
Advertisement
Anthropic Opus 5 Significantly Boosts Prompt Injection Resistance
Anthropic's Opus 5 demonstrates superior resistance to prompt injection attacks on the IPI benchmark, outperforming other leading LLMs, including GPT-5.6 variants.
CISA's Updated SBOM Guidance: Enhancing Software Supply Chain Transparency
CISA has released updated SBOM guidance, refining field definitions for greater software supply chain transparency. Debate continues on its impact on risk management.
Adform Script Poisoning: Crypto Wallet Swapping Attack
Adform's JavaScript was poisoned to swap crypto wallet addresses on customer sites.
Amgen Cloud Data Breach: Patient Health and Proprietary Data Exposed
Amgen confirms a data breach exposed patient health and corporate data stored in third-party cloud systems. Understand the impact and mitigation.
Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors
Ongoing cyberattacks by a suspected Chinese-speaking threat actor target Central Asian governments with OctLurk and SilkLurk backdoors for espionage and data theft.
North Korea Attribution, Data Breaches Impact OnTrac & UK Education
AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.
CISA Warns: Cyberattacks Disrupting US Water Utilities' PLCs
CISA issues an urgent warning regarding increased cyberattacks targeting internet-exposed Programmable Logic Controllers (PLCs) in US water and wastewater systems…
DeepSeek AI & Hermes Agent: Autonomous Server Exploitation
A threat actor is leveraging DeepSeek AI and the Hermes Agent for autonomous attacks against vulnerable, internet-exposed servers, demanding urgent defense.
Google Chrome Updates Resolve 1,442 Security Flaws
Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.
Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth
Cheap Android TV boxes are pre-installed with Fuyao malware, impersonating phones for ad fraud and turning devices into residential proxy nodes.
Facial Recognition at MSG: Surveillance, Privacy, and Activist Flagging
Madison Square Garden uses facial recognition on all patrons, flagging privacy activists, highlighting a 'privacy for me, surveillance for thee' dynamic in public spaces.
Interpol's I-GRIP System Curtails Fraudulent Payments: A Threat Intel Brief
Explore Interpol's I-GRIP system, a global initiative enabling rapid freezing of fraudulent payments and enhancing international cooperation against cyber-enabled…
Securing Digital Identity: Essential Certificate & Key Inventory
Understand why managing cryptographic certificates and keys, especially roots of trust, is paramount for digital security. Learn to build a robust inventory.
EU AI Act: New Team Addresses Deepfakes, Illicit Content, Hacking
The EU establishes a new team in Brussels to enforce the AI Act, targeting deepfakes, illicit content, and cyberattacks. AI developers face new transparency requirements.
Chinese Actor Leverages DeepSeek for Autonomous Exploitation
Palo Alto Networks reports Chinese actor 'knaithe' using DeepSeek and Hermes Agent for autonomous attacks, selecting public exploits.
OAuth 2.0 Device Code Phishing Escalates to Industrial Threat
Device code phishing, exploiting the OAuth 2.0 device authorization grant, is rapidly stealing access tokens. Learn how to defend against this growing threat.
CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence
CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.
CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability
CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.