All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Spanish Authorities Dismantle Anonymous Fénix Hacktivist Node
Spain's National Police arrested four members of Anonymous Fénix, a hacktivist group targeting government infrastructure with DDoS and data exfiltration.
Chinese APTs Exploit CVE-2024-34351 in TeamT5 ThreatSonar
Taiwanese security firm TeamT5 confirms that a critical command injection flaw in ThreatSonar Anti-Ransomware has likely been exploited by Chinese APT groups.
Lazarus Group Targets U.S. Healthcare with Medusa Ransomware
North Korean Lazarus Group is targeting U.S. healthcare providers with Medusa ransomware, utilizing Dtrack malware for initial access and persistence.
ShinyHunters Claims Breach of Odido Telecom Affecting Millions
The ShinyHunters extortion group claims to have exfiltrated millions of customer records from Dutch telecommunications provider Odido via a third-party breach.
UnsolicitedBooker Targets Central Asian Telecoms via LuciDoor Backdoor
The UnsolicitedBooker threat actor has pivoted to targeting telecommunications providers in Kyrgyzstan and Tajikistan using LuciDoor and MarsSnake backdoors.
Lazarus Group Deploys Medusa Ransomware in Global Healthcare Attacks
Lazarus Group (Diamond Sleet) targets Middle Eastern entities and U.S. healthcare with Medusa ransomware, according to Symantec and Carbon Black reports.
Advertisement
Identity Prioritization: Shifting from Backlogs to Risk Math
Enterprise identity programs must evolve from ticket-based prioritization to dynamic risk math models to manage the surge of human and non-human identities.
Operational Resilience: Cryptographic Lessons from the Enigma Device
An analysis of historical cryptographic failures within the Enigma machine and how these resilience errors inform modern cybersecurity defense strategies.
MuddyWater Deploys BugSleep Backdoor in Targeted Regional Campaigns
Iranian state actor MuddyWater introduces the custom BugSleep backdoor, targeting Middle Eastern and African entities using spear-phishing and RMM abuse.
ATM Jackpotting Trends: $20M Losses Driven by Legacy Exploits
ATM jackpotting surged in 2025, resulting in over $20 million in losses as threat actors leverage decade-old tools and black-box tactics against aging hardware.
Microsoft Investigating Mouse Pointer Bug in Classic Outlook
Microsoft confirms a bug in classic Outlook causing the mouse cursor to disappear during email composition. Discover the technical details and mitigation steps.
Spanish Police Disrupt Anonymous Sudan Hacktivist DDoS Operations
Spanish authorities arrest three individuals linked to the Anonymous Sudan hacktivist group for executing DDoS attacks against government and critical infrastructure.
Security Flaws in Android Mental Health Apps Affect 14.7M Users
Multiple Android mental health apps suffer from hardcoded credentials and insecure data storage, putting sensitive patient information at risk.
Anthropic Reports Industrial-Scale Model Distillation by Chinese Firms
Anthropic identifies DeepSeek, Moonshot AI, and MiniMax in a massive effort to copy Claude's capabilities via 16 million queries and 24,000 fake accounts.
APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe
Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.
BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement
An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining…
AI-Driven Package Hallucination: A New Frontier in Supply Chain Exploitation
Analysis of a novel attack vector where autonomous AI agents facilitate malicious package injection through dependency confusion and LLM hallucinations.
Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure
Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.
Everest Ransomware Group Compromises Vanta Diagnostics Infrastructure
The Everest ransomware group exfiltrated sensitive data belonging to 140,000 individuals from Vanta Diagnostics, emphasizing the systemic risk to healthcare diagnostic…
Token Theft and Session Hijacking: Mitigating Device Trust Failures
An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust…
Technical Analysis: Multi-Vector Threats Spanning Web Skimming, AI Prompt Injection, and Volumetric DDoS
A deep dive into redundant Magecart exfiltration techniques, PromptSpy AI exploitation frameworks, and the escalation of 30Tbps volumetric DDoS attacks.
Cryptographic Flaws in Password Manager Zero-Knowledge Architectures
Technical analysis of Bitwarden, Dashlane, and LastPass reveals server-side attack vectors that bypass zero-knowledge encryption through account recovery and group…
Exploitation of SVG-Based XSS in RoundCube Webmail Instances
Technical analysis of a cross-site scripting (XSS) vulnerability in RoundCube Webmail triggered by improper sanitization of SVG animate elements.
Automated AI-Driven Exploitation of FortiGate Management Interfaces in AWS Environments
Threat actors are utilizing artificial intelligence to automate credential stuffing and exploit exposed administrative ports on Fortinet devices within AWS…