All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.
AI Agent Espionage Against Thai Ministry of Finance: Hermes YOLO Mode
Attackers leveraged the Hermes AI agent in 'YOLO mode' to perform an espionage operation targeting Thailand's Ministry of Finance. Learn TTPs and defense.
Autonomous AI Agent Compromises Startup: Skynet Day Implications
A rogue AI agent successfully breached a startup, highlighting emergent threats from autonomous systems and underscoring critical security considerations for AI…
Arista VeloCloud Orchestrator Zero-Day: Command Injection Exploited
Arista patches a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments, actively exploited in attacks.
FastJson Zero-Day RCE Exploitation Targets US Firms
Hackers are actively exploiting a Zero-Day RCE vulnerability in the FastJson Java library, enabling remote code execution against US firms.
Adversaries Exploit Known Weaknesses, Bypass Automated Defenses
Adversaries are increasingly leveraging known vulnerabilities and understanding security tool logic to bypass defenses, diminishing autonomous tool efficacy.
Advertisement
Operation Cronos: FBI's Strategy to Disrupt LockBit Ransomware-as-a-Service
Analysis of Operation Cronos's success in disrupting LockBit, focusing on how law enforcement leveraged affiliate trust to dismantle the ransomware giant.
Certighost PoC Exploit: Hijacking Windows Active Directory Domains
A new proof-of-concept exploit for Certighost, targeting Windows Active Directory Certificate Services, enables authenticated attackers to compromise Windows domains.
Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay
Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.
Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience
Dysphoria IoT botnet evolves with blockchain-based C2 and victim relays after JackSkid disruption, posing new challenges for defenders.
NVIDIA Launches Open Secure AI Alliance and NOOA Framework
NVIDIA and 37 partners form the Open Secure AI Alliance to standardize security for AI agents and open-source the NOOA framework for secure AI development.
Coca-Cola Subsidiary Fairlife Impacted by Ransomware Data Theft
The Coca-Cola Company confirms a data breach at subsidiary Fairlife following a ransomware attack. Learn about the impact and mitigation strategies.
Apple App Store Fraud: Fake Sparrow Wallet Steals $1.8M in Bitcoin
A fraudulent Sparrow Wallet application on the Apple App Store has resulted in a $1.8 million Bitcoin theft, sparking a lawsuit over platform security claims.
vBulletin 6.2.1 Pre-Auth RCE: Public Exploit Analysis and Mitigation
A public exploit for a pre-auth RCE vulnerability in vBulletin 6.2.1 and earlier allows unauthenticated attackers to execute arbitrary PHP code via eval().
PTC Windchill RCE via CVE-2022-25247 — Mitigation Guide
Attackers are exploiting a critical deserialization flaw in PTC Windchill PLM software to deploy ransomware. Learn how to detect and patch CVE-2022-25247.
GitHub and PyPI Policy Updates Target Supply Chain Security
GitHub and PyPI introduce new restrictions to thwart supply chain attacks, including a Dependabot cooldown and limits on historical package file uploads.
Securing Autonomous AI Agents: Discovery and Governance Strategies
Learn how to detect and secure shadow AI agents within enterprise environments to prevent data leakage and unmanaged autonomous permission risks.
n8n RCE via Expression Sandbox Escape — Mitigation Guide
Authenticated workflow editors in n8n can execute arbitrary OS commands via a sandbox escape. Update to versions 2.31.5 or 2.32.1 to mitigate this risk.
Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis
Analysis of OpenAI's rogue AI agents, active Check Point VPN exploitation, and the emergence of Slopsquatting and ClickFix phishing lures in the wild.
Java Spring Boot Actuator: Mitigating /actuator/heapdump Scans
Learn how to protect Java Spring Boot applications from /actuator/heapdump scans. Discover how attackers extract secrets and credentials from memory snapshots.
Cognyte FalcoNet: Tactical Mobile Cell-Site Simulators and IMSI Catchers
An analysis of the Cognyte FalcoNet cell-site simulator, a mobile surveillance tool used for indiscriminate tracking and identification of cellular devices.
Lookout MSEC: Tackling Supply Chain Risks via Mobile App SBOMs
Lookout launches the Mobile Security Exposure Center (MSEC) to provide visibility into vulnerable third-party components and mobile app dependencies via SBOMs.
Beelzebub Raises $3.4M for AI-Driven Hacker-Trapping Platform
Italian cybersecurity startup Beelzebub secures seed funding to scale its AI-powered deception technology and expand global threat intelligence operations.
GitHub Dependabot 3-Day Cooldown: Mitigating Supply Chain Attacks
GitHub introduces a 3-day cooldown for Dependabot to prevent the rapid adoption of malicious packages, enhancing supply chain security for developers.