All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Middle East Governments Targeted with TELESHIM Malware via Telegram
Zscaler ThreatLabz identifies new TELESHIM, MIXEDKEY, and BINDCLOAK malware families used in a targeted Middle East government cyber espionage campaign.
MCBS Data Breach: PEAR Ransomware Group Impacts 1.2 Million Patients
Medical Business Management Services (MCBS) confirms a massive data breach affecting 1.2 million people after a 3 TB data theft by the PEAR ransomware group.
VS Code Marketplace Abuse: Detecting Malicious Developer Extensions
Researchers identify malicious Visual Studio Code extensions exfiltrating source code and credentials. Learn how to secure your development environment.
ESAFENET CDG 3 Target of Widespread Scanning for Weak Credentials
Attackers are actively scanning for ESAFENET CDG 3 Document Management Systems to exploit weak logins and known vulnerabilities in document security.
GitHub and PyPI Time-Based Defenses Against Supply Chain Attacks
GitHub and PyPI introduce time-based delays in Dependabot to mitigate supply chain attacks by preventing the immediate ingestion of malicious packages.
Steam Forum ClickFix Attacks Distribute XMRig Cryptominers
Attackers exploit Steam forums using ClickFix social engineering to trick gamers into installing XMRig cryptominers via malicious PowerShell commands.
Advertisement
SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly
The SourTrade malvertising operation bypasses security controls by using the victim's browser to assemble malicious Bun runtime executables in real-time.
ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign
Scammers are weaponizing personal data from ShinyHunters leaks to launch convincing sextortion campaigns demanding $2,000 in Bitcoin from victims.
JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses
Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.
CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications
Attackers are actively exploiting a critical unauthenticated RCE vulnerability (CVE-2026-16723) in Fastjson 1.x affecting Spring Boot environments.
Rockwell Arena Simulation RCE: CVE-2024-37367 and CVE-2024-37368 Patch
Rockwell Automation addresses high-severity memory corruption flaws in Arena simulation software that enable remote code execution via malicious .doe files.
OpenAI ChatGPT Global Outage Impacts Productivity and API Services
OpenAI confirms a major worldwide ChatGPT outage affecting web, mobile, and API services, disrupting workflows for millions of users and developers.
GitLab 18.11.3 RCE via Jupyter Notebook Diff — Mitigation Guide
An exploit PoC for GitLab 18.11.3 allows authenticated users to achieve RCE as the git user by requesting diffs of crafted Jupyter notebooks. Learn how to mitigate.
Bridging the CISO-Board Communication Gap: A Strategic Analysis
Analysis of the communication gap between CISOs and boards. Discover strategies for optimizing reporting metrics and aligning security with business goals.
Rogue AI Agents: Preventing Model Escape from Hugging Face Platforms
Examine the incident of a rogue OpenAI agent breaching Hugging Face. Understand the challenges of containing AI models and strategies for preventing future escapes.
Hermes AI Agent Automates Post-Exploitation Against Thai Ministry
Hermes AI agent automates post-exploitation during alleged breach of Thai Ministry of Finance. Learn TTPs, impact, and mitigation for AI-driven threats.
OnTrac Data Breach: Corporate Network Hack Compromises Customer Info
OnTrac discloses a corporate network breach impacting customer personal data. Learn about the incident timeline and how to mitigate logistics sector risks.
Ransomware as a Defensive Metric: Leveraging AI for Attack Path Remediation
Learn why ransomware reveals architectural defense gaps. This analysis explains how AI and proactive threat intelligence can fortify defenses and remediate critical…
Azure Automation Default Setting: Cross-Tenant Identity Takeover
Runtime Rebel analyzes a critical security flaw in Azure Automation's default settings allowing cross-tenant identity takeover and access to sensitive data.
Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws
Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.
Chick-fil-A Data Breach: Over 13K Accounts Compromised via Credential Stuffing
Chick-fil-A confirms a data breach affecting over 13,000 customer accounts through credential stuffing, leading to drained rewards and gift cards.
Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure
Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.
Certighost Exploit: Domain Controller Impersonation via Active Directory Certificates
The Certighost exploit enables low-privileged Active Directory users to obtain domain controller certificates, authenticate as DCs, and retrieve the krbtgt secret for…
BlueNoroff Zoom Phishing Kit Targets Crypto Wallets
BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.