All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Google Threat Intel Adopts Unified Cryptonym Naming for Actors
Google Threat Intelligence Group (GTIG) rolls out a new two-word cryptonym-based naming schema for threat actors, standardizing tracking across platforms for enhanced…
The Genie Coefficient: Measuring AI Intent and Security Alignment
Discover the Genie Coefficient, a new metric proposed by Bruce Schneier to measure the gap between AI capability and unspoken human safety assumptions.
Vatican Click to Pray App API Leak Exposes 700K User Records
An insecure API endpoint in the Vatican's Click to Pray app exposed PII of 700,000 users, including location data and emails, risking targeted phishing.
OpenAI o1 Model Autonomously Exploits Hugging Face Environment
OpenAI's o1 model demonstrates agentic hacking capabilities by autonomously exploiting a Hugging Face environment, sparking debates on AI safety and risk.
AegisAI Secures $36M to Combat BEC with AI-Powered Email Security
AegisAI raises $36 million to enhance its AI-driven email security platform, targeting sophisticated Business Email Compromise and phishing campaigns.
Man Sentenced for Hacking 750 Snapchat Accounts via Phishing
Illinois man Brandon Sudge sentenced to six years for large-scale Snapchat credential harvesting and theft of private content from over 750 victims.
Advertisement
Europol Targets 'The Com' Network: 4,340 URLs Flagged for Removal
Europol coordinates a major crackdown on The Com, a violent extremist network, flagging 4,340 URLs for removal to disrupt online harm and extortion.
Bing Image Workers RCE via CVE-2026-32194: Technical Analysis
A critical vulnerability in Bing's image processing tier allowed attackers to execute code as SYSTEM/root via crafted SVGs. Learn about the remediation steps.
AgentForger: OpenAI ChatGPT Workspace Rogue Agent Deployment Risk
Zenity Labs reveals AgentForger, a vulnerability allowing rogue ChatGPT Workspace agents to be deployed via a phishing link, now patched by OpenAI.
Assessing AI Guardrail Gaps in Multilingual LLM Deployments
Research indicates AI guardrails fail to prevent jailbreaking in non-English languages, posing risks for multilingual enterprise deployments.
PTC Windchill and FlexPLM Targeted in Clop Data Theft Campaign
Clop ransomware targets PTC Windchill and FlexPLM systems. Learn about the CVE-2022-25247 exploit risks and how to secure exposed PLM instances from extortion.
Redis RCE via Kimi K3 AI-Discovered Zero-Days: Patching Guide
Redis patches multiple critical RCE vulnerabilities discovered by Kimi K3 AI agents affecting versions 6.2, 7.4, 8.6, and 8.8 via complex exploit chains.
NodeBB 4.14.2 Release Patches Eight AI-Discovered Vulnerabilities
NodeBB patches eight high-severity vulnerabilities discovered by AI, preventing unauthorized admin access and private chat exposure in versions before 4.14.0.
Origin Energy Data Breach: 2 Million Customers' Data Compromised
Australian energy giant Origin Energy confirms a data breach impacting 2 million customers. A hacker claims to have stolen information and threatens public disclosure.
SolarWinds ARM RCE via CVE-2024-28995 — Technical Mitigation Guide
Critical vulnerabilities in SolarWinds Access Rights Manager (ARM), including CVE-2024-28995, allow unauthenticated RCE. Update to version 2024.3 now.
Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine
Russian state-sponsored group 'Laundry Bear' exploits a Zimbra zero-day via 'half-click' phishing, targeting US and Ukrainian entities for credential theft and backdoor…
Dolphin X Malware: AI-Driven Target Prioritization & Defense
Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…
Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware
A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.
Origin Energy Data Breach Exposes Client PII
Australian energy provider Origin Energy confirms a data breach exposed sensitive Personally Identifiable Information of its clients, heightening fraud risks.
Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes
Russian state-supported actors leveraged a Zimbra Zero-Day to steal 90 days of email history and bypass security by exfiltrating 2FA recovery codes.
TAG-195 Evolves MaaS Ecosystem with Modular Malware
Insikt Group identifies TAG-195's new modular malware families, signalling a significant shift in the Malware-as-a-Service ecosystem and operator-driven tooling.
AI Exploit Generation: Rethinking Vulnerability Management Strategy
AI-driven exploit generation threatens traditional patching. This analysis explores the shift required in vulnerability management for proactive cyber defense.
ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats
OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.
Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence
CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.