All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
ViPNet Update Mechanism Abused in Russian Government Targeting
Threat actors are leveraging the ViPNet private networking suite's update mechanism to distribute malware to Russian government and financial entities.
SonicWall SMA 1000 Zero-Day Exploitation: Analysis of UTA0533 TTPs
A technical analysis of zero-day exploitation against SonicWall SMA 1000 series appliances by threat actor UTA0533 to gain root access and persistence.
UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware
Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.
WordPress wp2shell RCE: Public Exploits Released for Core Flaws
Public exploits for wp2shell RCE flaws in WordPress Core are now available. Learn how to detect, mitigate, and patch these critical vulnerabilities immediately.
7-Zip 24.05 RCE via Malicious Archives: Patch Guidance
7-Zip version 24.05 addresses a critical remote code execution vulnerability found in archive handling. Learn how to detect and mitigate this risk in your SOC.
On-Device Age Estimation: Securing Biometric Identity at the Edge
Explore how on-device age estimation secures biometric data by processing facial geometry locally, reducing regulatory risks and preventing image transmission.
Advertisement
ACR Stealer Campaign Targets Microsoft Enterprise Credentials
Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.
WordPress Core RCE wp2shell: Versions 6.9 and 7.0 Vulnerable
Unauthenticated attackers can achieve RCE on WordPress 6.9 and 7.0 core installations via the wp2shell flaw. Learn how to secure your site today.
Blind Trust in AI: A Critical Threat to Enterprise Security
The increasing reliance on AI models for command interpretation and execution introduces severe cybersecurity risks by bypassing traditional oversight.
Inc Ransomware Exploits SonicWall SMA Zero-Days for Root Access
Inc Ransomware is actively exploiting chained zero-day vulnerabilities in SonicWall SMA appliances, achieving root-level capabilities.
HollowByte DDoS: OpenSSL Memory Exhaustion via 11-byte Payload
HollowByte enables unauthenticated DoS on OpenSSL servers, depleting memory with an 11-byte payload. Understand the impact and mitigation.
Abbott Labs Probes Dual Cyber Incidents, Data Theft, Extortion
Abbott Laboratories confirms unauthorized access to Exact Sciences systems and investigates alleged LabCentral breach amid extortion. Learn about the dual threat.
Malicious Vite npm Packages Deliver RAT via Blockchain C2
Seven malicious npm packages target Vite frontend projects. Dubbed ViteVenom, this software supply chain attack uses a four-tier blockchain C2 to deploy a RAT.
OpenSSL HollowByte Flaw: Memory Exhaustion via 11-Byte TLS Requests
The HollowByte vulnerability allows attackers to freeze OpenSSL server memory using 11-byte requests. Learn how to mitigate this denial-of-service risk.
Advanced Persistent Threat Tracking: Intelligence for Detection
Understand the methodologies and critical role of real-time cyber intelligence in detecting and mitigating Advanced Persistent Threat (APT) group activities.
Diverse Threat Landscape: Military Tracking, macOS Malware, Defense Ransomware
Analysis of diverse threats including reported Iranian tracking of US military phones, CrashStealer macOS malware, ransomware on a naval firm, and a Lidl data breach.
Evolving Carding Tactics: Residential Proxies & Fraud Detection Evasion
Cybercriminals leverage "clean" residential proxies, browser fingerprints, and device profiles to bypass modern fraud detection systems, enhancing carding success.
EY Data Breach: Third-Party Support System Exposes Client Data
Ernst & Young (EY) disclosed a data breach stemming from a compromise of a third-party IT support system, potentially exposing customer information.
North Korean Actors Use SVG Steganography to Deliver OtterCookie
North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.
Alan Turing’s Delilah: Technical Insights from the Bayley Papers
An analysis of the Delilah project, Alan Turing’s portable voice encryption system, based on the discovery of the historical Bayley papers.
Google Cloud Agentic Defense: Automating AI-Driven Security Response
Google Cloud integrates Wiz and Mandiant capabilities into its new Agentic Defense model, using AI agents to automate complex threat detection workflows.
Gold Eagle Clearinghouse: Centralizing AI Vulnerability Management
The White House Gold Eagle clearinghouse aims to coordinate AI vulnerability responses, yet technical implementation details remain unclear for security teams.
Beacon Security Secures $13M to Scale Security Data Platform
Beacon Security raises $13 million in seed funding to help organizations detect and hunt assets at machine speed by eliminating security data silos.
Securing Agentic AI: Governance Gaps and the MindStone Agent
Analyze the security risks of autonomous AI agents and broken governance frameworks as discussed in the SecurityWeek MindStone Agent report.