All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
UK Sentences Scattered Spider Hackers Over 2024 TfL Breach
Two Scattered Spider members sentenced in the UK for the 2024 TfL cyberattack. Detailed analysis of threat actor tactics and defensive recommendations.
Scattered Spider Members Sentenced for Transport for London Attack
Two members of the Scattered Spider threat group were sentenced to five years in prison for the 2024 TfL breach that exposed 5,000 customers' bank details.
23andMe $18M Settlement: Lessons in Protecting Genetic Data Privacy
23andMe agrees to an $18 million settlement with 43 attorneys general following a 2023 data breach that exposed sensitive genetic data of millions.
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.
TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns
TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.
Dismantling the €140M Iberian Cyber-Fraud and Smishing Ring
Spanish authorities disrupt a major cybercriminal network responsible for €140 million in fraud using smishing, vishing, and complex money laundering.
Advertisement
China Military Bans Top Cybersecurity Firms for Procurement Violations
Major Chinese firms like Qi-An-Xin and Sangfor face PLA procurement bans due to integrity violations, impacting China’s domestic cybersecurity landscape.
F5 BIG-IP and NGINX Vulnerabilities: CVE-2024-41730 and CVE-2024-39475
F5 releases critical security updates for BIG-IP and NGINX Plus, addressing authentication bypass, RCE, and memory corruption vulnerabilities.
Spirals Ransomware: Rapid Network Encryption in Under 24 Hours
Analysis of Spirals ransomware, a high-velocity threat actor capable of completing corporate intrusions and data encryption in less than one day.
Zoom CVE-2026-53412: Critical Windows Client Account Takeover Fix
Zoom releases critical security updates for CVE-2026-53412, a high-severity input validation flaw in Windows clients allowing unauthenticated account takeover.
OpenAI GPT-Red: Automating Prompt Injection Discovery for GPT-5.6 Sol
OpenAI reveals GPT-Red, an automated red-teaming model designed to detect prompt injection vulnerabilities and harden GPT-5.6 Sol via adversarial training.
Security Vendors Patch Severe RCE and LPE Vulnerabilities
Analysis of critical vulnerabilities in Trend Micro, Tanium, ESET, and Tenable products, including CVE-2024-48904 and local privilege escalation flaws.
UEFI Shim Bootloader Vulnerabilities: Secure Boot Blind Spot
Nearly a dozen vulnerable UEFI shim bootloaders remained trusted for years, allowing attackers to bypass Secure Boot for persistent malware and rootkit deployment.
Dutch Police Bust €100 Million Global Investment Fraud Syndicate
Analysis of the Dutch police operation against an international investment fraud ring that defrauded over 50,000 victims using deceptive trading platforms.
Dark Reading Expands DR Global: Tailored European Threat Intelligence
Dark Reading launches DR Global section, offering region-specific cybersecurity intelligence for European defenders.
Identity Attacks & MFA Bypass: The New Ransomware Entry Point
Identity-based attacks, particularly email phishing, are now the leading cause of ransomware infections.
Google Gemini CLI Abused by 'bandcampro' for Botnet Operations
Russian-speaking threat actor 'bandcampro' is leveraging Google's Gemini CLI as a hacking agent and to command a small-scale botnet.
CVE-2024-24691: Zoom Windows Client Account Takeover - Patch Now
Zoom has addressed CVE-2024-24691, a critical 9.6 CVSS vulnerability in Windows clients allowing unauthenticated account takeover. Learn how to patch and defend.
TuxBot v3 Evolution: Analyzing LLM-Assisted IoT Botnet Code
Researchers discover TuxBot v3, an IoT botnet framework developed using LLMs. The source code contains AI safety disclaimers and specific technical artifacts.
US Export Controls & Frontier AI: Securing Volatile Models
Explore the implications of US export controls on frontier AI models, highlighting regulatory uncertainty and strategies for security leaders to manage AI as a volatile…
Exposed Cloud Functions: Hardening GCP Serverless Against LFI & RCE
Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.
PromptFiction: Claude AI Vulnerability Exploits Malicious Prompts
Discover PromptFiction, a fixed vulnerability in Claude AI that allowed malicious prompts to trigger end-to-end attacks. Learn mitigation for AI agent security.
UK's AI Sovereignty Push: Cybersecurity Implications of Tech-xit
The UK's drive for tech sovereignty, spurred by US AI model restrictions, presents complex cybersecurity challenges and strategic reliance concerns.
Microsoft SharePoint RCE via CVE-2024-38094: Mitigation Guide
CISA adds three exploited SharePoint vulnerabilities to the KEV catalog, including CVE-2024-38094. Learn how to detect and mitigate these critical RCE flaws.