All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
CVE-2026-15409: SonicWall SMA 1000 Zero-Day Patch Guide
SonicWall warns of active zero-day exploitation for CVE-2026-15409 and CVE-2026-15410 in SMA 1000 appliances. Apply firmware updates immediately to prevent RCE.
Malicious GitHub Repositories: Infostealer Distribution Threat
Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware.
Spanish Police Dismantle €140M Cyber Fraud Ring: BEC & Investment Schemes
Spanish Police dismantle a sophisticated cybercrime organization responsible for €140 million in BEC and investment fraud, arresting four key individuals.
CVE-2026-44747: SAP NetWeaver ABAP Out-of-Bounds Write Flaw
SAP NetWeaver ABAP users must patch CVE-2026-44747 (CVSS 9.9) immediately to prevent authenticated attackers from exposing or modifying critical data via memory…
Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now
Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.
FBI Warns of Fake Permit Fee Wire Transfer Scams Targeting Property Owners
The FBI warns property owners of a government impersonation scam using fake planning and zoning permit invoices to trick victims into fraudulent wire transfers.
Advertisement
FIFA Network Vulnerability: Minimal Access Leads to Broad Compromise
An unidentified vulnerability exposed FIFA's network to compromise with minimal access, highlighting risks of overlooked attack surfaces and privilege escalation.
ClickFix Ecosystem: Evasive Attack-as-a-Service & YARA Detection
The ClickFix ecosystem offers rented, evasive attack vectors bypassing AV/EDR. Learn why YARA analysis is crucial for detecting this scalable threat.
Frontier AI Governance: Managing Cybersecurity Risks of Autonomous Models
Explore the cybersecurity challenges and governance needs of increasingly autonomous AI models, as states seek transparency amidst emerging risks.
VMware Avi Load Balancer: Severe Vulnerabilities Enable RCE, Bypass
VMware has patched 7 severe vulnerabilities in Avi Load Balancer, enabling authentication bypass, RCE, privilege escalation, and directory traversal.
Adobe ColdFusion RCE & Privilege Escalation Vulnerabilities Patched
Adobe addresses critical ColdFusion vulnerabilities, including RCE and Privilege Escalation flaws. Patching is essential for all administrators.
LastPass & Bitwarden Phishing: Analyzing Fake Security Alerts
LastPass and Bitwarden users face widespread phishing campaigns using fake security alerts to steal master passwords. Learn how to detect and mitigate these threats.
Progress ShareFile Zero-Day Flaw Prompts Emergency Shutdown
Progress Software confirms a high-severity zero-day vulnerability in ShareFile Storage Zone Controllers led to emergency shutdowns. Patch now.
RabbitMQ Flaws: OAuth Secret Leak & Cross-Tenant Data Exposure
Two RabbitMQ access control flaws enable OAuth secret leakage, cross-tenant data exposure, and potential messaging infrastructure takeover risks.
LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows
Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.
Jscrambler NPM Packages Poisoned in Supply Chain Attack
Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.
Valarian Raises $50M to Advance Sovereign Infrastructure Control Layer
Valarian secures $50M for its ACRA technology, enabling organizations to maintain data sovereignty over third-party communication and cloud platforms.
OFAC Sanctions VPN and Crypto Services Linked to Ransomware
US Treasury sanctions Cryptex and PM2VPN for facilitating money laundering and infrastructure for ransomware gangs like LockBit and Hive.
US Sanctions 1VPNS and Cryptor Seller for Ransomware Support
US OFAC sanctions First VPN Service (1VPNS) and a malware cryptor operator for providing critical infrastructure to ransomware groups and cybercriminals.
xAI Grok Build Repository Upload Risks: Analyzing CLI Data Exposure
xAI's Grok Build CLI version 0.2.93 discovered uploading entire Git repositories, including history and secrets, to remote storage without user consent.
Klue Security Incident: Analyzing Third-Party Supply Chain Impact
An analysis of the Klue security incident affecting Recorded Future, highlighting the risks of third-party SaaS vendors and competitive intelligence data.
UK and EU Sanction Russian APTs Over Critical Infrastructure Attacks
Recent UK and EU sanctions target Russian intelligence services following persistent cyber operations against government entities and critical infrastructure.
Yellow Teams: Pioneering Adversarial AI Security Methodologies
Explore how 'Yellow Teams' are crucial for assessing AI security, developing defensive strategies, and understanding AI's potential as both a cyber weapon and a shield.
Jscrambler npm Package Backdoored with Infostealer Malware
A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.