All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Nihon Kotsu Cyberattack: System Shutdowns Affect Japan's Largest Taxi Operator
Japan's largest taxi operator, Nihon Kotsu, confirmed a cyberattack forced system shutdowns. This analysis covers the incident's impact and mitigation.
ModHeader Extension Pulled Over Dormant Browsing Data Collector
ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.
CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization
CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.
GigaWiper: Modular Implant Combines Backdoor & Wiper Functions
Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.
CISA GitHub Leak: Lessons from AWS Govcloud Credential Exposure
Analysis of CISA's recent GitHub leak, detailing the exposure of AWS Govcloud keys and internal credentials, and providing critical lessons for cloud security.
Joomla Extensions RCE: CISA Warns of Active Exploitation
CISA alerts on actively exploited RCE vulnerabilities in Joomla's iCagenda and Balbooa Forms extensions, urging immediate patching to prevent arbitrary file uploads.
Advertisement
MemGhost Attack: Persistent Memory Poisoning in AI Agents via Email
The MemGhost attack targets AI agent memory systems via email, planting persistent false facts to stealthily manipulate long-term assistant behavior.
Threat Recap: Unpatched Exploits, Citrix Bleed 2, AI Attacks
Analysis of current cyber threats including persistent unpatched vulnerabilities, the emergence of Citrix Bleed 2 ransomware, and AI's role in attacker toolchains.
ScamBuster: AI-Driven Phishing Engagement for Threat Intel
Explore ScamBuster, an open-source, AI-driven tool that actively engages phishing attackers to gather intelligence on their TTPs, aiding threat detection and law…
Cybersecurity M&A Trends: Implications for Enterprise Security
Analyze the impact of 37 cybersecurity M&A deals in June 2026 on vendor ecosystems, supply chain risks, and security strategy for enterprises.
Jesse McGraw (GhostExodus): Examining the First ICS Hacking Conviction
A technical analysis of Jesse McGraw (GhostExodus), his compromise of hospital HVAC systems, and the evolution of industrial control system security threats.
Defending Entra ID: Lessons from Breach at the Beach CTF
Analyze common Entra ID attack vectors including service principal abuse and privilege escalation techniques based on the Breach at the Beach CTF.
Lidl Data Breach: Service Provider Hack Exposes Customer Info
Lidl notifies customers in Germany, Belgium, and Netherlands after a third-party service provider breach exposed personal data and order histories.
Meta Patent Details AI-Driven Emotional Tracking via Ambient Voice Analysis
Meta files patent for continuous AI voice monitoring to log user emotions and activities, raising significant privacy and biometric data security concerns.
Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks
Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.
AI Data Center Expansion and the Concentration of Corporate Power
Analysis of the bipartisan opposition to AI data centers and the strategic risks posed by the concentration of wealth and power within the AI industry.
EU Sanctions Russian Intel Officers for APT28 Cyber Operations
The EU imposes sanctions on Russian GRU officers linked to APT28 for long-term cyber espionage and sabotage targeting government and infrastructure.
CVE-2024-45519: Zimbra Collaboration Suite RCE Patch Guidance
Zimbra patches a critical RCE vulnerability (CVE-2024-45519) affecting the postjournal service. Security teams should prioritize patching and monitoring.
Russian APTs Target Critical Infrastructure via Edge Device Exploits
US and allies warn of Russian state-sponsored actors targeting edge devices to infiltrate critical infrastructure. Learn how to mitigate these threats.
Joomla RCE via CVE-2026-48939 and CVE-2026-38294 — Mitigation Guide
CISA adds CVE-2026-48939 and CVE-2026-38294 to KEV after zero-day exploitation of Joomla iCagenda and Balbooa Forms extensions. Patch immediately.
Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits
A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker's toolkit and session cookies.
Scans Target Model Context Protocol Servers and AI Credentials
Security researchers observe an increase in scans targeting Model Context Protocol (MCP) servers and AI credentials, potentially exposing sensitive data.
Analyzing Remcos RAT Delivery via Malicious LNK Files
Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.
GPT-5.6 Sol Usage Limits Relaxed: Analyzing OpenAI's Scaling Response
OpenAI temporarily lifts rate limits for GPT-5.6 Sol following a massive surge in demand. Explore the implications for AI infrastructure and enterprise security.