All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Anthropic Extends Claude Fable 5 Access: Enterprise Migration Impacts
Anthropic extends Claude Fable 5 access for paid users until July 19. Learn how this availability extension impacts enterprise AI security and infrastructure.
RedHook Android Malware: Abusing Wireless ADB for Local Shell Access
RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.
GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns
Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.
Balochistan Police Portal Exploited in Multi-Group Espionage Campaign
Multiple threat actors weaponize Balochistan Police infrastructure, compromising criminal records and citizen data in a multi-year espionage operation.
jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack
The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.
ACSC Warns of Global Campaign Targeting Vulnerable CMS Platforms
The ACSC warns of a global campaign targeting WordPress, Joomla, and Drupal. Learn how to identify web shells and secure your CMS against automated attacks.
Advertisement
June 2026 CVE Landscape: Analyzing the 49% Surge in Critical Risks
Analyzing the June 2026 CVE landscape, which saw 60 high-impact vulnerabilities and a 49% increase in critical risks requiring immediate remediation.
Wireshark 4.6.7 Update: Resolving 12 Critical Dissector Vulnerabilities
Wireshark 4.6.7 addresses 12 vulnerabilities and 16 bugs. Learn how to apply the Wireshark 4.6.7 patch guidance to prevent dissector crashes and DoS attacks.
AI Surveillance Systems: Analyzing the Risks of Automated Enforcement
A technical evaluation of pervasive AI-powered surveillance, automated rule enforcement via machine learning, and the security implications of integrated data.
Ghostcommit: Hidden Prompt Injection in Images Targets AI Agents
Researchers demonstrate Ghostcommit, a technique using images to hide prompt injection attacks that trick AI agents into exfiltrating repository secrets.
Zimbra Classic Web Client Stored XSS Leads to Session Hijacking
Zimbra warns of a critical stored XSS vulnerability in the Classic Web Client allowing attackers to execute malicious code via crafted emails.
Healthcare Service Provider Cyberattacks Surge — Supply Chain Risk
Cyberattacks on healthcare service providers more than doubled in H1 2026, signaling a shift in targeting toward the medical supply chain and data aggregators.
Jen Ellis: Connecting Cyber Researchers to Political Machinery
A look at Jen Ellis' work bridging the gap between security researchers and policy makers, emphasizing vulnerability disclosure and researcher protections.
AssuranceAmerica Data Breach Impacts 7M; DHS Database Hacked
Analysis of the AssuranceAmerica data breach affecting 7 million individuals and the reported hack of a DHS database.
U-Boot Vulnerabilities: How to Mitigate CVE-2024-42433 Firmware Flaws
Six vulnerabilities in the U-Boot bootloader, including CVE-2024-42433, allow for stealthy firmware attacks and bypass of secure boot on embedded devices.
Odido Data Breach Analysis: Dutch Police Suspect Local Hacker Involvement
Dutch National Police identify strong indications of local hacker involvement in the February data breach at telecommunications provider Odido.
Ryuk Ransomware Affiliate Pleads Guilty to US Hacking Charges
A 34-year-old Armenian national faces 15 years in prison for his role in the Ryuk ransomware operation, which targeted U.S. hospitals and businesses.
Progress ShareFile Storage Zone Controller Security Threat - Shut Down Now
Progress Software urges customers to shut down ShareFile Storage Zone Controllers immediately following reports of a credible external security threat.
Injective Labs npm Package Compromise Steals Crypto Keys
Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.
Analyzing Microsoft BitLocker Security Wrapper Vulnerabilities
New security vulnerabilities identified in a Microsoft BitLocker security wrapper pose a risk to organizations and potentially ATMs, potentially leading to compromise.
Parallel APT Cyber Espionage Targets Balochistan Police
Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan's Balochistan Police, detailed by SentinelOne.
Insider Threat: Security Expert Sentenced for BlackCat/ALPHV Aid
Former ransomware negotiator Angelo Martino received a 70-month prison sentence for aiding the BlackCat/Alphv ransomware group, highlighting insider threat risks.
Zimbra Classic Web Client XSS: Critical Flaw Under Active Exploit
A critical XSS vulnerability in Zimbra Classic Web Client is under active exploitation, allowing credential theft and session hijacking.
AI Agents Expand Attack Surface: Managing Non-Human Identities
AI agents accelerate non-human identity growth, creating security gaps. Proactive identity governance and visibility are crucial for defense.