All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
OWA Light Retirement in Exchange Server: Planning for the Change
Microsoft is retiring OWA Light in Exchange Server. This advisory details the operational impact, affected versions, and critical steps for administrators to manage user…
Meta Muse AI Uses Public Instagram Photos By Default
Meta's new Muse Image AI tool leverages public Instagram photos and reels for AI image generation, enabled by default, raising privacy concerns.
Digital Identity Security: Investment Reflects Evolving Threat Landscape
Investment in digital identity security platforms highlights ongoing critical need for robust defense against modern cyber threats and data breaches.
Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws
Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.
Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide
Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.
GhostApproval Symlink Flaws Threaten AI Coding Assistants
GhostApproval symlink vulnerabilities in six AI coding assistants allow malicious repositories to execute code, risking developer workstation compromise. Update software.
Advertisement
AI Coding Agents Vulnerable to Friendly Fire Command Execution
AI coding agents like Anthropic's Claude Code and OpenAI's Codex are susceptible to Friendly Fire attacks, leading to unintended local code execution.
Mount Royal University Data Breach: Network Intrusion, Data Theft, and Deletion
Mount Royal University confirms a significant data breach involving network intrusion, data theft, and subsequent deletion of files from storage systems.
Roundcube Flaw Exploited by China-Linked Group Against Academics
A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.
Fake Paysafe/Skrill SDKs on npm & PyPI Steal Credentials
Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.
Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software
A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…
New 'Leash' Backdoors Target SOHO Routers: China-Linked APT Update
A China-linked APT group has expanded its toolkit with new 'Leash' backdoors (LongLeash, DogLeash, JarLeash), targeting SOHO routers for persistent access and command…
Accenture Data Breach: Source Code Theft Confirmed
Accenture confirms a data breach involving source code theft. Runtime Rebel analyzes the incident, potential impacts, and recommends urgent mitigation steps for similar…
Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk
A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.
HalluSquatting: AI Coding Assistants Tricked into Botnet Malware
New HalluSquatting research reveals how attackers can register fake project names hallucinated by AI coding assistants to deploy botnet malware onto developer systems.
AI Coding Agents Mimic Malicious Activity in Endpoint Detections
AI coding agents like Claude Code and OpenAI Codex are triggering endpoint security alerts by performing actions similar to human attackers, demanding rule adjustments.
Defensive AI Agents: Countering the Rise of Local AI Model Attacks
The true AI threat is not large frontier models, but cheap local AI models enabling scalable attacks. Learn why CISOs must build defensive AI agents now.
Five Eyes Warns: AI Models Posing Autonomous Hacking Risks
Five Eyes intelligence agencies warn of escalating cyber risks from advanced AI models, capable of autonomous hacking. Understand implications and defense strategies.
Zero-Day Acquisition Firm Raises Red Flags: Trust and Supply Chain Risks
A cybersecurity startup offering millions for zero-days is operated by convicted felons. This raises concerns about vulnerability integrity and supply chain risks.
Dialogflow CX 'Rogue Agent' Bug Enabled AI Conversation Hijacking
A 'Rogue Agent' vulnerability in Google Dialogflow CX could have allowed attackers to silently manipulate AI conversations, exfiltrate data, and compromise multiple…
DuckDuckGo Browser Enhances Privacy with YouTube Ad Blocking
DuckDuckGo's privacy-focused browser now blocks most YouTube video ads, bolstering user privacy against tracking and unwanted commercial interruptions.
AI-Enhanced Service Desk Attacks: Impersonation & Prevention
AI is significantly escalating service desk impersonation attacks. This analysis details three key methods threat actors employ and provides critical mitigation…
SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks
Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.
EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption
Analysis of the EvilTokens ghost phishing campaign targeting Microsoft 365 users via browser-side decryption to bypass traditional email security gateways.