All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
CVE-2026-40138: BeyondTrust Pre-Auth Bypass in Remote Support & PRA
BeyondTrust patched CVE-2026-40138, a critical pre-authentication vulnerability in Remote Support and PRA, enabling unauthenticated device takeover. Patch immediately.
Critical RCEs: FortiNAC CVE-2023-33300 & SonicWall SMA Zero-Day
Two critical vulnerabilities, FortiNAC RCEs (CVE-2023-33300, CVE-2023-33299) and a SonicWall SMA zero-day SQLi, require immediate patching and mitigation.
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.
RCS Service Discovery via DNS NAPTR Records Explained
Understanding how Rich Communication Services (RCS) relies on DNS NAPTR records for service discovery and connection establishment, and its security implications for…
France Mandates Quantum-Safe Encryption by 2027
France's ANSSI will stop certifying non-quantum-safe encryption products from 2027, compelling government and critical operators to adopt post-quantum solutions.
JadePuffer: First LLM-Driven Ransomware Leverages Langflow Flaw
Analysis of JadePuffer, the first reported LLM-driven ransomware, which exploited a Langflow vulnerability to exfiltrate database data and encrypt systems.
Advertisement
NetScaler Memory Disclosure Flaw Under Active Exploitation
Attackers are actively exploiting a new memory disclosure flaw in Citrix NetScaler products, rapidly weaponizing a public proof-of-concept.
Business-Aligned Risk Management: Bridging Security & Enterprise Goals
Learn how organizations can transition from technical, isolated security data to a continuous, business-aligned risk management lifecycle, enhancing security outcomes.
Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell
Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.
EtherRAT Malware via Microsoft Teams IT Support Impersonation
Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.
Job Interview Phishing Targets Google Accounts of Marketing Professionals
A new phishing campaign impersonates 30+ major brands to lure marketing professionals into fake job interviews, aiming to steal their Google account credentials.
CVE-2026-53359: Linux KVM Guest-to-Host Escape via Januscape Flaw
A critical 16-year-old use-after-free vulnerability, Januscape (CVE-2026-53359), in Linux KVM allows guest VMs to escape to the host on Intel and AMD x86 systems.
Iran-Linked Hackers Deploy New Cavern C2 Against Israeli Targets
Iranian state-sponsored threat actors are using a novel modular C2 framework, Cavern (Cav3rn), to compromise Israeli IT and government entities.
SkillCloak: Malicious AI Agent Skills Evade Static Code Scanners
Researchers at HKUST reveal SkillCloak, a technique using self-extracting packing to allow malicious AI agent skills to bypass static security analysis.
Opera GX Mod Auto-Installation Vulnerability Analysis
A critical flaw in Opera GX allowed malicious sites to auto-install mods and exfiltrate sensitive data. Learn how to detect and mitigate this browser threat.
Flipper Zero Transitions to Community-Led Firmware Development Model
Flipper Devices shifts firmware development to a community-centric model, raising new considerations for supply chain integrity and security update lifecycles.
JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle
Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.
Kairos Group Extorts $1M from US Government in Data-Theft Campaign
A US government entity paid $1M to the Kairos group to prevent a data leak, signaling a shift from traditional ransomware to pure data-theft extortion.
PolinRider: North Korean Hackers Push 108 Malicious Packages
Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.
Open Source Zero-Days and ATM Jackpotting: Analysis of Recent Threats
Legal actions against ATM jackpotting crews and hacktivists highlight ongoing risks in open-source security and financial infrastructure.
NetNut Residential Proxy Disrupted: 2M Android Devices Cut Off
A joint operation disrupted NetNut, a residential proxy network leveraging over 2 million compromised Android devices, including smart TVs and streaming boxes.
FatFs Vulnerabilities: Securing Embedded Devices Against RCE
Security researchers at runZero have disclosed seven vulnerabilities in the widely used FatFs library, impacting millions of IoT and industrial devices.
CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android
Critical Linux kernel 'Bad Epoll' flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.
ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit
ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.