All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft
North Korea-linked actors use malicious npm packages ('rollup-packages-polyfill-core', 'rollup-runtime-polyfill-core') to steal developer secrets, mimicking Rollup…
Flock Safety's 'Vehicle Fingerprint' Tech: Covert Vehicle Surveillance
Flock Safety's 'Vehicle Fingerprint' technology allows law enforcement to track vehicles without license plates, raising significant privacy concerns and expanding…
Chinese LLMs Reshape Cyber Defense: Attacker Advantage
Chinese Large Language Models (LLMs) are poised to shift the cyber defense balance, potentially giving attackers an advantage. Understand the implications.
Agentic AI Automates Ransomware Attacks via Langflow Exploitation
Agentic AI agents demonstrate automated multi-stage ransomware attacks using Langflow, raising concerns for AI development security and future threat automation.
Pegasus Spyware Targets MEP Investigating Surveillance
Former European Parliament Member Stelios Kouloglou was repeatedly targeted with Pegasus spyware while investigating surveillance tools.
Armored Likho Leverages BusySnake Stealer Against Critical Sectors
Undocumented threat actor Armored Likho targets government and electric power sectors in Russia, Brazil, and Kazakhstan with BusySnake Stealer.
Advertisement
Peter Stokes Extradition: Impact on Scattered Spider Operations
Technical analysis of the extradition of Peter Stokes and the persistent TTPs of the Scattered Spider threat actor group targeting enterprise networks.
Medtronic Breach: ShinyHunters Exfiltrates 3.8M Patient Records
Medtronic confirms a data breach by ShinyHunters impacting 3.8 million people, exposing personal and protected health information (PHI) from corporate IT systems.
PamStealer: New macOS Malware Targets PAM for Password Exfiltration
Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.
Google Disrupts NetNut Malicious Residential Proxy Network
Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.
Cybersecurity Mission Creep: Policy Expansion & Governance Risks
Examines how policy issues like misinformation, social media safety, and antitrust are being 'cybersecuritized,' leading to urgent, exceptionalist governance responses…
Apple's Accelerated Patch Policy: Responding to AI Exploit Generation
Apple is shifting to more frequent security updates in response to AI's ability to accelerate exploit development, demanding faster patching cycles from organizations.
Cybercrime Risk Shift: Australian SMBs Under Increased Pressure
Analysis of shifting cybercrime landscape in Australia, detailing how institutional safeguards impact SMBs and necessitate updated defense strategies for small…
FBI Seizes NetNut Proxy Platform & Popa Botnet Operations
The FBI, in partnership, seized NetNut residential proxy platform and disrupted the Popa botnet, which compromised millions of devices.
Auditing AI-Driven Software Development: Security Governance Strategies
Learn how to audit AI-generated code and govern AI tool usage to mitigate security risks in modern software development lifecycles.
CitrixBleed: NetScaler Memory Disclosure Exploited Post-Disclosure
CitrixBleed, a new vulnerability in NetScaler appliances, is being actively exploited using public PoC code to retrieve arbitrary memory content. Patch immediately.
Claude Fable Relaunch: Performance Degradation & AI Reliability Concerns
The Claude Fable AI model's relaunch shows significant performance degradation, raising concerns for security professionals evaluating AI tool reliability.
Anthropic Clarifies Claude Fable 5 Availability Post-July 7
Anthropic clarifies Claude Fable 5 availability post-July 7 for subscribers, noting the AI model's temporary departure from usage-based plans.
CVE-2025-5777: Anubis Ransomware Exploits Citrix Bleed 2
Anubis ransomware affiliates exploit Citrix Bleed 2 (CVE-2025-5777) and BYOVD techniques to breach networks via RMM tools and supply chain credentials.
NetNut (Popa) Residential Proxy Disruption: Impact & Defense
Google, FBI, and Lumen have disrupted NetNut (Popa), a vast residential proxy network, reducing its pool of compromised home devices by millions.
Google's €4.1B EU Fine Stands: Android Antitrust Implications
Google loses final appeal against its €4.1 billion EU antitrust fine concerning Android's dominance. Understand the compliance implications for tech giants.
AI Compute Hijacking and BlueHammer Ransomware Analysis
Analysis of emerging threats including AI compute hijacking via sandbox escapes, BlueHammer ransomware TTPs, and logic flaws in Apple email services.
Identity Lifecycle for AI Agents: Addressing Governance Gaps
Traditional Identity Lifecycle Management (ILM) models fail to govern autonomous AI agents, creating security blind spots. Learn why and how to adapt.
ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.