All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Alleged Scattered Spider Hacker Extradited: Mitigating Social Engineering
An alleged Scattered Spider member's extradition highlights ongoing efforts against sophisticated social engineering and identity-based attacks impacting major…
FortiBleed: Credential Theft Fuels INC & Lynx Ransomware Intrusions
Analysis of the FortiBleed campaign, linking mass FortiGate credential theft to INC and Lynx ransomware operations for follow-on intrusions.
JADEPUFFER AI Agent Exploits Langflow RCE for Automated Ransomware
The threat actor JADEPUFFER has pioneered the use of AI agents to automate end-to-end ransomware attacks via Langflow RCE, from initial access to data wiping.
Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance
Runtime Rebel analyzes Iranian-nexus TAG-182's use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.
CVE-2024-45133: Apache Druid RCE via YAML Deserialization
Critical unauthenticated RCE in Apache Druid CVE-2024-45133 allows attackers to execute code via unsafe SnakeYAML deserialization in ingestion tasks.
ClickFix Social Engineering: How to Detect Fake Browser Update Attacks
ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.
Advertisement
Adaptive Phishing: How Attackers Fingerprint Devices via User-Agents
Threat actors are using real-time device fingerprinting to deliver OS-specific phishing payloads, increasing the success rates of social engineering attacks.
Microsoft Teams: New Controls for AI Bot Meeting Access
Microsoft Teams introduces new admin policies requiring organizer approval for external AI bots, enhancing control over automated participants in sensitive meetings.
Lynx Ransomware Linked to Massive FortiBleed Credential Theft
Threat actors behind Lynx and INC ransomware leverage FortiBleed campaign to harvest over 440,000 Fortinet VPN credentials via CVE-2023-48788 exploits.
Medtronic Data Breach: ShinyHunters Campaign Exposes Customer PII
Medtronic notifies customers of a data breach linked to ShinyHunters. Learn how cloud credential theft led to the exposure of patient and customer records.
CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide
CISA adds CVE-2026-45659, a high-severity SharePoint Server deserialization flaw, to KEV catalog after confirmed active exploitation by threat actors.
Unpatched Argo CD repo-server RCE via Internal Port Exposure
An unpatched vulnerability in the Argo CD repo-server allows unauthenticated attackers to achieve RCE and potentially take over Kubernetes clusters.
Adobe ColdFusion, Campaign Classic RCE via 7 Critical Flaws – Patch Now
Adobe addresses 7 critical CVSS 10.0 flaws in ColdFusion and Campaign Classic, enabling RCE and privilege escalation. Immediate patching is essential.
Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users
Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.
Papa Johns' Surveillance-Based Advertising: Data Privacy Concerns
Papa Johns partners with NBCU and Instacart to leverage grocery purchase data for hyper-targeted ads. Learn about the privacy implications and data usage.
Securing Events: Integrating Threat Intel & Digital Security
Event security demands a unified approach to cyber and physical threats. Learn how proactive threat intelligence and robust digital defenses safeguard events.
NetScaler Vulnerabilities: HTTP/2 Bomb & High-Severity Info Disclosure
Citrix addresses six NetScaler vulnerabilities, including a new HTTP/2 Bomb and a high-severity information disclosure bug similar to CitrixBleed.
Adobe ColdFusion & Campaign Classic: Critical RCE Patches
Adobe has released critical patches for ColdFusion and Campaign Classic, addressing seven vulnerabilities with 10/10 CVSS scores that allow remote code execution.
Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency
Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.
Oracle EBS: Over 900 Instances Exposed to Ongoing Attacks
Over 900 Oracle E-Business Suite (EBS) instances are exposed online, facing ongoing attacks targeting a critical flaw. Learn the risks and mitigation steps.
Microsoft's Post-Quantum Cryptography Acceleration: A 2029 Shift
Microsoft accelerates its post-quantum cryptography (PQC) timeline to 2029, urging security professionals to assess current encryption standards and prepare for…
2026 Cybersecurity Assessment: Bridging the Awareness-Resilience Gap
The 2026 Bitdefender Cybersecurity Assessment reveals a critical gap between cyber risk awareness and operational resilience.
Metamask Phishing Campaign Targets Secret Recovery Phrases
Threat actors are targeting Metamask users with phishing emails designed to harvest Secret Recovery Phrases, leading to the total loss of cryptocurrency assets.
How Agentjacking Exploits AI Coding Agents via Fake Bug Reports
Researchers demonstrate 'Agentjacking,' a technique using indirect prompt injection to hijack AI coding agents through malicious GitHub bug reports.