Skip to main content

All Articles

Security Intelligence

3414 articles · Updated every 8 hours

Severity (this page):

Advertisement

INFO
Threat Intel

Alleged Scattered Spider Hacker Extradited: Mitigating Social Engineering

An alleged Scattered Spider member's extradition highlights ongoing efforts against sophisticated social engineering and identity-based attacks impacting major…

Runtime Rebel Intel
5 min read · Jul 2, 2026
FortiBleed: Credential Theft Fuels INC & Lynx Ransomware Intrusions
HIGH
Threat Intel

FortiBleed: Credential Theft Fuels INC & Lynx Ransomware Intrusions

Analysis of the FortiBleed campaign, linking mass FortiGate credential theft to INC and Lynx ransomware operations for follow-on intrusions.

Runtime Rebel Intel
4 min read · Jul 2, 2026
JADEPUFFER AI Agent Exploits Langflow RCE for Automated Ransomware
HIGH
Threat Intel

JADEPUFFER AI Agent Exploits Langflow RCE for Automated Ransomware

The threat actor JADEPUFFER has pioneered the use of AI agents to automate end-to-end ransomware attacks via Langflow RCE, from initial access to data wiping.

Runtime Rebel Intel
4 min read · Jul 2, 2026
Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance
HIGH
Threat Intel

Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance

Runtime Rebel analyzes Iranian-nexus TAG-182's use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.

Runtime Rebel Intel
5 min read · Jul 2, 2026
HIGH
Vulnerabilities

CVE-2024-45133: Apache Druid RCE via YAML Deserialization

Critical unauthenticated RCE in Apache Druid CVE-2024-45133 allows attackers to execute code via unsafe SnakeYAML deserialization in ingestion tasks.

Runtime Rebel Intel
4 min read · Jul 2, 2026
ClickFix Social Engineering: How to Detect Fake Browser Update Attacks
HIGH
Threat Intel

ClickFix Social Engineering: How to Detect Fake Browser Update Attacks

ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.

Runtime Rebel Intel
3 min read · Jul 2, 2026

Advertisement

Adaptive Phishing: How Attackers Fingerprint Devices via User-Agents
HIGH
Threat Intel

Adaptive Phishing: How Attackers Fingerprint Devices via User-Agents

Threat actors are using real-time device fingerprinting to deliver OS-specific phishing payloads, increasing the success rates of social engineering attacks.

Runtime Rebel Intel
4 min read · Jul 2, 2026
INFO
Cloud Security

Microsoft Teams: New Controls for AI Bot Meeting Access

Microsoft Teams introduces new admin policies requiring organizer approval for external AI bots, enhancing control over automated participants in sensitive meetings.

Runtime Rebel Intel
4 min read · Jul 2, 2026
HIGH
Threat Intel

Lynx Ransomware Linked to Massive FortiBleed Credential Theft

Threat actors behind Lynx and INC ransomware leverage FortiBleed campaign to harvest over 440,000 Fortinet VPN credentials via CVE-2023-48788 exploits.

Runtime Rebel Intel
4 min read · Jul 2, 2026
HIGH
Data Breach

Medtronic Data Breach: ShinyHunters Campaign Exposes Customer PII

Medtronic notifies customers of a data breach linked to ShinyHunters. Learn how cloud credential theft led to the exposure of patient and customer records.

Runtime Rebel Intel
4 min read · Jul 2, 2026
CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide
HIGH
Vulnerabilities

CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide

CISA adds CVE-2026-45659, a high-severity SharePoint Server deserialization flaw, to KEV catalog after confirmed active exploitation by threat actors.

Runtime Rebel Intel
3 min read · Jul 2, 2026
Unpatched Argo CD repo-server RCE via Internal Port Exposure
HIGH
Vulnerabilities

Unpatched Argo CD repo-server RCE via Internal Port Exposure

An unpatched vulnerability in the Argo CD repo-server allows unauthenticated attackers to achieve RCE and potentially take over Kubernetes clusters.

Runtime Rebel Intel
3 min read · Jul 2, 2026
Adobe ColdFusion, Campaign Classic RCE via 7 Critical Flaws – Patch Now
HIGH
Vulnerabilities

Adobe ColdFusion, Campaign Classic RCE via 7 Critical Flaws – Patch Now

Adobe addresses 7 critical CVSS 10.0 flaws in ColdFusion and Campaign Classic, enabling RCE and privilege escalation. Immediate patching is essential.

Runtime Rebel Intel
5 min read · Jul 1, 2026
Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users
HIGH
Malware

Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users

Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.

Runtime Rebel Intel
4 min read · Jul 1, 2026
INFO
Threat Intel

Papa Johns' Surveillance-Based Advertising: Data Privacy Concerns

Papa Johns partners with NBCU and Instacart to leverage grocery purchase data for hyper-targeted ads. Learn about the privacy implications and data usage.

Runtime Rebel Intel
4 min read · Jul 1, 2026
Securing Events: Integrating Threat Intel & Digital Security
INFO
Threat Intel

Securing Events: Integrating Threat Intel & Digital Security

Event security demands a unified approach to cyber and physical threats. Learn how proactive threat intelligence and robust digital defenses safeguard events.

Runtime Rebel Intel
4 min read · Jul 1, 2026
HIGH
Vulnerabilities

NetScaler Vulnerabilities: HTTP/2 Bomb & High-Severity Info Disclosure

Citrix addresses six NetScaler vulnerabilities, including a new HTTP/2 Bomb and a high-severity information disclosure bug similar to CitrixBleed.

Runtime Rebel Intel
4 min read · Jul 1, 2026
CRITICAL
Vulnerabilities

Adobe ColdFusion & Campaign Classic: Critical RCE Patches

Adobe has released critical patches for ColdFusion and Campaign Classic, addressing seven vulnerabilities with 10/10 CVSS scores that allow remote code execution.

Runtime Rebel Intel
4 min read · Jul 1, 2026
INFO
Supply Chain

Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency

Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.

Runtime Rebel Intel
4 min read · Jul 1, 2026
CRITICAL
Threat Intel

Oracle EBS: Over 900 Instances Exposed to Ongoing Attacks

Over 900 Oracle E-Business Suite (EBS) instances are exposed online, facing ongoing attacks targeting a critical flaw. Learn the risks and mitigation steps.

Runtime Rebel Intel
4 min read · Jul 1, 2026
Microsoft's Post-Quantum Cryptography Acceleration: A 2029 Shift
INFO
Threat Intel

Microsoft's Post-Quantum Cryptography Acceleration: A 2029 Shift

Microsoft accelerates its post-quantum cryptography (PQC) timeline to 2029, urging security professionals to assess current encryption standards and prepare for…

Runtime Rebel Intel
4 min read · Jul 1, 2026
2026 Cybersecurity Assessment: Bridging the Awareness-Resilience Gap
INFO
Threat Intel

2026 Cybersecurity Assessment: Bridging the Awareness-Resilience Gap

The 2026 Bitdefender Cybersecurity Assessment reveals a critical gap between cyber risk awareness and operational resilience.

Runtime Rebel Intel
4 min read · Jul 1, 2026
HIGH
Threat Intel

Metamask Phishing Campaign Targets Secret Recovery Phrases

Threat actors are targeting Metamask users with phishing emails designed to harvest Secret Recovery Phrases, leading to the total loss of cryptocurrency assets.

Runtime Rebel Intel
4 min read · Jul 1, 2026
How Agentjacking Exploits AI Coding Agents via Fake Bug Reports
HIGH
Threat Intel

How Agentjacking Exploits AI Coding Agents via Fake Bug Reports

Researchers demonstrate 'Agentjacking,' a technique using indirect prompt injection to hijack AI coding agents through malicious GitHub bug reports.

Runtime Rebel Intel
4 min read · Jul 1, 2026