All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Azure CLI Password Spray Campaign: Defending 81 Million Login Attempts
A massive password spray campaign targeting Azure CLI via LSHIY hosting infrastructure has been detected, highlighting the urgent need for conditional access.
Dawnguard Raises $6.3M for Security Architecture Automation Platform
Dawnguard secures $6.3M in seed funding to automate security architecture reviews and accelerate secure cloud infrastructure deployment at scale.
Anthropic Claude Fable 5 Restored After U.S. Export Control Lift
Anthropic restores global access to Claude Fable 5 following the lifting of U.S. export controls linked to jailbreaking vulnerabilities and security concerns.
Phantom Squatting: How Attackers Weaponize AI-Hallucinated Domains
Security researchers have identified 'Phantom Squatting,' a technique where attackers register non-existent domains hallucinated by AI for phishing.
China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor
A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.
CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware
Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.
Advertisement
Anthropic Claude 5 Sonnet: Enterprise Performance and Safety Analysis
Anthropic releases Claude 5 Sonnet, achieving performance parity with Opus 4.8. Technical analysis of safety benchmarks and cybersecurity implications.
Anthropic Restores Fable 5 and Mythos 5 Access After Export Lift
Anthropic is set to restore global access to its Fable 5 and Mythos 5 AI models following the lifting of Department of Commerce export controls this Wednesday.
NetScaler ADC CVE-2026-8451: Mitigating Arbitrary File Read Risks
Citrix patches six NetScaler ADC and Gateway vulnerabilities, including CVE-2026-8451. Secure your infrastructure against file reads and denial-of-service.
AI Agents Vulnerable to Data Leak via Poisoned MCP Tools
Microsoft warns that malicious tool descriptions for AI agents can lead to stealthy data exfiltration, bypassing security controls by mimicking routine actions.
AI-Generated Workflows: Hidden Vulnerabilities & Control Gaps
Explore the silent security disaster of AI-generated workflows. Understand hidden vulnerabilities, control gaps, and the critical need for human oversight in AI-driven…
GuardFall: Shell Injection Risks in Open-Source AI Coding Agents
GuardFall bypass exposes 10 of 11 popular open-source AI coding agents to decades-old shell injection vulnerabilities. Understand the threat and mitigation.
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.
June Apple Security Updates for iOS, macOS, Safari: Patch Now
Apple released essential security updates for iOS/iPadOS, macOS, and Safari in June. Learn why timely patching is critical for protecting your devices and data.
AI-Enhanced Video Surveillance: Implications for Mass Spying
Explore how AI is transforming video surveillance, enabling natural language queries on footage and facilitating mass spying capabilities, with global examples.
NIST NVD Enrichment Changes: Impact on CVE Coverage and Accuracy
NIST's reduction in NVD enrichment impacts CVE coverage and data accuracy, challenging security professionals to adapt vulnerability management strategies.
Supreme Court Upholds Cellphone Location Data Privacy
The Supreme Court's ruling extends constitutional privacy protections to cell phone location history, impacting geofence warrants and data access for law enforcement.
Red Teaming & Proactive Security Insights from IBM X-Force Red Founder
Explore the evolution of red teaming and proactive security strategies through the lens of Chris Thompson, founder of IBM X-Force Red.
Microsoft Teams Enhances Meeting Security with New Bot Protection Policy
Microsoft introduces a new admin policy for Teams meetings, preventing unapproved third-party bots from joining, mitigating meeting bombing incidents.
Aflac Japan Data Breach Exposes Customer Financial Data
Aflac Japan subsidiary data breach exposed personal and bank account details for an undisclosed number of customers. Review impact and mitigation.
AirDrop and Quick Share: Proximity Flaws Cause Crashes and Bypass Checks
Researchers found six security flaws in AirDrop and Quick Share, enabling nearby attackers to crash devices and bypass security checks without user interaction.
CVE-2026-48558: SimpleHelp OIDC Authentication Bypass & Malware
Threat actors are actively exploiting CVE-2026-48558, a critical SimpleHelp OpenID Connect authentication bypass vulnerability, to deploy TaskWeaver and Djinn Stealer…
Critical Flaw Exposes Indian Government Data in National Portal
A critical vulnerability and several others exposed private data within Indian government systems, allowing potential takeover of a national portal.
Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.