All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Quantifind Secures Funding for AI-Native Risk Intelligence Expansion
Quantifind's $200M funding will accelerate its AI-native risk intelligence platform, enhancing capabilities for financial crime detection and compliance globally.
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
A critical vulnerability in SimpleHelp is actively exploited to deploy malware, targeting credentials, SSH keys, and crypto wallets. Immediate patching is essential.
Windows BlueHammer Flaw Exploited by Ransomware Gangs — Patch Now
CISA warns that ransomware gangs are now exploiting the BlueHammer privilege escalation vulnerability in Microsoft Defender to bypass security controls.
CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE Threat
A critical pre-authentication RCE (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute root commands via a crafted API request.
BioShocking Attack: AI Browsers Leak Credentials Via Deception
LayerX's BioShocking technique exploits AI browsers like ChatGPT Atlas, Perplexity Comet, and Claude to leak user credentials through deceptive game scenarios.
CVE-2024-2821: Critical RCE in Daktronics Controllers — Patch Now
Critical vulnerabilities (CVE-2024-2821, CVE-2024-2822, CVE-2024-2823) in Daktronics Venus 1500 and Vanguard controllers allow remote hacking of highway signs and…
Advertisement
ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen
ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC, exfiltrating public data, logs, and configuration files. Review PeopleSoft security.
Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters
Nissan discloses a data breach impacting current and former employees, attributed to an exploited Oracle PeopleSoft zero-day vulnerability linked to the ShinyHunters…
Malicious Perplexity Chrome Extension Intercepts User Data
A malicious Chrome extension impersonating Perplexity AI intercepted user search queries and address bar inputs, routing them via attacker infrastructure, posing a…
Russia's Evolving Influence Ecosystem: Global Pivot & AI Integration
Russia's influence ecosystem pivots from Ukraine-centric operations to global targets, leveraging generative AI and hybrid cyber-IO tactics.
Weak RSA Keys with Many Zeros Found In-the-Wild: Factoring Risk
New research reveals a class of weak RSA keys containing many zero bits, making them vulnerable to factoring.
Claude Code Indirect Prompt Injection: Hijacking Developer Machines
Researchers demonstrate a new attack method leveraging indirect prompt injection in Claude Code, enabling the hijack of developer machines via malicious code in…
WhatsApp Introduces Usernames to Bolster Phone Number Privacy
WhatsApp's new optional username feature allows users to connect without sharing their phone number, significantly enhancing personal data privacy and security.
Agentic AI Identity Problem: New Attack Surface for Enterprises
Agentic AI systems pose novel identity and access management challenges, creating new attack vectors for data exfiltration and privilege escalation.
US Targets Russian-Linked UNC5792, UNC4221 Hackers of Messaging Apps
US State Dept. offers $10M for info on Russian-linked UNC5792 & UNC4221 groups targeting WhatsApp, Signal users. Learn about nation-state threats.
Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks
Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.
Analyzing WhatsApp Usernames: A Shift in User Identity and Data Privacy
WhatsApp introduces usernames to enhance user privacy, decoupling identity from phone numbers. This article analyzes the feature's impact on OSINT and data privacy.
Automated Favicon.ico Reconnaissance for Host Enumeration
Understand how attackers automate favicon.ico analysis for host reconnaissance. Learn to identify and defend against this common, yet often overlooked, enumeration…
Police Drones: Disarmament & Future Security Implications
Sacramento County Sheriff's drone disarmed a suspect with a magnet, raising critical discussions on robotic policing and cyber-physical security risks.
DirtyClone: Linux Kernel Privilege Escalation via Page Cache Manipulation
DirtyClone, a variant of DirtyFrag, allows unprivileged local users to exploit a Linux kernel flaw to manipulate the page cache and achieve root privileges.
DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains
The U.S. Justice Department seized nearly 400 domains illegally streaming FIFA World Cup matches, disrupting copyright infringement and protecting users from associated…
Post-Quantum Cryptography: Securing Credentials from Future Threats
Quantum computers threaten current public-key cryptography, jeopardizing encrypted credentials and sensitive data.
DCloud Uni-App Exploited: 236K Sites Fuel Crypto Scams & Phishing
Over 236,000 DCloud Uni-App sites are co-opted for widespread crypto scams, pig butchering, and phishing operations. Learn how to detect and mitigate these threats.
OpenAI's GPT-5.6 Sol: Implications for Cybersecurity AI
OpenAI unveils GPT-5.6 Sol, touted as its most advanced cybersecurity AI, matching rivals while using fewer tokens. We analyze its potential impact.