All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Millions of Passports Leaked via Low-Value Identity Verification Breach
A database of nearly a million passports globally was leaked online, originating from a breach in a low-value ID verification system, exposing high-value credentials.
Linux Foundation's Project Akrites: Bolstering Open Source Security
Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.
AI-Native Contextual Security: Nebulock's $25M Funding Impact
Nebulock secures $25M for AI-native contextual security, emphasizing advanced threat hunting, proactive detection, and behavioral analytics capabilities.
Securing Autonomous AI Agents: Identity Governance Challenges
AI agents are rapidly deployed in enterprises, inheriting permissions and operating autonomously.
CVE-2026-43503: Linux Kernel DirtyClone Flaw Grants Root Access
DirtyClone (CVE-2026-43503) is a Linux kernel privilege escalation allowing local users to gain root access via cloned network packets. Patch now.
Mexico's 2025–2030 Cybersecurity Plan: Addressing Evolving Threats
Analysis of Mexico's 2025–2030 National Cybersecurity Plan, evaluating its strategy against ransomware, organized crime, and AI-driven threats.
Advertisement
Recorded Future's Hybrid Threat Intelligence Methodology
Examine Recorded Future's Insikt Group methodology, which blends human expertise with automated analysis to deliver actionable threat intelligence, improving defensive…
Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit
Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.
AI Search Summary Liability: German Court Redefines Publisher Role
A landmark German court ruling declares Google liable for its AI search summaries, setting a significant precedent for AI content providers and data integrity.
Russian APT Gamaredon Upgrades UAC-0010 Malware Arsenal
Analysis of Russian APT Gamaredon's (UAC-0010) upgraded arsenal, featuring stealthier Pterodo malware loading and volatile C2 infrastructure rotation.
CVE-2022-25247: PTC Windchill RCE Exploited in the Wild
CISA warns of active exploitation of CVE-2022-25247, an RCE flaw in PTC Windchill PLM software. Learn how to detect and mitigate this critical threat.
Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign
Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.
Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations
Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.
Cellebrite UFED Forensic Extraction from Activist iPhone in Russia
Technical analysis of forensic tool usage by Russian authorities against activists, highlighting the persistence of extraction tools in sanctioned regions.
Cisco CUCM SSRF Flaw: Rapid Exploitation & Root Privilege Escalation
Attackers are rapidly weaponizing a Cisco Unified CM server-side request forgery (SSRF) flaw, escalating privileges to root. Immediate patching is critical.
Philip Martin Joins Uber as CISO to Lead Enterprise Security
Uber appoints former Coinbase CSO Philip Martin as CISO to oversee its global enterprise security organization and strategic defensive operations.
SIM-Swapping Ring Busted: Millions in Crypto Theft via Telecom Hacks
Polish authorities dismantle a sophisticated SIM-swapping ring that hijacked telecom partners and email accounts to steal millions in cryptocurrency.
Anthropic's Claude Cowork Mobile: Enterprise Security Implications
Anthropic tests Claude Cowork on mobile, enabling long-running AI tasks. This analysis covers potential data, access, and shadow IT risks for security teams.
Police Collusion Sustains SE Asian Cybercrime and Scam Centers
Corruption and police collusion in Southeast Asia facilitate a multi-billion dollar cybercrime industry, complicating international law enforcement efforts.
Windows 10 ESU Extended to 2027: Security Implications
Microsoft extends free Windows 10 Extended Security Updates (ESU) for consumers until October 2027. Understand the security implications and planning for end-of-life.
Shopify Shop App Abused for Callback Phishing Attacks
Attackers are exploiting the Shopify Shop app's order tracking features to launch callback phishing attacks, tricking users into installing remote access tools.
ThreatsDay Bulletin: Proxyware, Legacy Flaws, and AI Crime Trends
Analysis of recent cybersecurity threats including smart TV proxyware, a 24-year curl bug, and AI-driven cybercrime trends impacting enterprise security.
"Adblock for YouTube" Extension: Dormant Script Injection Threat
A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.
LLM Prompt Injection: Role Confusion Exposes Core Architectural Flaws
An in-depth analysis of LLM prompt injection, detailing how 'role confusion' in model representations undermines tag-based security and demands architectural solutions.