All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
NDR for Incident Response Teams: Richard Bejtlich on Visibility
Richard Bejtlich explains why NDR is essential for security operations to bridge visibility gaps and move beyond high-volume, low-context alert triage.
Analyzing Internet Background Radiation and Automated Scanning Trends
An analysis of automated cybercrime traffic and internet background radiation, detailing how botnets exploit vulnerabilities like CVE-2017-17215.
CVE-2026-20245: Zero-Day Root Privilege Escalation in Cisco SD-WAN
Attackers are exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN Manager to gain root access. Learn how to detect and remediate CVE-2026-20245.
Chrome 149 Update Patches 18 High-Severity UAF Vulnerabilities
Google releases Chrome 149 to address 18 severe vulnerabilities, including multiple use-after-free defects in Graphics, Dawn, and Mojo components.
NIST Drafts Updated IoT Security Guidance for Federal Networks
NIST updates its IoT security guidance to help federal agencies manage risks and establish product cybersecurity requirements for connected devices.
Cisco Catalyst SD-WAN CVE-2026-20245 Root Access Exploit Analysis
Exploitation of Cisco Catalyst SD-WAN zero-day CVE-2026-20245 allows root access. Mandiant reveals active abuse months prior to the June 2026 disclosure.
Advertisement
Malware Evades AI Analysis with 'Forbidden Text' Tactics
Threat actors embed 'forbidden' text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers.
2026 FIFA World Cup Cyber Threats: Infrastructure & Phishing Analysis
An analysis of the cyber threat landscape for the 2026 FIFA World Cup, detailing infrastructure risks, social engineering, and mitigation strategies.
Cisco SD-WAN CVE-2023-20252 Exploited via Rogue Peering - Patch Now
Attackers exploited Cisco SD-WAN Manager flaws like CVE-2023-20252 for two months before disclosure. Learn how to secure your vManage infrastructure today.
AI Agent Traps: Information as an Attack Surface for Autonomous Systems
Attackers exploit trusted data sources to deploy AI agent traps, leading to hidden content injections and cognitive state poisoning for autonomous AI systems.
Nathaniel Saavedra Sentenced for 2022 DraftKings Account Takeover
21-year-old hacker 'Snoopy' sentenced to 18 months in prison for the DraftKings cyberattack that compromised 60,000 accounts via credential stuffing in 2022.
Google Update: New Search and Play History Privacy Controls
Google launches new privacy tools for Search and Play, allowing users to disable personalization and quickly delete recent activity to improve data privacy.
Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen
Law enforcement and private sector dismantled infrastructure for Amadey and StealC malware, leading to 27M stolen credentials recovery. Learn impact & defense.
CVE-2025-67038: Lantronix EDS5000 Series Critical Code Injection
CISA warns of active exploitation of CVE-2025-67038, a critical code injection flaw impacting Lantronix EDS5000 Series devices. Patch immediately.
Amadey & StealC Malware C2 Infrastructure Disrupted
Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.
Amadey & StealC Malware Operations Disrupted by Operation Endgame
Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.
CISA Warns: Ubiquiti UniFi & Lantronix Flaws Actively Exploited
CISA warns of active exploitation against Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Security professionals must patch immediately.
Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories
Novee Security uncovered Cordyceps, a critical CI/CD workflow flaw exposing over 300 GitHub repositories to supply chain compromise, affecting major organizations.
DoJ Seizes HuiOne Cloud Account in Cyber Scam Crackdown
US authorities seized a cloud account tied to HuiOne Group and sanctioned Prince Group entities involved in global money laundering and cyber scam operations.
Autonomous Agentic AI Adversaries: Managing Machine-Speed Cyber Threats
The transition to agentic AI adversaries marks the end of human-speed threats. Learn how autonomous agents automate exploit discovery and execution at scale.
2026 World Cup Scams: Detecting SEO Hijacking and Purchase Fraud
Threat actors are using SEO hijacking and compromised domains to scale purchase scams targeting the 2026 FIFA World Cup. Learn how to identify these TTPs.
CVE-2024-6387: OpenSSH regreSSHion RCE — Mitigation Guide
Critical analysis of CVE-2024-6387 (regreSSHion) in OpenSSH. Learn technical details of the signal handler race condition and how to defend Linux systems.
Linux Process Name Masquerading: Analyzing T1036 Obfuscation
Explore the technical methods behind Linux process name masquerading (MITRE ATT&CK T1036) used by actors like Velvet Ant to evade detection.
Cordyceps: Defending Against Malicious Pull Requests in CI/CD
The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.