All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
OAuth Token Theft: How Icarus Targets Salesforce via Klue Breach
Attackers known as Icarus are exploiting compromised OAuth tokens from Klue to exfiltrate sensitive Salesforce data. Learn how to mitigate supply chain risks.
Scattered Spider Members Plead Guilty to Transport for London Attack
Two members of Scattered Spider pleaded guilty to the August 2024 Transport for London cyberattack, highlighting the group's social engineering efficacy.
CVE-2024-20230: Critical RCE in Cisco Unified CM Actively Exploited
Cisco confirms active exploitation of CVE-2024-20230, a critical 9.9 CVSS vulnerability in Unified Communications Manager. Urgent patching is required.
Cisco Unified CM CVE-2026-20230: File-Write Path to Root Exploited
Exploitation of CVE-2026-20230 in Cisco Unified CM allows unauthenticated root access via file-write. Critical security updates are required to prevent compromise.
Tata Electronics Confirms Cyberattack and Data Leak
Tata Electronics confirms a cyberattack impacting its IT infrastructure, leading to data leakage. Analysis of the breach and defense strategies.
CVE-2026-20230: Cisco Unified CM SSRF Actively Exploited
Cisco Unified CM Server is vulnerable to CVE-2026-20230, a high-severity SSRF flaw now under active exploitation. Patch immediately to prevent attacks.
Advertisement
Windows 11 KB5095093: New Point-in-Time Restore and Bug Fixes
Microsoft releases KB5095093 for Windows 11 24H2, introducing a critical Point-in-Time restore feature and addressing multiple system-level bugs.
AI Agent Skill Security Bypass: Fake Skill Reached 26,000 Agents
A security firm demonstrated how a fake AI agent skill bypassed marketplace security scans, reaching 26,000 agents, including corporate accounts, highlighting critical…
FortiBleed: 110 Million Credentials Harvested via FortiGate Firewalls
Russian-speaking threat actors harvest 110 million credentials from 430,000 FortiGate firewalls globally. Learn to detect and mitigate FortiBleed tactics.
Dify AI Platform Data Exposure: Multi-Tenant Risks
Dify AI platform users face critical data exposure flaws, enabling access to private chats, documents, and internal APIs in multi-tenant environments.
Proactive Exploit Validation: Mitigating Rapidly Weaponized Vulnerabilities
Security teams face rapidly weaponized vulnerabilities. Learn how to proactively validate exploitability and fortify defenses against emerging threats, even before…
Scattered Spider Members Plead Guilty in TfL Infrastructure Attack
Two members of the Scattered Spider threat group plead guilty to the 2024 Transport for London hack, exposing risks of identity-based social engineering.
Anthropic Fable 5 Jailbroken: Bypassing AI Guardrails for Malicious Use
Anthropic's Fable 5, a version of Mythos Preview designed with cyberattack prevention guardrails, was jailbroken quickly. This exposes AI model security flaws.
Dify AI Platform Vulnerabilities: How to Mitigate DifyTap Exploit
Researchers discover DifyTap vulnerabilities in the Dify AI platform, allowing attackers to exfiltrate chat histories and secrets through SSRF and RCE.
FortiBleed: FortiGate Firewalls Used as Credential Stealers
Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.
CISO and CIO Role Convergence: Leadership Insights from Carl Froggett
Explore the strategic benefits of merging CISO and CIO roles to improve organizational security posture and operational efficiency in modern enterprises.
Samsung KNOX Kernel Attack Flaw: Millions of Galaxy Devices Exposed
High-severity use-after-free vulnerability in Samsung KNOX exposed millions of Galaxy devices (S9-S25) to kernel attacks for years.
Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT
Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.
Agentic AI Cyber Warfare: Risks of Autonomous Offensive Operations
Analyze the shift from human-led to autonomous agentic AI cyber attacks, exploring detection challenges and strategies for mitigating offensive AI agents.
Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT
Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.
CVE-2024-40766: SonicWall SonicOS Patch and Configuration Guide
Analysis of CVE-2024-40766, a critical improper access control flaw in SonicWall SonicOS exploited by ransomware groups. Learn how to secure management interfaces.
Xsolis Data Breach: 1.4 Million Records Compromised
Healthcare AI provider Xsolis reports a major data breach affecting 1.4 million individuals, exposing Social Security numbers and protected health information.
US Executive Order Accelerates Federal PQC Migration Deadlines
New US Executive Order mandates federal agencies transition high-value assets to Post-Quantum Cryptography by 2030 to mitigate future quantum threats.
WhatsApp Phishing Campaign Deploys VBScript to Compromise PCs
Attackers target WhatsApp users with malicious ZIP files disguised as business documents to deliver VBScript-based remote access malware.