All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
OpenAI Expands Daybreak: Using GPT-5.5-Cyber to Patch Vulnerabilities
OpenAI enhances its Daybreak initiative with GPT-5.5-Cyber, a specialized model designed for deep codebase analysis to identify and remediate security flaws.
WhatsApp VBScript Campaign Installs ManageEngine RMM — Technical Guide
Attackers are targeting WhatsApp Desktop users with malicious VBScripts to install ManageEngine RMM, enabling unauthorized remote access and control.
JaredFromSubway MEV Bot Exploit: $15 Million Lost in Logic Hack
An attacker drained $15 million from the JaredFromSubway Ethereum MEV bot by manipulating its trading logic through the use of malicious bait tokens.
ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored
Attackers compromised ShapedPlugin's distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.
Professional Athletes, Wearables, and Biometric Data Privacy Risks
Explores critical privacy and security implications of biometric data from wearable devices for professional athletes, offering data governance recommendations.
Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto
Analysis of a cross-platform clipboard hijacker spread via elaborate fake reputation campaigns on GitHub, YouTube, and VirusTotal to steal cryptocurrency.
Advertisement
Gravity SMTP Flaw Exploited: WordPress Data Harvest & Remediation
Attackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin to exfiltrate sensitive data, including API keys and server info.
Squidbleed: Heartbleed-Style Data Exposure in Squid Proxy
A critical flaw dubbed Squidbleed in Squid Proxy, affecting versions 3.5-6.x, enables Heartbleed-style memory leakage exposing user credentials and session data.
Rise of 'Search Your Target' Markets for Stolen Credentials
Explores the emerging underground market where attackers pay to precisely search stolen credential databases for specific target organizations and accounts.
Microsoft AutoGen Studio RCE via AutoJack Flaw — Patch Now
Microsoft patched the AutoJack vulnerability chain in AutoGen Studio, enabling remote code execution through malicious AI agent manipulation.
Squidbleed: 29-Year-Old Squid Proxy Bug Leaks Cleartext HTTP Requests
A 29-year-old heap over-read vulnerability, dubbed 'Squidbleed,' in Squid web proxy's default configuration can leak cleartext HTTP requests and credentials.
DifyTap Flaws Expose AI Chats in Dify Platform Without Auth
Zafran Security details DifyTap, a set of four vulnerabilities in Dify, allowing unauthenticated access to cross-tenant AI chat data. Learn impact and mitigation.
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.
CVE-2024-0012: Critical PAN-OS Management Interface RCE Analysis
Technical analysis of CVE-2024-0012 affecting Palo Alto Networks PAN-OS. Learn how to detect CVE-2024-0012 exploit and implement immediate mitigation steps.
Fortinet FortiBleed Campaign: 86,000+ VPN Credentials Stolen
Fortinet addresses the FortiBleed campaign involving 86,000+ confirmed working credentials. Technical analysis and mitigation steps for security professionals.
Apple A-Series BootROM Bypass: Usbliter8 Exploit Technical Analysis
Technical breakdown of the Usbliter8 exploit affecting millions of iPhones. Learn why this hardware-level BootROM vulnerability cannot be patched.
AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network
Security researchers have identified AryStinger, a new malware family using 4,300 legacy routers as a reconnaissance proxy network to bypass security.
CSIS Deploys First-of-Its-Kind Warrant to Neutralize Foreign Botnets
Canada's CSIS utilized a unique threat reduction warrant to access and clean botnet-infected IoT devices and servers located within Canadian borders.
TPWD Data Breach: Third-Party Vendor Compromise Impacts 3 Million
A significant data breach at a Texas Parks and Wildlife Department vendor exposed PII of 3 million individuals. Learn about the supply chain risks involved.
AryStinger Botnet: Thousands of D-Link Routers Compromised as Proxies
The AryStinger botnet has compromised over 4,000 D-Link routers, converting them into malicious proxies using automated exploits for end-of-life hardware.
North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages
Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.
Prinz Eugen Ransomware Prioritizes Recent Files to Maximize Impact
Prinz Eugen ransomware targets files modified within 30 days to disrupt active operations, using a Go-based encrypter and unconventional ransom demands.
CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys
Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.
US Export Controls Force Global Anthropic Fable 5 Shutdown
US government classifies Anthropic Fable 5 as a dangerous munition, leading to a total access shutdown and highlighting new risks in AI export controls.