All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
FortiBleed: 73,932 FortiGate Systems Exposed – Credential Leak Analysis
Analysis of the FortiBleed campaign, detailing the exposure of administrative and VPN credentials for over 73,000 Fortinet FortiGate firewalls and critical mitigation…
CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance
Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.
Klue OAuth Breach: Icarus Threat Group Targets Salesforce
Klue confirms an OAuth token breach by the Icarus group, potentially exposing customer Salesforce environments. Learn how to secure your integrations.
GentleKiller EDR Framework: The Gentlemen RaaS Defense Evasion Tactics
The Gentlemen RaaS leverages the GentleKiller framework to terminate 400+ security processes. Learn how this tool impairs EDR and antivirus defenses.
usbliter8 Exploit Breaks Apple A12/A13 SecureROM Boot Chain
Paradigm Shift researchers disclose 'usbliter8', an unpatchable hardware exploit enabling arbitrary code execution in Apple A12 and A13 SecureROM, requiring physical…
AI & Threat Proliferation: Impact on Cybersecurity Teams & Roles
Examines how AI and increasing cyber threats are stressing cybersecurity teams, driving demand for specialized expertise and organizational shifts.
Advertisement
CryptoBandits Malware: Tor-Abusing Backdoor & Data Theft
CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.
GCP Config Connector Takeover: Unpatched Flaw Critical for Cloud Environments
An unpatched flaw in GCP Config Connector poses a critical takeover risk to Google Cloud environments.
AI Agents: The Emerging Identity & Governance Challenge
Unmanaged AI agents pose significant security risks by operating as uncontrolled identities with access to sensitive enterprise systems. Learn mitigation strategies.
Texas Data Breach Exposes 3M Driver's Licenses via Vendor
A data breach at a third-party vendor of the Texas Parks and Wildlife Department exposed over 3 million driver's licenses, impacting Texans' PII.
Operation Endgame Disrupts SocGholish: WordPress Site Remediation
Operation Endgame targets SocGholish infrastructure, cleaning 14,971 WordPress sites. Understand the impact and crucial remediation steps for web administrators.
AutoJack: AI Browsing Agents Hijacked for Host RCE via Web Pages
Microsoft researchers reveal AutoJack, a novel exploit chain where malicious web pages hijack AI browsing agents to achieve remote code execution on host systems.
Mitigating State Digital Surveillance Risks: Spyware, AI, & Interception
Analyze the state digital surveillance risk landscape, detailing how governments leverage spyware, AI, and network interception to monitor travelers and how to mitigate…
Klue Security Incident: Mitigating Third-Party Risk in Intelligence
Analyze the impact of the Klue security incident on Recorded Future. Learn how to secure SaaS integrations and improve third-party vendor risk management.
eBanking Phishing Using IPv4-Mapped IPv6 Addresses Detected
Analysis of a sophisticated eBanking phishing campaign targeting a major Belgian bank, leveraging IPv4-mapped IPv6 addresses for obfuscation.
Bypass AI Malware Scanners via Policy-Triggering Prompt Injection
Malware authors are embedding 'forbidden' text into code to trigger safety refusals in AI-mediated security scanners, effectively bypassing automated analysis.
Operation Escaneo: Hybrid Espionage and Cybercrime Trends in LatAm
Analysis of Operation Escaneo, a threat group blending intelligence collection with cybercrime across Latin America using njRAT and AsyncRAT variants.
Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines
Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.
Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service
Researchers link the massive Popa Android botnet to NetNut, a residential proxy provider. The botnet exploits millions of TV boxes for fraud and scraping.
Cisco Acquires WideField Security to Advance Splunk Agentic SOC
Cisco expands its security portfolio by acquiring WideField Security to integrate identity and session context into Splunk’s AI-driven Agentic SOC platform.
Klue Supply Chain Attack Hits Salesforce Instances of Security Firms
Attackers breached competitive intelligence platform Klue, exfiltrating data from Salesforce instances of customers including Huntress and Recorded Future.
FortiBleed Data Leak: Securing Fortinet VPNs Against Exposure
CISA warns organizations after 74,000 Fortinet VPN credentials were leaked online. Learn how to mitigate the FortiBleed threat and secure your network.
Cyberstalking Charges Filed Over AI-Generated Deepfake Harassment
A New York man faces federal cyberstalking charges for allegedly using AI-generated deepfakes and imposter social media profiles to target a college student.
CVE-2025-20701: Apple Patches Beats Studio Buds Eavesdropping Flaw
Apple addresses CVE-2025-20701, a high-severity flaw in Beats Studio Buds allowing nearby attackers to bypass pairing consent and access the microphone.