All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
1Password Acquires Apono: Enhancing Just-in-Time Access Governance
1Password's acquisition of Apono integrates just-in-time access governance, strengthening privileged access management for human, machine, and AI identities.
Microsoft Office Launch Issues After June Windows Updates
Microsoft confirms issues preventing third-party applications from launching Office apps or opening documents on Windows systems after recent June updates.
BGP Hijacking: India's Telegram Ban Impacts UAE Access & Mitigation
Explore the technical details of India's Telegram ban, its collateral impact on UAE users, alleged BGP hijacking by Reliance, and MTProto proxy mitigation.
MongoBleed: Unauthenticated Credential Theft via Server Memory
Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…
Adversarial Exposure Validation: Enhancing Security Prioritization
Learn how 'adversarial exposure validation' transforms raw security visibility into confident, actionable prioritization for overwhelmed security teams.
Phantom Stealer: Fileless Credential Theft & Evasion
Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.
Advertisement
Isira Adithya: Research Insights and Bug Bounty Defense Strategies
Examine the methodologies of security researcher Isira Adithya and how ethical hacker insights improve vulnerability management and web application security.
iRhythm Data Breach: Ransomware Group Steals Healthcare Data
Digital health company iRhythm confirms a data breach following a ransomware attack, resulting in stolen patient and operational data. Learn mitigation.
Malicious JetBrains Plugins Steal AI API Keys: Supply Chain Risks
Researchers discovered 15 malicious plugins on the JetBrains Marketplace designed to exfiltrate sensitive AI API keys from developers' IDE environments.
Rokarolla Android Malware Targets 217 Financial Apps
New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.
ClickFix Campaigns Expand Delivery with New Loaders and Fake Lures
ClickFix campaigns are now deploying BabaDeda, Lorem Ipsum, and Potemkin loaders through fake browser update social engineering lures.
Google Vertex AI SDK Model Hijacking via Bucket Squatting
A Google Cloud Vertex AI SDK vulnerability allows attackers to hijack model uploads and achieve RCE through bucket squatting and malicious Pickle files.
Microsoft Copilot 'SearchLeak' Attack: AI Prompt Injection Data Theft
Analysis of the critical Microsoft Copilot 'SearchLeak' attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.
AI's Dual Role in Cybersecurity: Defense and Attack Strategies
Explore how artificial intelligence transforms cybersecurity, empowering both defenders and attackers.
Magnitude Secures $10M to Advance AI in Third-Party Risk Management
Magnitude emerges from stealth with $10 million in funding to evolve third-party risk management using autonomous AI agents, bolstering supply chain security.
CVE-2026-54420: LiteSpeed cPanel Plugin Flaw Under Active Exploit
CISA warns of active exploitation targeting CVE-2026-54420 in LiteSpeed cPanel user-end plugin, urging immediate patching for server security.
Imposter Scams: Analyzing Record $3.5B Projected Losses in 2025
The FTC warns that imposter scams will cause $3.5 billion in losses by 2025. Understand evolving TTPs, target demographics, and effective mitigation strategies.
Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089
Critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under active exploitation. Patch immediately.
94% of Incidents Masked by Anonymized Infrastructure: Attribution Failures
A new survey reveals 94% of cybersecurity incidents leverage anonymized infrastructure, hindering attribution efforts. Security teams struggle despite vast IP data.
Tech Coalition Athena: Collaborative OSS Vulnerability Pre-Disclosure
The Athena coalition, comprising over two dozen organizations, establishes a shared platform to proactively triage and remediate open-source software vulnerabilities…
Earth Lusca Deploys New SprySOCKS Windows Variant Against Governments
Earth Lusca has ported the SprySOCKS Linux malware to Windows, targeting government entities globally. Analyze the TTPs and learn how to detect this threat.
FortiSandbox RCE via CVE-2024-23108 and CVE-2024-23109 — Patch Now
Unauthenticated attackers are exploiting critical command injection flaws in Fortinet FortiSandbox to achieve RCE. Apply security updates immediately.
Cisco Catalyst SD-WAN Manager CVE-2026-20262 Exploited in the Wild
Cisco patches an actively exploited medium-severity vulnerability in Catalyst SD-WAN Manager (CVE-2026-20262) that allows authenticated file creation.
ScarCruft Deploys NarwhalRAT via Fake Microsoft Security Alerts
North Korean threat actor ScarCruft (APT37) is deploying NarwhalRAT via spear-phishing emails that mimic official Microsoft Account security notifications.