All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
CVE-2023-6110: Rogue Account Creation in SimpleHelp — Patch Now
Attackers can exploit an OIDC implementation flaw in SimpleHelp servers to create unauthorized technician accounts. Immediate update to 5.2.24 is required.
DOJ Seizes CFAKE & SOCFAKE: Combating Non-Consensual Deepfake Imagery
The U.S. Department of Justice seized CFAKE.com and SOCFAKE.com, disrupting deepfake nude sites under the TAKE IT DOWN Act to combat online abuse.
North Korean APT Targets Developers via Malicious Tooling
North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.
Chinese Espionage: Google Workspace Rule Abuse in Research Sectors
China-linked threat actors exploited REDCap server backdoors and manipulated Google Workspace mail rules to exfiltrate North American research data.
UNC6508 Targets REDCap Servers: Espionage via INFINITERED Malware
PRC-nexus threat actor UNC6508 exploits REDCap servers in North America's medical and military research sectors, deploying INFINITERED malware for long-term espionage…
AI-Native OS: The Future of Social Engineering Defense
Explore how AI-native operating systems are poised to transform social engineering defenses, shifting vigilance from users to automated systems.
Advertisement
China-Nexus Actor: Year-Long Espionage Against US Researchers
A China-nexus actor spied on US researchers for a year, stealing RedCAP credentials and exfiltrating sensitive data from numerous institutions, discovered by Google.
The Gentlemen Ransomware Halts Mackay Sugar Operations
Mackay Sugar, Australia's second-largest sugar producer, suffered a ransomware attack by 'The Gentlemen' group, halting mill operations and impacting critical…
CVE-2026-20262: Cisco SD-WAN vManage Root Privilege Escalation Fix
Cisco patches CVE-2026-20262, a critical Zero-Day flaw in Catalyst SD-WAN Manager allowing authenticated attackers to escalate to root privileges.
OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks
Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.
Microsoft 365 Copilot SearchLeak: One-Click Data Exfiltration
Varonis Threat Labs uncovered 'SearchLeak', a one-click flaw in Microsoft 365 Copilot Enterprise Search allowing exfiltration of emails, files, and MFA codes.
LiteLLM Proxy Server Takeover via Critical Vulnerability Chain
Researchers at Obsidian Security have identified a three-vulnerability chain in LiteLLM that allows low-privilege users to gain full server control.
NewCore Secures $66M for AI and Machine Identity Platform
NewCore emerges from stealth with $66 million to develop a security-first identity platform protecting human, machine, and AI agent access.
UNC6508: Chinese Cyberespionage Targets North American Research
Google's Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.
China-Linked Espionage Targets REDCap Servers, Stealing Medical Data
China-linked threat actors breached exposed REDCap servers, deploying InfiniteRed malware to steal sensitive medical research from a North American institution.
Tackling AI-Driven Code Sprawl: CISO Strategies for Shadow Tooling
Explore how CISOs are confronting the security challenges of AI-driven code sprawl, shadow tooling, and governance gaps in enterprise environments.
Malicious Chrome Wallpaper Extensions Distribute Adware
Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts.
Onboarding Password Risk: Securing First-Day Account Access
Temporary onboarding passwords, often sent insecurely and reused, pose significant risk. Learn how to secure initial employee access and mitigate threats.
MSI Malware Detection: Statistical Analysis for Base64 Payloads
Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.
Maine Disables Data Breach Notification Portal Over Fake Submissions
The Maine Attorney General's office has taken its data breach notification portal offline after threat actors submitted fraudulent reports for Discord and VRChat.
FBI and Google Dismantle Outsider Enterprise Phishing Service
Law enforcement and Google disrupt Outsider Enterprise, a massive Phishing-as-a-Service platform responsible for $1.9 billion in losses.
CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active
Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass flaw in PAN-OS GlobalProtect. Apply critical security patches now.
Sniper Dz Phishing-as-a-Service Targets MENA Region via Facebook
Sniper Dz phishing campaigns leverage fake Facebook accounts and browser alerts to steal credentials from users across the Middle East and North Africa.
FortiSIEM RCE via CVE-2024-23108: Technical Mitigation Guide
Analysis of critical RCE vulnerabilities CVE-2024-23108 and CVE-2024-23109 in Fortinet FortiSIEM, including detection methods and remediation steps.