All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Analyzing AI Security and Governance in the 21st Century
Exploration of upcoming cybersecurity policy shifts in Europe, focusing on AI governance, national defense strategies, and digital humanism concepts for 2026.
FBI Disrupts AI-Powered Outsider Enterprise PhaaS Operation
The FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a Chinese-based AI-powered phishing service that deployed over a million malicious URLs.
Iowa School District Hack: Sentencing Highlights Insider Threat Risks
Former Iowa school IT employee sentenced to 21 months for malicious infrastructure disruption and data tampering against his former employer.
npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks
npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.
Chinese Hackers Hijack Auth Flow for Decade-Long Espionage
Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.
CVE-2026-20253: Unauthenticated RCE in Splunk Enterprise <10.2.4
Critical flaw CVE-2026-20253 in Splunk Enterprise allows unauthenticated RCE by creating/truncating files. Patch versions <10.2.4 and <10.0.7 immediately.
Advertisement
US Government Orders Anthropic to Restrict Foreign Access to AI Models
Anthropic suspends Fable 5 and Mythos 5 models worldwide following a US government order to block foreign national access due to jailbreak concerns.
Lumma Stealer Distributed via Fake EditPro AI Image Generator
Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.
Oracle PeopleSoft CVE-2026-35273 Exploit: CISA KEV Mitigation Guide
CISA adds CVE-2026-35273 in Oracle PeopleSoft to its KEV catalog. Learn how to mitigate this missing authentication vulnerability and protect enterprise systems.
AI Centralization Risks: Analysis of the Sovereign Wealth Fund Model
An analysis of Senator Bernie Sanders' proposal for an AI sovereign wealth fund to mitigate systemic risks of AI centralization and power concentration.
Anthropic Disables Fable 5 and Mythos 5 for Export Control Compliance
Anthropic has taken its Fable 5 and Mythos 5 AI models offline following a Trump administration directive aimed at restricting foreign access to advanced AI.
US Bans Anthropic Fable 5 and Mythos 5 Over National Security Risks
Anthropic suspends Fable 5 and Mythos 5 AI models following a US government order citing national security risks regarding access by foreign nationals.
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.
ICS Exposure Persists as OT Attack Surface Expands
Analysis of Industrial Control System (ICS) exposure, its persistence amidst expanding attack surfaces, and vital steps for operational technology security.
phpBB Authentication Bypass: Admin Login Vulnerability Patched
A decade-old authentication bypass in phpBB forum software, affecting versions up to 3.3.11, allowed attackers to log in as any user, including administrators.
Maine Data Breach Portal Offline After Fraudulent Disclosures
Maine's Department of the Secretary of State disabled its data breach notification portal following the publication of fraudulent breach reports on its site.
Chinese Smishing Network 'Outsider' Leverages Gemini AI for Phishing
Google sues a Chinese smishing network operating 'Outsider' PhaaS, accused of using Gemini AI to craft sophisticated phishing messages targeting Americans.
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.
AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers
Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.
Claude Fable 5: No Major Security Shift from Mythos
Anthropic's Claude Fable 5 retains security posture of Mythos 5, improving over Mythos Preview. This analysis details its implications for secure AI integration.
Iranian Handala Group Claims Cal Water Hack, Exposing PII
Iranian cyber group Handala claims responsibility for breaching Cal Water, exposing 5GB of customer PII and RTKBase platform credentials.
Securing Advanced AI Models: Addressing Dual-Use Risks
Industry professionals discuss critical aspects of AI model security, focusing on dual-use capabilities, robust safeguards, and effective tiered access mechanisms.
Microsoft Resolves Windows Update Failures with WUSA via Network Share
Microsoft has fixed an issue causing Windows updates released since May 2024 to fail when installed via the WUSA installer from a network share.
AI's Impact on MDR: Adapting to Evolving Threat Landscapes
Explore how AI is reshaping the cybersecurity threat landscape, challenging traditional MDR models, and what security professionals must do to adapt.