All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Agentjacking: Tricking AI Coding Agents into Malicious Code Execution
Agentjacking is a new attack where crafted Sentry error reports trick AI coding agents into executing arbitrary code on developer systems, risking intellectual property…
Iranian & Russian Cyber-Enabled Maritime Sanctions Evasion Tactics
Explore the sophisticated cyber tactics used by Iranian and Russian shadow fleets to evade sanctions, leveraging fake maritime websites and fraudulent documents.
Measuring Cyber Threat Intelligence ROI: An Executive Perspective
Understand how security leaders can effectively measure and communicate the business value of their threat intelligence programs to executive stakeholders.
CVE-2026-35273: Oracle PeopleSoft RCE Exploited as Zero-Day by ShinyHunters
Mandiant and GTIG identified ShinyHunters (UNC6240) exploiting CVE-2026-35273, a critical RCE in Oracle PeopleSoft, targeting higher education.
CVE-2026-28742 & Others: Naxclow IoT Platform Critical Flaws
CISA warns of multiple critical vulnerabilities in Naxclow IoT Platform, including hard-coded cryptographic keys, authorization bypasses, and credential exposure.
Ivanti Sentry Max-Severity Flaw Exploited Within 24 Hours
A critical Ivanti Sentry vulnerability was actively exploited within 24 hours of public disclosure. Defenders must patch immediately to prevent compromise.
Advertisement
Sophisticated Phishing: AI Elevates Attack Quality Amidst Volume Drop
Phishing attack volume decreased 20%, yet AI-driven sophistication increases risk. Organizations must adapt defenses to counter targeted, high-quality social engineering.
Anthropic Fable 5 AI Jailbreak Claim: Analysis & Mitigations
An alleged prompt-based AI jailbreak of Anthropic's Fable 5 is disputed. This analysis covers the claim, Anthropic's response, and mitigation strategies for large…
Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide
Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.
Tchap Messenger Breach: 73,000 French Government Accounts Exposed
Analysis of the security breach affecting the French Tchap messaging platform, exposing 73,000 government accounts and increasing phishing risks.
Ivanti Sentry CVE-2023-35081: CISA Issues Urgent 3-Day Patch Mandate
CISA adds CVE-2023-35081 to its KEV catalog, ordering federal agencies to patch Ivanti Sentry path traversal flaws to prevent remote code execution.
Europol Dismantles AudiA6 Crypto Laundering Hub Used by Ransomware
Europol disrupts AudiA6, a crypto laundering service used by ransomware gangs to wash €336M. Analysis of the impact on cybercriminal financial pipelines.
Maine Breach Portal Abuse: Misinformation Campaign Targets Public Disclosures
Fraudulent data breach disclosures were submitted to Maine's official breach portal, leading to public posting of unverified claims and corporate denials.
Kyuden Data Breach: Physical Loss of 10.9 Million Customer Records
Kyushu Electric Power reports the physical loss of a hard drive containing personal data of over 10.9 million customers during a disposal transport process.
Managing SOC Analyst Burnout: How to Reduce Security Alert Fatigue
Examine the technical drivers of alert fatigue in the SOC and how AI-driven automation and contextualization help teams prioritize genuine security threats.
OpenClaw AI Agent Vulnerabilities: Code Execution & Data Leakage
New research reveals OpenClaw AI agents can be tricked into executing malicious code or exfiltrating sensitive data via seemingly benign inputs like vCards and location…
Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide
ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.
Yarbo Mobile App & Cloud: Critical Robot Fleet Vulnerabilities
Critical vulnerabilities CVE-2026-10557 & CVE-2026-7368 in Yarbo mobile app and cloud allow attackers to control robot fleets via hard-coded credentials.
CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters
Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.
AI-Enhanced Threats Expose MSP Security Gaps: Integrated Defense
AI-driven attacks are pushing MSP security stacks to their limits. Learn why integrated solutions, automation, and rapid recovery are essential for defending against…
AudiA6 Crypto-Laundering Service Dismantled: Impact on Ransomware
Law enforcement dismantled AudiA6, a major crypto-laundering service used by ransomware groups and cybercriminals to process over $380 million.
Cybersecurity Stars Awards 2026: Valuing Invisible Security Work
The 2026 Cybersecurity Stars Awards highlight critical, often unseen, security efforts. We analyze the impact of recognizing technical excellence.
The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties
Analysis of The Gentlemen ransomware reveals its worm-like propagation, double extortion tactics, and operational ties to LockBit, Qilin, and Medusa RaaS schemes…
SignalTrace: ALPRs Enhanced for Bluetooth Device Tracking
Leonardo's SignalTrace technology upgrades Automatic License Plate Readers to collect unique identifiers from Bluetooth devices, enabling individual tracking.