All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
OnyxC2 Stealer: Enterprise-Grade Info-Theft for $250/Month
OnyxC2 stealer targets over 200 applications and extensions, using encrypted payloads, DLL sideloading, and in-memory execution to evade detection.
CISA BOD 26-04: Prioritizing KEV Catalog Vulnerability Patching
CISA's BOD 26-04 mandates federal agencies prioritize patching vulnerabilities in the KEV catalog. Learn its impact and how to enhance your vulnerability management.
CISA Mandates Critical Ivanti & ActiveMQ Patching in 3 Days
CISA's BOD 26-04 requires federal agencies to patch critical, exploited Ivanti Connect Secure and Apache ActiveMQ vulnerabilities within 72 hours.
Coupang Data Breach Leads to Record $409M Fine in South Korea
South Korea's PIPC fined e-commerce giant Coupang a record $409 million for a massive data breach affecting over 37 million customers.
OceanLotus Targets Vietnam with SPECTRALVIPER Backdoor in FireAnt Attack
OceanLotus APT targets Vietnamese infrastructure and stock investors with SPECTRALVIPER backdoor in multi-year cyber espionage and supply chain campaigns.
AI and the Collapse of the Vulnerability Management Buffer
AI-driven exploitation has eliminated the time buffer between vulnerability discovery and weaponization, prompting a strategic shift toward BAS.
Advertisement
China's Evolving NEO Strategy: PLA and SOE Integration Analysis
Recorded Future's analysis of 37 Chinese noncombatant evacuation operations (NEOs) reveals the integration of PLA assets and SOE logistics from 2005 to 2025.
2026 FIFA World Cup: Mitigating Cyber-Physical Threats in Host Cities
Technical analysis of cyber-physical risks for the 2026 FIFA World Cup, focusing on critical infrastructure protection and incident response strategies.
Framing Protection Trends: Defending Against Clickjacking
Analyze the 3-year adoption trends of X-Frame-Options and CSP frame-ancestors across 1 million domains to improve your clickjacking defense strategy.
CISA KEV Update: Active Exploitation of Arista, Cisco, and Chrome
CISA adds CVE-2026-7473, CVE-2026-11645, and CVE-2026-20245 to its Known Exploited Vulnerabilities catalog following evidence of active exploitation.
NSO Group Phishing Operations Persist Against WhatsApp Users
NSO Group continues to target WhatsApp users with phishing attacks in violation of court orders. Learn how to detect NSO Group phishing attacks today.
CISA Updates Federal Patching Mandates to Combat AI-Driven Threats
CISA updates federal directive to require 3-day patching for critical flaws, addressing the rapid exploitation speeds enabled by artificial intelligence.
Chinese and North Korean APT Activity Surges Across APAC Markets
Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.
June 2026 Patch Tuesday: Microsoft Fixes 200 Flaws — Patch Now
Microsoft’s June 2026 Patch Tuesday addresses a record-breaking 200 vulnerabilities, including 36 critical flaws and several with public exploit code.
Identifying The Gentlemen Ransomware: Operations and Tactics
Analysis of The Gentlemen ransomware group, its aggressive 90% affiliate payout model, and investigations into the identity of its primary administrator.
University of Nottingham Confirms Breach After ShinyHunters Data Leak
The University of Nottingham confirms a data breach after the ShinyHunters group leaked over 450,000 records, highlighting risks to academic data security.
University of Nottingham Data Breach: 450,000 Student Records Exposed
Nottingham University confirms a data breach affecting over 450,000 students and alumni. Analyze the risks of identity theft and targeted phishing campaigns.
Windows Server 2025 BitLocker Recovery Bug: Mitigation Guide
Microsoft resolves a Windows Server 2025 bug causing systems to boot into BitLocker recovery modes following recent security updates. Patching guidance inside.
GitHub to Disable npm Install Scripts by Default in Version 12
GitHub announces breaking changes for npm v12, disabling install scripts by default to prevent malicious code execution and enhance supply chain security.
Infostealers: Millions of Devices Compromised for Credential Theft
Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.
CVE-2024-5027: Langflow Path Traversal Exploited in Attacks
Security researchers observe active exploitation of CVE-2024-5027, a high-severity path traversal flaw in the Langflow AI platform allowing arbitrary file writes.
Miasma Worm Source Code Briefly Leaked on GitHub
Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks.
Bypassing Identity Verification: Mitigating Phishing & MFA Fatigue
Attackers exploit weak identity verification through phishing, MFA fatigue, and social engineering. Learn best practices to secure access.
JDY Botnet: China-Linked Campaign Targets US Military Networks
Analysis of the China-linked JDY botnet's expanded targeting of U.S. military networks, its reconnaissance TTPs, and critical mitigation strategies.