All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
FortiSandbox Command Injection (CVE-2026-25089) & Critical Vendor Patches
Critical patches from Fortinet, Ivanti, and SAP address vulnerabilities including CVE-2026-25089 (FortiSandbox command injection), enabling RCE and info disclosure.
JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices
China-linked JDY botnet now controls 1,500+ SOHO/IoT devices, actively expanding cyber reconnaissance for state-sponsored operations.
Bridging the Gap: Addressing Automated Pentest Blind Spots
Automated penetration tests often miss critical vulnerabilities. Learn why a hybrid approach combining automation with expert-driven manual testing is essential for…
ServiceNow Flaw Exploited: Unauthenticated Access to Customer Instances
ServiceNow advises customers of a critical flaw leading to unauthorized access to hosted instances.
Anthropic Claude Fable 5 Release: Evaluating AI Cyber Safeguards
Anthropic releases Claude Fable 5 with specialized safety classifiers to prevent cyber misuse while offering Claude Mythos 5 for vetted security researchers.
Adobe Addresses 123 Vulnerabilities: Focus on Experience Manager RCE
Adobe's extensive patch cycle resolves 123 vulnerabilities across multiple products, with a critical focus on Experience Manager arbitrary code execution flaws.
Advertisement
Microsoft Patch Tuesday: 200 Vulnerabilities Addressed
Microsoft addressed 200 vulnerabilities in its latest Patch Tuesday, including three publicly disclosed flaws. Prompt patching is essential for defense.
Claude Fable 5: Anthropic Unveils New High-Performance AI Model
Anthropic releases Claude Fable 5, a limited-time high-performance AI model based on the Mythos architecture, targeting advanced reasoning and efficiency.
Protobuf.js RCE Vulnerabilities: Node.js Security Mitigation Guide
Six high-severity vulnerabilities in protobuf.js enable RCE and DoS in Node.js apps. Learn how to detect and mitigate these Proto6 flaws in your environment.
ServiceNow Data Exposure via Unauthenticated API Flaw
ServiceNow warns customers about a security incident after attackers exploited an unauthenticated API vulnerability to access and query customer instance data.
Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges
Analysis of 'RoguePlanet' zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.
SAP NetWeaver & Commerce Cloud: Urgent Critical Patches Released
SAP addresses 15 vulnerabilities, including four critical flaws in NetWeaver AS Java and Commerce Cloud, requiring immediate patching to prevent remote exploitation.
Veeam Backup & Replication RCE via CVE-2026-44963 — Patch Guide
A critical RCE flaw (CVE-2026-44963) in Veeam Backup & Replication allows authenticated domain users to execute code. Patch immediately.
Meta's Expanded Use of Off-Site Data for AI and Personalization
Meta announces it will use off-site business data for AI chatbot responses and feed personalization, extending beyond targeted advertising. Review data policies.
Siemens KACO Blueplanet Inverter Vulnerabilities: CVE-2025-40946 & CVE-2026-41125
Critical Siemens KACO Blueplanet Inverters are vulnerable to credential derivation (CVE-2025-40946) and SQL injection (CVE-2026-41125).
GPS-Based Key Distribution: Analysis of U.S. Military OTAR Protocols
Analysis of how the U.S. military utilizes public GPS signals as a global numbers station for covert encryption key distribution and OTAR/OTAD operations.
CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw
Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.
LLM-Assisted Exploit Creation: Claude Mythos Accelerates N-Day Attacks
Researchers demonstrate how Claude 3.5 Sonnet can automate exploit development, turning newly disclosed N-day vulnerabilities into functional attacks in hours.
OpenSSL 3.4.1 and 3.0.16 Patches: Fix for CVE-2025-0167 High-Severity Bug
OpenSSL releases patches for 18 vulnerabilities, including a high-severity AI-discovered bug, CVE-2025-0167. Learn how to secure your infrastructure now.
GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware
GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.
Anthropic Mythos Preview: Advancing AI Offensive Security Performance
XBOW evaluates Anthropic's Mythos Preview model, revealing high efficacy in automated vulnerability discovery, reverse engineering, and exploit development.
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.
SAP NetWeaver and Commerce CVE-2024-21733 Mitigation Guide
SAP releases January 2024 security updates addressing critical vulnerabilities in BusinessObjects, NetWeaver, and Commerce Cloud. Patch now to prevent RCE.
Atsign AI Architect: Securing Agentic AI with Cryptographic Invisibility
Atsign launches AI Architect to protect agentic software by using cryptographic identities, eliminating exposed ports and reducing the attack surface.