All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Anthropic Mythos Preview: Advancing AI Offensive Security Performance
XBOW evaluates Anthropic's Mythos Preview model, revealing high efficacy in automated vulnerability discovery, reverse engineering, and exploit development.
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.
SAP NetWeaver and Commerce CVE-2024-21733 Mitigation Guide
SAP releases January 2024 security updates addressing critical vulnerabilities in BusinessObjects, NetWeaver, and Commerce Cloud. Patch now to prevent RCE.
Atsign AI Architect: Securing Agentic AI with Cryptographic Invisibility
Atsign launches AI Architect to protect agentic software by using cryptographic identities, eliminating exposed ports and reducing the attack surface.
Tchap Messaging Breach: French Government Account Hijacking
French digital affairs directorate DINUM confirms a security breach of the Tchap messaging platform following a targeted account hijacking incident.
Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware
Researchers demonstrate an autonomous AI worm using local open-weight LLMs to navigate networks and replicate without human intervention or cloud services.
Advertisement
CVE-2025-8088: Russia-Aligned Groups Exploit WinRAR Flaw in Ukraine
Russia-linked actors Earth Dahu and UAC-0226 exploit the CVE-2025-8088 WinRAR path traversal flaw to deploy info-stealers against Ukrainian organizations.
Python-Based Infostealer Masked as PDF Targets Browser Credentials
Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.
CISA Adds CVE-2026-42271 and CVE-2026-50751 to KEV Catalog
CISA warns of active exploitation involving BerriAI LiteLLM and Check Point Security Gateways. Learn how to mitigate these critical security flaws.
Google Patches CVE-2026-11645: 5th Chrome Zero-Day Exploited in 2026
Google addresses CVE-2026-11645, a critical zero-day vulnerability in Chrome being actively exploited. Learn about patch guidance and detection strategies.
CVE-2024-4947: Google Patches Fifth Chrome Zero-Day of 2024
Google addresses CVE-2024-4947, a high-severity V8 type confusion vulnerability in Chrome being exploited in the wild. Update to version 125.0.6422.60 now.
Check Point CVE-2024-24919: CISA Warns of Ransomware Exploitation
CISA mandates emergency patching for CVE-2024-24919 after Check Point VPN devices were targeted by ransomware gangs to gain initial network access.
CVE-2026-42271: BerriAI LiteLLM RCE Exploited in the Wild
CISA warns of active exploitation of CVE-2026-42271 in BerriAI LiteLLM. This command injection flaw allows attackers to achieve RCE and compromise AI proxies.
CVE-2024-24919: Check Point VPN Zero-Day Exploited by Qilin Affiliate
Check Point Security Gateway vulnerability CVE-2024-24919 is being exploited in the wild, enabling unauthenticated information disclosure and network access.
Silent Ransom Group Targets US Law Firms via Vishing and Intrusions
Silent Ransom Group (Luna Moth) targets US law firms using vishing and physical intrusions for data extortion. Technical analysis and mitigation strategies.
Autonomous Offensive Security Platforms: Enhancing Proactive Defense
Explore the rise of autonomous offensive security platforms, their role in proactive defense, and what security professionals need to know about these emerging…
SoFi Hong Kong Data Breach via Third-Party Vendor Compromise
Analysis of the SoFi Hong Kong data breach impacting customer information, stemming from a third-party vendor compromise. Includes mitigation strategies.
NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks
Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.
Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets
New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.
NSO Group's WhatsApp Phishing Blocked: Meta Files Contempt Order
Meta detected and blocked new spear-phishing attacks by NSO Group targeting WhatsApp users, leading to a federal court contempt order filing.
CVE-2026-23111: Linux Kernel nf_tables LPE and Container Escape
A one-character use-after-free vulnerability in the Linux kernel nf_tables subsystem allows local root access and container escapes. Patch immediately.
May 2026 CVE Landscape: Prioritize Remediation for High-Impact Threats
Analysis of the May 2026 CVE landscape, highlighting a 11% increase in high-impact vulnerabilities and critical risk scoring for security teams.
TeamPCP Campaign Update: Mini Shai-Hulud Framework Gains Adoption
Analysis of the TeamPCP supply chain campaign, the open-sourcing of the Mini Shai-Hulud framework, and its adoption by diverse threat actor groups in 2026.
Zcash Orchard Pool Logic Error Enables Infinite ZEC Minting
A critical vulnerability in the Zcash Orchard privacy pool allowed attackers to bypass validation and counterfeit ZEC via zero-knowledge proof flaws.