All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Anthropic Project Glasswing: AI Vulnerability Discovery Challenges
Anthropic's Project Glasswing identifies 23,000 potential vulnerabilities via the Mythos AI model, highlighting the massive gap between discovery and patching.
Cybersecurity M&A Analysis: Market Consolidation Trends May 2026
Analysis of 26 major cybersecurity M&A deals in May 2026 involving Cisco, Zscaler, and Akamai, highlighting industry consolidation and strategic shifts.
WhatsApp Alleges NSO Group Violation of Anti-Hacking Injunction
WhatsApp files a federal contempt order against NSO Group, alleging continued platform exploitation for spyware delivery despite a court-ordered ban.
Oxford University Data Breach: CareerConnect Compromise Analysis
Oxford University warns of a data breach affecting CareerConnect, a platform managed by Group GTI. Personal data of students and alumni was compromised.
CVE-2024-24919: Qilin Ransomware Gang Exploits Check Point VPN Zero-Day
Check Point confirms that the Qilin ransomware group exploited CVE-2024-24919, a critical flaw in VPN gateways, to gain unauthorized network access.
Mythos Threat Actor Analysis: Novel SAST Chain Exploitation Revealed
Technical analysis of the Mythos threat actor methodology, involving complex chaining of common software vulnerabilities to achieve deep system compromise.
Advertisement
AI Phishing Scaling SOC Alert Volume: Reducing Tier 1 Overload
AI-driven phishing campaigns are flooding security teams with high-quality lures. Learn how to optimize SOC workflows and reduce analyst alert fatigue.
CVE-2024-28995: SolarWinds Serv-U Path Traversal Exploited — Patch Now
SolarWinds patches CVE-2024-28995, a high-severity path traversal flaw in Serv-U exploited in the wild. Learn how to detect and mitigate this file disclosure risk.
OpenAI Expands ChatGPT Account Security with New Session Controls
OpenAI rolls out Active Sessions and Lockdown Mode for ChatGPT, providing users and administrators with granular visibility into unauthorized account access.
Instagram Account Hijacking: Meta AI Support Exploited by Attackers
Attackers manipulated Meta's AI-powered support system to hijack over 20,000 Instagram accounts via unauthorized password resets. Learn how to secure accounts.
VS Code Extension Auto-Update Delay: Mitigating Supply Chain Attacks
Microsoft introduces a two-hour delay for VS Code extension auto-updates to prevent rapid compromise during software supply chain attacks.
UNC3753: Vishing and Physical Intrusions Fuel U.S. Data Extortion
Mandiant identifies UNC3753 targeting U.S. legal and financial sectors through sophisticated vishing and physical breaches to execute data theft extortion.
Excel VBA Macro Obfuscation: How to Detect Hidden Payloads
Learn how to analyze and detect obfuscated VBA macros in Excel files using oledump.py. Technical guide on character substitution and string reversal techniques.
Microsoft Intelligent Terminal: AI Integration and Security Risks
An analysis of Microsoft's Intelligent Terminal fork. Explore technical architecture, LLM data privacy risks, and securing AI-integrated terminal environments.
Silent Ransom Group Callback Phishing Targets US Law Firms
Silent Ransom Group (Luna Moth) is using callback phishing and legitimate remote access tools to extort U.S. law firms without using file-encrypting ransomware.
C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation
C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.
Emphere Raises $2.1M to Advance AI-Powered Vulnerability Remediation
Emphere secures $2.1M in seed funding to scale its AI-driven platform, focusing on automating the remediation of security vulnerabilities in software code.
CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover
Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.
OpenAI ChatGPT Lockdown Mode: Mitigating Prompt Injection Exfiltration
OpenAI introduces ChatGPT Lockdown Mode for personal accounts to prevent prompt injection attacks from exfiltrating sensitive data via external tools.
Opal Security Series B: Scaling AI-Native Identity Governance
Opal Security secures $23 million in Series B funding to scale its AI-native identity governance platform for hybrid and multi-cloud environments.
SolarWinds Serv-U DoS Vulnerability CVE-2026-28318 Added to CISA KEV
CISA adds CVE-2026-28318 to its KEV catalog following active exploitation of a high-severity DoS vulnerability in SolarWinds Serv-U file server software.
Bright Data SDK: Smart TVs Used as AI Web-Scraping Proxies
Smart TVs and iOS apps are being converted into web-scraping exit nodes via embedded SDKs, fueling residential proxy networks used by AI companies.
Toshiba and Muji Impacted by Polyfill Supply Chain Attack
Toshiba and Muji have warned of malicious login prompts appearing on their sites. This follows the takeover of the Polyfill.io domain used for script injection.
CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Exploit
CISA warns of active exploitation of CVE-2026-28318, an uncontrolled resource consumption flaw in SolarWinds Serv-U. Immediate patching is critical for all organizations.