All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
SolarWinds Serv-U DoS Vulnerability CVE-2026-28318 Added to CISA KEV
CISA adds CVE-2026-28318 to its KEV catalog following active exploitation of a high-severity DoS vulnerability in SolarWinds Serv-U file server software.
Bright Data SDK: Smart TVs Used as AI Web-Scraping Proxies
Smart TVs and iOS apps are being converted into web-scraping exit nodes via embedded SDKs, fueling residential proxy networks used by AI companies.
Toshiba and Muji Impacted by Polyfill Supply Chain Attack
Toshiba and Muji have warned of malicious login prompts appearing on their sites. This follows the takeover of the Polyfill.io domain used for script injection.
CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Exploit
CISA warns of active exploitation of CVE-2026-28318, an uncontrolled resource consumption flaw in SolarWinds Serv-U. Immediate patching is critical for all organizations.
Exposed Fuel Tank Gauges: US Gas Stations Face Active Cyberattacks
Threat actors are actively exploiting Internet-exposed fuel tank gauges at US gas stations, risking significant disruption to fuel supply and operations.
Chinese APT UNC5221 Deploys New Malware for M365 Persistence
Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…
Advertisement
CVE-2024-28995: SolarWinds Serv-U Exploit Leads to Server Crashes
CISA warns of active exploitation of SolarWinds Serv-U CVE-2024-28995. Attackers are leveraging this directory traversal flaw to crash vulnerable servers.
npm Supply Chain Attack: IronWorm and Miasma Malware Analysis
Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.
Holistic Threat Intelligence Sourcing for Enhanced Defense
Explore how holistic threat intelligence sourcing across diverse data streams empowers proactive defense and provides a comprehensive view of emerging cyber threats.
UNC3753 Targets US Law Firms with Vishing & Physical Intrusions
UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.
AI-Powered Internet Worm Prototype: Understanding the New Threat Model
Researchers prototyped an AI-powered internet worm that carries its own LLM for autonomous operation post-compromise. Understand this evolving threat model.
Agentic AI Worms: Defending Against LLM-Powered Lateral Movement
Enterprise security teams must prepare for agentic AI worms capable of autonomous adaptation, self-replication, and automated exploitation within a year.
OWASP CVE Lite CLI: Strengthening Supply Chain Security for Developers
OWASP's CVE Lite CLI provides a fast, local method for developers to identify vulnerable dependencies and mitigate supply chain risks early in development.
2026 Verizon DBIR Analysis: Securing the Browser Against Phishing
The 2026 Verizon DBIR identifies browser-layer security gaps as a primary threat vector, highlighting risks from phishing, shadow AI, and malicious extensions.
Exposed US Gas Station ATG Systems Threaten Critical Infrastructure
Over 900 US-based Automatic Tank Gauge (ATG) systems are exposed online, risking fuel theft, physical damage, and environmental incidents via remote access.
OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS
Security researchers have identified OP-512, a China-nexus threat cluster targeting Microsoft IIS servers with a bespoke web shell framework for espionage.
Asin Android Spyware Targets Arabic Users via Fake War Maps
ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.
Trump AI Executive Order: Frontier Model Testing and Federal Security
Analysis of the White House Executive Order on voluntary AI frontier model testing and its impact on federal security protocols and compliance requirements.
ShinyHunters Leak 234 GB of DentaQuest Data Impacting 2.6 Million
The ShinyHunters extortion group leaked 234 GB of data from DentaQuest, impacting 2.6 million individuals. Learn about the risks and how to protect PHI.
Unpatched Comodo Antivirus Flaw and Anthropic AI Threat Mapping
Researchers reveal an unpatched privilege escalation flaw in Comodo Antivirus and a new taxonomy for AI-driven cyber threats by Anthropic and the UK AISI.
Optimizing AI-Powered Security Operations Platforms for SOC Value
Analysis of why only 10% of SOC teams report excellent value from AI tools and how to improve security operations through second-wave agentic AI integration.
MSI-Branded Image Steganography: Analysis of WeTransfer Phishing
Analysis of a recurring phishing campaign using steganography in MSI-branded images to deliver malicious payloads via WeTransfer links and bypass security.
RCI Hospitality Data Breach: 40,000 SSNs Exposed in Intrusion
RCI Hospitality Holdings confirms a network intrusion impacting 40,000 individuals, involving stolen Social Security numbers and employee data files.
Five Eyes Warning: Chinese Intelligence Job Recruitment Tactics
Five Eyes agencies issue an advisory on Chinese intelligence officers using fake job offers on professional sites to recruit personnel with security clearances.