All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
TA4922 Expands Global Cybercrime: Analysis of Diverse TTPs
Runtime Rebel analyzes TA4922's expanding global cybercrime operations, detailing diverse TTPs and providing actionable mitigation strategies for security professionals.
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.
Hola Browser for Windows Compromised: Cryptominer Delivery via Supply Chain
Critical alert: Hola Browser for Windows compromised in a supply chain attack, delivering an undeclared cryptominer. Learn to detect and mitigate the threat.
Brave Origin: Reducing Browser Attack Surface via Paid Minimalism
Brave Software launches Brave Origin, a subscription-based minimalist browser that removes AI, crypto, and VPN features to prioritize privacy and performance.
Data Sovereignty Challenges: Geopolitical Tensions & EU Residency Implications
Explore the growing imperative for data sovereignty, driven by geopolitical tensions, and how EU data residency options address evolving compliance requirements.
DentaQuest Data Breach: 2.6 Million Accounts Exposed via MOVEit
DentaQuest confirms a massive data breach impacting 2.6 million users following the exploitation of a critical MOVEit Transfer vulnerability.
Advertisement
Cyber Threats to the 2026 FIFA World Cup: A Strategic Assessment
An analysis of cyber fraud, espionage, and influence operations targeting the 2026 FIFA World Cup across North America and its host nations.
Hitachi Energy MACH HiDraw RCE via CVE-2026-7310 — Patch Guide
Hitachi Energy addresses a heap-based buffer overflow in MACH HiDraw version 9.22. Learn how to mitigate CVE-2026-7310 and protect critical ICS assets.
CVE-2026-21404: NAVTOR NavBox SOAP Credential Bypass and Mitigation
NAVTOR NavBox version 4.16.1.20 is vulnerable to hard-coded credentials in its SOAP implementation, allowing local attackers to manipulate application files.
Offroad Exits Stealth to Address Non-Human Identity Security Risk
Offroad emerges with $7 million to secure the enterprise identity landscape, focusing on machine identities, AI agents, and identity posture management.
IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack
Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.
WFP Palestine Breach: 600,000 Gaza Households' Data Exposed
The UN World Food Programme confirms a data breach in its Palestine registration portal, exposing sensitive data for 600,000 households in the Gaza Strip.
Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking
A critical flaw in Anthropic's Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.
Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide
Cisco patches CVE-2026-20230, a high-severity SSRF in Unified Communications Manager. Learn how public PoC code impacts your security and find remediation steps.
Meta AI Chatbot Exploited for Instagram Account Takeover
Attackers manipulate Meta's AI support chatbot to reset Instagram passwords and hijack accounts via unauthorized email updates and location spoofing.
Mirasvit Full Page Cache Warmer RCE via CVE-2024-34961 - Patch Now
Attackers are exploiting a critical RCE vulnerability in Mirasvit's Full Page Cache Warmer for Magento. Learn how to detect and mitigate CVE-2024-34961.
Google Gemini Hijack: Command Injection via Messaging Notifications
Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.
CVE-2024-20469: Critical Cisco Unified CM Root Escalation Risk
Cisco patches a critical SQL injection flaw (CVE-2024-20469) in Unified Communications Manager that allows remote attackers to gain full root-level access.
French and Spanish Police Dismantle Major Fake ID Marketplace
Authorities dismantle a sophisticated marketplace supplying high-quality fraudulent identity documents to smuggling networks across the European Union.
Operation FlutterBridge: New FlutterShell Backdoor Targets macOS
Researchers discover Operation FlutterBridge, a malvertising campaign delivering the FlutterShell backdoor to macOS users via Google and YouTube ads.
TA4922 Expands Phishing Campaigns to Europe and South Africa
China-linked TA4922 threat actor expands targeting to the UK, Germany, Italy, and South Africa using ValleyRAT and Atlas RAT malware in high-tempo attacks.
Microsoft Rust-Based Coreutils for Windows: Security Analysis
Microsoft is adopting Rust-based Coreutils for Windows, offering a memory-safe alternative to legacy GnuWin32 tools. Learn about the security implications.
VS Code One-Click GitHub Token Theft via URI Handler Exploitation
A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.
Cisco Unified CM SSRF CVE-2024-20455 — Public PoC Mitigation Guide
Cisco warns of critical SSRF vulnerabilities in Unified CM with public PoC exploit code. Learn how to detect and patch CVE-2024-20455 to protect your network.