All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code
New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.
VS Code Zero-Day Exploit: Stealing GitHub Tokens via URI Handlers
Security researcher mthcht reveals a VS Code zero-day vulnerability allowing GitHub token theft via URI handlers. Learn how to defend against this exploit.
Google Android Scam Detection: Real-Time AI Defense Against Fraud
Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.
Weedhack MaaS Campaign Targets Minecraft Users via CountLoader
McAfee Labs reports the Weedhack campaign spreading CountLoader and cryptominers through fake Minecraft mods on YouTube. Learn detection and mitigation.
HTTP/2 Bomb: Remote DoS Affects NGINX, Apache, and Microsoft IIS
Researchers identify HTTP/2 Bomb vulnerability affecting NGINX, Apache, and IIS default settings, allowing remote denial-of-service attacks on web servers.
PHP RCE via CVE-2024-4577 — Windows Argument Injection Analysis
Technical analysis of the CVE-2024-4577 vulnerability affecting PHP on Windows. Learn how argument injection leads to RCE and how to secure PHP-CGI environments.
Advertisement
Kali365 Phishing-as-a-Service Expands to Target AWS and Okta
The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.
AI as Security Enabler: CISO Strategies for Modern Defense
Zoom's CISO details AI's role in augmenting security teams, addressing challenges like talent gaps and alert fatigue, and strategic CISO insights.
US Executive Order on AI: Vetting Advanced Models for National Security
Executive Order mandates pre-release vetting of advanced AI models for national security risks, impacting developers and federal oversight strategies.
OpenAI GPT-3.5 Upgrades & Legacy Model Retirement: Security Impact
OpenAI is upgrading GPT-3.5 models and retiring legacy versions. Understand the impact on AI-powered security tools and data processing. Stay informed.
Microsoft Coreutils for Windows: Security and Memory Safety Analysis
Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.
CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595
CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.
Hardening Automatic Tank Gauge Systems Against Cyber Threats
CISA and partners warn of active cyber threats targeting Automatic Tank Gauge (ATG) systems. Learn to secure critical infrastructure assets now.
China's Dual-Method Cyberattack Targets Czech, Taiwan Orgs with Azureveil
Nation-state actors linked to China employ dual-method spear-phishing with Azureveil malware to target Czech and Taiwan organizations for data theft.
DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware
DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate…
AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery
New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.
Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine
Russian threat actor Gamaredon weaponizes a WinRAR path traversal flaw to deploy GammaWorm and GammaSteel malware against Ukrainian entities.
CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day
Google's June 2026 security update fixes 124 vulnerabilities, including CVE-2025-48595, a zero-day privilege escalation flaw under active exploitation.
Handala Brand Evolution: Iran MOIS Shifts to Hybrid Physical Attacks
Iran’s MOIS expands the Handala brand into hybrid operations, combining cyber espionage with physical sabotage targeting U.S. and Israeli interests.
Misconfigured MSAL for Android Exposes Microsoft Account Tokens
A vulnerability in the Microsoft Authentication Library for Android allowed unauthorized apps to intercept OAuth tokens, impacting billions of users.
AI Automation and the Shrinking Vulnerability Exploitation Window
Analyze the impact of AI-driven automation on the vulnerability lifecycle and the debate between tooling vs. operational security failures.
Meta AI Support Abuse Leads to Instagram Account Hijacking
Attackers exploit Meta AI support tools to bypass traditional security and hijack Instagram profiles, leaving legitimate users locked out of their accounts.
Microsoft Exchange Online Outage: North America and Germany Impacts
Microsoft Exchange Online outage disrupts mail flow in North America and Germany, causing email delays and NDR errors. Learn how to monitor service health.
Windows 11 BitLocker Bypass: Nightmare Eclipse Exploit Analysis
Microsoft threatens legal action against researcher Nightmare Eclipse after the release of a Windows 11 BitLocker bypass. Learn how to detect and mitigate.