All Articles
Security Intelligence
3551 articles · Updated every 8 hours
Advertisement
Rogue LLM Endpoints: Data Exposure & RCE Risk for AI Agents
Unverified LLM endpoints pose significant risks, enabling data leakage and potential remote code execution via compromised AI agent sessions.
Diagnosing LLM Safety Fragility with Perturbation Probing
New research introduces Perturbation Probing to diagnose LLM safety fragility, revealing guardrails are often concentrated in few neurons.
Spring Ring Voice Phishing Targets Microsoft Teams Users
Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.
Evaluating LLMs for SOC Operations and Log Analysis
Discover how Cisco Talos evaluated 66 model and reasoning combinations for SOC workflows, focusing on cost, speed, and consistency.
Deobfuscating Malicious JavaScript for Threat Analysis
Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.
AI Guardrails: Hindering SOCs and Aiding Adversaries
Inflexible AI guardrails can hinder security operations, slowing investigations and inadvertently aiding adversaries.
Advertisement
OpenAI Disrups LLM-Powered Social Engineering Operations
OpenAI disrupts a Cambodian threat network leveraging ChatGPT for complex multi-stage social engineering, romance scams, and fraud.
Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets
Chinese-speaking threat actors targeted the Philippines Nuclear Agency and naval contractors, exploiting known vulnerabilities in ownCloud and WordPress.
DoD Refrigeration Outages: Hacking or Malfunction?
Multiple U.S. DoD commissaries report refrigeration outages, leading to speculation of cyberattack amidst a lack of official cause.
Infostealers Target Anthropic Claude Users via Session Theft
Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.
TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks
Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.
Nightmare Eclipse Releases HardBreacher Kaspersky Exploit
Security researcher Nightmare Eclipse releases HardBreacher, a privilege escalation proof-of-concept targeting Kaspersky Endpoint Security.
Cronos Blockchain Halted After $6M Tectonic DeFi Exploit
A price manipulation attack on Tectonic’s TONIC token led to a $6M Ethereum theft from the Cronos blockchain, forcing an emergency network restart.
North Korean Job Fraud Expands Beyond IT: New Sectors Targeted
DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.
Nigeria Advances Sovereign Cloud for Cyber, National Security
Nigeria is implementing a sovereign cloud strategy with new policies to boost national cybersecurity, data control, and domestic technical capabilities.
Nutex Health Suffers Data Breach, Sensitive Data Exfiltrated
Nutex Health experienced a data breach exposing patient, employee, and operational data. The company is assessing the full impact.
Hackers Abuse npm Mirrors to Host Phishing Redirects
Threat actors exploit npm and its mirroring platforms like UNPKG to host malicious HTML pages, impersonating Cloudflare CAPTCHAs for phishing redirects.
CVE-2026-60004: Gitea Code Injection Under Active Exploitation
CISA confirms active exploitation of CVE-2026-60004, a Gitea code injection vulnerability allowing shell command execution with repository write access.
AI Email Summarizers Vulnerable to Hidden HTML Prompts
Attackers can use invisible HTML prompts to manipulate AI email summarizers, generating false information and potential security risks.
Alice Secures $140M to Enhance AI Model Defenses and Guardrails
AI security firm Alice raised $140M to combat adversarial AI, prompt injection, and jailbreak attempts in generative AI systems.
U.S. Sanctions Iran-Linked Hackers Targeting Critical Infrastructure
U.S. Treasury sanctions Iran-linked cyber actors, including Mabna Institute members, for critical infrastructure breaches and cyber theft.
Mexico’s Cybersecurity Plan 2025-2030: Addressing Rising Threats
Mexico's National Cybersecurity Plan 2025-2030 aims to strengthen defenses against ransomware, state-sponsored espionage, and cybercrime.
Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata
Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.
State of AI-Enabled Malware: Real-World Impact and Defenses
Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.