All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Operation Magnus: Dutch Police Disrupt 17-Million-Device Botnet
Dutch authorities dismantle a massive 17-million-device botnet used as an illicit residential proxy network to mask cybercriminal activities and bypass security.
Microsoft Teams and Office Web File Access Disruptions - Mitigation Guide
Microsoft is investigating a service incident impacting file access in Teams and Office for the web, causing operational delays for global enterprises.
WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops
Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.
Military AI Integration: Strategic Risks and Technical Guardrails
Analyze the Pentagon's acceleration of battlefield AI and the technical risks of autonomous systems, highlighting the need for human-centric oversight.
Dragos Acquires Phosphorus to Enhance xIoT Asset Visibility
Dragos acquires xIoT security specialist Phosphorus to integrate automated remediation and expanded asset visibility into its industrial cybersecurity platform.
CVE-2020-1472: How Attackers Exploit Windows Netlogon RCE — Patch Now
Threat actors are actively exploiting Zerologon (CVE-2020-1472), a critical Windows Netlogon RCE vulnerability that allows for full domain takeover.
Advertisement
Closing the Window: Why Faster Vulnerability Alerts are Critical
Attackers exploit vulnerabilities faster than ever. Learn why reducing the window of exposure through automated alerts is essential for modern cybersecurity.
Operation Dragon Weave: APT Targeting Czech Republic and Taiwan
China-aligned Operation Dragon Weave targets Czech and Taiwanese government and tech sectors using spear-phishing to deploy the AdaptixC2 agent framework.
PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap
An analysis of active PAN-OS exploitation, a new Linux authentication flaw, and the rise of AI-powered OAuth phishing kits targeting enterprise environments.
Geopolitical Competition and Cyber Risks of Humanoid Robotics
Analysis of how global competition for humanoid robots and embodied AI introduces physical risks and supply chain vulnerabilities for organizations.
WP Maps Pro Flaw Exploited for Admin Account Creation — Patch Now
Attackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on affected sites.
Quishing Evasion: Malicious QR Codes Bypassing Security Filters
A technical analysis of how malicious QR codes (quishing) bypass email security filters and actionable mitigation steps for security operations centers.
NetSupport RAT Infection: How to Detect Unidentified Loader Exploits
Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.
YARA-X 1.17.0 Release: Enhanced Performance for Malware Analysis
YARA-X version 1.17.0 release introduces five performance improvements and a bugfix for the Rust-based malware detection engine. Enhance your scanning speed.
CVE-2024-10642: WP Maps Pro Exploited to Create WordPress Admin Accounts
Attackers are exploiting a critical privilege escalation flaw in the WP Maps Pro WordPress plugin to create rogue admin accounts without authentication.
Dutch Police Seize 200 Servers to Dismantle 17-Million Device Botnet
Dutch authorities and the NCSC dismantled a global botnet affecting 17 million devices. Learn how the seizure of 200 servers impacts global cybercrime operations.
CVE-2024-5910: Palo Alto GlobalProtect Auth Bypass Exploited - Patch Now
Palo Alto Networks warns that attackers are exploiting CVE-2024-5910, a critical authentication bypass in GlobalProtect gateway. Learn how to secure your PAN-OS.
Flowise RCE via CVE-2024-31621 — Mitigation Guide
Exploit code is public for a critical RCE vulnerability in Flowise. Attackers use malicious chatflow imports to compromise self-hosted servers.
Russian Intelligence Intensifies Tech Procurement and Infrastructure Recon
Russian spies are leveraging front companies and cyber espionage to bypass sanctions and gather intelligence for potential attacks on Western infrastructure.
CVE-2024-52336: How CIFSwitch Grants Root Access on Linux Systems
The CVE-2024-52336 vulnerability, known as CIFSwitch, allows local privilege escalation to root by abusing CIFS key requests in the Linux kernel.
CVE-2026-0257: PAN-OS GlobalProtect Auth Bypass Under Exploitation
Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass vulnerability affecting PAN-OS and Prisma Access GlobalProtect gateways.
CVE-2026-0257: Palo Alto PAN-OS Auth Bypass Under Active Attack
CISA adds CVE-2026-0257, an actively exploited authentication bypass in Palo Alto Networks PAN-OS, to its KEV catalog.
Cybersecurity Evolution: Reflecting Two Decades of Industry Change
Dark Reading's 20th anniversary 'Name That Toon' offers a unique lens into two decades of cybersecurity progress and challenges, as seen by industry professionals.
23andMe 2023 Data Breach: AG Sues Over Exposed Health Data
California AG sues 23andMe for a 2023 credential stuffing data breach exposing genetic and personal health data of 6.9 million users.