All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
CVE-2026-35616: FortiClient EMS Exploit Delivers EKZ Infostealer
Attackers are actively exploiting CVE-2026-35616, an authentication bypass in FortiClient EMS, to deploy the EKZ infostealer. Protect your organization now.
FBI Warning: Fake FIFA World Cup Sites Target Fans with Fraud
FBI warns of fraudulent websites impersonating FIFA for the 2026 World Cup, engaging in data theft, fake ticket sales, and hospitality scams.
Gogs Authenticated RCE: Arbitrary Code Execution - Mitigation Guide
A critical RCE vulnerability in Gogs allows authenticated users to execute arbitrary code. Runtime Rebel provides an analysis and urgent mitigation guidance.
CVE-2026-6332: Schneider Electric EcoStruxure HVAC Source Code Disclosure
A cleartext storage vulnerability in Schneider Electric EcoStruxure Machine Expert HVAC (CVE-2026-6332) exposes sensitive source code. Update to v1.10.0.
CVE-2021-22291: ABB EIBPORT V3 <3.9.2 Session Hijacking Vulnerability
ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.
Cyber Insurance Mandates: Quantifying Risk to Reshape Enterprise Security
Explore how cyber insurance requirements are driving organizations to quantify cyber risk, impacting security investments and overall security posture.
Advertisement
Securing Agentic AI Deployments: Mitigating Overlap Risks
Understanding the security risks in agentic AI deployments is crucial. This article outlines how AI agents' interaction with software tools creates vulnerabilities and…
Carnival Data Breach: 6 Million Customer Records Exposed
A data breach at Carnival Cruise Line exposed personal information for nearly 6 million customers, raising significant identity theft risks.
Geordie Secures $30M for AI Security and Governance Platform
Geordie raises $30M in Series A funding to address enterprise AI security risks, focusing on governance, visibility, and data protection for LLM deployments.
Leveraging SIEM for MSPs: Strategies to Reduce SOC Alert Fatigue
Explore how Managed Service Providers use SIEM to consolidate security logs, reduce alert noise, and improve incident response times in modern SOC environments.
Gogs Self-Hosted Git RCE via Zero-Day: Mitigation Guide
An unpatched zero-day vulnerability in Gogs self-hosted Git service allows attackers to achieve remote code execution, impacting Internet-facing instances.
Microsoft Condemns Public Zero-Day Disclosures, Advocates CVD
Microsoft reiterates strong support for Coordinated Vulnerability Disclosure, criticizing immediate public zero-day disclosures after a researcher's account removal.
FortiClient EMS Critical Flaw Exploited for Credential Stealing
Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.
CVE-2023-48788: Critical FortiClient EMS RCE Under Active Exploitation
Exploitation of CVE-2023-48788 in FortiClient EMS allows unauthenticated remote code execution. Administrators must patch to version 7.2.3 or 7.0.11 immediately.
BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover
BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.
Romanian Hacker Sentenced for Breach of Oregon Government Networks
Adrian-Tiberiu Oprea sentenced to 56 months for a multi-year cyber campaign targeting Oregon government systems and dozens of U.S. organizations.
Enterprise AI Risk Concentrated Among Power Users in 2026 Report
LayerX Security’s 2026 report reveals that enterprise AI risk is concentrated among power users, highlighting a significant visibility gap for security teams.
Nordic Cyber Resilience: Why Regional CISOs Report Threat Stability
An analysis of Nordic cybersecurity resilience, exploring why CISOs in northern Europe report stable threat levels despite rising geopolitical tensions.
JINX-0164 Targets Crypto Firms with macOS Malware and Fake Lures
The JINX-0164 threat actor targets cryptocurrency firms via recruitment-themed social engineering, macOS-specific malware, and CI/CD infrastructure exploits.
Silent Ransom Group Targets Law Firms via Physical Social Engineering
FBI warns of Silent Ransom Group (Luna Moth) targeting law firms using physical social engineering and data theft for extortion. Learn how to defend.
Akira Ransomware Kill Chain: Log Analysis for Early Detection
Analyze Akira Ransomware kill chain stages using perimeter and endpoint logs to detect initial access, privilege escalation, and pre-encryption activity.
SEO Poisoning and AI Chatbots Spread GPU Mining Malware
Threat actors are using SEO poisoning and manipulated AI chatbot recommendations to distribute persistent GPU mining malware to high-performance systems.
Actively Exploited CVEs: Daemon Tools Lite, TanStack, Nx Console
CISA added three vulnerabilities—CVE-2026-8398, CVE-2026-45321, CVE-2026-48027—to its KEV Catalog due to active exploitation. Prioritize patching.
GCHQ Warning: Russian Gray Zone Tactics and AI-Driven Cyber Threats
GCHQ Director Anne Keast-Butler warns that AI is an unstoppable force that Russian state-sponsored actors are leveraging for gray zone cyber operations.