All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
FBI’s 2025 Internet Crime Report: Trends and Outlook
The FBI's 2025 Internet Crime Report highlights evolving cybercrime trends, victim impact, and reporting significance for US security professionals.
AI-Assisted Exploit Development Shorthand Vulnerability Windows
AI tools enable attackers to develop exploits for newly disclosed CVEs in hours, outpacing traditional vulnerability scanner detection capabilities.
Latin American Government Data Leaks: Uruguay Incident Analysis
Analysis of the massive 5.8 million record leak in Uruguay and the growing trend of cybercriminals targeting Latin American government data for monetization.
CVE-2024-45404: Pretalx Logic Flaw Enables Full Account Takeover
Researchers discover a critical logic flaw in Pretalx versions prior to 2024.1.0 that allows attackers to hijack organizer accounts and manipulate events.
Glassworm Botnet Infrastructure Disrupted: Solana and DHT C2 Analysis
Researchers disrupt the Glassworm botnet, which utilized Solana blockchain and BitTorrent DHT for resilient C2 to target software developers.
Optimizing Active Directory Security with Modern Password Policies
Learn how to implement NIST-compliant Active Directory password policies using passphrases and breached password protection to reduce identity-based risks.
Advertisement
Malicious npm Package Targets Claude AI User Data — Technical Analysis
Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.
Grandoreiro and BTMOB RAT Campaigns Target Windows and Android Users
Analysis of Grandoreiro and BTMOB malware campaigns targeting financial sectors in Spain, Portugal, and Latin America through Windows and Android platforms.
The Transition from Perimeter Defense to AI-Native Security
Examine the 20-year shift from legacy perimeter firewalls to modern AI-native security architectures and identity-centric defense strategies.
RevEng.AI Secures $15M for AI-Powered Software Binary Analysis
RevEng.AI raises $15 million to scale BinNet, a proprietary AI model designed to automate binary analysis and detect hidden backdoors in software assets.
AI Risk Summit: Navigating Enterprise AI Governance and Vulnerabilities
Analysis of the 2025 AI Risk Summit and its focus on adversarial machine learning, enterprise AI governance frameworks, and securing LLM integrations.
CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw
CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.
Silent Ransom Group: FBI Warns of In-Person Data Theft at Law Firms
The FBI warns that Silent Ransom Group is conducting physical data theft attacks against US law firms using unauthorized building access and hardware.
Managing Shadow AI Tools: A Framework for Secure Enterprise Integration
Unvetted AI tools pose significant data privacy and security risks. Learn how to discover and manage shadow AI usage without impacting employee productivity.
GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2
CrowdStrike, Google, and Shadowserver disrupt the GlassWorm malware C2 infrastructure, halting a persistent developer-focused supply chain attack campaign.
CVE-2024-50498: Patch Exploited LiteSpeed cPanel Plugin Zero-Day
CISA warns of active exploitation of CVE-2024-50498 in LiteSpeed cPanel plugins, allowing attackers to execute scripts with root privileges. Patch now.
Physical Access Risks: FBI Warns of In-Person USB Attacks by SRG
FBI alerts law firms of Silent Ransom Group operatives using physical social engineering and USB drives to infiltrate networks and exfiltrate sensitive data.
Windows 11 KB5089573: Performance and Reliability Fixes for 24H2/25H2
Microsoft releases KB5089573 preview for Windows 11 24H2 and 25H2, addressing Task Manager bugs, ReFS performance issues, and Sandbox stability errors.
Ajax Football Club Hack: Suspect Arrested in Almere Data Breach
Dutch police arrested a 35-year-old suspect linked to the AFC Ajax data breach involving the theft of sensitive personal data of players and staff.
AI Chatbot Poisoning: Defending Against Malicious Cryptojacking Links
Microsoft warns of threat actors manipulating AI chatbot recommendations to deliver cryptojacking malware via poisoned web search results.
DrayTek Vigor RCE: Patching CVE-2024-41585 Command Injection
Critical OS command injection in DrayTek Vigor routers allows unauthenticated RCE. Learn how to patch CVE-2024-41585 and protect your network edge.
CVE-2023-47359 & More: Critical Vulnerabilities in ABB Ability Camera Connect
Multiple critical and high-severity vulnerabilities in ABB Ability Camera Connect (VLC component <=1.5.0.14) could lead to RCE or DoS. Update to 1.5.0.15 now.
CVE-2026-7251: Hard-coded Password in Eppendorf BioFlo 320
Critical hard-coded password vulnerability (CVE-2026-7251) in Eppendorf BioFlo 320 bioreactors allows full remote control. Patch immediately.
Passive Wi-Fi Sensing: Surveillance Risks & Privacy Implications
Researchers warn about Wi-Fi sensing technology's potential for passive surveillance, turning routers into privacy threats. Learn the risks and mitigation.