All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.
Megalodon Malware: GitHub Repo Compromise & Secret Theft
Analysis of the Megalodon malware campaign, which compromised over 5,500 GitHub repositories in six hours to steal developer credentials and sensitive secrets.
Iranian APT33 Targets Aviation with Updated MimicC2 and PowerLess
Iranian APT Nimbus Manticore (APT33) targets aviation and software firms using new MimicC2 framework and updated PowerLess tools for stealthy operations.
Marlin AI: Autonomous Investigation for SaaS Security Posture
AppOmni's Marlin AI enhances SaaS security by automating misconfiguration analysis, activity investigation, and remediation recommendations across enterprise…
Charter Data Breach Confirmed: ShinyHunters Extortion Threat
Charter Communications confirms a data breach following an extortion threat by ShinyHunters.
KnowledgeDeliver RCE via CVE-2024-52648 — Mitigation Guide
Attackers are exploiting a critical zero-day vulnerability (CVE-2024-52648) in KnowledgeDeliver LMS to deploy Godzilla web shells. Secure your servers now.
Advertisement
Varonis Atlas Claude Compliance API Integration for AI Governance
Varonis Atlas integrates the Claude Compliance API to monitor enterprise AI usage, identify sensitive data risks, and ensure regulatory compliance for LLMs.
MuddyWater 2026 Espionage: DLL Side-Loading Across 9 Countries
Iranian group MuddyWater targets industrial manufacturing and financial sectors in a global 2026 espionage campaign using DLL side-loading techniques.
Professional Standards in the Evolution of Threat Intelligence
Explore the impact of professional journalism on threat intelligence and the legacy of Tim Wilson in establishing standards for information sharing.
Anthropic Claude Enterprise Security Governance via 28 Integrations
Anthropic expands Claude’s security posture with 28 integrations from CrowdStrike, Okta, and Microsoft to enhance enterprise AI visibility and governance.
7-Eleven Data Breach: 185,000 Records Leaked by ShinyHunters
Analysis of the 7-Eleven data breach involving threat actor ShinyHunters, impacting 185,000 users and exposing sensitive PII including dates of birth.
Automated Endpoint Isolation in Microsoft Defender for Endpoint
Microsoft Defender for Endpoint now features automatic device isolation to block lateral movement and contain high-confidence security breaches effectively.
CVE-2026-45659: SharePoint RCE via Deserialization - Patch Now
Microsoft addresses CVE-2026-45659, a high-severity RCE flaw in SharePoint Server caused by untrusted data deserialization. Learn how to mitigate this risk.
AI-Powered DDoS Attacks: Emerging Tactics and Defensive Strategies
Threat actors are leveraging artificial intelligence to automate DDoS attacks, increasing speed and evasion capabilities against traditional network defenses.
Windows Server 2016 DC Lookup Failures: KB5037763 Mitigation Guide
Microsoft confirms a regression in Windows Server 2016 causing LSASS crashes and domain controller lookup failures after the May 2024 security update.
Drupal 7.x SQL Injection CVE-2014-3704 — Active Exploitation Alert
CISA adds Drupalgeddon SQL injection (CVE-2014-3704) to KEV catalog, mandating federal agencies to patch critical legacy systems against active exploits.
CVE-2026-5426: KnowledgeDeliver LMS Zero-Day Exploited for Godzilla Shell
Attackers exploited a zero-day in KnowledgeDeliver LMS (CVE-2026-5426) using hard-coded ASP.NET keys to deploy Godzilla web shells and Cobalt Strike Beacons.
Nimbus Manticore Targets Aviation via MiniFast and MiniJunk V2
Iranian threat actor Nimbus Manticore utilizes SEO poisoning and phishing to deploy MiniFast malware against global aviation and software organizations.
Analyzing Suspicious TLS Traffic Patterns with JA3 Fingerprinting
Improve threat detection by identifying TLS handshake anomalies, JA3 fingerprints, and SNI mismatches to expose hidden malicious network activity.
ACR Stealer Distributed via Fake Claude AI Desktop Site
Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.
Anthropic Claude Code Integration of Mythos Model Raises Security Risks
Anthropic may be integrating its restricted Mythos model into Claude Code, raising concerns about autonomous agentic capabilities and AI safety levels.
TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub
TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.
Analyzing Microsoft Access VBA Macros for Malware Detection
Learn how threat actors use Microsoft Access .accdb files to execute malicious VBA code and how to analyze these OLE streams for incident response.
Netherlands Seizes 800 Servers Linked to Russian Intelligence Proxies
Dutch authorities arrested hosting providers and seized 800 servers used by Russian intelligence for DDoS and disinformation campaigns following EU sanctions.