All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Ghost CMS CVE-2022-41654: Over 700 Websites Compromised
Attackers are exploiting a critical Ghost CMS vulnerability to inject malicious scripts into sites belonging to Harvard, Oxford, and DuckDuckGo.
Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap
Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.
Radiology Associates of Richmond Breach Affects 266,000 Patients
A data breach at Radiology Associates of Richmond has exposed the sensitive health and personal information of over 266,000 individuals.
Oncology Institute Discloses Third-Party Data Breach via Vendor
The Oncology Institute reports a data breach involving a third-party vendor, potentially TriZetto, exposing patient PHI and sensitive healthcare data.
FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts
The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.
Next-Gen NDR: Reducing Alert Fatigue with Agentic AI Capabilities
Examine how agentic AI is transforming Network Detection and Response to mitigate alert fatigue and improve threat triage efficiency for SOC teams.
Advertisement
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.
Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories
Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.
CVE-2026-5426: RCE via ViewState Deserialization in KnowledgeDeliver
Attackers exploit CVE-2026-5426 in the KnowledgeDeliver LMS to achieve RCE via shared ASP.NET machine keys. Immediate key rotation and patching are required.
Chinese-Language PhaaS: Real-Time OTP Interception and Tokenization
Chinese-language PhaaS providers like Darcula are shifting to real-time OTP interception and digital wallet tokenization to bypass modern MFA controls.
Wireshark 4.6.6: Fixing Critical Vulnerability and Dissector Bugs
Wireshark 4.6.6 release addresses one security vulnerability and 11 functional bugs. Learn how this update secures packet analysis and prevents dissector crashes.
CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign
A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.
Laravel Lang Hijack: Supply Chain Attack via Malicious GitHub Tags
Analysis of the Laravel Lang supply chain attack involving malicious GitHub tags v13.8.1 and v13.8.2 used to steal environmental secrets and credentials.
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.
npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks
GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.
Italy Dismantles CINEMAGOAL App for Streaming Auth Token Theft
Italian authorities dismantled the CINEMAGOAL piracy app, which harvested authentication tokens and session cookies from users to access streaming services.
Anthropic Project Glasswing Uncovers 10,000 High-Severity Flaws
Anthropic's Claude Mythos AI identifies over 10,000 critical and high-severity vulnerabilities in systemically important software via Project Glasswing.
Underminr Vulnerability: Bypassing DNS Filtering via Trusted Domains
The Underminr vulnerability affects 88 million domains, allowing attackers to hide C2 traffic and bypass DNS filtering using shared infrastructure.
Laravel-Lang PHP Packages Compromised: Credential Stealer Alert
Multiple Laravel-Lang PHP packages have been compromised to deliver a cross-platform credential stealer. Learn how to detect and mitigate this supply chain threat.
Obfuscating Strings in C++ Implants: Detection and Analysis
Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.
CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation - Patch Now
Exploitation of CVE-2026-48172 in the LiteSpeed cPanel plugin allows local users to gain root access. Organizations should update to version 1.2.2 immediately.
ABB B&R Automation Studio <6.5: Multiple Critical SQLite Vulnerabilities
Critical SQLite vulnerabilities in ABB B&R Automation Studio <6.5 expose ICS to RCE, data exposure, and unauthorized access. Update to version 6.5 immediately.