All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
CVE-2026-9082: Drupal Core SQL Injection Under Active Exploitation
CISA adds CVE-2026-9082, a critical Drupal Core SQL Injection vulnerability, to KEV Catalog due to active exploitation. Immediate patching required for all organizations.
CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository
A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.
Akamai Acquires LayerX: Enterprise Browser Security Trends 2024
Akamai's acquisition of LayerX highlights the strategic shift toward secure enterprise browsers to mitigate SaaS risks and protect unmanaged devices.
CVE-2026-9082: Drupal Under Active Exploitation – Patch Now
Critical Drupal vulnerability CVE-2026-9082 is actively exploited shortly after disclosure. Urgent patching is required to prevent compromise of thousands of websites.
FIOD Seizes 800 Servers: Disruption of Bulletproof Hosting
Dutch authorities seize 800 servers from a bulletproof hosting provider, disrupting infrastructure for cyberattacks, disinformation, and interference campaigns.
Ghostwriter Targets Ukraine Government with Prometheus Phishing
Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware.
Advertisement
Dismantling First VPN: Global Takedown of Ransomware Infrastructure
Authorities dismantle First VPN Service, a critical infrastructure hub used by 25 ransomware groups for masking data theft and DDoS attacks.
Verizon DBIR 2024: Healthcare Targeted by Social Engineering
An analysis of the 2024 Verizon DBIR healthcare findings, highlighting the surge in social engineering, ransomware, and supply chain vulnerabilities.
CISA Data Leak: AWS GovCloud Keys Exposed via Public GitHub Repo
Lawmakers demand answers from CISA after a contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting urgent credential rotation.
Huawei AR2500 Exploitation: Industrial Router Flaw Analysis
An analysis of the Huawei AR2500 industrial router exploitation that triggered a major telecom outage and CISA's new KEV nomination process.
CVE-2023-41179: Trend Micro Apex One RCE Exploited in Attacks
Trend Micro patches CVE-2023-41179, a critical zero-day in Apex One and Worry-Free Business Security exploited to execute arbitrary commands on Windows systems.
Tech Support Fraud: Executives Plead Guilty in Infrastructure Case
Former executives of CallerReady plead guilty to facilitating global tech support scams by providing call-tracking and CRM infrastructure to fraudsters.
Webworm Group Exploits Discord and MS Graph to Target EU Governments
China-linked threat actor Webworm utilizes Discord and Microsoft Graph API for C2 infrastructure in a campaign targeting European government organizations.
FBI Disrupts First VPN Service Used by Ransomware Groups
The FBI and international partners dismantled First VPN, a specialized service used by dozens of ransomware groups for reconnaissance and intrusions.
Canadian Man Arrested for Kimwolf Botnet Operations
Jacob Butler faces US extradition for operating the Kimwolf botnet. Analysis of the arrest, botnet infrastructure, and its role in the initial access market.
Ubiquiti Patches Critical UniFi OS Command Injection Vulnerabilities
Ubiquiti has addressed three critical vulnerabilities (CVE-2024-42025, CVE-2024-42027, CVE-2024-42028) in UniFi OS that allow unauthenticated RCE via local networks.
Bypassing Hardware Gates: Exploitability of Vulnerable Drivers
Technical analysis of how researchers bypass hardware-gating to exploit Windows kernel-mode drivers without physical devices in BYOVD attacks.
Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows
Automated Megalodon attack pushes 5,718 malicious commits to GitHub repositories to exfiltrate secrets via GitHub Actions workflows.
Analysis of Cross-Platform NPM Stealer Using Discord Webhooks
Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.
Grafana Codebase Stolen via TanStack Supply Chain Attack
Grafana confirms unauthorized access to private GitHub repositories after a developer token leaked in the TanStack breach was not rotated.
CVE-2026-34926: TrendAI Apex One Directory Traversal Exploit Analysis
TrendAI patches a critical zero-day directory traversal vulnerability (CVE-2026-34926) in Apex One on-premise currently exploited in the wild.
US and Canada Charge Suspected KimWolf Botnet Operator
Authorities dismantle the KimWolf botnet following the arrest of a Canadian national linked to nearly two million global device infections and DDoS attacks.
CVE-2025-34291 & CVE-2023-41179: CISA Warns of Active Exploitation
CISA adds Langflow and Trend Micro Apex One vulnerabilities to KEV. Learn how to mitigate CVE-2025-34291 and CVE-2023-41179 to prevent active exploitation.
Kimwolf Botnet Operator Jacob Butler Arrested in DDoS-for-Hire Case
DOJ arrests Canadian operator of the Kimwolf botnet, a variant of the AISURU malware, used in large-scale DDoS-for-hire attacks against global targets.