All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
RFID Vulnerabilities: Analyzing Ghost on the Wire Security Risks
Technical analysis of passive RFID tag security vulnerabilities including cloning and relay attacks revealed in the Ghost on the Wire research.
Communicating AI's Impact on Vulnerability Discovery to Boards
Security leaders must articulate AI-driven vulnerability trends and strategic resource needs to their boards, translating technical risks into business impact.
Securing Agentic AI Workflows with Advanced AI BOM Frameworks
Learn why CISOs must transition from traditional SBOMs to Agentic-Ready AI BOMs to manage risks in autonomous AI systems and data supply chains.
Kimwolf Botmaster Arrested: Impacts on IoT Botnet DDoS Mitigation
Canadian and U.S. authorities arrest the alleged operator of the massive Kimwolf IoT botnet, linked to millions of compromised devices and disruptive DDoS attacks.
Linux Process-Specific HTTP Proxying: Tools and Analysis Gaps
Explores the utility of process-specific HTTP proxying for Linux debugging and reverse engineering, highlighting the absence of a generic solution akin to Proxifier.
CVE-2022-4304: Hitachi Energy GMS600 Timing Side Channel Vulnerability
Hitachi Energy GMS600 versions 1.3.0-1.3.1 affected by CVE-2022-4304, an OpenSSL timing side channel leading to TLS decryption. Patch to 1.3.2 now.
Advertisement
ABB Terra AC Wallbox <=1.8.33 Buffer Overflows: Patch Now
CISA warns of three buffer overflow vulnerabilities (CVE-2025-10504, CVE-2025-12142, CVE-2025-12143) in ABB Terra AC Wallbox EV chargers, leading to potential remote…
AI-Assisted macOS Kernel Exploit on Apple M5 Hardware
Security researchers used Anthropic’s Mythos AI to develop a macOS kernel memory corruption exploit for the Apple M5 chip in just five days. Patch now.
AI Agent Identity Security: Budget Dynamics & Governance Priorities
New Omdia research reveals AI agent proliferation is fundamentally altering enterprise identity security budget dynamics, demanding distinct governance and management…
GCP API Keys Remain Active Post-Deletion: A 23-Minute Security Flaw
A security researcher found Google Cloud Platform (GCP) API keys stay active for 23 minutes post-deletion, posing a significant risk.
Apple's App Store Fraud Prevention: Over $11B Blocked
Runtime Rebel analyzes Apple's disclosure of blocking $11B in App Store fraud over six years, detailing the ongoing fight against malicious apps.
Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript
Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.
Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis
Recent intelligence highlights a surge in Linux rootkits and router zero-day vulnerabilities targeting trusted system components and AI-driven intrusions.
Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy
Researchers discover Showboat, a modular Linux post-exploitation framework used in Middle East telecom attacks to establish persistent SOCKS5 proxy backdoors.
Underminr Attack: How Attackers Hijack Trusted Brand CDNs
The Underminr exploit allows threat actors to use CDN infrastructure to hijack brand reputation and cloak malicious traffic. Learn how to detect and mitigate.
Ocean Launches Agentic AI Email Security Platform with $28M Funding
Ocean emerges from stealth with $28M to deploy specialized AI agents that simulate human reasoning to detect sophisticated phishing and BEC threats.
Cisco Secure Workload RCE via CVE-2025-20165 — Mitigation Guide
Cisco patches a critical 9.8 CVSS vulnerability in Secure Workload REST APIs that allows unauthenticated attackers to gain Site Admin privileges.
Flipper One: The Evolution of Linux-Based Hardware Pentesting Tools
Flipper Devices announces the Flipper One, an open Linux platform. Analyze the security implications and defensive requirements for this modular hacking tool.
Police Seize First VPN Service Linked to Global Ransomware Attacks
International law enforcement dismantles First VPN, a bulletproof service used by threat actors for ransomware deployment and anonymous data exfiltration.
Securing Identity Attack Paths: Protecting Cached AWS Credentials
Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.
Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited
Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.
Malicious PDF Structure Analysis and Obfuscation Detection
Learn how to detect malicious PDF obfuscation and analyze internal structures like /OpenAction and /JS streams to identify hidden malware payloads.
CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited
CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.
GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft
GitHub confirms the theft of 4,000 internal repositories by threat actor TeamPCP. Learn the technical implications and defense strategies for security teams.