All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Software Supply Chain Security: Addressing Visibility Gaps
An analysis of the growing software supply chain crisis, focusing on the acceleration of vulnerability exploitation and the lack of systemic visibility.
GitHub Repository Breach Linked to TanStack Supply Chain Attack
GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.
CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus
Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.
CVE-2026-46333: Nine-Year-Old Linux Kernel Privilege Escalation Flaw
A long-standing Linux kernel flaw, CVE-2026-46333, allows local users to achieve root access and disclose sensitive data on major Linux distributions.
AI in Cybersecurity: Weighing Risks, Benefits, and Defender Concerns
Analysis of cybersecurity professionals' perceptions on AI's dual role, exploring its potential to enhance defenses against evolving threats while acknowledging…
CVE-2026-9082: Drupal Core RCE via Database API (PostgreSQL)
A highly critical flaw, CVE-2026-9082, in Drupal Core's database abstraction API allows RCE, privilege escalation, and info disclosure on PostgreSQL sites.
Advertisement
GitHub Internal Repositories Breached via Nx Console VS Code Extension
GitHub confirms internal repository breach after an employee device was compromised by a poisoned Nx Console VS Code extension in a supply chain attack.
SonicWall Gen6 SSL-VPN MFA Bypass: Incomplete Patching Leads to Compromise
Hackers are bypassing MFA on SonicWall Gen6 SSL-VPN appliances via brute-force due to incomplete patching, enabling ransomware tool deployment.
Ukraine Identifies Odesa-Based Infostealer Operator
Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.
AI Security: Beyond Benchmarks, Towards Process-Driven Assurance
Traditional security benchmarks fail for AI. This analysis details the challenges in measuring AI security and advocates for process-driven risk management and vigilance.
Analyzing Process and Culture Gaps in Modern Data Breaches
Analysis of recent breach data reveals that culture and visibility issues are primary drivers of security incidents despite legislative mandates.
Infosecurity Europe: Leveraging Insights for Threat Intelligence
Runtime Rebel analyzes the general importance of security conferences like Infosecurity Europe for staying updated on evolving threats and industry trends.
OT Robot OS Command Injection: Unauthenticated RCE — Patch Now
Critical command injection vulnerability in OT Robot OS allows unauthenticated attackers to gain remote control, posing significant disruption risks to industrial…
YellowKey BitLocker Bypass: Microsoft Mitigates Data Access
Microsoft addresses the 'YellowKey' BitLocker bypass, preventing unauthorized data access via the FsTx Auto Recovery Utility in WinRE. Understand the threat.
Quantum-Safe Key Distribution: Securing the Post-Quantum Era
Quantum Bridge secures $8M for quantum-safe key distribution. Learn why current cryptography faces quantum threats and how to prepare for future security challenges.
Zero Trust: Why Device Security is Essential Beyond Identity
Identity-only security fails against stolen tokens and compromised devices. Learn why robust device security is critical for effective Zero Trust strategies.
Grafana Breach After TanStack Attack: Token Rotation Failure
Grafana suffered a data breach due to a GitHub workflow token not rotated after the TanStack npm supply-chain attack, impacting user data. Learn the details.
Microsoft RAMPART and Clarity: Securing AI Agents Against Exploitation
Microsoft open-sources RAMPART and Clarity to provide developers with frameworks for red teaming and observing autonomous AI agents against prompt injection.
AI BOMs in Security: CISO Guide to Usability & Influence
Explore how CISOs can effectively prepare for and integrate AI Bill of Materials (AI BOMs) into their modern security programs, influencing their generation for better…
320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack
A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.
Claude Code Sandbox Bypass: Anthropic Patches CLI Vulnerability
Anthropic recently addressed a sandbox bypass in Claude Code. This vulnerability could have allowed data exfiltration when combined with prompt injection.
CVE-2024-51567: How Attackers Exploit Arch Linux genfstab — Patch Now
A public exploit for PinTheft (CVE-2024-51567) allows local attackers to gain root privileges on Arch Linux via the genfstab script. Update to version 31.
Drupal Core Security Release: Preparing for High-Risk Exploitation
Drupal warns of a critical core security update with high exploitation risk. Learn how to prepare for patches and protect your CMS from potential RCE.
Typosquatting Evolution: How AI Lookalike Domains Target Supply Chains
Attackers are weaponizing AI-generated lookalike domains within third-party scripts, turning typosquatting into a sophisticated supply chain threat for enterprises.