All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
AI Bills of Materials: Essential for Proactive AI Supply Chain Security
Explore the emerging necessity of AI Bills of Materials (AI BOMs) to manage complex AI supply chain risks and enhance transparency in AI systems by 2026.
ChromaDB RCE via CVE-2024-34359 — Mitigation and Patch Guide
Discover how unauthenticated attackers exploit CVE-2024-34359 in ChromaDB for remote code execution. Learn detection strategies and patch requirements now.
Abuse of MSHTA in Stealthy Malware Delivery Chains
Attackers are abusing the legacy Windows MSHTA utility to deliver malware silently via phishing and fake downloads, bypassing EDR through LOLBIN techniques.
Windows Update Failures in Restricted Networks via January 2025 Patch
Microsoft confirms January 2025 non-security updates cause Windows Update failures in restricted networks. Learn how to resolve metadata service connection errors.
Drupal Core Security Update May 2026: Critical Patch Advisory
Drupal warns of an urgent core security update on May 20, 2026. Security teams must prepare for immediate patching to prevent exploit development.
EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow
The EvilTokens platform has compromised 340+ Microsoft 365 organizations by weaponizing OAuth Device Code Flows to bypass multi-factor authentication.
Advertisement
Universal Robots PolyScope 5 RCE via CVE-2024-8153 — Patch Now
Critical OS command injection vulnerability in Universal Robots PolyScope 5 allows attackers to compromise industrial robot fleets. Patch to version 5.19.0.
GitHub Actions Supply Chain Attack: actions-cool/issues-helper
Analysis of the actions-cool/issues-helper supply chain attack where tags were redirected to steal credentials. Learn how to detect and mitigate this threat.
Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer
Security researchers have identified a compromised version of the Nx Console VS Code extension (18.95.0) containing a malicious credential stealer.
OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.
CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack
Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.
CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure
A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development.
SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor
A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.
Interpol Operation Ramz: 53 Servers Seized and 200+ Arrests Made
Interpol's Operation Ramz dismantled cybercrime infrastructure across MENA, seizing 53 servers used for phishing and malware while arresting 200 suspects.
TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis
TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.
Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments
The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.
Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign
Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.
Mitigating Shadow AI: Framework for Detecting Unauthorized AI Tools
Comprehensive guide for security professionals on identifying, assessing, and governing unsanctioned AI applications to prevent corporate data leakage.
INTERPOL Operation Ramz: 201 Arrested in MENA Cybercrime Crackdown
INTERPOL's Operation Ramz results in 201 arrests across 13 MENA countries, disrupting infrastructure used for phishing, BEC, and financial fraud schemes.
Iranian Cyber Offensive Targets Critical Fuel Tank Gauge Systems
Iranian threat actors are targeting insecure automatic tank gauges in fuel infrastructure, posing risks of physical disruption and environmental damage.
Grafana GitHub Token Compromise: Codebase Stolen via PAT
Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.
Reducing Phishing Exposure: Strategies for Rapid Evidence Recovery
Learn how SOC teams can close the visibility gap in phishing detection and use evidence-based analysis to prevent business disruption after a click.
Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use
Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.
YellowKey: Bypassing Windows 11 BitLocker TPM Protections
Technical analysis of YellowKey, a zero-day exploit bypassing Windows 11 BitLocker. Learn how physical access allows attackers to extract encryption keys.