All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
CVE-2024-41662: Chaining OpenClaw Flaws for Sandbox Escape
CyberArk researchers uncover the Claw Chain in OpenClaw, allowing attackers to escape sandboxes, steal credentials, and deploy persistent backdoors.
US Healthcare Data Breaches: Millions Impacted via Tracking Pixels
Millions of patient records were exposed in major healthcare breaches at Kaiser Permanente, City of Hope, and HealthEC due to tracking pixels and system access.
Windows 11 Resizable Taskbar and Start Menu Preview Analysis
Microsoft initiates testing for resizable taskbar and Start menu features in Windows 11 Insider builds, addressing long-standing UI customization requests.
Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws
Ivanti, Fortinet, n8n, and SAP release urgent security patches for critical vulnerabilities including CVE-2026-5444 and CVE-2026-8043. Update systems now.
Developer Workstations: The New Front in Software Supply Chain Attacks
A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.
CVE-2024-31079: Critical NGINX RCE Vulnerability Exploitation
Active exploitation of CVE-2024-31079 in the NGINX HTTP/3 module allows for RCE and DoS. Security teams must patch NGINX Open Source and Plus immediately.
Advertisement
Grafana Labs Breach: Coinbase Cartel Claims Data Theft — Analysis
Grafana confirms a security breach after the Coinbase Cartel group claimed to have stolen sensitive data, including customer and infrastructure information.
DirtyDecrypt: How Attackers Exploit Linux Kernel rxgk for Root Access
Learn about DirtyDecrypt, a local privilege escalation vulnerability in the Linux rxgk module. Discover how to detect and mitigate this root access threat.
Windows 11 KB5089549 Security Update Installation Failure Analysis
Microsoft confirms Windows 11 KB5089549 security update fails with error 0x800f0922. Learn how to troubleshoot and resolve these installation issues.
MiniPlasma 0-Day: Windows SYSTEM Privilege Escalation via cldflt.sys
Technical analysis of the MiniPlasma zero-day vulnerability in cldflt.sys enabling SYSTEM privilege escalation on fully patched Windows systems.
Fast16: Pre-Stuxnet Lua Malware Targets Nuclear Physics Simulations
New analysis reveals Fast16 malware tampered with uranium-compression simulations, predating Stuxnet as a sophisticated tool for nuclear cyber sabotage.
South Korea Deepfake Election Law: Testing AI Content Regulations
South Korea implements strict laws banning AI-generated deepfakes in elections. Explore the technical challenges of detection and legislative enforcement.
Pwn2Own Berlin 2026: Critical RCE and Escalation Targets Identified
Security researchers demonstrate critical zero-day exploits against Windows, VMware, and AI systems at Pwn2Own Berlin 2026, earning over $1.3 million.
Windows MiniPlasma Zero-Day Exploit: How to Mitigate LPE Threats
A new zero-day exploit dubbed MiniPlasma allows local attackers to gain SYSTEM privileges on fully patched Windows systems. Learn detection and mitigation steps.
Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow
Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.
NGINX CVE-2026-42945: Heap Buffer Overflow Exploited — Patch Now
Active exploitation of CVE-2026-42945 in NGINX ngx_http_rewrite_module allows for worker process crashes and remote code execution. Update to version 1.31.0.
Grafana GitHub Token Leak: Codebase Access and Extortion Attempt
Grafana discloses a security incident where an unauthorized party used a GitHub token to download source code, leading to a failed extortion attempt.
Azure Backup for AKS Vulnerability: Risks of Silent Patches
A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.
Funnel Builder Plugin Exploited for WooCommerce Checkout Skimming
Attackers are exploiting a vulnerability in the Funnel Builder WordPress plugin to inject skimming scripts and steal payment data from WooCommerce sites.
Turla Updates Kazuar Backdoor with Modular P2P Botnet Capabilities
Russian threat actor Turla (Secret Blizzard) has upgraded its Kazuar backdoor with peer-to-peer botnet functionality and modular architecture for stealth.
NGINX HTTP/3 RCE via CVE-2024-24989 — Mitigation Guide
Proof of Concept code released for critical NGINX CVE-2024-24989 and CVE-2024-24990. Learn how to detect and patch these HTTP/3 vulnerabilities immediately.
AI-Generated Code and Autonomous Agents: New Risks for Defenders
AI agents are automating vulnerability discovery in AI-generated codebases, forcing a shift in defensive security strategies and response times.
BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion
Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.
CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation
CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.