All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits
Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.
Funnel Builder WordPress Plugin Exploited for Credit Card Skimming
Critical vulnerability in Funnel Builder WordPress plugin actively exploited to inject credit card skimming JavaScript into WooCommerce checkout pages.
April 2026 CVE Landscape: Prioritizing 37 High-Impact Vulnerabilities
Runtime Rebel analyzes Recorded Future's April 2026 CVE landscape, highlighting 37 high-impact vulnerabilities for urgent remediation amidst rising risks.
Security Brief: Data Breaches, ShinyHunters Activity, and App Flaws
Analyzes recent security events: Nvidia cloud gaming data breach, FBI warning on ShinyHunters hacking Canvas, and critical flaws in Audi mobile applications.
Microsoft Edge: Hardening Against Cleartext Password Exposure
Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.
CVE-2024-2123 & CVE-2024-2510: Avada Builder Patch Guidance
Critical flaws in Avada Builder WordPress plugin (CVE-2024-2123, CVE-2024-2510) allow for credential theft and LFI. Immediate update to version 3.11.7 required.
Advertisement
OpenClaw "Claw Chain" Flaws: Data Theft and Persistence Risks
Researchers at Cyera have identified the Claw Chain, a set of four OpenClaw vulnerabilities enabling data theft, privilege escalation, and persistent access.
Bypassing AI-Based Age Verification via Facial Obfuscations
Research reveals that AI-driven age estimation systems can be bypassed using physical facial alterations, highlighting flaws in biometric verification models.
20 Years of Cybersecurity: Strategic Insights from Industry Pioneers
Leading cybersecurity experts reflect on two decades of evolving threats, bug bounties, and the critical transition toward identity-centric security models.
American Lending Center Data Breach: 123,000 Impacted by Ransomware
American Lending Center confirms a June 2023 ransomware attack compromised sensitive data of 123,000 individuals, highlighting long-term forensic challenges.
CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild
Microsoft warns of CVE-2026-42897, a critical Exchange Server zero-day exploited in the wild. Implement Extended Protection mitigations immediately to secure systems.
CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability
Microsoft warns of CVE-2024-49040, a zero-day spoofing vulnerability in Exchange Server exploited to bypass security filters and impersonate trusted senders.
Microsoft Introduces Remote Rollback for Faulty Windows Drivers
Microsoft expands its Known Issue Rollback capability to Windows drivers, allowing remote remediation of faulty updates that cause boot loops or crashes.
Weaponized Trust: Analyzing the Abuse of Administrative Utilities
Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.
PAN-OS RCE via CVE-2024-3400 — Critical Vulnerability Mitigation Guide
Exploit analysis and mitigation for CVE-2024-3400, a critical command injection flaw in Palo Alto Networks PAN-OS GlobalProtect allowing unauthenticated RCE.
Malware Evolution: How New Libraries and Languages Bypass EDR
Attackers are adopting Go, Rust, and custom libraries to evade static signatures. Learn how to adapt your detection engineering for modern malware binaries.
Cisco SD-WAN RCE via CVE-2026-20182 — Mitigation Guide
Cisco patches CVE-2026-20182, the sixth SD-WAN zero-day exploited in 2026. Learn how threat actor UAT-8616 leverages this flaw for targeted attacks.
Chrome 148 Update: Patching Critical Use-After-Free Vulnerabilities
Google releases Chrome 148 addressing critical-severity use-after-free vulnerabilities.
Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit
CISA adds CVE-2026-20182 to its KEV catalog after reports of active exploitation against Cisco Catalyst SD-WAN Controllers. Critical patch required.
CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server
Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.
SecurityScorecard Acquires Driftnet: Boosting Supply Chain Threat Intelligence
SecurityScorecard's acquisition of Driftnet aims to enhance third-party ecosystem visibility, strengthening defenses against supply chain attack vectors.
SDR-Based Disruptions in Taiwan Rail Highlight ICS Security Gaps
An SDR-based interference incident in Taiwan underscores critical vulnerabilities in rail signaling and the need for enhanced OT security protocols.
CVE-2024-7109: Burst Statistics WordPress Plugin Auth Bypass Exploited
Hackers are actively exploiting CVE-2024-7109, a critical authentication bypass in Burst Statistics WordPress plugin, to gain admin access. Patch immediately.
TeamPCP Threatens Sale of Mistral AI Source Code Repositories
TeamPCP hackers claim to have exfiltrated 22GB of source code from Mistral AI. This report analyzes the breach impact and API key security risks.