Skip to main content

All Articles

Security Intelligence

3410 articles · Updated every 8 hours

Severity (this page):

Advertisement

ShinyHunters Extorts Instructure: 3.65TB Canvas LMS Data Breach Analysis
HIGH
Data Breach

ShinyHunters Extorts Instructure: 3.65TB Canvas LMS Data Breach Analysis

Instructure reaches an agreement with ShinyHunters after a massive 3.65TB data breach affecting Canvas LMS users across thousands of educational institutions.

Runtime Rebel Intel
4 min read · May 12, 2026
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
HIGH
Supply Chain

Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages

TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.

Runtime Rebel Intel
4 min read · May 12, 2026
HIGH
Malware

Malicious Windows 11 ISOs Deliver Vidar Infostealer — Analysis

Security researchers warn of fake Windows 11 ISO installers delivering Vidar and RedLine infostealers through sophisticated DLL side-loading techniques.

Runtime Rebel Intel
4 min read · May 12, 2026
HIGH
Vulnerabilities

Apple May 2024 Security Updates Address 84 Vulnerabilities

Apple's May 2024 security updates patch 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and visionOS. Immediate patching is crucial for all users.

Runtime Rebel Intel
4 min read · May 12, 2026
Empowering Human Defenses: Addressing Threats Unstoppable by Tech
INFO
Threat Intel

Empowering Human Defenses: Addressing Threats Unstoppable by Tech

Cybersecurity defenses often overlook the human element. This analysis details how employees are the critical first line against advanced social engineering and insider…

Runtime Rebel Intel
5 min read · May 12, 2026
FCC Adjusts Foreign Router Ban: Supply Chain Security Implications
INFO
Supply Chain

FCC Adjusts Foreign Router Ban: Supply Chain Security Implications

The FCC has modified its ban on non-compliant foreign-made routers, extending deadlines for federal agencies. This impacts government supply chain security efforts.

Runtime Rebel Intel
5 min read · May 12, 2026

Advertisement

HIGH
Supply Chain

Compromised Checkmarx Jenkins Plugin Spreads Infostealer

Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data.

Runtime Rebel Intel
4 min read · May 12, 2026
MEDIUM
Compliance

GM Settles for $12.75M Over Unauthorized Driver Data Sales

General Motors reaches a $12.75 million settlement with California for selling driver telematics data to brokers without consent, violating CCPA regulations.

Runtime Rebel Intel
4 min read · May 12, 2026
INFO
Threat Intel

Frame Security Secures $50M for Human Risk Management Platform

Frame Security emerges from stealth with $50M investment to develop a cybersecurity awareness and training platform, addressing human risk factors.

Runtime Rebel Intel
4 min read · May 11, 2026
cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor
CRITICAL
Vulnerabilities

cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor

A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is under active exploitation to deploy the Filemanager backdoor.

Runtime Rebel Intel
4 min read · May 11, 2026
Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack
HIGH
Supply Chain

Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack

TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.

Runtime Rebel Intel
3 min read · May 11, 2026
INFO
Threat Intel

Bot Mitigation with CAPTCHAs: Understanding Cloudflare Turnstile

Understand how Cloudflare Turnstile and other CAPTCHAs mitigate bot traffic, improve web performance, and enhance security against automated attacks.

Runtime Rebel Intel
4 min read · May 11, 2026
CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels
HIGH
Vulnerabilities

CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels

Analysis of CVE-2024-1086 (Dirty Frag), a netfilter vulnerability enabling local privilege escalation to root across major enterprise Linux distributions.

Runtime Rebel Intel
3 min read · May 11, 2026
INFO
Supply Chain

Defending CI/CD Pipelines with Build Application Firewalls

Examine how Build Application Firewalls (BAF) provide runtime protection for software pipelines to mitigate sophisticated supply chain attacks and data theft.

Runtime Rebel Intel
4 min read · May 11, 2026
MEDIUM
Identity & Access

Active Directory Post-Breach Persistence: Why Password Resets Fail

Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.

Runtime Rebel Intel
4 min read · May 11, 2026
MEDIUM
Vulnerabilities

Canvas LMS Vulnerability Leads to Portal Defacement — Patch Guidance

Instructure confirms a Canvas LMS vulnerability allowed attackers to deface login portals with extortion messages. Learn how to secure your LMS environment.

Runtime Rebel Intel
4 min read · May 11, 2026
Linux Rootkits and macOS Crypto Stealers Surge in Supply Chain Attacks
HIGH
Threat Intel

Linux Rootkits and macOS Crypto Stealers Surge in Supply Chain Attacks

Analysis of recent threats involving Linux rootkit persistence, macOS crypto-stealing malware, and the exploitation of poisoned supply chain downloads.

Runtime Rebel Intel
3 min read · May 11, 2026
AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure
HIGH
Threat Intel

AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure

Google identifies the first in-the-wild zero-day exploit for 2FA bypass developed using AI, signaling a shift in cybercriminal vulnerability discovery.

Runtime Rebel Intel
3 min read · May 11, 2026
HIGH
Threat Intel

AI-Augmented Zero-Day Exploitation and Autonomous Malware Orchestration

GTIG report reveals how threat actors leverage generative AI for zero-day discovery, autonomous Android malware orchestration, and AI supply chain attacks.

Runtime Rebel Intel
4 min read · May 11, 2026
INFO
Threat Intel

LLM Text-in-Text Steganography: Emerging Covert Channel Risks

Analysis of how Large Language Models enable sophisticated text-in-text steganography for covert communication, data exfiltration, and C2 operations.

Runtime Rebel Intel
4 min read · May 11, 2026
AI-Driven Exploit Development: How Adversaries Automate Attacks
MEDIUM
Threat Intel

AI-Driven Exploit Development: How Adversaries Automate Attacks

Cyber adversaries are leveraging Large Language Models to accelerate exploit development and automate complex attack chains, posing new risks to cloud security.

Runtime Rebel Intel
4 min read · May 11, 2026
HIGH
Data Breach

Skoda Online Shop Data Breach: Portal Vulnerability Analysis

Skoda Auto confirms a data breach affecting online shop customers. Attackers exploited a portal vulnerability to access PII including names and addresses.

Runtime Rebel Intel
3 min read · May 11, 2026
INFO
Vulnerabilities

Google’s Big Sleep AI Agent Discovers Real-World SQLite Zero-Day

Google Project Zero and DeepMind’s Big Sleep agent identifies an exploitable stack-based buffer underflow in SQLite, marking a shift in AI vulnerability discovery.

Runtime Rebel Intel
4 min read · May 11, 2026
HIGH
Vulnerabilities

CVE-2024-45785: AI-Generated Zero-Day Exploit Targets BigTree CMS

Google's Threat Intelligence Group discovered a zero-day in BigTree CMS exploited via AI-generated code. Update to version 4.4.16 to prevent remote execution.

Runtime Rebel Intel
3 min read · May 11, 2026