All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
ShinyHunters Extorts Instructure: 3.65TB Canvas LMS Data Breach Analysis
Instructure reaches an agreement with ShinyHunters after a massive 3.65TB data breach affecting Canvas LMS users across thousands of educational institutions.
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.
Malicious Windows 11 ISOs Deliver Vidar Infostealer — Analysis
Security researchers warn of fake Windows 11 ISO installers delivering Vidar and RedLine infostealers through sophisticated DLL side-loading techniques.
Apple May 2024 Security Updates Address 84 Vulnerabilities
Apple's May 2024 security updates patch 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and visionOS. Immediate patching is crucial for all users.
Empowering Human Defenses: Addressing Threats Unstoppable by Tech
Cybersecurity defenses often overlook the human element. This analysis details how employees are the critical first line against advanced social engineering and insider…
FCC Adjusts Foreign Router Ban: Supply Chain Security Implications
The FCC has modified its ban on non-compliant foreign-made routers, extending deadlines for federal agencies. This impacts government supply chain security efforts.
Advertisement
Compromised Checkmarx Jenkins Plugin Spreads Infostealer
Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data.
GM Settles for $12.75M Over Unauthorized Driver Data Sales
General Motors reaches a $12.75 million settlement with California for selling driver telematics data to brokers without consent, violating CCPA regulations.
Frame Security Secures $50M for Human Risk Management Platform
Frame Security emerges from stealth with $50M investment to develop a cybersecurity awareness and training platform, addressing human risk factors.
cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor
A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is under active exploitation to deploy the Filemanager backdoor.
Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack
TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.
Bot Mitigation with CAPTCHAs: Understanding Cloudflare Turnstile
Understand how Cloudflare Turnstile and other CAPTCHAs mitigate bot traffic, improve web performance, and enhance security against automated attacks.
CVE-2024-1086: Dirty Frag Local Privilege Escalation in Linux Kernels
Analysis of CVE-2024-1086 (Dirty Frag), a netfilter vulnerability enabling local privilege escalation to root across major enterprise Linux distributions.
Defending CI/CD Pipelines with Build Application Firewalls
Examine how Build Application Firewalls (BAF) provide runtime protection for software pipelines to mitigate sophisticated supply chain attacks and data theft.
Active Directory Post-Breach Persistence: Why Password Resets Fail
Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.
Canvas LMS Vulnerability Leads to Portal Defacement — Patch Guidance
Instructure confirms a Canvas LMS vulnerability allowed attackers to deface login portals with extortion messages. Learn how to secure your LMS environment.
Linux Rootkits and macOS Crypto Stealers Surge in Supply Chain Attacks
Analysis of recent threats involving Linux rootkit persistence, macOS crypto-stealing malware, and the exploitation of poisoned supply chain downloads.
AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure
Google identifies the first in-the-wild zero-day exploit for 2FA bypass developed using AI, signaling a shift in cybercriminal vulnerability discovery.
AI-Augmented Zero-Day Exploitation and Autonomous Malware Orchestration
GTIG report reveals how threat actors leverage generative AI for zero-day discovery, autonomous Android malware orchestration, and AI supply chain attacks.
LLM Text-in-Text Steganography: Emerging Covert Channel Risks
Analysis of how Large Language Models enable sophisticated text-in-text steganography for covert communication, data exfiltration, and C2 operations.
AI-Driven Exploit Development: How Adversaries Automate Attacks
Cyber adversaries are leveraging Large Language Models to accelerate exploit development and automate complex attack chains, posing new risks to cloud security.
Skoda Online Shop Data Breach: Portal Vulnerability Analysis
Skoda Auto confirms a data breach affecting online shop customers. Attackers exploited a portal vulnerability to access PII including names and addresses.
Google’s Big Sleep AI Agent Discovers Real-World SQLite Zero-Day
Google Project Zero and DeepMind’s Big Sleep agent identifies an exploitable stack-based buffer underflow in SQLite, marking a shift in AI vulnerability discovery.
CVE-2024-45785: AI-Generated Zero-Day Exploit Targets BigTree CMS
Google's Threat Intelligence Group discovered a zero-day in BigTree CMS exploited via AI-generated code. Update to version 4.4.16 to prevent remote execution.