All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Operationalizing Purple Teaming: Automating Red and Blue Workflows
An analysis of how manual processes and bureaucratic friction undermine purple teaming, and strategies for better technical integration between security teams.
CVE-2026-43284: 'Dirty Frag' Linux Vulnerability Exploited — Patch Now
Analysis of the 'Dirty Frag' (Copy Fail 2) Linux kernel vulnerabilities CVE-2026-43284 and CVE-2026-43500, which enable potential remote code execution.
Canvas LMS Cyberattack: Thousands of Schools Face Service Disruption
Canvas LMS restores services after a significant cyberattack disrupted online learning for thousands of students globally during critical exam periods.
TrickMo Android Trojan Uses TON Blockchain for Covert C2
TrickMo Android banking malware adopts The Open Network (TON) blockchain for decentralized C2, targeting European users via accessibility service abuse.
Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer
A malicious Hugging Face repository impersonating OpenAI's privacy tool reached 244k downloads, delivering a Rust-based information stealer to Windows users.
PyPI Supply Chain Threat: Deceptive Packages Target Developers
Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.
Advertisement
YoroTrooper Campaign Hits 500+ Orgs: Espionage and Malware Tactics
Analysis of the multi-year YoroTrooper phishing campaign targeting critical infrastructure, aviation, and government sectors with custom malware stealers.
YARA-X 1.16.0 Release: Performance Gains for Malware Detection
YARA-X 1.16.0 introduces key improvements and bugfixes for the Rust-based pattern matching engine. Explore how these updates optimize malware detection.
Claude.ai Malvertising: How Attackers Abuse Shared Chats for macOS Malware
Threat actors are leveraging Google Ads and legitimate Claude.ai shared chats to distribute macOS infostealers, effectively bypassing traditional web filters.
Crimenetwork Marketplace Takedown: Impact on Underground Cybercrime
German authorities dismantled the Crimenetwork marketplace reboot, arresting its operator and seizing infrastructure used for global illicit digital trade.
CVE-2026-7482: Bleeding Llama Memory Leak in Ollama — Patch Now
Remote attackers can exploit CVE-2026-7482 in Ollama to leak process memory. Protect your AI infrastructure from the Bleeding Llama vulnerability impact.
JDownloader Site Compromise: Python RAT Distribution Analysis
Attackers compromised JDownloader's site to distribute malicious installers containing a Python-based RAT. Learn how to detect and mitigate this threat.
Fake OpenAI Hugging Face Repository Distributes Infostealer Malware
Attackers leveraged a fraudulent OpenAI repository on Hugging Face to distribute infostealers. Learn to detect and mitigate these AI supply chain threats.
cPanel/WHM Security Update: Mitigating CVE-2026-29201 Risks
cPanel and WHM release patches for three vulnerabilities, including CVE-2026-29201, which allows for privilege escalation and remote code execution.
ShinyHunters Claims Second Attack Against Instructure: PII at Risk
The threat actor ShinyHunters has launched a second attack against Instructure, putting the PII of hundreds of millions of EdTech users at immediate risk.
Evolution of Cyber Threats: Lessons from Cybersecurity History
Explore the comprehensive history of cybersecurity, from early viruses to modern AI-powered threats, and understand the evolution of defense strategies.
CVE-2026-42208: BerriAI LiteLLM SQLi Exploitation — Patch Now
CISA adds CVE-2026-42208, a critical SQL injection vulnerability in BerriAI LiteLLM, to KEV catalog. Active exploitation confirmed.
Polymarket: Insider Betting & Geopolitical Information Risk
An analysis by the Anti-Corruption Data Collective highlights rampant insider betting on Polymarket's military and political markets, posing significant geopolitical…
TCLBANKER Malware: Brazilian Trojan Spreads via WhatsApp and Outlook
TCLBANKER (REF3076) targets 59 financial platforms using the SORVEPOTEL worm. Learn how to detect and mitigate this evolving Brazilian banking trojan.
PamDOORa Backdoor and Windows Phone Link OTP Theft Analysis
Recent intelligence highlights the PamDOORa Linux backdoor and malware leveraging Windows Phone Link to bypass OTP-based authentication mechanisms.
AI-Driven SOC Workflows: Why Scaling Analysts Fails to Solve Alert Fatigue
Examine why hiring more analysts cannot solve SOC alert fatigue and how AI-driven threat investigation workflows are necessary to reduce MTTR effectively.
NVIDIA GeForce NOW Data Breach Impacts Armenian Users via GFN.AM
NVIDIA confirms a data breach affecting GeForce NOW users in Armenia via partner GFN.AM, exposing emails and partial payment data. Learn how to respond.
7.3M Downloads: Analyzing Fraudulent Android Call History Apps
Researchers discover 28 fraudulent Android apps on the Google Play Store that trick millions of users into expensive, fraudulent subscriptions.
Braintrust AWS Breach: Immediate AI Provider API Key Rotation Required
Braintrust prompts users to rotate API keys after unauthorized AWS account access compromised AI provider secrets. Learn about the impact and mitigation.