All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Polish Water ICS Breaches: Attackers Alter Operational Parameters
Poland's ABW reports unauthorized access to five water treatment plants where attackers gained control over operational parameters, risking public safety.
Zara Data Breach: 197,000 Customer Records Leaked on Hacking Forum
Spanish fashion retailer Zara suffers a significant data breach exposing PII for 197,000 customers, fueling concerns over targeted phishing and identity theft.
Ivanti EPMM CVE-2023-35078 Zero-Day: Urgent CISA Patch Directive
CISA orders federal agencies to patch Ivanti EPMM CVE-2023-35078 within four days following active zero-day exploitation against government networks.
One Missed Threat Per Week: The Risk of Ignoring Low-Severity Alerts
Analysis of 25 million security alerts reveals that ignoring low-severity telemetry causes enterprise SOC teams to miss one significant threat every week.
Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks
A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.
Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215
Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.
Advertisement
Linux Kernel Dirty Frag: CVE-2024-26610 LPE Vulnerability Analysis
Technical analysis of the Dirty Frag Linux kernel vulnerability (CVE-2024-26610), exploring its impact on IPv4 fragmentation and mitigation strategies.
CVE-2026-6411: MAXHUB Pivot Client Hardcoded AES Key — Patch Guide
Exploit analysis of CVE-2026-6411 in MAXHUB Pivot client. Learn how hardcoded AES keys and MQTT enrollment flaws lead to data disclosure and DoS.
Tom Parker Rumored as Next CISA Director: Operational Impact Analysis
Analysis of the potential CISA leadership transition to Tom Parker and how an operational focus may reshape national cybersecurity and incident response.
PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery
PCPJack malware replaces TeamPCP, utilizing Apache Parquet files for stealthy cloud secret theft across multiple service providers and environments.
RansomHouse Claims Trellix Breach: Internal Data Leak Analysis
The RansomHouse extortion group claims to have breached Trellix internal systems. Analyze the potential impact of this security vendor compromise and mitigation steps.
PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments
PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.
Dirty Frag: Linux Kernel Zero-Day Enables Local Privilege Escalation
The Dirty Frag zero-day vulnerability allows local attackers to gain root access on major Linux distributions via an exploit in kernel fragmentation handling.
"Dirty Frag" Linux Kernel LPE: Unpatched Root Access Risk
An unpatched Linux kernel vulnerability dubbed Dirty Frag allows local privilege escalation to root, building on the exploitation patterns of CVE-2026-31431.
Canvas Platform Breach: Extortion Threatens 275M Student Data
A cybercrime group's data extortion attack on the Canvas education platform disrupted services and threatens to leak data from 275 million students and faculty.
TCLBanker Malware Targets Fintech via WhatsApp and Outlook
TCLBanker malware uses trojanized Logitech AI installers to target 59 banking apps and spreads automatically via WhatsApp and Outlook messages.
ShinyHunters Defaces Canvas Login Portals in Extortion Campaign
ShinyHunters breached Instructure, defacing Canvas login portals for numerous educational institutions, potentially impacting user credentials and initiating extortion.
AI Safety Debates Emerge From OpenAI Legal Clash
The legal dispute involving Elon Musk and OpenAI leaders spotlights critical discussions on AI's risks to humanity and the imperative for robust governance.
ClickFix Attacks Distribute Vidar Stealer: ACSC Warning & Mitigation
The ACSC warns Australian organizations of active ClickFix social engineering attacks deploying Vidar Stealer malware, risking data theft. Learn detection and mitigation.
PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access
New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.
PCPJack Credential Stealer: Cloud System Exploitation & Spread
PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…
Ivanti EPMM RCE via CVE-2026-6973 — Mitigation Guide
Ivanti warns of active exploitation of CVE-2026-6973, a high-severity RCE flaw in Endpoint Manager Mobile (EPMM) allowing admin-level access on core servers.
Harvest Now, Decrypt Later (HNDL): Quantum Risk for Long-Lived Data
Understand the 'Harvest Now, Decrypt Later' (HNDL) threat model, where adversaries collect encrypted data today to decrypt with future quantum computers.
CVE-2026-6973: Ivanti EPMM Exploited in the Wild — Patch Guidance
CISA adds CVE-2026-6973, an improper input validation vulnerability in Ivanti Endpoint Manager Mobile, to the KEV catalog following active exploitation.