All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Trellix Source Code Breach: Understanding Potential Supply Chain Risks
A deep dive into the Trellix source code repository breach, analyzing potential supply chain implications, intellectual property risks, and recommended mitigations for…
Cisco Acquires Astrix: Tackling Non-Human Identity Risks for AI & Machines
Cisco's acquisition of Astrix Security targets emerging non-human identity risks in AI and machine access, enhancing identity-centric security for cloud environments.
Backdoored PyTorch Lightning Package Drops Credential Stealer
A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials.
Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure
Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.
MOVEit Automation Critical Authentication Bypass Mitigation Guide
Progress Software has patched a critical authentication bypass in MOVEit Automation. Secure your managed file transfer workflows and sensitive data today.
VENOMOUS#HELPER Phishing Campaign Exploits SimpleHelp and ScreenConnect
VENOMOUS#HELPER phishing campaign targets over 80 organizations using SimpleHelp and ScreenConnect RMM tools for persistent unauthorized remote access.
Advertisement
DShield Honeypot Updates: Ensuring Timely Threat Data Collection
SANS ISC announces upcoming updates for DShield honeypots. Learn why these automatic updates are crucial for maintaining effective threat intelligence collection.
Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia
China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.
DigiCert Revokes Certificates After Support Portal Compromise
DigiCert is revoking TLS/SSL certificates following a breach where attackers used support chat to compromise an internal analyst's workstation and portal.
April 2026 Cybersecurity M&A Roundup: Strategic Market Consolidation
An analysis of 33 cybersecurity M&A deals from April 2026, featuring strategic moves by Palo Alto Networks, Fortra, and Airbus to consolidate the market.
Identity-Based Fraud Tactics Targeting Credit Unions
Analysis of structured loan fraud targeting credit unions through stolen identities, KYC bypass techniques, and synthetic credential exploitation.
Trellix Source Code Repository Breach Analysis and Impact
Trellix confirms a data breach following unauthorized access to source code repositories via a third-party service. Learn the impact and mitigation steps.
AI-Powered Phishing and GitHub RCE: Analyzing Modern Breach Trends
Threat actors are using AI-powered phishing and GitHub RCE to move from simple breaches to long-term occupation of SaaS and open-source environments.
Security Analysis of Prediction Market Oracle Manipulation on Polymarket
An investigation into the vulnerabilities of decentralized oracles, including physical sensor tampering and insider trading risks within Polymarket.
The Evolution of Cybersecurity Journalism: A Dark Reading Retrospective
An analysis of how Dark Reading shaped cybersecurity intelligence reporting since 2006 and the impact of editorial independence on threat awareness.
OpenAI Advanced Account Security: Mitigating AI Identity Risks
OpenAI releases Advanced Account Security features for ChatGPT, including FIDO2 support and session management to prevent unauthorized account access.
CVE-2024-1086: Copy Fail Linux Privilege Escalation Under Exploitation
CISA adds CVE-2024-1086 (Copy Fail) to its KEV catalog after Microsoft observes exploitation of this Linux Netfilter privilege escalation vulnerability.
CVE-2024-5805: MOVEit Automation Authentication Bypass Mitigation Guide
Progress Software has issued a patch for a critical authentication bypass vulnerability in MOVEit Automation, tracked as CVE-2024-5805 with a CVSS of 9.1.
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing
China-linked threat actor Silver Fox targets Russian and Indian organizations using tax-themed lures to deliver the novel ABCDoor malware via phishing waves.
AI-Assisted Attacks: Lessons from the Kaikatsu Club Data Breach
Analyze the 2025 Kaikatsu Club breach where AI-assisted malicious code allowed a teenager to steal 7 million user records, signaling a new era of cyber threats.
Instructure Data Breach: Student IDs and Private Messages Exposed
Edtech leader Instructure discloses a data breach involving student IDs and user messages after hackers disrupted services and threatened data leaks.
cPanel CVE-2026-41940 Exploitation: 40,000 Servers Compromised
Attackers leverage a zero-day vulnerability in cPanel, identified as CVE-2026-41940, to gain administrative access to over 40,000 hosting servers.
Global Law Enforcement Shuts Nine Crypto Scam Centers, Seizes $701M
International authorities arrest 276 suspects and shut down nine cryptocurrency investment fraud centers, recovering $701 million in illicit assets.
Malicious PDF Files: Analyzing AcroForm JavaScript for Initial Access
Security analysts have identified malicious PDF files utilizing AcroForm dictionaries to execute JavaScript and fetch remote payloads from external servers.