All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
OpenEMR Flaws: Database Compromise, RCE, and Patient Data Theft Risks
Analysis of 38 security flaws in OpenEMR, an EHR platform used by over 100,000 healthcare providers, enabling database compromise, RCE, and data theft.
GitHub High-Severity Bug Discovered via AI Reverse Engineering
Wiz utilized AI reverse-engineering to uncover a high-severity vulnerability within GitHub, demonstrating advanced discovery methods for complex bugs.
Roblox Account Hijacking: 610,000 Accounts Compromised and Sold
Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.
LiteLLM Proxy Data Exposure & Modification — Urgent Patch Required
Critical vulnerability in LiteLLM proxy enables unauthorized database read/modify access. Exploitation observed shortly after disclosure. Patch immediately.
European Police Dismantle €50 Million Crypto Investment Fraud Ring
Authorities in Austria and Albania shut down a massive crypto investment scam involving fraudulent call centers and over €50 million in victim losses.
CVE-2020-27686: cPanel and WHM 2FA Authentication Bypass Mitigation
Administrators must patch cPanel and WHM immediately to address a critical 2FA bypass vulnerability that allows attackers to brute-force security codes.
Advertisement
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.
Firefox 150 Patch: 271 Zero-Days Found via Claude Mythos — Update Now
Firefox 150 addresses 271 vulnerabilities discovered by Anthropic’s Claude Mythos AI model, highlighting a shift in automated vulnerability discovery.
Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed
Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.
Internet-Facing VNC and RDP Expose ICS/OT Systems — Remediation Guide
Forescout research identifies hundreds of exposed VNC servers in critical sectors, posing severe risks to global industrial control systems and OT environments.
Windows Kernel LPE CVE-2024-21338: Lazarus Group Exploits Zero-Day
CISA adds CVE-2024-21338 to KEV catalog after Lazarus Group exploited the Windows Kernel vulnerability to deploy rootkits and bypass security controls.
cPanel Authentication Bypass: Patch Guidance for Versions 11.132.0.29
cPanel releases critical updates to address an authentication bypass vulnerability affecting all supported versions. Administrators should patch immediately.
Optimizing Exposure Management: Beyond CVSS and Patch Fatigue
A technical analysis of Continuous Threat Exposure Management (CTEM) and why modern security teams must prioritize vulnerabilities based on business risk.
Detecting and Mitigating Money Mule Accounts to Prevent APP Fraud
Learn how intelligence-driven mule account detection disrupts the fraud ecosystem and prevents Authorized Push Payment losses before funds are exfiltrated.
CVE-2024-24919: Exploit Analysis and Check Point Gateway Mitigation
Technical analysis of CVE-2024-24919, a critical information disclosure vulnerability in Check Point Security Gateways exploited for credential harvesting.
CVE-2024-1708 & CVE-2026-32202: CISA KEV Update — Patch Now
CISA adds CVE-2024-1708 and CVE-2026-32202 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in the wild.
NSA GRASSMARLIN XXE Vulnerability CVE-2026-6807 — Mitigation Guide
CISA warns of a Medium-severity XXE vulnerability in NSA GRASSMARLIN. With the tool reaching end-of-life, defenders must address CVE-2026-6807 via decommissioning.
NSA Insider Threat Lessons: Chris Inglis on Post-Snowden Security
Former NSA Deputy Director Chris Inglis reflects on the Snowden leaks, offering critical insights for CISOs on insider threat detection and enculturation.
BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware
BlueNoroff leverages AI avatars and stolen video to compromise crypto executives via fake Zoom calls and the Hidden Risk macOS malware family.
GitHub Enterprise Server RCE via CVE-2024-6800 — Mitigation Guide
GitHub has patched a critical RCE vulnerability (CVE-2024-6800) in GHES that allows remote attackers to gain administrative access via SAML SSO bypass.
Microsoft Teams Free Backend Change Disrupts Chat and Calling
Microsoft confirms a backend configuration change has broken core functionality for Microsoft Teams Free users, impacting global business communication.
CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection
Attackers are actively exploiting CVE-2026-42208, a critical SQL injection flaw in LiteLLM, within 36 hours of disclosure. Patch to prevent database compromise.
Quantifying Cyber Risk: CISO Budgeting with Insurance Data
CISOs now have powerful data from cyber insurance policies to quantify cyber risk, demonstrate ROI, and justify critical security investments to boards.