All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
GopherWhisper APT Abuses Legitimate Services in Government Attacks
China-linked APT GopherWhisper targets Southeast Asian governments using Go-based backdoors and legitimate cloud services for stealthy C2 communications.
fast16: Uncovering the Pre-Stuxnet Lua-Based Sabotage Framework
Researchers identify fast16, a 2005-era Lua-based malware targeting high-precision engineering software for industrial sabotage predating Stuxnet.
Rethinking Threat Intelligence: Transitioning to Autonomous SOC Operations
Examine the shift from manual analysis to autonomous action by 2026. Learn how AI agents and high-fidelity data bridge the gap between intel and remediation.
CISA KEV Update: Samsung, SimpleHelp, and D-Link Flaws Exploited
CISA adds four vulnerabilities to its Known Exploited Vulnerabilities catalog, including Samsung MagicINFO 9 and D-Link DIR-823X flaws. Patching is required.
Bluetooth Tracker Exploitation: Tracking Military Assets via Mail
A recent incident involving a Dutch naval vessel highlights the operational security risks of low-cost Bluetooth trackers hidden in physical mail.
CISA KEV Catalog Adds Exploited Samsung and SimpleHelp Vulnerabilities
CISA adds four exploited flaws in SimpleHelp, Samsung MagicINFO 9, and D-Link routers to its KEV catalog, mandating remediation by May 2026.
Advertisement
US Dismantles Myanmar-Based Investment Fraud and Domain Network
US authorities charge 29 individuals and seize 500+ domains linked to a massive Myanmar-based financial fraud operation targeting US citizens.
Firestarter Malware Persists on Cisco Firewalls Post-Update
U.S. and U.K. agencies warn about Firestarter malware exhibiting post-update persistence on Cisco Firepower and Secure Firewalls running ASA/FTD.
ADT Confirms Data Breach Amid ShinyHunters Extortion Threat
ADT confirms a data breach following a ShinyHunters extortion attempt. Customer data is at risk; security professionals must advise enhanced vigilance.
FIRESTARTER Backdoor Exploits Cisco Firepower ASA Software
CISA and NCSC reveal FIRESTARTER, a persistent backdoor targeting Cisco Firepower devices running ASA software, used in federal agency compromises.
AI-Powered Phishing Surges: Defending Against Advanced Attacks
Explore the surge in AI-powered phishing, how threat actors are leveraging it for personalized attacks, and critical defensive strategies for organizations.
Beyond Code Security: Managing Your Expanding Attack Surface
Organizations often overlook security gaps in shadow IT, SaaS, and AI agents. Learn to manage an expanding attack surface beyond just secure code.
Student Data Exposed via Mythos One Systems; Lovable App Breach
Analysis of recent incidents: unauthorized access to Mythos One student management systems impacting colleges, and a data exposure event affecting Lovable dating app…
Fast16 Sabotage Malware: Precursor to State-Sponsored Cyber Warfare
Analysis of Fast16, a pre-Stuxnet sabotage malware linked to US-Iran cyber tensions, designed to tamper with high-precision calculation software results.
Zimbra XSS Attacks: Over 10,000 Servers Vulnerable — Patch Now
Ongoing cross-site scripting (XSS) attacks exploit a flaw in Zimbra Collaboration Suite (ZCS), leaving over 10,000 online servers vulnerable.
DORA Article 9: Credential Management for Financial Resilience
Understand how the EU Digital Operational Resilience Act (DORA) mandates strict identity controls and credential management for financial institutions.
Chinese Spear-Phishing Campaign Targets NASA Defense Software
NASA OIG reveals a multi-year spear-phishing campaign by a Chinese national impersonating researchers to exfiltrate sensitive U.S. defense software.
Firestarter Backdoor Infects Cisco Firewall at US Federal Agency
Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.
Microsoft Enterprise Copilot: New Uninstall Policy for Admins
Microsoft introduces a new policy setting allowing IT administrators to uninstall Copilot from enterprise devices, enhancing management and control over AI features.
26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis
Researchers discover 26 malicious apps on the Apple App Store impersonating crypto wallets to steal seed phrases via trojanized software and browser redirects.
Secure AI Agent Delegation: Bridging the Authority Gap
AI agents introduce a structural authority gap in enterprise security. Learn how continuous observability serves as a decision engine for delegation.
Ivanti EPMM RCE via CVE-2025-22514: Technical Analysis and Patching
Critical security alert for Ivanti EPMM: CVE-2025-22514 and CVE-2025-22515 allow remote command injection and file uploads. Patch to version 12.1.0.1 immediately.
UNC6692 Social Engineering: Deploying the SNOW Custom Malware Suite
UNC6692 leverages Microsoft Teams and S3-hosted payloads to deploy the SNOW modular malware ecosystem, targeting enterprise Windows environments.
Copperhelm Debuts Agentic Cloud Security Platform with $7M Seed Round
Copperhelm emerges from stealth with $7M in funding to launch an agentic cloud security platform focused on autonomous remediation and alert fatigue reduction.