All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign
A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.
LMDeploy SSRF: CVE-2026-33626 Exploit and Mitigation Guide
Attackers are actively exploiting CVE-2026-33626, a high-severity SSRF in LMDeploy, to access sensitive LLM data. Learn how to detect and patch this flaw.
Tropic Trooper APT Targets Home Routers and Japanese Infrastructure
Tropic Trooper expands operations to target Japanese entities and home routers using specialized malware like Chinoiserie to obfuscate attack origins.
Chinese State-Backed Actors Industrialize Botnets for Covert Ops
Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.
CVE-2024-52317: Critical File Upload Bug in Breeze Cache — Patch Now
Attackers are actively exploiting a critical unauthenticated file upload vulnerability (CVE-2024-52317) in the Breeze Cache WordPress plugin.
CVE-2025-65856: Authentication Bypass in Xiongmai XM530 IP Cameras
Critical authentication bypass (CVE-2025-65856) in Xiongmai XM530 IP Camera firmware allows unauthenticated remote access to video streams and sensitive data.
Advertisement
CVE-2026-3893: Unauthenticated Access in Carlson VASCO-B GNSS Receiver
Critical CVE-2026-3893 in Carlson VASCO-B GNSS Receivers <1.4.0 allows unauthenticated remote alteration of critical system functions. Update to v1.4.0+.
Trigona Ransomware: Custom Tool for Faster Data Exfiltration
Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.
Supply Chain Attack: Bitwarden CLI npm Package Compromised
Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.
UNC6692 Impersonates IT Helpdesk to Deploy SNOW Malware via Teams
UNC6692 threat actors are impersonating IT helpdesk staff via Microsoft Teams to deliver custom SNOW malware, highlighting risks in SaaS messaging apps.
Building Digital Trust: The Imperative of Cyber Threat Intelligence
Explore how cyber threat intelligence and collaboration cultivate digital trust, enabling secure innovation and proactive defense against evolving threats.
State-Sponsored Cyber Operations Targeting Critical Mineral Supply Chains
Geopolitical tensions over critical minerals fuel a rising threat of state-sponsored cyber operations targeting the global mining sector and supply chains.
FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall
CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.
Anthropic AI Agent Memory Vulnerability: Data Exposure Risks
Cisco discovered a significant memory handling vulnerability in Anthropic AI agents, risking data exposure. This highlights persistent security challenges in AI systems.
Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage
A Chinese state-sponsored APT is exploiting Microsoft Outlook, Slack, Discord, and file.io for C2, deploying PlugX and ShadowPad in espionage operations targeting…
AI in Vulnerability Discovery: 360 Digital Security Group's Claims Examined
Runtime Rebel examines 360 Digital Security Group's claims of using AI to discover over 1,000 vulnerabilities, including at Tianfu Cup, and the implications for security…
Cloudsmith Funding Boosts Software Supply Chain Security Efforts
Cloudsmith secures $72M in Series C funding to accelerate development of its software supply chain management platform, enhancing artifact security and integrity.
Rituals Cosmetics Breach: My Rituals Database PII Exposure
Rituals Cosmetics discloses a data breach affecting its My Rituals membership database. Learn about the PII exposure, risk of credential stuffing, and mitigation.
Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments
A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.
Analyzing the $290M DeFi Breach and macOS LotL Exploitation
An analysis of the $290 million DeFi protocol hack, macOS living-off-the-land techniques, and ProxySmart SIM farming operations identified in recent reports.
CVE-2024-23296: Apple Patches Actively Exploited Notification Flaw
Apple releases urgent security updates for iOS and iPadOS to address CVE-2024-23296, a memory corruption vulnerability in Notification Services seeing active use.
China-Nexus Covert Networks: Defending Against SOHO-Based Botnets
CISA and international partners warn against the strategic use of SOHO and IoT botnets by China-nexus actors to mask malicious activity and target CNI.
iPhone Notification Database Forensic Extraction: Signal Privacy Risk
FBI forensic extraction recovered deleted Signal messages from the iOS notification database. Analyze the technical risks and learn how to secure your device.
AI-Driven Cloud Attacks: The Zealot PoC and Autonomous Exploitation
Research into 'Zealot' reveals how AI-driven cloud attack simulations execute full-scale breaches faster than human defenders can effectively intervene.