All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Defensive Strategies for Routine Workflow Weaponization
Attackers are pivoting from technical exploits to weaponizing trusted workflows. Learn how to detect and mitigate these behavioral identity-based threats.
Rilian Secures $17.5M Seed for AI-Native Security Orchestration
Rilian raises $17.5 million to scale its AI-native security orchestration platform, aiming to automate complex SOC workflows and reduce alert fatigue.
CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now
CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.
GopherWhisper APT Abuses Outlook and Slack for Stealthy C2
Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.
Anthropic Project Glasswing: The Shift to AI-Driven Zero-Day Discovery
Anthropic delays Project Glasswing after its AI model identifies critical zero-day vulnerabilities across major tech stacks, sparking a massive patching effort.
AI Impact on Vulnerability Management: Real-World Trends and Risks
Analyze how artificial intelligence impacts vulnerability research and discovery, separating industry hype from technical reality for security professionals.
Advertisement
Chinese Telegram Guarantee Marketplaces: Post-Huione Evolution
Analysis of Chinese-language Telegram marketplaces using guarantee services to facilitate money laundering and fraud following the Huione Guarantee shutdown.
CVE-2024-21412: Microsoft Defender Zero-Day Exploitation and Analysis
Analysis of a Microsoft Defender zero-day vulnerability used to extract NTLM hashes from the SAM database and achieve system-level privileges.
CVE-2026-28950: Apple Fixes iOS Notification Data Retention Flaw
Apple patches CVE-2026-28950 in iOS and iPadOS, a logging issue that allowed deleted notifications to persist on devices, impacting forensic privacy.
Critical RCE Threats: Confluence OGNL & Exchange Server Patching
Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.
CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis
CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.
The Gentlemen Ransomware Group: Rapid Escalation and Sophistication
An analysis of 'The Gentlemen' ransomware group, highlighting their rapid operational scaling and sophisticated attack methods impacting organizations globally.
iOS 17.5.1 Notification Data Retention Bug — Mitigation Guide
Apple releases iOS 17.5.1 to address a Notification Services flaw where deleted data persisted on devices due to database corruption issues.
ICE Deploys Graphite Spyware: Privacy Implications and Risks
U.S. Immigration and Customs Enforcement (ICE) uses Graphite spyware, raising privacy concerns for individuals and potential civil liberty issues.
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…
UK Cyber Chief: Russia, Iran, China Drive Top Cyber Threats
NCSC warns British businesses of escalating cyber threats from state-sponsored groups in Russia, Iran, and China, urging preparedness for potential large-scale attacks.
Mastodon DDoS Attack: Mitigating Availability Threats on Fediverse
Analysis of recent DDoS attacks targeting Mastodon and Bluesky. Understand the impact on distributed social platforms and effective mitigation strategies.
Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption
Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.
CVE-2025-29635: Mirai Exploits EoL D-Link Routers
A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks.
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.
Checkmarx KICS Docker Repository and VS Code Extension Hijacked
Unknown threat actors hijacked the checkmarx/kics Docker Hub repository, overwriting official image tags to distribute malicious code via supply chain.
Lotus Wiper Analysis: Destructive Malware Targets Venezuelan Energy
Analysis of Lotus Wiper malware shows how it targets Venezuelan energy infrastructure by overwriting disks and disabling critical system recovery mechanisms.
Microsoft Universal Print Issues Traced to Graph API Code Change
Microsoft identifies a recent Graph API code change as the root cause for ongoing Universal Print sharing issues affecting user ability to create printer shares.
Microsoft Teams Efficiency Mode: Optimizing Resource Usage for PCs
Microsoft introduces Efficiency Mode for Teams to reduce CPU and memory consumption on resource-constrained devices, improving overall system responsiveness.