All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Moltbook Data Exposure: 1.5M AI Agent API Tokens Leaked
Moltbook database exposure revealed 1.5 million API tokens and plaintext OpenAI keys, highlighting risks of third-party credential sharing in AI agents.
Lotus Wiper Malware Targets Venezuelan Energy Sector
Kaspersky researchers uncover Lotus Wiper, a destructive malware targeting Venezuelan energy and utility systems via malicious batch scripts.
Security Risks of Agentic AI in Enterprise Ecosystems
Analysis of security risks in Agentic AI adoption, focusing on prompt injection, autonomous execution, and enterprise mitigation strategies.
Telegram tdata Credential Harvesting: Risks and Mitigation Strategies
Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.
Redis RCE via CONFIG Command Abuse: Detection and Mitigation
Learn how attackers exploit exposed Redis instances using the CONFIG command to achieve RCE and the specific steps required to secure your infrastructure.
CVE-2026-27668: Privilege Escalation in Siemens RUGGEDCOM CROSSBOW
Authenticated User Administrators can escalate privileges in Siemens RUGGEDCOM CROSSBOW SAM-P versions prior to 5.8. Update to mitigate CVE-2026-27668 risks.
Advertisement
Silex SD-330AC and AMC Manager RCE via CVE-2026-32956 — Patch Now
Silex Technology devices face critical RCE and DoS risks via 13 vulnerabilities. Critical infrastructure defenders must update to firmware Ver 1.50 immediately.
Microsoft Defender Binaries Exploited as Attack Tools
Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.
Oracle April 2026 CPU: 481 Patches for Unauthenticated Flaws
Oracle's April 2026 Critical Patch Update addresses 481 vulnerabilities across 28 product families, including 300+ unauthenticated remote exploits.
CVE-2024-38094: 1,300+ SharePoint Servers At Risk of RCE
Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2024-38094, a critical RCE vulnerability actively exploited by threat actors.
CVE-2023-38171: ASP.NET Core Privilege Escalation — Mitigation Guide
Microsoft issues emergency OOB security updates for a critical ASP.NET Core privilege escalation flaw. Learn how to patch affected systems now.
CVE-2026-5752: Root RCE and Sandbox Escape in Cohere AI Terrarium
CVE-2026-5752 is a critical CVSS 9.3 flaw in Cohere AI's Terrarium sandbox allowing root-level code execution and container escape via prototype traversal.
Mustang Panda Targets Indian Banks with New LOTUSLITE Variant
Mustang Panda deploys a new LOTUSLITE malware variant against Indian financial institutions and South Korean policy entities for cyber espionage operations.
BlackCat Ransomware Negotiator Scheme: Insider Threat Implications
A ransomware negotiator's guilty plea in a BlackCat scheme highlights critical insider threat risks and the importance of stringent controls in ransom payment processes.
Scattered Spider Member Tylerb Pleads Guilty: Smishing Analysis
Tyler Robert Buchanan's guilty plea exposes Scattered Spider smishing tactics that compromised 12+ tech firms and stole millions in cryptocurrency.
France Titres Data Breach: Identity Documents Stolen by L33T Hacker
France Titres confirms a data breach after threat actor L33T claims to have stolen 400,000 files, including identity document scans and personal citizen data.
Malicious Crypto Apps on Apple App Store Target Private Keys
Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to…
Security Expert Aids BlackCat Ransomware, Exposing IR Risks
A US security expert pleaded guilty to collaborating with the BlackCat ransomware group, leveraging his negotiation role.
Lotus Data Wiper Targets Venezuelan Energy Utilities
Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.
SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware
Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.
Google Antigravity RCE via Prompt Injection — Mitigation Guide
Google patched a critical RCE flaw in its AI-based Antigravity tool, stemming from a prompt injection vulnerability allowing sandbox escape and arbitrary code execution.
Ofcom Probes Telegram and Chat Sites Over Online Safety Act Compliance
The UK's Ofcom investigates Telegram, Monkey, and Yubo regarding CSAM sharing concerns and potential violations of the Online Safety Act regulatory framework.
Multi-Signal Fraud Prevention for the Customer Journey
Protect digital platforms from account takeover and payment fraud. This guide covers how identity, device, and network signals improve security without friction.
Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks
Angelo Martino pleaded guilty to collaborating with BlackCat (ALPHV) ransomware operators, facilitating credential-based breaches and high-stakes negotiations.