All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
BRIDGE:BREAK: 22 Flaws in Lantronix and Silex Serial Converters
Forescout researchers uncover 22 BRIDGE:BREAK vulnerabilities in Lantronix and Silex serial-to-IP converters, risking device hijacking and data tampering.
Grupo Seguritech: Risks of Mexico’s Surveillance Expansion
An analysis of Grupo Seguritech's expansion into the US market, evaluating the security and privacy implications of international surveillance infrastructure.
Chinese APT Targeting Indian Banks and Korean Policy Circles
Chinese state-sponsored threat actors are conducting cyber-espionage against Indian financial institutions and South Korean policy entities using recycled TTPs.
CISA KEV Expansion: Exploit Guidance for Cisco, Kentico, and Zimbra
CISA adds 8 vulnerabilities to the KEV catalog, including critical flaws in Cisco ASA and Zimbra. Analyze technical impact and remediation requirements.
Progress MOVEit and LoadMaster Patched Against Critical RCE and Bypass
Progress Software releases critical patches for MOVEit Transfer and LoadMaster addressing RCE and authentication bypass vulnerabilities like CVE-2024-5806.
Insider Threat: Former Negotiator Pleaded Guilty to BlackCat Attacks
A former cybersecurity negotiator at DigitalMint has pleaded guilty to conducting BlackCat (ALPHV) ransomware attacks against U.S. organizations.
Advertisement
CVE-2023-46604: Apache ActiveMQ RCE Exploited by HelloKitty - Patch Now
Over 6,400 Apache ActiveMQ servers are exposed to RCE via CVE-2023-46604. Threat actors like HelloKitty are actively exploiting this high-severity flaw.
NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil
Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.
Defending Against Identity-Based Attacks and Stolen Credentials
Identity-based attacks use stolen credentials to bypass security. Learn why these attacks are the primary entry point and how to mitigate the risk.
Python Infostealer Targeting Browser Credentials and Discord Tokens
Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.
Malware Delivery via Malicious .WAV Files — Technical Analysis
Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.
CISA KEV Update: Eight New Vulnerabilities in Cisco, TeamCity, and Zimbra
CISA adds eight vulnerabilities to the KEV Catalog, including flaws in Cisco SD-WAN and JetBrains TeamCity, requiring immediate federal agency remediation.
Axios npm Supply Chain Attack: Malicious Payloads and Mitigation
Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.
CISA Adds 8 Flaws to KEV: Cisco and PaperCut Exploited in the Wild
CISA adds 8 vulnerabilities to its KEV catalog, including PaperCut and Cisco SD-WAN Manager flaws, with federal patching deadlines set for May 2026.
Satoshi Nakamoto Identity: Adam Back and Bitcoin's Origins
Explores the resurfaced speculation that Adam Back is Satoshi Nakamoto, examining the evidence and implications for Bitcoin's ethos.
OAuth Token Hijacking in AI Tools: Vercel Breach Analysis
An investigation into how stolen OAuth tokens from a Vercel employee's AI tool session led to unauthorized internal access and the risks of AI integration.
Malicious Crypto Wallets Infiltrate China's Apple App Store
26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.
KelpDAO $290 Million Heist Linked to North Korea’s Lazarus Group
KelpDAO suffers a $290 million crypto-heist attributed to the North Korean Lazarus Group, highlighting ongoing threats to DeFi liquid restaking protocols.
Securing Serial-to-IP Devices: Mitigating Thousands of OT Bugs
Industrial serial-to-IP converters are riddled with thousands of vulnerabilities, posing a significant risk to legacy infrastructure and OT environments.
CVE-2026-5760: SGLang RCE via Malicious GGUF Models - Patch Now
Critical CVE-2026-5760 command injection in SGLang allows remote code execution via GGUF files. High-performance LLM serving environments are at risk.
WhatsApp Metadata Leak: Exposure Risks and Mitigation Strategies
WhatsApp's metadata leakage allows strangers to infer limited user information without interaction, potentially aiding targeted social engineering or other malicious…
Scattered Spider Member Tyler Buchanan Pleads Guilty in US
Tyler Buchanan, a British national linked to the Scattered Spider cybercrime group, pleaded guilty in the US to charges of hacking, fraud, and cryptocurrency theft.
Beyond Backups: Essential BCDR for Ransomware & Operational Resilience
Learn why traditional data backups are insufficient for business continuity. This analysis highlights the critical role of BCDR in mitigating ransomware and outage…
Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs & Mitigations
Microsoft warns of helpdesk impersonation attacks via Teams external collaboration.