All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Claude Mythos Preview: Anthropic Limits Access to Vulnerability AI
Anthropic restricts Claude Mythos Preview access to critical infrastructure providers due to its advanced capability to exploit zero-day vulnerabilities.
DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense
Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.
Scattered Spider Arrest and ShowDoc Vulnerability Exploitation
Analysis of the arrest of a Scattered Spider member, active exploitation of ShowDoc vulnerabilities, and the introduction of the Satellite Cybersecurity Act.
CVE-2023-46604: Apache ActiveMQ RCE Exploited in the Wild
CISA warns of active exploitation for CVE-2023-46604, a critical RCE flaw in Apache ActiveMQ used by ransomware groups. Update to version 5.18.3 or later.
Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads
Google announces Android 17 privacy updates and Play policy changes after blocking 8.3 billion ads and 24.9 million fraudulent accounts throughout 2025.
Business Impersonation Fraud: Analyzing Identity Gaps in 2024
Analysis of how attackers exploit identity verification gaps to execute financial fraud and brand impersonation, from shell companies to AI-driven scams.
Advertisement
Lumma Stealer and Sectop RAT Dual Infection Chain Analysis
Technical breakdown of the Lumma Stealer and Sectop RAT (ArechClient2) infection chain, detailing C2 communication and persistence mechanisms.
PDF JavaScript Exploitation: Analysis of PowerShell Delivery
Technical analysis of malicious PDF documents using embedded JavaScript and /OpenAction triggers to execute PowerShell for initial access and C2 establishment.
CVE-2026-34197: Apache ActiveMQ Exploit Added to CISA KEV Catalog
CISA alerts organizations to the active exploitation of CVE-2026-34197 in Apache ActiveMQ. Federal agencies must patch this input validation flaw immediately.
Cursor AI RCE via Indirect Prompt Injection — Mitigation Guide
Security researchers demonstrate how indirect prompt injection in Cursor AI could lead to full shell access on developer workstations. Patch immediately.
ZionSiphon Malware Targets Israeli Water Treatment ICS
Security analysis of ZionSiphon, a backdoor malware targeting Israeli desalination and water treatment facilities via ICS vulnerabilities.
DraftKings Credential Stuffing: Memphis Man Sentenced to 30 Months
Kamerin Stokes sentenced to 30 months for selling 60,000+ hacked DraftKings accounts. Technical analysis of the 2022 credential stuffing attack and mitigations.
Windows Server Domain Controllers Hit by LSASS Reboot Loops
Microsoft confirms LSASS crashes causing persistent reboot loops on Windows Server Domain Controllers following the April 2024 security update cycle.
Operation PowerOFF Seizes 53 DDoS Domains and 3M Criminal Accounts
Operation PowerOFF disrupts DDoS-for-hire services by seizing 53 domains and exposing 3 million user accounts, marking a major blow to booter service providers.
NIST Limits NVD Enrichment Amid 263% Surge in CVE Submissions
NIST scales back enrichment of the National Vulnerability Database (NVD) due to a 263% volume increase, impacting vulnerability management workflows.
CVE-2026-5387: AVEVA Pipeline Simulation Privilege Escalation
Unauthenticated attackers can exploit CVE-2026-5387 in AVEVA Pipeline Simulation <=2025_SP1_build_7.1.9497.6351 to modify critical ICS simulation parameters and training…
Apache ActiveMQ CVE-2026-34197: CISA KEV Update & Mitigation
CISA adds high-severity CVE-2026-34197 in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog. Learn how to secure your message broker infrastructure.
Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.
Public-Private Operational Collaboration for National Cyber Defense
An analysis of why government-private sector operational collaboration is essential for defending critical infrastructure against sophisticated threat actors.
Analyzing ZionSiphon: Malware Targeting Water Treatment OT Systems
Investigate ZionSiphon malware, an OT-specific threat designed to sabotage water treatment and desalination facilities.
Operation PowerOFF: Global Takedown of 53 DDoS-for-Hire Domains
Law enforcement agencies seized 53 booter domains and identified 75,000 users in the latest phase of Operation PowerOFF targeting the DDoS-as-a-Service market.
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.
OpenAI Widens GPT-5.4-Cyber Access Following Anthropic Mythos
OpenAI expands access to GPT-5.4-Cyber, a specialized model for defensive security, following Anthropic's Mythos release to aid security analysts.
Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware
Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.