All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
PowMix Botnet Targets Czech Workers via Randomized C2 Traffic
Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.
Google Deploys Gemini AI to Combat Malvertising and Brand Fraud
Google expands the use of Gemini LLMs to detect sophisticated ad scams, blocking 5.5 billion ads and countering AI-generated brand impersonation tactics.
Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation
Analysis of recent threats including a Microsoft Defender zero-day, SonicWall brute-force campaigns, and critical RCE in legacy Microsoft Excel components.
AI-Powered Exploitation: Scaling Enterprise Defense at Machine Speed
As AI models accelerate vulnerability discovery and exploit development, enterprises must transition to automated security operations to mitigate growing risks.
Strategic Human-LLM Interaction: Research into AI Trust and Rationality
New research shows humans attribute higher rationality and cooperation to LLMs in strategic games, impacting trust in automated cybersecurity environments.
CVE-2024-36985: Splunk Enterprise RCE via File Upload - Patch Guide
Splunk patches a high-severity RCE vulnerability (CVE-2024-36985) allowing low-privileged users to execute code on Windows-based Enterprise instances.
Advertisement
Artemis AI Security Platform: Defending Against Autonomous Threats
Artemis emerges from stealth with $70M to provide AI-powered defense against autonomous threats targeting applications, cloud workloads, and user identities.
McGraw Hill Data Breach: 13.5 Million Accounts Leaked by ShinyHunters
Threat actor ShinyHunters leaks 13.5 million McGraw Hill user records following a Salesforce environment breach. Includes password hashes and PII.
Cisco Webex Services CVE-2024-20419: Manual Patch Guidance
Cisco identifies a critical improper certificate validation flaw in Webex Services. This advisory details the required manual remediation steps for admins.
REF6598 Exploits Obsidian Plugins to Deploy PHANTOMPULSE RAT
Attackers are targeting finance and crypto sectors by abusing Obsidian plugins to deliver the PHANTOMPULSE RAT via sophisticated social engineering.
Cisco Patches Critical RCE and SSO Flaws in ISE and Webex Services
Cisco releases patches for four critical vulnerabilities, including CVE-2026-20184, which allows RCE and user impersonation in Identity Services and Webex.
SVG File Phishing: How Attackers Hide Malicious JavaScript in Images
Discover how attackers use Scalable Vector Graphics (SVG) to embed malicious JavaScript for phishing and credential theft while bypassing security filters.
Germany Ransomware Surge: How SafePay and Qilin Target Mittelstand
Germany sees a 92% surge in data leaks as ransomware actors like SafePay and Qilin pivot toward the Mittelstand and professional services sectors.
6-Year Ransomware Campaign Targets Turkish SMBs: An Analysis
A persistent six-year ransomware operation has targeted Turkish home users and SMBs, exploiting under-reporting to maintain operational longevity.
Claude Code and Gemini CLI: Prompt Injection via Code Comments
Research reveals how Claude Code, Gemini CLI, and GitHub Copilot agents are vulnerable to prompt injection attacks via malicious source code comments.
Windows Server 2025 KB5082063 Update Fails to Install — Analysis
Microsoft is investigating reports of KB5082063 failing to install on Windows Server 2025, leaving systems potentially vulnerable to unpatched threats.
DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud
Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.
UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware
UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.
Optimizing Security Operations via Threat Intelligence Workflows
Explore how to integrate threat intelligence into SIEM, EDR, and IAM systems to improve security maturity and automate defensive response workflows.
Compromised DVRs: Identifying and Mitigating IoT Botnet Threats
Explore how Digital Video Recorders (DVRs) are compromised and incorporated into IoT botnets.
NGINX-UI Critical Flaw: Attackers Can Alter NGINX Configs
A critical flaw in nginx-ui allows attackers to remotely restart, create, modify, and delete NGINX configuration files, posing significant risk to web servers.
AgingFly Malware: Credential Theft Operations Against Ukraine
Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…
CVE-2024-57353: Nginx UI Auth Bypass Actively Exploited — Patch Now
Attackers are exploiting CVE-2024-57353, a critical authentication bypass in Nginx UI, to achieve full server takeover. Update to v2.0.0.beta.39 immediately.
Asia's Digital Supply Chain Security: Regulatory Differences & AI Risks
Analyzes unique security risks in Asia's digital supply chain, highlighting challenges from regulatory disparities, interconnected ecosystems, and the rise of AI.