All Articles
Security Intelligence
3410 articles · Updated every 8 hours
Advertisement
Pro-Russian Group Cyberattack on Swedish Energy Infrastructure
Sweden publicly attributes a cyberattack on a western Swedish heating plant to a pro-Russian group, highlighting critical infrastructure threats.
Signed Software Abuse: How Malicious Scripts Disable EDR and AV
Analysis of signed adware being used to deploy antivirus-killing scripts with SYSTEM privileges across government and healthcare sectors.
Abused n8n Webhooks Facilitate Automated Malware Delivery Since 2025
Threat actors are weaponizing n8n AI workflow automation webhooks to bypass email filters and distribute malware in persistent phishing campaigns.
TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud
TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.
Big Tech Compliance Failures in CA Privacy Law Opt-Out Requests
An audit reveals Google, Meta, and Microsoft frequently ignore California privacy law opt-out requests, posing significant compliance and data privacy risks.
Preparing for Q-Day: Quantum Risk Management and PQC Transition
Q-Day poses a systemic risk to current encryption. Learn why quantum risk management is vital and how to transition to NIST post-quantum algorithms now.
Advertisement
Capsule Security Launches AI Agent Runtime Protection Platform
Israeli startup Capsule Security emerges from stealth with $7 million in funding to provide real-time behavioral monitoring for autonomous AI agents.
Nginx UI CVE-2026-33032: Critical RCE Exploited in the Wild
Exploitation of CVE-2026-33032 in the Nginx UI management tool allows for remote takeover. Learn how to detect and mitigate this critical security threat.
CVE-2022-21882: CISA Warns of Windows Task Host Exploit in the Wild
CISA adds CVE-2022-21882 to the KEV catalog. Learn how to mitigate this Windows Task Host privilege escalation vulnerability affecting Win32k.sys.
Microsoft Awards $2.3M for Cloud and AI Vulnerabilities at Zero Day Quest
Microsoft pays $2.3 million for nearly 700 vulnerability submissions targeting Azure, Microsoft 365, and AI services during the Zero Day Quest event.
SAP CVE-2026-27681: Critical SQL Injection Vulnerability Patch Guidance
April Patch Tuesday addresses a critical 9.9 CVSS SQL injection vulnerability in SAP Business Warehouse and updates for Microsoft, Adobe, and Fortinet.
CVE-2026-33032: Critical nginx-ui Authentication Bypass Under Attack
Threat actors are exploiting CVE-2026-33032, a critical authentication bypass in nginx-ui (MCPwn), allowing full server takeover and Nginx configuration control.
Defense in Depth: Architectural Lessons from the Theodosian Walls
Analysis of the multi-layered defensive strategy of the Theodosian Walls and how historical security principles apply to modern enterprise architecture.
Microsoft and Salesforce Patch Prompt Injection Flaws in AI Agents
Researchers identified prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce that could allow attackers to exfiltrate sensitive data.
Ivanti Neurons for ITSM Patches CVE-2024-45504 and CVE-2024-45505
Ivanti addresses two high-severity flaws in Neurons for ITSM, CVE-2024-45504 and CVE-2024-45505, preventing session persistence and cross-user data exposure.
Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse
Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.
Microsoft Resolves Windows Server 2025 Automatic Upgrade Bug
Microsoft has addressed a critical deployment bug where Windows Server 2019 and 2022 systems were unexpectedly upgraded to Windows Server 2025 via KB5044284.
Windows Update Triggers BitLocker Recovery: Mitigation and Analysis
Microsoft confirms April security updates cause unexpected BitLocker recovery prompts on Windows Servers. Learn how to resolve the boot issues and recover keys.
SharePoint Zero-Day Fixed in Microsoft April 2026 Security Updates
Microsoft addresses 169 vulnerabilities, including an actively exploited SharePoint zero-day. Learn how to secure your environment against these flaws.
CVE-2024-21762 and Ivanti Flaws: Edge Gateway Scanning Escalates
Technical analysis of ongoing scanning activity targeting Ivanti and Fortinet SSL-VPN gateways. Learn to detect exploits and apply critical mitigations.
ICS Patch Tuesday: 8 Industrial Giants Patch Critical Vulnerabilities
Analysis of new security advisories from Siemens, Schneider Electric, and others regarding critical infrastructure vulnerabilities and remediation steps.
OpenAI GPT-5.4-Cyber: Defensive AI for Security Teams
OpenAI unveils GPT-5.4-Cyber, a model optimized for defensive security. Learn how it assists SOC teams in threat detection and vulnerability remediation.
Microsoft $10B Investment: Advancing Japan's AI and Cybersecurity
Microsoft commits $10 billion to Japan for AI infrastructure and cybersecurity, focusing on sovereign AI requirements and national digital resilience.
Navigating the Future Threat Landscape with Integrated Intelligence
Discover how integrated threat intelligence solutions are evolving to help security professionals proactively defend against the complex 2026 cyber threat landscape.