Advertisement
Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits
A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker's toolkit and session cookies.
Scans Target Model Context Protocol Servers and AI Credentials
Security researchers observe an increase in scans targeting Model Context Protocol (MCP) servers and AI credentials, potentially exposing sensitive data.
GPT-5.6 Sol Usage Limits Relaxed: Analyzing OpenAI's Scaling Response
OpenAI temporarily lifts rate limits for GPT-5.6 Sol following a massive surge in demand. Explore the implications for AI infrastructure and enterprise security.
Anthropic Extends Claude Fable 5 Access: Enterprise Migration Impacts
Anthropic extends Claude Fable 5 access for paid users until July 19. Learn how this availability extension impacts enterprise AI security and infrastructure.
GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns
Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.
Balochistan Police Portal Exploited in Multi-Group Espionage Campaign
Multiple threat actors weaponize Balochistan Police infrastructure, compromising criminal records and citizen data in a multi-year espionage operation.
ACSC Warns of Global Campaign Targeting Vulnerable CMS Platforms
The ACSC warns of a global campaign targeting WordPress, Joomla, and Drupal. Learn how to identify web shells and secure your CMS against automated attacks.
AI Surveillance Systems: Analyzing the Risks of Automated Enforcement
A technical evaluation of pervasive AI-powered surveillance, automated rule enforcement via machine learning, and the security implications of integrated data.
Ghostcommit: Hidden Prompt Injection in Images Targets AI Agents
Researchers demonstrate Ghostcommit, a technique using images to hide prompt injection attacks that trick AI agents into exfiltrating repository secrets.
Healthcare Service Provider Cyberattacks Surge — Supply Chain Risk
Cyberattacks on healthcare service providers more than doubled in H1 2026, signaling a shift in targeting toward the medical supply chain and data aggregators.
Jen Ellis: Connecting Cyber Researchers to Political Machinery
A look at Jen Ellis' work bridging the gap between security researchers and policy makers, emphasizing vulnerability disclosure and researcher protections.
Ryuk Ransomware Affiliate Pleads Guilty to US Hacking Charges
A 34-year-old Armenian national faces 15 years in prison for his role in the Ryuk ransomware operation, which targeted U.S. hospitals and businesses.
Parallel APT Cyber Espionage Targets Balochistan Police
Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan's Balochistan Police, detailed by SentinelOne.
Insider Threat: Security Expert Sentenced for BlackCat/ALPHV Aid
Former ransomware negotiator Angelo Martino received a 70-month prison sentence for aiding the BlackCat/Alphv ransomware group, highlighting insider threat risks.
Cyber-Financial Crime Convergence: Proactive Payment Fraud Disruption
Explore how the convergence of cyber and financial crime fuels payment fraud. Learn about proactive strategies for pre-monetization disruption and intelligence-driven…
AI Governance Risks: Why Guardrails Are Critical for Secure Deployment
Organizations face significant risks, from data breaches to regulatory non-compliance, without robust AI governance guardrails. Learn to secure AI deployments.
AI Linguistic Convergence: Security Risks of Human-AI Speech Drift
LLMs training on scripted data creates a feedback loop where humans adopt AI speech patterns, complicating social engineering detection and authentication.
Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities
Iranian state-sponsored cyber operations are broadening targets beyond critical infrastructure. All organizations must secure Internet-facing systems.
GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts
Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.
Cyberwarfare Fallout: Global Business Cybersecurity Gameplans
Businesses globally face increased cyberwarfare risks from geopolitical conflicts. Learn how collateral damage impacts operations and why strategic wartime cybersecurity…
UK's Agentic AI Cyber Defense Plan & Industry Pledge
The UK government unveils its Agentic AI Cyber Defense Plan and an industry pledge involving 16 tech giants to bolster national security and cyber resilience.
Summer IT Coverage Gaps: Mitigating Operational Security Risks
Reduced IT staffing during summer vacations creates security blind spots and increases incident response times. Learn how to mitigate operational risks and maintain…
Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise
Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing. Learn how this sophisticated platform compromises accounts and critical mitigation…
Athena: A New Clearinghouse for Actionable Threat Intelligence
Runtime Rebel announces Athena, a operational cybersecurity clearinghouse sharing findings and fixes to enhance organizational defenses and streamline vulnerability…