Intelligence Reports

Expert threat analysis, incident breakdowns, and security guidance for practitioners.

Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
REPORT // 001

Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes

Microsoft's July 2026 Patch Tuesday shattered every previous record, delivering fixes for 622 unique CVEs — including three zero-days, two of them under active exploitation — and more than 60 critical

Access Report
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
REPORT // 002

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

Microsoft has shipped its July 2026 Patch Tuesday updates, closing a record-setting 570 security flaws across its product line — the largest monthly batch the company has ever released. The rollup inc

Access Report
Armored Likho APT Targeting Government, Electric Power Entities
REPORT // 003

Armored Likho APT Targeting Government, Electric Power Entities

Kaspersky has detailed a newly identified advanced persistent threat group it calls Armored Likho, which is running a mix of financially motivated and espionage operations against government bodies, e

Access Report
Accenture admits to 'isolated matter' after crook tries to flog alleged 35GB haul
REPORT // 004

Accenture admits to 'isolated matter' after crook tries to flog alleged 35GB haul

Accenture has acknowledged what it calls an "isolated matter" after a criminal advertised roughly 35GB of data allegedly lifted from the consulting firm's internal systems — a trove said to include so

Access Report
Microsoft patches RoguePlanet Defender zero-day vulnerability
REPORT // 005

Microsoft patches RoguePlanet Defender zero-day vulnerability

Microsoft has shipped a fix for a Microsoft Defender zero-day dubbed "RoguePlanet," tracked as [CVE-2026-50656](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656), which lets a loc

Access Report
Agentic AI Used to Conduct Ransomware Attack via Langflow
REPORT // 006

Agentic AI Used to Conduct Ransomware Attack via Langflow

Cloud security firm Sysdig has documented what it describes as the first fully agentic, AI-driven ransomware operation: a threat actor tracked as JadePuffer used a large language model to autonomously

Access Report
Hackers target misconfigured proxies to access paid LLM services
REPORT // 007

Hackers target misconfigured proxies to access paid LLM services

Attackers are scanning the internet for badly configured proxy servers that expose access to commercial large language model (LLM) platforms, according to threat intelligence firm GreyNoise. Since lat

Access Report
Dormant Iran APT is Still Alive, Spying on Dissidents
REPORT // 008

Dormant Iran APT is Still Alive, Spying on Dissidents

Iran's oldest known state-aligned hacking crew — tracked as "Prince of Persia" or "Infy" — never actually disappeared. After roughly three years of public silence, SafeBreach researcher Tomer Bar repo

Access Report
Anonymous researcher drops 0-day 'exploitarium' repo
REPORT // 009

Anonymous researcher drops 0-day 'exploitarium' repo

An anonymous researcher operating under the handle "bikini" published what they describe as working exploit code for zero-day flaws spanning 15 software products and open source projects, dropping the

Access Report
Russia's 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
REPORT // 010

Russia's 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

Russia's long-running Gamaredon cyber-espionage group — also tracked as Aqua Blizzard, Armageddon, and BlueAlpha — has substantially modernized its toolkit and command-and-control (C2) practices, acco

Access Report
Tata Electronics confirms cyberattack as hackers leak data
REPORT // 011

Tata Electronics confirms cyberattack as hackers leak data

Tata Electronics, the semiconductor and electronics manufacturing arm of India's Tata Group, has confirmed it was hit by a cyberattack that affected portions of its IT infrastructure. The company says

Access Report
Microsoft uses AI to link two malware operations in racketeering suit
REPORT // 012

Microsoft uses AI to link two malware operations in racketeering suit

Microsoft, working alongside international law enforcement and several security firms, has dismantled the infrastructure behind two prolific information-stealing and loader malware families, StealC an

Access Report
Europe Evolves Into Ransomware's Favorite Region
REPORT // 013

Europe Evolves Into Ransomware's Favorite Region

Ransomware operators are increasingly turning their attention to Europe. Security firm Black Kite logged 684 ransomware attacks across the continent in the first four months of 2026 — a 55% jump over

Access Report
Microsoft working on Defender patch for RoguePlanet zero-day
REPORT // 014

Microsoft working on Defender patch for RoguePlanet zero-day

Microsoft has acknowledged a zero-day elevation-of-privilege flaw in Microsoft Defender, publicly nicknamed "RoguePlanet," and says it is building a security update to fix it. Now tracked as CVE-2026-

Access Report
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
REPORT // 015

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

A researcher operating under the handle Nightmare Eclipse has published a proof-of-concept exploit dubbed "RoguePlanet" that abuses a race condition in Microsoft Defender to launch a SYSTEM-level comm

Access Report
6-Year Ransomware Campaign Targets Turkish Homes & SMBs
REPORT // 016

6-Year Ransomware Campaign Targets Turkish Homes & SMBs

A newly published report from Acronis describes a ransomware operation that has likely been running since at least 2020, targeting home users and small or medium-sized businesses (SMBs) across Turkey.

Access Report
ServiceNow discloses security incident exposing customer data
REPORT // 017

ServiceNow discloses security incident exposing customer data

ServiceNow has notified customers of a security incident in which a flaw in a vulnerable API endpoint allowed unauthenticated access to data inside hosted customer instances. The company says it pushe

Access Report
Microsoft patches Exchange Server zero-day exploited in attacks
REPORT // 018

Microsoft patches Exchange Server zero-day exploited in attacks

Microsoft has shipped a fix for an actively exploited Exchange Server flaw that lets attackers run arbitrary JavaScript in the browsers of Outlook Web Access users. Tracked as CVE-2026-42897, the high

Access Report
Max-Severity Ivanti Sentry Flaw Exploited Within 24 Hours
REPORT // 019

Max-Severity Ivanti Sentry Flaw Exploited Within 24 Hours

A maximum-severity flaw in Ivanti Sentry was being exploited in the wild within a day of becoming public, with attackers leaning on a freely available proof-of-concept to break in. Tracked as CVE-2026

Access Report
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
REPORT // 020

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

Google says a critical flaw in Oracle's PeopleSoft software has been exploited as a zero-day by the cybercrime group ShinyHunters to steal data from organizations, with the education sector bearing th

Access Report
New Windows Zero-Day Exploit 'RoguePlanet' Released
REPORT // 021

New Windows Zero-Day Exploit 'RoguePlanet' Released

A security researcher operating under the handle Nightmare Eclipse (also known as Chaotic Eclipse) has published a fresh proof-of-concept exploit for an unpatched Windows flaw, arriving just after Mic

Access Report
ChatGPT falls to new data-pilfering attack as a vicious cycle in AI continues
REPORT // 022

ChatGPT falls to new data-pilfering attack as a vicious cycle in AI continues

Radware's ZombieAgent attack revives its ShadowLeak technique against ChatGPT, bypassing OpenAI's fix to exfiltrate user data one character at a time — another reminder that indirect prompt injection remains unsolved.

Access Report
Nation-State Hackers Put Defense Industrial Base Under Siege
REPORT // 023

Nation-State Hackers Put Defense Industrial Base Under Siege

Google and Recorded Future report that China-, Russia-, and other state-linked groups burned at least two dozen edge-device zero-days in a year to pre-position inside defense industrial base networks for persistent access.

Access Report
Foxconn Ransomware Attack Shows Nothing Is Safe Forever
REPORT // 024

Foxconn Ransomware Attack Shows Nothing Is Safe Forever

The Nitrogen ransomware group claims it stole 8TB of data from Foxconn, including material tied to Dell, Google, Apple, and Nvidia. Foxconn confirmed a cyberattack on North American factories that are now resuming production.

Access Report
Dutch data watchdog caught up in Ivanti zero-day attacks
REPORT // 025

Dutch data watchdog caught up in Ivanti zero-day attacks

The Dutch Data Protection Authority confirmed it was breached through Ivanti EPMM zero-days (CVE-2026-1281, CVE-2026-1340) in a January 29 attack that also exposed staff data at the Council for the Judiciary.

Access Report
Iranian cyber espionage disguised as a Chaos Ransomware attack
REPORT // 026

Iranian cyber espionage disguised as a Chaos Ransomware attack

Rapid7 attributes a fake Chaos ransomware intrusion to Iran's MuddyWater APT — a false-flag espionage operation that used Microsoft Teams social engineering, credential theft, and data exfiltration without ever encrypting files.

Access Report
Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks
REPORT // 027

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks

Check Point warns that CVE-2026-50751 (CVSS 9.3), an authentication-bypass zero-day in its VPN and firewall gateways, has been exploited since May 7, including by a Qilin ransomware affiliate. Hotfixes and IoCs are available.

Access Report
CISA orders feds to patch Windows flaw exploited as zero-day
REPORT // 028

CISA orders feds to patch Windows flaw exploited as zero-day

CISA has ordered federal agencies to patch CVE-2026-32202, a zero-click NTLM hash-leak Windows zero-day that Akamai found lingering after an incomplete fix for the APT28-linked CVE-2026-21510.

Access Report
Microsoft's Patch Tuesday Starts 2026 With a Bang — & a Zero-Day
REPORT // 029

Microsoft's Patch Tuesday Starts 2026 With a Bang — & a Zero-Day

Microsoft's first Patch Tuesday of 2026 addresses 112 CVEs, led by an actively exploited Desktop Window Manager zero-day (CVE-2026-20805) and including NTFS remote-code-execution and VBS Enclave privilege-escalation flaws.

Access Report
CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day
REPORT // 030

CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day

Microsoft confirmed active in-the-wild exploitation of CVE-2026-42897 (CVSS 8.1), a cross-site scripting zero-day in Exchange Server's Outlook Web Access. With no patch yet, admins are urged to apply temporary mitigations immediately.

Access Report
Apple discloses first actively exploited zero-day of 2026
REPORT // 031

Apple discloses first actively exploited zero-day of 2026

Apple patched CVE-2026-20700, a memory-corruption zero-day in the dyld component of iPhones and iPads that was already used in sophisticated targeted attacks. CISA added it to its KEV catalog; fixes ship in iOS and iPadOS 26.3.

Access Report
Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group
REPORT // 032

Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group

Google and Mandiant say China-linked UNC6201 abused a critical hardcoded-credential zero-day (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since mid-2024, deploying the GrimBolt and BrickStorm backdoors.

Access Report
Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home
REPORT // 033

Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home

Researchers used a poisoned Google Calendar invite to hijack Gemini and control a smart home — among 14 indirect prompt-injection attacks shown at Black Hat. Google says it has shipped fixes.

Access Report
Google says criminals used AI-built zero-day in planned mass hack spree
REPORT // 034

Google says criminals used AI-built zero-day in planned mass hack spree

Google's Threat Intelligence Group says criminals used AI to discover and weaponize a 2FA-bypass zero-day for a planned mass-hacking campaign, in what it calls the first confirmed real-world case.

Access Report
Iran-linked hackers disrupt operations at US critical infrastructure sites
REPORT // 035

Iran-linked hackers disrupt operations at US critical infrastructure sites

Six federal agencies warn that Iran-linked hackers are disrupting programmable logic controllers at US water, energy, and government sites, exploiting internet-exposed Rockwell/Allen-Bradley devices.

Access Report
Feds quash widespread Russia-backed espionage network spanning 18,000 devices
REPORT // 036

Feds quash widespread Russia-backed espionage network spanning 18,000 devices

Russia's APT28 hijacked more than 18,000 routers across 120+ countries for espionage before an FBI-led operation dismantled the DNS-hijacking network, officials and researchers said.

Access Report
Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files
REPORT // 037

Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files

Foxconn confirmed a cyberattack on its North American factories after the Nitrogen ransomware gang claimed to have stolen 8 TB of data, including files tied to Intel, Apple, Google, Dell, and Nvidia.

Access Report
The Canvas Hack Is a New Kind of Ransomware Debacle
REPORT // 038

The Canvas Hack Is a New Kind of Ransomware Debacle

A breach and extortion attempt by ShinyHunters forced Instructure to put Canvas in maintenance mode during US finals week, disrupting thousands of schools and exposing student data.

Access Report
Chaos erupts as cyberattack disrupts learning platform Canvas amid finals
REPORT // 039

Chaos erupts as cyberattack disrupts learning platform Canvas amid finals

A cyberattack knocked the Canvas learning platform offline during US finals week. Instructure linked it to a breach claimed by ShinyHunters, exposing names, emails, student IDs, and messages.

Access Report
Microsoft warns of new Defender zero-days exploited in attacks
REPORT // 040

Microsoft warns of new Defender zero-days exploited in attacks

Microsoft is patching two actively exploited Defender zero-days — RedSun (CVE-2026-41091, SYSTEM escalation) and UnDefend (CVE-2026-45498, which blocks definition updates). CISA ordered agencies to fix them by June 3.

Access Report
With Complex Cloud Services, Small Errors Lead to Compromises
REPORT // 041

With Complex Cloud Services, Small Errors Lead to Compromises

Token Security showed how an over-permissioned role and lingering secrets in Zapier's AWS Lambda sandbox could chain into a near-total takeover, reaching private repos and an NPM publishing token.

Access Report
Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
REPORT // 042

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

Attackers have exploited a patched SQL injection flaw (CVE-2026-26980) in the Ghost CMS to compromise more than 700 websites — including DuckDuckGo, Harvard, and Oxford — injecting ClickFix malware, per Qianxin.

Access Report
Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
REPORT // 043

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Mandiant says attackers exploited a hardcoded-machineKey zero-day (CVE-2026-5426) in the KnowledgeDeliver LMS, using ViewState deserialization to deploy Godzilla web shells and a Cobalt Strike backdoor.

Access Report
ThreatsDay: Microsoft Edge Stores Passwords in Plaintext, ICS Zero-Days, and Shortened Patch Deadlines
REPORT // 044

ThreatsDay: Microsoft Edge Stores Passwords in Plaintext, ICS Zero-Days, and Shortened Patch Deadlines

This week's threat intelligence roundup covers Microsoft Edge's plaintext password exposure in process memory, new industrial control system zero-days, and US officials considering dramatically shorte

Access Report
2026: The Year AI-Assisted Attacks Went Mainstream
REPORT // 045

2026: The Year AI-Assisted Attacks Went Mainstream

2026 has become a watershed year for AI-enabled cyberattacks. What was once theoretical — AI discovering vulnerabilities, generating exploits, and automating full attack chains — is now a documented r

Access Report
China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists
REPORT // 046

China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists

Cybersecurity researchers have disclosed a broad China-aligned espionage campaign targeting government and defense sectors across South, East, and Southeast Asia, along with one European government be

Access Report
18-Year-Old NGINX Flaw CVE-2026-42945 Enables Unauthenticated RCE — Patch Now
REPORT // 047

18-Year-Old NGINX Flaw CVE-2026-42945 Enables Unauthenticated RCE — Patch Now

Cybersecurity researchers disclosed a critical vulnerability in NGINX Plus and NGINX Open Source that remained undetected for 18 years. Dubbed NGINX Rift, the flaw allows unauthenticated remote code e

Access Report
GitHub Breached via Malicious VS Code Extension: 3,800 Internal Repositories Exfiltrated
REPORT // 048

GitHub Breached via Malicious VS Code Extension: 3,800 Internal Repositories Exfiltrated

GitHub confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension, tracing the attack to the broader TanStack npm supply-chain

Access Report
Microsoft Defender Zero-Days CVE-2026-41091 and CVE-2026-45498 Actively Exploited
REPORT // 049

Microsoft Defender Zero-Days CVE-2026-41091 and CVE-2026-45498 Actively Exploited

Microsoft has warned of two actively exploited vulnerabilities in Microsoft Defender, with CISA adding both to its Known Exploited Vulnerabilities catalog and requiring federal agency patching by June

Access Report
How China-Linked Threat Actors Build and Exploit Their Zero-Day Vulnerability Pipeline
REPORT // 050

How China-Linked Threat Actors Build and Exploit Their Zero-Day Vulnerability Pipeline

China-linked threat actors use a coordinated ecosystem to obtain zero-day vulnerabilities — not just individual discoveries. Understanding this pipeline is critical for defenders facing persistent nat

Access Report
Ransomware Attack on CodeRED Knocks Out Emergency Alert Systems Across the US
REPORT // 051

Ransomware Attack on CodeRED Knocks Out Emergency Alert Systems Across the US

A ransomware attack targeting a third-party emergency alert system used across the United States has resulted in a data breach and significant disruptions, leaving cities and counties unable to send e

Access Report
West Pharmaceutical Services Hit by Ransomware Attack Disrupting Global Operations
REPORT // 052

West Pharmaceutical Services Hit by Ransomware Attack Disrupting Global Operations

Pennsylvania pharma giant West Pharmaceutical Services experienced a significant ransomware incident on May 4, prompting immediate action to contain the attack and causing global operational disruptio

Access Report
Iranian APT MuddyWater Masquerades as Chaos Ransomware to Hide Espionage Operations
REPORT // 053

Iranian APT MuddyWater Masquerades as Chaos Ransomware to Hide Espionage Operations

The Iran-linked APT actor MuddyWater has been observed performing an intrusion masquerading as a ransomware attack, according to Rapid7 research. The intrusion relied on social engineering tactics com

Access Report
First AI-Built Zero-Day Used by Criminals in Planned Mass Hack Campaign
REPORT // 054

First AI-Built Zero-Day Used by Criminals in Planned Mass Hack Campaign

Google's Threat Intelligence Group has identified what it believes is the first documented case of cybercriminals using AI to discover and weaponize a zero-day vulnerability for a large-scale attack c

Access Report
Axios Supply Chain Attack Proves AI-Powered Security Is Now Mandatory
REPORT // 055

Axios Supply Chain Attack Proves AI-Powered Security Is Now Mandatory

A suspected North Korean threat actor inserted malicious code into Axios, a widely used JavaScript library downloaded approximately 100 million times weekly across enterprises, startups, and governmen

Access Report
Google: State-Sponsored Hackers Now Use AI at Every Stage of the Cyberattack Cycle
REPORT // 056

Google: State-Sponsored Hackers Now Use AI at Every Stage of the Cyberattack Cycle

A new report from Google found evidence that state-sponsored hacking groups have leveraged AI tool Gemini at nearly every stage of the cyber attack cycle.

Access Report
Windows BitLocker Zero-Day YellowKey Bypasses Encryption, PoC Released
REPORT // 057

Windows BitLocker Zero-Day YellowKey Bypasses Encryption, PoC Released

A security researcher has published proof-of-concept exploits for two unpatched Microsoft Windows vulnerabilities called YellowKey and GreenPlasma. YellowKey functions as a BitLocker bypass, while Gre

Access Report
Trellix Discloses Data Breach After Source Code Repository Hack
REPORT // 058

Trellix Discloses Data Breach After Source Code Repository Hack

Cybersecurity firm Trellix disclosed a data breach after attackers gained unauthorized access to a portion of its source code repository.

Access Report
CISA Orders Federal Agencies to Patch BlueHammer Zero-Day CVE-2026-33825 in Microsoft Defender
REPORT // 059

CISA Orders Federal Agencies to Patch BlueHammer Zero-Day CVE-2026-33825 in Microsoft Defender

CISA has given U.S. government agencies two weeks to secure their Windows systems against a Microsoft Defender privilege escalation vulnerability that has been exploited in zero-day attacks.

Access Report
Microsoft May 2026 Patch Tuesday Fixes 120 Flaws Including 17 Critical RCE Vulnerabilities
REPORT // 060

Microsoft May 2026 Patch Tuesday Fixes 120 Flaws Including 17 Critical RCE Vulnerabilities

Microsoft released its May 2026 Patch Tuesday updates addressing 120 vulnerabilities, with no zero-day exploits disclosed this month.

Access Report
Instructure Canvas Data Breach: ShinyHunters Claims 275 Million Records Stolen
REPORT // 061

Instructure Canvas Data Breach: ShinyHunters Claims 275 Million Records Stolen

Educational technology company Instructure has confirmed a cybersecurity incident affecting its Canvas learning management system. The ShinyHunters extortion gang has claimed responsibility for the at

Access Report
Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited in Active Attacks
REPORT // 062

Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited in Active Attacks

Cisco is alerting organizations to a critical authentication bypass vulnerability in its Catalyst SD-WAN Controller and Manager platforms. Tracked as CVE-2026-20182 with a maximum severity rating of 1

Access Report
CVE-2026-24061: Critical telnetd Flaw Grants Unauthenticated Root
REPORT // 063

CVE-2026-24061: Critical telnetd Flaw Grants Unauthenticated Root

CVE-2026-24061 is a CVSS 9.8 auth bypass in GNU InetUtils telnetd giving unauthenticated remote attackers instant root shell access. Active exploitation confirmed — patch now.

Access Report
cPanel WHM Auth Bypass CVE-2026-41940: What You Must Know
REPORT // 064

cPanel WHM Auth Bypass CVE-2026-41940: What You Must Know

CVE-2026-41940 is a critical cPanel & WHM authentication bypass exploited as a zero-day, affecting 70M+ domains. Patch immediately to all supported versions.

Access Report
CVE-2026-31431: Copy Fail Gives Root on All Major Linux Distros
REPORT // 065

CVE-2026-31431: Copy Fail Gives Root on All Major Linux Distros

CVE-2026-31431 "Copy Fail" is a Linux kernel logic flaw letting unprivileged users gain root via a 732-byte Python script on Ubuntu, RHEL, SUSE, and Amazon Linux.

Access Report
CVE-2026-24061: GNU telnetd Auth Bypass Grants Root Shell
REPORT // 066

CVE-2026-24061: GNU telnetd Auth Bypass Grants Root Shell

CVE-2026-24061 is a critical GNU InetUtils telnetd flaw letting unauthenticated remote attackers gain instant root shell access via argument injection.

Access Report
CVE-2026-24061: Critical Telnetd RCE Vulnerability Explained
REPORT // 067

CVE-2026-24061: Critical Telnetd RCE Vulnerability Explained

SafeBreach Labs uncovers the root cause of CVE-2026-24061, a CVSS 9.8 GNU telnetd auth-bypass flaw enabling unauthenticated RCE as root on Linux systems.

Access Report
Dirty Frag CVE-2026-43284: Linux Kernel Privilege Escalation
REPORT // 068

Dirty Frag CVE-2026-43284: Linux Kernel Privilege Escalation

Dirty Frag (CVE-2026-43284) is a deterministic Linux LPE exploiting ESP and RxRPC kernel flaws. Learn what's affected and how to mitigate now.

Access Report
PCPJack: Cloud Worm Stealing Credentials at Scale in 2026
REPORT // 069

PCPJack: Cloud Worm Stealing Credentials at Scale in 2026

PCPJack is a cloud worm credential-theft framework targeting Kubernetes, Docker, and Redis — evicting TeamPCP malware while harvesting enterprise and financial credentials.

Access Report
Prompt Injection Flaws Enable RCE in Popular AI Agent Frameworks
REPORT // 070

Prompt Injection Flaws Enable RCE in Popular AI Agent Frameworks

Microsoft researchers expose how prompt injection in AI agent frameworks escalates to remote code execution — learn which systems are at risk and how to defend them.

Access Report
Dirty Frag: Linux Kernel LPE Vulnerability Under Active Attack
REPORT // 071

Dirty Frag: Linux Kernel LPE Vulnerability Under Active Attack

Dirty Frag is an actively exploited Linux local privilege escalation vulnerability targeting kernel memory-fragment handling, enabling root access post-compromise via SSH, web shells, or containers.

Access Report
Copy Fail & DirtyFrag: Linux Kernel Privilege Escalation
REPORT // 072

Copy Fail & DirtyFrag: Linux Kernel Privilege Escalation

Copy Fail and DirtyFrag exploit Linux page cache corruption to gain root access. Learn how these CVEs work and how to detect them with EQL and auditd.

Access Report
CVE-2026-21440: AdonisJS Path Traversal to Arbitrary File Write
REPORT // 073

CVE-2026-21440: AdonisJS Path Traversal to Arbitrary File Write

CVE-2026-21440 is a critical CVSS 9.2 path traversal flaw in @adonisjs/bodyparser enabling arbitrary file writes and remote code execution. Patch now.

Access Report
Axios NPM Supply Chain Attack: Analysis, IOCs & Mitigation
REPORT // 074

Axios NPM Supply Chain Attack: Analysis, IOCs & Mitigation

Deep dive into the Axios npm supply chain attack: how WAVESHAPER.V2 RAT was deployed, indicators of compromise, and mitigation steps to protect your pipeline.

Access Report
Weekly Threat Intel: Medtronic Breach, AI Attacks & Zero-Days
REPORT // 075

Weekly Threat Intel: Medtronic Breach, AI Attacks & Zero-Days

This week's threat intelligence roundup covers the Medtronic data breach, AI-powered phishing kits, cPanel zero-day exploitation, and VECT 2.0 ransomware wiping files.

Access Report
npm Supply Chain Attacks: Shai-Hulud Wave & How to Defend
REPORT // 076

npm Supply Chain Attacks: Shai-Hulud Wave & How to Defend

Unit 42 tracks wormable npm supply chain attacks targeting CI/CD pipelines in 2026. Learn how Shai-Hulud and Mini Shai-Hulud work and how to protect your org.

Access Report
CI/CD Pipeline Abuse: Detecting Attacks with LLM Analysis
REPORT // 077

CI/CD Pipeline Abuse: Detecting Attacks with LLM Analysis

CI/CD pipelines are the new crown jewels for attackers. Learn how LLM-augmented signal detection catches GitHub Actions, GitLab CI, and Azure DevOps abuse before secrets are stolen.

Access Report
CVE-2026-31431 "Copy Fail": Linux Kernel LPE Flaw Explained
REPORT // 078

CVE-2026-31431 "Copy Fail": Linux Kernel LPE Flaw Explained

CVE-2026-31431 "Copy Fail" lets local users gain root in seconds by corrupting the Linux page cache via AF_ALG sockets. Learn the root cause, impact, and detection.

Access Report
CVE-2026-31431: Copy Fail Linux Root Privilege Escalation
REPORT // 079

CVE-2026-31431: Copy Fail Linux Root Privilege Escalation

CVE-2026-31431 "Copy Fail" lets attackers escalate to root on Linux across cloud and Kubernetes environments. A working exploit is in the wild — patch now.

Access Report
CVE-2026-41940: cPanel & WHM Auth Bypass Actively Exploited
REPORT // 080

CVE-2026-41940: cPanel & WHM Auth Bypass Actively Exploited

CVE-2026-41940 is a CVSS 9.8 authentication bypass in cPanel & WHM exploited in the wild. Learn the technical details, affected versions, and how to patch now.

Access Report
DAEMON Tools Compromised in Active Supply Chain Attack
REPORT // 081

DAEMON Tools Compromised in Active Supply Chain Attack

Kaspersky reveals DAEMON Tools versions 12.5.0.2421–2434 are trojanized with backdoors hitting 100+ countries. Here's what you need to know now.

Access Report
Copy Fail: 732-Byte Script Gets Root on Every Major Linux Distro
REPORT // 082

Copy Fail: 732-Byte Script Gets Root on Every Major Linux Distro

CVE-2026-31431 is a deterministic Linux kernel logic bug that chains AF_ALG and splice() into a stealthy 4-byte page cache write, granting root without races or recompilation.

Access Report
Project Glasswing: AI Finds Bugs, But Who Actually Fixes Them?
REPORT // 083

Project Glasswing: AI Finds Bugs, But Who Actually Fixes Them?

Project Glasswing's Mythos AI uncovered decades-old vulnerabilities at scale — yet fewer than 1% were patched, revealing a critical remediation gap in cybersecurity.

Access Report
CVE-2026-33825: BlueHammer Zero-Day Exploited in Wild
REPORT // 084

CVE-2026-33825: BlueHammer Zero-Day Exploited in Wild

CVE-2026-33825, a CVSS 7.8 Microsoft Defender privilege escalation flaw dubbed BlueHammer, is being actively exploited using public PoC code. Patch now.

Access Report
UNC6692 Targets Executives via Teams Help Desk Scam
REPORT // 085

UNC6692 Targets Executives via Teams Help Desk Scam

UNC6692 impersonated IT help desks on Microsoft Teams to deploy SNOW malware, targeting 77% senior employees in a 30-day campaign. Learn how to defend against this threat.

Access Report
Vercel Confirms Data Breach via Third-Party AI OAuth Compromise
REPORT // 086

Vercel Confirms Data Breach via Third-Party AI OAuth Compromise

Vercel confirmed a security breach after threat actors linked to ShinyHunters claimed to sell stolen data including API keys, source code, and employee records.

Access Report
Adobe Patches Actively Exploited Acrobat Reader CVE-2026-34621
REPORT // 087

Adobe Patches Actively Exploited Acrobat Reader CVE-2026-34621

Adobe patches CVE-2026-34621, an actively exploited Acrobat Reader flaw enabling remote code execution via malicious PDFs since December 2025.

Access Report
Medusa Ransomware Hits Healthcare with Lightning-Speed Attacks
REPORT // 088

Medusa Ransomware Hits Healthcare with Lightning-Speed Attacks

Medusa ransomware group Storm-1175 exploits zero-days within hours, targeting healthcare, finance, and education across the US, UK, and Australia.

Access Report
April 2026 Cloud Security: Supply Chain Attacks & Critical RCEs
REPORT // 089

April 2026 Cloud Security: Supply Chain Attacks & Critical RCEs

April 2026 brought wave after wave of cloud threats — from TeamPCP's supply chain cascade to a Telnetd RCE hitting 23% of cloud environments. Here's what matters.

Access Report
North Korea's APT37 Deploys RokRAT via Facebook Social Engineering
REPORT // 090

North Korea's APT37 Deploys RokRAT via Facebook Social Engineering

North Korea's APT37 threat group is leveraging Facebook accounts and trojanized PDFelement installers to deliver RokRAT malware for espionage and data theft.

Access Report
Palo Alto & SonicWall Patch High-Severity Security Flaws
REPORT // 091

Palo Alto & SonicWall Patch High-Severity Security Flaws

Palo Alto Networks and SonicWall release critical patches for high-severity vulnerabilities in Cortex platforms and SMA1000 firewalls. Here's what you need to know.

Access Report
ScarCruft APT37 Deploys BirdCall Android Spyware via Game Platform
REPORT // 092

ScarCruft APT37 Deploys BirdCall Android Spyware via Game Platform

North Korean APT37 (ScarCruft) has weaponized a Chinese Android game platform to distribute BirdCall spyware, targeting Korean-speaking users with advanced surveillance capabilities.

Access Report
2026: How AI-Assisted Attacks Are Reshaping Cyber Threats
REPORT // 093

2026: How AI-Assisted Attacks Are Reshaping Cyber Threats

AI is dramatically lowering the barrier for cybercriminals in 2026, enabling a 7M-user breach and accelerating exploits at unprecedented scale. Here's what defenders need to know.

Access Report
NASCAR Ransomware Attack: SSNs Stolen by Medusa Group
REPORT // 094

NASCAR Ransomware Attack: SSNs Stolen by Medusa Group

NASCAR confirms a March–April 2025 ransomware attack exposed names and Social Security numbers. Medusa group claims 1TB stolen and demands $4M ransom.

Access Report
TeamPCP Mini Shai Hulud Supply Chain Attack Targets SAP npm
REPORT // 095

TeamPCP Mini Shai Hulud Supply Chain Attack Targets SAP npm

TeamPCP's "Mini Shai Hulud" npm supply chain attack compromised SAP ecosystem packages to steal CI/CD secrets, cloud credentials, and Kubernetes tokens at scale.

Access Report
Google Patches Chrome Zero-Day CVE-2025-14174 Exploited in Wild
REPORT // 096

Google Patches Chrome Zero-Day CVE-2025-14174 Exploited in Wild

Google has patched CVE-2025-14174, a high-severity Chrome zero-day actively exploited in the wild, now linked to two newly patched Apple zero-days.

Access Report
European Space Agency Confirms Data Breach: 200GB Stolen
REPORT // 097

European Space Agency Confirms Data Breach: 200GB Stolen

The European Space Agency confirmed a breach after hacker '888' claimed to sell 200GB of stolen data including source code, credentials, and API tokens from ESA systems.

Access Report
M&S Ransomware Attack: Customer Data Stolen by DragonForce
REPORT // 098

M&S Ransomware Attack: Customer Data Stolen by DragonForce

Marks & Spencer confirms personal customer data was stolen in a DragonForce ransomware attack, exposing names, addresses, and order history for millions.

Access Report
ScarCruft Hacks Gaming Platform to Spread BirdCall Malware
REPORT // 099

ScarCruft Hacks Gaming Platform to Spread BirdCall Malware

North Korean APT ScarCruft compromised sqgame.net since late 2024, deploying BirdCall malware targeting Android and Windows users for surveillance and data theft.

Access Report
iClicker ClickFix Attack Used Fake CAPTCHA to Target Students
REPORT // 100

iClicker ClickFix Attack Used Fake CAPTCHA to Target Students

The iClicker website was compromised in a ClickFix attack that tricked millions of students and instructors into executing malware via a fake CAPTCHA prompt.

Access Report
SharePoint Zero-Day Exploited: Microsoft Patches 165 Vulnerabilities
REPORT // 101

SharePoint Zero-Day Exploited: Microsoft Patches 165 Vulnerabilities

Microsoft's April 2026 Patch Tuesday addresses 165 CVEs including an actively exploited SharePoint zero-day (CVE-2026-32201) added to CISA's KEV catalog.

Access Report
Rhysida Ransomware Hits Tennessee Hospital: 337K Exposed
REPORT // 102

Rhysida Ransomware Hits Tennessee Hospital: 337K Exposed

A Rhysida ransomware attack on Cookeville Regional Medical Center exposed data of 337,000 patients — SSNs, financial records, and medical histories now freely online.

Access Report
How AI Is Turning Your VPN Into an Attack Highway in 2026
REPORT // 103

How AI Is Turning Your VPN Into an Attack Highway in 2026

AI-powered attackers are exploiting VPN vulnerabilities faster than security teams can respond. Learn what the April 2026 Patch Tuesday fixes mean for your remote access security.

Access Report
NIST Revamps CVE Prioritization: What It Means for You
REPORT // 104

NIST Revamps CVE Prioritization: What It Means for You

NIST is shifting to a risk-based CVE prioritization model, focusing on high-impact vulnerabilities. Here's what security teams need to know about the NVD changes.

Access Report
April 2026 Patch Tuesday: 167 Fixes, Zero-Days & Records
REPORT // 105

April 2026 Patch Tuesday: 167 Fixes, Zero-Days & Records

Microsoft patches 167 CVEs including a SharePoint zero-day and BlueHammer in Windows Defender. Plus Adobe and Chrome emergency fixes you need now.

Access Report
Microsoft April 2026 Patch Tuesday: SharePoint Zero-Day Among 165 Fixes
REPORT // 106

Microsoft April 2026 Patch Tuesday: SharePoint Zero-Day Among 165 Fixes

Microsoft's April 2026 Patch Tuesday patches 165 vulnerabilities including an actively exploited SharePoint zero-day (CVE-2026-32201). Here's what you need to know.

Access Report
Adobe Fixes Actively Exploited Acrobat Reader RCE CVE-2026-34621
REPORT // 107

Adobe Fixes Actively Exploited Acrobat Reader RCE CVE-2026-34621

Adobe has patched CVE-2026-34621, an actively exploited Acrobat Reader flaw enabling remote code execution via malicious PDFs. Update immediately to stay protected.

Access Report
AI Privilege Amplification: Why Old Vulnerabilities Are Deadlier
REPORT // 108

AI Privilege Amplification: Why Old Vulnerabilities Are Deadlier

AI agents don't create new vulnerability types — they amplify existing ones. Learn how CVE-2026-26144 signals a dangerous new era of AI-powered exploitation.

Access Report
NIST Limits CVE Enrichment After 263% Vulnerability Surge
REPORT // 109

NIST Limits CVE Enrichment After 263% Vulnerability Surge

NIST restricts CVE enrichment after a 263% surge in vulnerability submissions since 2020, prioritizing KEV catalog and federal software while thousands of CVEs shift to "Not Scheduled."

Access Report
Three Microsoft Defender Zero-Days Exploited in the Wild
REPORT // 110

Three Microsoft Defender Zero-Days Exploited in the Wild

Three critical Microsoft Defender zero-days actively exploited since April 10, 2026 enable privilege escalation and denial-of-service attacks — two remain unpatched.

Access Report
Microsoft April 2026 Patch Tuesday: 167 CVEs and Zero-Days
REPORT // 111

Microsoft April 2026 Patch Tuesday: 167 CVEs and Zero-Days

Microsoft patched a record-breaking 167 vulnerabilities this Patch Tuesday, including a SharePoint zero-day and the BlueHammer Windows Defender flaw. Here's what you need to know.

Access Report
Zero-Days, Data Breaches & AI Risks: Cybersecurity Week 2026
REPORT // 112

Zero-Days, Data Breaches & AI Risks: Cybersecurity Week 2026

This week's cybersecurity roundup covers critical zero-days, high-profile data breaches, AI-driven threats, and lessons from Deloitte, TSA, and Mazda vulnerabilities.

Access Report
CISA Flags Second Critical Ivanti EPMM Flaw as Actively Exploited
REPORT // 113

CISA Flags Second Critical Ivanti EPMM Flaw as Actively Exploited

CISA adds CVE-2026-1340, a critical Ivanti EPMM code injection flaw with a 9.8 severity score, to its Known Exploited Vulnerabilities catalog amid thousands of attacks.

Access Report
CISA Adds Fortinet FortiClient EMS Flaw to KEV Catalog
REPORT // 114

CISA Adds Fortinet FortiClient EMS Flaw to KEV Catalog

CISA added CVE-2026-35616, a Fortinet FortiClient EMS improper access control vulnerability, to its KEV Catalog due to active exploitation. Learn what to do now.

Access Report
Fortinet Patches CVE-2026-35616: Critical EMS Flaw Exploited
REPORT // 115

Fortinet Patches CVE-2026-35616: Critical EMS Flaw Exploited

Fortinet patches CVE-2026-35616 (CVSS 9.1) in FortiClient EMS, actively exploited since March 31, 2026, enabling privilege escalation on vulnerable endpoints.

Access Report
Boggy Serpens: Iran's Evolving APT Threat in 2026
REPORT // 116

Boggy Serpens: Iran's Evolving APT Threat in 2026

Iranian threat group Boggy Serpens (MuddyWater) escalates cyberespionage with AI-enhanced malware, Rust-based tools, and trusted relationship compromises targeting critical infrastructure.

Access Report
CISA Warns: Langflow RCE & Trivy Supply Chain Attack
REPORT // 117

CISA Warns: Langflow RCE & Trivy Supply Chain Attack

CISA adds CVE-2026-33017 and CVE-2026-33634 to its KEV catalog as attackers exploit Langflow RCE within 20 hours and compromise Trivy's supply chain.

Access Report
Critical Progress ShareFile Flaws Enable Pre-Auth RCE Attacks
REPORT // 118

Critical Progress ShareFile Flaws Enable Pre-Auth RCE Attacks

Two chained vulnerabilities in Progress ShareFile's Storage Zones Controller allow unauthenticated remote code execution. Patch to version 5.12.4 immediately.

Access Report
GitHub Security Lab: Securing Open Source Together
REPORT // 119

GitHub Security Lab: Securing Open Source Together

GitHub Security Lab unites developers and security researchers to protect open source software—discover their mission, research findings, and the Advisory Database.

Access Report
CVE-2026-2441: Chrome Use-After-Free RCE Exploit
REPORT // 120

CVE-2026-2441: Chrome Use-After-Free RCE Exploit

CVE-2026-2441 is a CVSS 8.8 Chrome use-after-free vulnerability in Blink CSS actively exploited in the wild. Learn the technical details, impact, and how to patch now.

Access Report
CVE-2026-21440: Path Traversal to RCE in AdonisJS
REPORT // 121

CVE-2026-21440: Path Traversal to RCE in AdonisJS

CVE-2026-21440 is a CVSS 9.2 critical path traversal flaw in @adonisjs/bodyparser enabling arbitrary file write and remote code execution. Patch now.

Access Report
CVE-2026-33017: Critical Langflow RCE Vulnerability
REPORT // 122

CVE-2026-33017: Critical Langflow RCE Vulnerability

A critical unauthenticated RCE flaw (CVE-2026-33017, CVSS 9.3) in Langflow ≤1.8.13 allows full server compromise via unsafe Python exec(). Patch now.

Access Report
Ivanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340 Exploited
REPORT // 123

Ivanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340 Exploited

Critical CVSS 9.8 zero-days in Ivanti EPMM enable unauthenticated RCE. Discover attacker tradecraft, webshell deployment tactics, and how to respond.

Access Report
CVE-2026-33017: Langflow RCE Exploited Within 20 Hours
REPORT // 124

CVE-2026-33017: Langflow RCE Exploited Within 20 Hours

CVE-2026-33017 is a critical unauthenticated RCE in Langflow AI pipelines, actively exploited within 20 hours of disclosure. Learn attacker tactics and how to defend.

Access Report
Progress ShareFile Pre-Auth RCE: CVE-2026-2699 & CVE-2026-2701
REPORT // 125

Progress ShareFile Pre-Auth RCE: CVE-2026-2699 & CVE-2026-2701

Researchers chained two ShareFile vulnerabilities — an auth bypass and RCE flaw — to fully compromise on-prem Storage Zone Controllers without authentication.

Access Report
Cisco Dev Environment Breached: Source Code Stolen via Trivy
REPORT // 126

Cisco Dev Environment Breached: Source Code Stolen via Trivy

Cisco confirms a breach tied to the Trivy supply chain attack, with threat actors stealing source code from 300+ repositories and multiple AWS credentials.

Access Report
Axios npm Package Hijacked to Deploy Cross-Platform RAT
REPORT // 127

Axios npm Package Hijacked to Deploy Cross-Platform RAT

North Korean hackers compromised the Axios npm package — 400M monthly downloads — injecting malware targeting Linux, Windows, and macOS. Here's what you need to know.

Access Report
Progress ShareFile RCE Flaws Enable Pre-Auth Attacks
REPORT // 128

Progress ShareFile RCE Flaws Enable Pre-Auth Attacks

Two chained vulnerabilities in Progress ShareFile allow unauthenticated attackers to exfiltrate files and execute remote code on exposed Storage Zone Controllers.

Access Report
The Evolving Landscape of Ransomware Attacks in 2024
REPORT // 129

The Evolving Landscape of Ransomware Attacks in 2024

Discover how ransomware tactics have evolved and what organizations can do to protect themselves against these sophisticated threats.

Access Report
Implementing Zero Trust Architecture: A Practical Guide
REPORT // 130

Implementing Zero Trust Architecture: A Practical Guide

Learn step-by-step how to implement Zero Trust principles in your organization to enhance your security posture.

Access Report
Data Breach: What Cybersecurity Professionals Must Know
REPORT // 131

Data Breach: What Cybersecurity Professionals Must Know

Comprehensive guide on data breach prevention, detection, and response for cybersecurity professionals.

Access Report
Building an Efficient GPU Server with NVIDIA GeForce RTX 4090s/5090s
REPORT // 132

Building an Efficient GPU Server with NVIDIA GeForce RTX 4090s/5090s

Learn how to build an efficient GPU server for cybersecurity tasks like password cracking, malware analysis, and cryptocurrency forensics.

Access Report
APT34: Jason Project - Analysis of Exchange Mail Brute-Force Tool
REPORT // 133

APT34: Jason Project - Analysis of Exchange Mail Brute-Force Tool

Technical analysis of the APT34 Jason tool - a .NET GUI for brute-forcing Microsoft Exchange accounts via EWS/OAB to harvest emails.

Access Report
International Hacker Arrested in Thailand: $10M Asset Seizure in Global Cyber Operation
REPORT // 134

International Hacker Arrested in Thailand: $10M Asset Seizure in Global Cyber Operation

Analysis of the international cybercrime operation leading to the arrest of a notorious hacker in Thailand, with over $295,000 in assets seized.

Access Report
The Bybit Hack: A $1.4 Billion Ethereum Heist – Technical Breakdown
REPORT // 135

The Bybit Hack: A $1.4 Billion Ethereum Heist – Technical Breakdown

Detailed technical analysis of the largest crypto heist in history and lessons for securing digital assets.

Access Report
Emerging Threats in Supply Chain Security
REPORT // 136

Emerging Threats in Supply Chain Security

Analyzing the latest supply chain attack vectors and how organizations can defend against them.

Access Report
Technical Analysis of Cyber Attacks in Albania
REPORT // 137

Technical Analysis of Cyber Attacks in Albania

Technical analysis of cyber attacks in Albania based on the Albanian cybersecurity report.

Access Report