Latest IntelligenceAdvisoriesPage 1
Search by keyword →
MikroTik RouterOS bugs actively exploited in device takeover attacks
CERT Polska is warning MikroTik customers to urgently update RouterOS after confirming that attackers are exploiting two critical SSH vulnerabilities to gain fu...

WhatsApp rolls out emergency fix for locked Android photo access bug
WhatsApp announced it has begun rolling out a fix for an Android privacy issue that could allow someone with physical access to a locked phone to view the owner...

Lenovo ID flaw let attackers access Dropbox accounts without passwords
Dropbox users are reporting unauthorized account access caused by a flaw in Lenovo’s email verification process that allowed attackers to create Lenovo IDs usin...

Apple sends mercenary spyware alerts to targeted iPhone users
Apple has sent a new round of threat notifications to iPhone users it believes may have been targeted with mercenary spyware. The warnings are issued to people ...

WhatsApp rolls out new feature that flags potential scam messages
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [....

WhatsApp adds on-device scam detection without sending chats to Meta
Meta has unveiled an early version of Scam Alert, an optional WhatsApp security feature that uses an on-device machine learning model to identify messages that ...

CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic c...

LastPass, Bitwarden users targeted with fake security alerts
LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. [...]...

Webinar tomorrow: Why modern email attacks require a new approach to defense
Tomorrow's webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks whil...

FBI: Russian hackers now target Signal backup recovery keys
The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery K...

WhatsApp is now warning users attempting to message unknown numbers
WhatsApp has introduced a new security feature designed to make users think twice before starting conversations with unfamiliar phone numbers. The new “tr...

CISA warns of max severity Ubiquiti flaws exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-et...

CISA warns of cyberattacks targeting fuel tank monitoring systems
CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge ...

Verizon VoLTE network found missing IPsec protections for SIP signaling
The CERT Coordination Center (CERT/CC) has disclosed a security issue affecting Verizon's Voice over LTE (VoLTE) infrastructure, warning that SIP signaling traf...

Citizen Lab urges Canada to withdraw parts of Bill C-22 over privacy concerns
Citizen Lab and the Canadian Civil Liberties Association (CCLA) are urging lawmakers to withdraw key provisions of Canada's proposed lawful access legislation, ...

FBI warns of fake FIFA websites running World Cup fraud schemes
The FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and hospitali...

Sextortionist sentenced to 33 years for targeting 145 children
A Canadian man was sentenced to 33 years in prison after pleading guilty to targeting more than 145 children across the United States, some as young as 6 years ...

FBI warns of Kali365 phishing kit targeting Microsoft 365 accounts
The FBI has issued a warning about a phishing-as-a-service (PhaaS) platform known as “Kali365” that is being used to compromise Microsoft 365 accounts through s...

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentic...

Mozilla calls on UK to exclude VPNs from age verification rules
Mozilla urged UK regulators not to impose age restrictions on VPN services, warning that such measures would weaken privacy protections for all users while doin...