Latest IntelligenceThreat IntelligencePage 1
Search by keyword →
Hackers build AI frameworks for widescale credential theft
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]...

Google warns hackers are deploying AI agents in autonomous attacks
Cybercriminals and state-backed hackers are moving beyond using AI as a coding or research assistant and are instead building agentic systems that can autonomou...

Attackers conceal phishing lures using invisible Unicode characters
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. [...]...

Malicious “privacy browser” hijacks PCs with mouse and keyboard injection
Security researchers at Intezer have uncovered a deceptive browser application that can remotely inject keyboard and mouse commands into Windows systems. The ca...

Google removes uBlock Origin from Chrome Web Store in final Manifest V2 purge
Google has removed uBlock Origin from the Chrome Web Store as it completes the final stage of its years-long phase-out of Manifest V2 extensions. The removal al...

EU puts ChatGPT, Reddit, and Roblox under stricter DSA rules
The European Commission has designated ChatGPT, Reddit, and Roblox as services subject to the strictest requirements of the EU’s Digital Services Act (DSA) afte...

ShinyHunters claims McKesson data breach exposing 284 million patient records
The ShinyHunters threat group claims it compromised McKesson and obtained data on over 284 million patient records, including highly sensitive medical, identity...

ShinyHunters claims McKesson data breach exposing 284 million patients
The ShinyHunters threat group claims it compromised McKesson and obtained data on over 284 million patients, including highly sensitive medical, identity, presc...

19 Chrome and Edge extensions caught harvesting crypto wallet seeds
Security researchers have uncovered 19 malicious Chrome and Edge extensions delivering cryptocurrency wallet drainers, credential stealers, session hijacking to...

Brave launches Email Aliases to hide users’ real email addresses
Brave has launched a built-in Email Aliases feature that lets users create disposable forwarding addresses directly from website sign-up forms, preventing sites...

Proton suffers major data center outage, says no user data was lost
Proton experienced a global service outage earlier today after a critical cooling failure hit one of its data centers in Frankfurt, disrupting access to Proton ...

Meta agrees to $17.1 billion settlement over alleged harms to children
Meta has agreed to pay up to $17.1 billion and make sweeping changes to Facebook and Instagram under a proposed multistate settlement resolving claims that its ...

WhatsApp adds multiple passkeys and stronger two-step verification
WhatsApp is rolling out support for multiple passkeys, stronger two-step verification passwords, and additional information for calls from unknown numbers. The ...

Firefox moves to adopt JPEG XL with safer Rust-based decoder
Mozilla is preparing to enable JPEG XL support in Firefox, bringing the modern image format closer to broad browser adoption alongside AVIF. The company says it...

DuckDuckGo finds one-third of AI users share secrets they hide from people
A DuckDuckGo survey of nearly 2,000 US adults found that 32% of people who use AI chatbots have shared information they withheld from friends, relatives, collea...

ReliaQuest says claimed ShinyHunters attack was successfully blocked
ReliaQuest says it contained a social engineering attack that briefly gave a threat actor access to a single employee identity session but did not allow access ...
Alibaba spotted using WebAudio fingerprinting for user tracking
Alibaba is facing scrutiny over its use of WebAudio fingerprinting, a browser-tracking technique that can help distinguish users by measuring subtle differences...

Russian hackers abuse WhatsApp device linking to spy on high-value targets
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features across WhatsApp, Google, and Microsoft to compromise academics, ...

AI-powered cyberattacks are targeting critical infrastructure in the US
US agencies are warning that threat actors are actively using AI-generated exploitation scripts to target Siemens S7 programmable logic controllers (PLCs) deplo...

Hackers compromise 14,500 Dahua web cameras in 35-day campaign
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]...