Latest IntelligencePage 26
Search by keyword →
Japanese telco suffers breach exposing 14.2 million email passwords
KDDI has disclosed that an email system it operates for internet service providers (ISPs) was breached in a cyberattack, potentially exposing email account info...

Critical python.org Vulnerability Allowed Attackers to Forge Admin-Level API Requests
A critical authentication bypass vulnerability in the python.org release management API could have allowed attackers to impersonate administrators, potentially ...

$3 Million Reportedly Stolen in Polymarket Hack
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen ...

Polymarket suffers supply chain attack leading to $3 million crypto theft
Polymarket says it has contained a supply chain attack that injected malicious code into its website after a compromised third-party vendor exposed some users t...

KuinaExtractor Uses Telegram Exfiltration, UAC Bypass, and Sandbox Detection for Stealth
A newly uncovered infostealer called KuinaExtractor has been quietly evolving for over six months, posing a serious and growing threat to users across multiple ...

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files t...

Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
Turla has been using the backdoor against government and military organizations in Ukraine for espionage. The post Russian APT Deploys ‘StockStay’ B...

CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments
A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastruc...

Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff
Russian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months a...

Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages
Supply chain attackers are getting more creative, and the latest threat is proof of that. A malware campaign known as Miasma has been caught hiding inside widel...

Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2
A new and highly sophisticated malware loader has been found hiding inside what appears to be a harmless Minecraft mod. Researchers have uncovered a campaign th...

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill V...

New Enterprise-Ready MCP Specification Brings New Security Challenges
A major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators. The post...

CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks
CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vu...

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed a...

Microsoft Extends Windows 10 Security Updates for Users Up to October 2027
Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 1...

Philip Martin Joins Uber as Chief Information Security Officer
Martin brings experience from Coinbase, Palantir, Amazon, and the U.S. Army to lead Uber's cybersecurity and enterprise security organization. The post Philip M...
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of th...

OpenAI Reportedly Delays ChatGPT 5.6 Release Following Trump Administration Request
OpenAI has agreed to stagger the public release of its latest AI model, GPT-5.6, after the Trump administration formally requested the company limit initial acc...

Anthropic is testing desktop-like Claude Cowork for mobile
Anthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. [...]...