Latest IntelligencePage 27
Search by keyword →Robinhood Cuts Access Approval Time to Support High-Velocity Development
The fintech company's engineering-first application security team re-engineered the process for granting system access, making it easier and more secure for dev...

Poland busts SIM-swapping gang tied to millions in crypto theft
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts ...
In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments....
Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers....
EdTech Attackers Shift From Schools to Their Software Suppliers
Educational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters'...

Order-tracking app Shop abused to push callback phishing attacks
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into ...
Local Police Collusion Hampers Crackdown on Asian Scam Centers
With tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement e...

Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to con...

Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation
Russian authorities deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone of opposition politician Andrey Pivovarov in Ju...

WhatsApp is now warning users attempting to message unknown numbers
WhatsApp has introduced a new security feature designed to make users think twice before starting conversations with unfamiliar phone numbers. The new “tr...

Windows Secure Boot Certificate Expired — Billions of PCs Affected Including Linux Distros
The clock has run out. As of June 24, 2026, the first of Microsoft’s original Secure Boot certificates, the Microsoft Corporation KEK CA 2011, has officia...

New macOS malware embeds fake errors to confuse AI analysis tools
A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debuggi...

PirloTV sports piracy network disrupted as 44 domains seized
A major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains. [...]...

Best Pentesting Tools for Internal vs External Testing
A penetration test should answer a simple question: where could an attacker get in, and what could they reach after that? The answer changes when the test looks...

Bluekit phishing kit adopts browser-in-the-middle for login theft
The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle ca...

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the ...

The Four Elevations of Effective Fraud Prevention
Fraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and ...

25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally Patched
A critical security flaw lurking in curl for over 25 years has been patched, as part of a record-breaking security release that fixed 18 CVEs, the most ever iss...

Shopify Shop app users are seeing fake orders in purchase histories
Scammers are placing fake purchase receipts inside Shopify's Shop app, exploiting users' trust in order-tracking applications to lure them into calling fraudule...

LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials
LokiBot, one of the oldest credential-stealing malware families still active today, has resurfaced in a new multi-stage campaign designed to steal credentials f...