Latest IntelligencePage 28
Search by keyword →
Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials From Developers
A new wave of malicious npm packages is targeting developers who work with cloud and serverless infrastructure. The threat, known as the Shai-Hulud payload carr...

AWS AiTM Phishing Kit Steals Console Credentials and MFA Codes in Real Time
A newly discovered phishing kit is targeting Amazon Web Services users by silently stealing login credentials and multi-factor authentication codes the moment a...

AiTM Phishing Kits Steal Console Credentials and MFA Codes from AWS Environments
A newly discovered phishing kit is targeting Amazon Web Services users by silently stealing login credentials and multi-factor authentication codes the moment a...

Rust macOS Backdoor Uses Interactive Shell and Telegram File Uploads for Data Theft
A newly identified Rust-based macOS backdoor has raised alarms across the security community, combining a hidden interactive shell with Telegram-based file uplo...

Runlayer Raises $30 Million in Series A Funding
The startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises. The post Runlayer Raises $30 Million in Series A Fundi...

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted ...

Webinar: Why account takeovers remain one of the hardest threats to stop
Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar exp...

Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack
Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Says No OT Systems Bre...

Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply
Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Finds No Evidence of O...

GrapheneOS cites Hyundai, KIA as it pressures Volkswagen over app block
GrapheneOS is calling on Volkswagen customers to pressure the automaker into restoring compatibility with its mobile app after users reported last week that the...

ManageEngine AD360 Integration Flaw Exposes User Identity and Role Information to Attackers
ManageEngine has disclosed a high-severity vulnerability, tracked as CVE-2026-11374, affecting several of its identity and access management solutions when inte...

Japan’s army used USB drives with Chinese malware for a year
Japan's Ground Self-Defense Force (JGSDF) reportedly used counterfeit USB flash drives infected with malware linked to previously identified Chinese threat acti...

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-...

Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation:...

GitLab Patches Code Execution, Information Disclosure Vulnerabilities
The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosur...

Gemini 3.5 Flash Released With Computer Use Capabilities that Build Agents
Google has officially released Gemini 3.5 Flash with native “computer use” capabilities, marking a significant shift toward autonomous AI agents that can intera...

WhatsApp to Warn Users Before Starting Chats With New Phone Numbers
WhatsApp is rolling out a new security warning on both Android and iOS that appears before users even open a conversation with an unknown phone number. WABetaIn...
Europe Evolves Into Ransomware's Favorite Region
After a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers....

Malicious Chrome Extension Uses Native Messaging Host to Execute PowerShell Commands
A newly discovered malware campaign has turned Google Chrome into a remote backdoor without breaking any of the browser’s built-in rules. Spotted in June ...

25-Year-Old Vulnerability Patched in Curl
The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl...