Latest IntelligencePage 30
Search by keyword →
Malicious Edge Extension Uses Chrome Native Messaging to Execute Code on Victim Systems
A new and deceptive malware campaign has been uncovered, one that turns an everyday browser extension into a dangerous tool for system compromise. Security rese...
Do CISOs Need a Code of Ethics?
Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks its time for a CISO code of ethics to ensur...

Tor Project to disable support for Tor 0.4.8 on September 1
The Tor Project has announced plans to stop supporting Tor 0.4.8 and earlier releases on September 1, 2026, as it prepares the network for the deployment of Art...

When Information Becomes the Attack Surface – Understanding AI Agent Traps
From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. The post When Information ...

EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps
 EvilTokens is drawing attention in phishing investigations for abusing Microsoft Device Code authentication and hiding key parts of its att...

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS500...

Hackers Exploiting Cisco Catalyst SD-WAN Manager 0-Day Flaw to Gain Root-Level Access
A sophisticated threat actor is actively targeting SD-WAN infrastructure at a major service provider. The campaign culminated in the exploitation of a zero-day ...
More Malicious OpenClaw Skills Threaten AI Supply Chain
OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats....

Mozilla proposes privacy-preserving alternative to CAPTCHAs
Mozilla has unveiled a new proposal called PACT (Private Access Control Tokens), a framework designed to help websites distinguish legitimate users from abusive...
Authorities Disrupt Password-Stealing Malware StealC Infrastructure in Global Operation
Europol and law enforcement partners across multiple countries have dealt a significant blow to the cybercriminal ecosystems powering StealC, Amadey, and SocGho...

Authorities Disrupt Stealer Malware StealC and Amadey Infrastructure in Global Operation
Europol and law enforcement partners across multiple countries have dealt a significant blow to the cybercriminal ecosystems powering StealC, Amadey, and SocGho...

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the...

Fake Income Tax Assessment Notice Delivers RAT-Like Malware to Windows Users
Cybercriminals are now using fake government tax notices to push dangerous malware onto Windows computers, and the tactic is proving alarmingly effective. A new...

Amadey, StealC, and SocGholist malware disrupted by ‘Operation Endgame’
A coordinated international law enforcement and private-sector operation has dismantled major parts of the infrastructure behind the SocGholish, Amadey, and Ste...

PoC Exploit Released for Microsoft Exchange Server Elevation of Privilege Vulnerability
A public proof-of-concept exploit is now available for CVE-2026-45504, a high‑severity server-side request forgery vulnerability in Microsoft Exchange Server th...

Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability
A large-scale cyber campaign targeting Laravel Livewire applications has been uncovered, with attackers exploiting a critical remote code execution (RCE) flaw t...

Critical Webmin Vulnerabilities Allow Attackers to Impersonate as Any User
Critical security flaws in Webmin have exposed systems to severe risks, allowing attackers to impersonate users, bypass authentication, and gain root-level cont...

Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash S...

White House Orders Federal Agencies to Migrate Systems to Post-Quantum Cryptography
The White House has issued a major executive order directing U.S. federal civilian agencies to migrate high‑value systems to post‑quantum cryptography (PQC), wi...

PoC Exploit Released for libssh2 Remote Code Execution Vulnerability
A public proof-of-concept (PoC) exploit for the critical libssh2 remote code execution vulnerability tracked as CVE-2026-55200 is now available, significantly i...