Latest IntelligencePage 5
Search by keyword →
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables...

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if succe...
Windows Device Identifier Feature Leads to Arrest of Scattered Spider Hacking Group Member
A persistent Microsoft device identifier was used to unravel the anonymity of an alleged Scattered Spider operator, according to a federal superseding complaint...
Windows Device Identifier Used to Arrest Scattered Spider Hacking Group Member
A persistent Microsoft device identifier was used to unravel the anonymity of an alleged Scattered Spider operator, according to a federal superseding complaint...

Fast-mcp-telegram Vulnerability Allow Attackers to Access Sensitive Files
A critical security flaw has been discovered in the fast-mcp-telegram package that could allow remote attackers to access sensitive Telegram session d...
'BusySnake' Infostealer Slithers into Critical Infrastructure Networks
A threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan....

uBlock Origin Chrome extension now blocks known ClickFix sites
uBlock Origin has quietly added protections against ClickFix attacks to its built-in badware filter list, helping block access to websites that attempt to trick...
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Attackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit ...

EFF-led coalition urges FTC to reject X’s bid to end privacy oversight
A coalition of 15 public-interest organizations is urging the U.S. Federal Trade Commission (FTC) to reject X Corp.'s request to terminate or weaken a 2022 priv...

Phishing poses as big-brand job interview to steal Google accounts
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google acc...

Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, givin...

ExpressVPN adds passkeys on password manager, passes security audit
ExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault impo...

Top 10 Best Next-Generation Firewall (NGFW) Solutions in 2026
If you’re shortlisting the best next-generation firewall for 2026, Palo Alto Networks’ PA-Series is our top overall pick for its App-ID application control and ...

Google Chrome extensions must meet new privacy standards by August 1
Google has announced a set of Chrome Web Store policy changes that tighten rules around extension data collection, improve transparency requirements, and prohib...

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog ...

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-con...

Vietnam arrests suspects behind HiAnime anime piracy service
Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shu...

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. ...

Microsoft Device Code Phishing Attack Steals Tokens Through Legitimate Login Page
A new phishing technique is tricking users into handing over their Microsoft account tokens without a fake website in sight. Attackers are exploiting a legitima...

Gemini Live Voice Session Flaw Enables Tool Injection Through Misconfigured Ephemeral Tokens
A security flaw in how developers implement Google’s Gemini Live API allows attackers to hijack browser-based AI voice sessions, override system prompts, ...