Category: Threat Intel
- ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
- Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
- Weekly Update 522: Live From Oslo with Scott Helme
- ShinyHunters claims FBI breach was revenge for false report
- Fake Claude Max giveaway hides a Google account phishing trap
- Device Code Phishing: How Scammers Gain Account Access
- Reimagining the SOC for the agentic era in Microsoft Defender
- Research on Models Engaging in Genie-Like Behavior
- Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
- Placeholder domain used in dev docs now serves ClickFix attacks
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
- GitLab Issue Email Address Leak Enables Code Push and CI Execution
- Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
- Elsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign
- The Truth about GET and HTTP Standards
- Macfinger ClickFix Campaign (Sep 22)
- ISC Stormcast For Wednesday, September 23rd, 2026
- Unmasking EvilTokens: Getting to the root of device code phishing
- Chinese Hackers Exploit WordPress and Zyxel Flaws to Steal Government Data
- Rogue external MFA providers can steal passwords during logins