Category: Threat Intel
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
- ISC Stormcast For Monday, September 21st, 2026
- TerminalFix PNG Steganography
- Reverse-Engineering Flock Cameras
- WordPress Click2Shell flaw lets hackers execute PHP on the server
- CISA alerts of active exploitation of three Linux kernel flaws
- BigCommerce Alerts Merchants of Data Breach Linked to Ribon Apps
- Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
- Fake LastPass Authenticator Installer Uses Microsoft-Signed Driver to Disable Antivirus and EDR
- Researchers escape OpenAI Codex sandbox to run commands on host
- Malicious npm packages evade install-script defenses at runtime
- North Korean WaterPlum hackers infected 30,000 devices worldwide
- BragJack hijacks AI browser agents via malicious extensions
- Identity Visibility in 2026: The Foundation of Identity Security
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
- Anthropic's Claude Struggles with CAPTCHAs
- Friday Squid Blogging: On Squid Egg Sacs
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
- Gyazo Server Flaw Exposes 23.6 Million User Records