Intelligence Feed
- Canva hacked via vendor’s Salesforce instance; Other customers affected as well
- FBI Hack Exposed FBI's Own Hacking Unit
- ShinyHunters claims FBI breach was revenge for false report
- Fake Claude Max giveaway hides a Google account phishing trap
- Device Code Phishing: How Scammers Gain Account Access
- Reimagining the SOC for the agentic era in Microsoft Defender
- Research on Models Engaging in Genie-Like Behavior
- Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
- New RemControl Android banking malware targets users in Europe and Canada
- Placeholder domain used in dev docs now serves ClickFix attacks
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
- GitLab Issue Email Address Leak Enables Code Push and CI Execution
- Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
- ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability
- Introducing CAIRN: Frontier Tracking for AI-Integrated Malware
- The Closed Quorum: Inside the first reported autonomous AI C2 implant
- Israeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companies
- ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data
- Elsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign
- Researchers used Claude to hack OpenAI