REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 40 of 57
microsoft_mstic · tlp:amber · 5/29/2026, 4:00:00 PM
Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. The post Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection appeared first on Microsoft Security Blog . As threats become more coordinated and faster to execute, endpoint protection has become the proving ground for modern defense. For the seventh consecutive t…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/29/microsoft-is-named-a-leader-in-the-2026-gartner-magic-quadrant-for-endpoint-protectionlwn_kernel · tlp:amber · 5/29/2026, 2:29:18 PM
[$] A loadable crypto module for FIPS certification Many organizations require US Federal Information Processing Standard (FIPS) certification of the crypto code they are running. The certification process is lengthy, but the bigger problem is that the way the crypto subsystem is built into the kernel makes the result unable to be reused across kernel updates. I have proposed a patch series that decouples the crypto subsystem into a standalone loadable module, allowing a cer…
lwn_kernel · tlp:amber · 5/29/2026, 2:09:30 PM
Nesbitt: Protestware for coding agents Andrew Nesbitt has written a blog post detailing a recent incident with the jqwik library for property-based testing in Java. On May 25, the 1.10.0 release of jqwik included a change that attempts to instruct coding agents to disregard previous instructions and delete jqwik tests and code. I think this is a new class of supply-chain input worth keeping an eye on, mostly because of how little of the existing tooling has any opinion …
Read original ↗https://lwn.net/Articles/1075315lwn_kernel · tlp:amber · 5/29/2026, 1:12:08 PM
Security updates for Friday Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, cockpit, firefox, flatpak, httpd, kernel, and kernel-rt), Debian (kernel, kitty, lemonldap-ng, nagios4, python-flask-httpauth, and roundcube), Fedora (CImg, gmic, haveged, jpegxl, kernel, libpng, mapserver, mingw-qt6-qtsvg, openbao, perl-Sereal, perl-Sereal-Decoder, perl-Sereal-Encoder, and podofo), Mageia (bind, graphicsmagick, microcode, nginx, packages, perl-Catalyst-Plugin-Aut…
Read original ↗https://lwn.net/Articles/1075310cisa_alerts · tlp:amber · 5/29/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of …
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/29/cisa-adds-one-known-exploited-vulnerability-catalogeset · tlp:amber · 5/29/2026, 7:30:00 AM
This month in security with Tony Anscombe – May 2026 edition In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit This month in security with Tony Anscombe – May 2026 edition Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH…
Read original ↗https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-may-2026snyk_blog · tlp:amber · 5/29/2026, 4:00:00 AM
Fix SCA issues at scale in your terminal with Snyk Remediation Agent in the CLI Stop security backlogs. Snyk's Remediation Agent in the CLI pairs AI reasoning with Snyk security intelligence to fix SCA issues at scale directly in your terminal. Fix SCA issues at scale in your terminal with Snyk Remediation Agent in the CLI | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platfo…
Read original ↗https://snyk.io/blog/snyk-remediation-agent-in-the-clisnyk_blog · tlp:amber · 5/29/2026, 4:00:00 AM
How Relay Network Adopted AI Coding Securely and Built the Foundation for Agentic Development See how Relay Network securely adopted AI coding with Snyk and GitHub Copilot, implementing "secure at inception" to reduce vulnerabilities and accelerate development. How Relay Network Adopted AI Coding Securely and Built the Foundation for Agentic Development | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Mod…
Read original ↗https://snyk.io/blog/relay-network-ai-coding-securely-coagentic-developmentmicrosoft_mstic · tlp:amber · 5/29/2026, 3:04:52 AM
Typosquatted npm packages used to steal cloud and CI/CD secrets The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt related activity. The post Typosquatted npm packages used to steal cloud and CI/CD secrets appeared first on Microsoft Security Blog . In this article Attack …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/28/typosquatted-npm-packages-used-steal-cloud-ci-cd-secretshuggingface_blog · tlp:amber · 5/29/2026, 12:00:00 AM
Profiling in PyTorch (Part 1): A Beginner's Guide to torch.profiler Profiling in PyTorch (Part 1): A Beginner's Guide to torch.profiler Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back …
Read original ↗https://huggingface.co/blog/torch-profilerlwn_kernel · tlp:amber · 5/28/2026, 10:16:27 PM
Rust 1.96.0 released Version 1.96.0 of the Rust programming language has been released. Changes include a new set of Copy -implementing Range types, assertions with pattern matching, a number of stabilized APIs, and two Cargo vulnerability fixes. Rust 1.96.0 released [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Rust 1.96.0 …
Read original ↗https://lwn.net/Articles/1075180ars_security · tlp:amber · 5/28/2026, 8:29:53 PM
Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code Undisclosed addition in jqwik instructed AI coding agents to delete app output. The controversy over vibe coding reached a new high this week after a developer added hidden instructions to his open source Java testing app to sabotage projects performed by AI coding agents. The instructions were added to jqwik , a test engine for JUnit 5, a platform for testing Java virtual machine frameworks. O…
Read original ↗https://arstechnica.com/security/2026/05/fed-up-with-vibe-coders-dev-sneaks-data-nuking-prompt-injection-into-their-codetalos · tlp:amber · 5/28/2026, 6:00:27 PM
Less panic patching, more precision In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter. Welcome to this week's edition of the Threat Source newsletter.  Recently, Martin closed his introduction with a  warning : Ready or not, the time of much patching is coming. I've been chewing on that one for a while because I&ap…
Read original ↗https://blog.talosintelligence.com/less-panic-patching-more-precisionlwn_kernel · tlp:amber · 5/28/2026, 5:58:12 PM
Górny: why Gentoo? Gentoo developer Michał Górny has written a lengthy article explaining the philosophy and purpose of the Gentoo Linux distribution, in response to a thread on Mastodon : Gentoo is a source-first distribution, which means the primary method of installing software is to build it from source. Of course, that doesn't mean manually building stuff, following some kind of how-to: finding all the dependencies, installing them manually, going through a series of ma…
Read original ↗https://lwn.net/Articles/1075148microsoft_mstic · tlp:amber · 5/28/2026, 3:00:00 PM
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target. The post The Gentlemen ransomware: Dissecting a self-propagating Go…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptorlwn_kernel · tlp:amber · 5/28/2026, 2:29:19 PM
[$] Policies for merging new filesystems In a filesystem-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , Amir Goldstein wanted to discuss his proposed documentation on adding new filesystems to the kernel. There are a number of unmaintained and untestable filesystems already in the kernel, which are a burden to VFS-layer developers who are trying to make sweeping changes, such as switching to folios and the "new" mount API. Goldstein'…
Read original ↗https://lwn.net/Articles/1074557lwn_kernel · tlp:amber · 5/28/2026, 1:30:09 PM
IBM's "Project Lightwell" IBM has sent out a press release touting a claimed $5 billion investment into an operation called Project Lightwell: Project Lightwell will establish a trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale. The clearinghouse will serve as a security coordination layer, using advanced AI capabilities to validate and test fixes across an unprecedented volume of open source code. Th…
Read original ↗https://lwn.net/Articles/1075065cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
MacGregor Voyage Data Recorder (VDR) G4e View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker gaining administrator access to the device. The following versions of MacGregor Voyage Data Recorder (VDR) G4e are affected: MacGregor Voyage Data Recorder (VDR) G4e <V5.250 CVSS Vendor Equipment Vulnerabilities v3 8.3 Danelec MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials, Insufficiently Protected Credentials, Use of…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-01cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
ABB EIBPORT View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmware update is available that resolves these privately reported vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could access sensitive information stored inside the device and can change the configuration of the device. The following versions of ABB EIBPORT are …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-03cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter View CSAF Summary Successful exploitation of this vulnerability could result in an attacker gaining administrator access to the device. The following versions of Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter are affected: USR-W610 RS232/485 to Wi-Fi/Ethernet Converter 7.03T.07 CVSS Vendor Equipment Vulnerabilities v3 9.8 Jinan USR IOT Technology Lim…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-02cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
XCharge C6 View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain administrator rights or execute code on the affected device. The following versions of XCharge C6 are affected: C6 CVSS Vendor Equipment Vulnerabilities v3 9.8 XCharge XCharge C6 Download of Code Without Integrity Check, Stack-based Buffer Overflow, Initialization of a Resource with an Insecure Default Background Critical Infrastructure Sectors: Transportation System…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-08cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
ABB Busch-Welcome 2 Wire Door Opener Actuator View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could gain physical, unauthorized access to a Building where the product is installed The following versions of ABB Busch-Welcome 2 Wire Door Opener Actuator are affected: Switch Actuator 4 DU vers:all/* Switch actuator, door/light 4 DU vers:all/* CVSS …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-04cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
Fourth Frontier Frontier X Mobile Application, Frontier X2 View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm. The following versions of Fourth Frontier Frontier X Mobile Application, Frontier X2 are affected: Frontier X Android application vers<v15.0.0 Frontier X IOS application vers<v2…
Read original ↗https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-148-01cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
Schneider Electric EcoStruxure Machine Expert HVAC View CSAF Summary Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC/) product is a programming software for Modicon M171-M172 logic controllers. Failure to apply the remediation provided below may risk in revealing sensitive information, which could result in disclosing protecte…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-07cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
KMW CCTV Security Cameras View CSAF Summary Successful exploitation of this vulnerability may grant full unauthorized access to camera feeds and settings. The following versions of KMW CCTV Security Cameras are affected: KM-IP521 IPCAM_V4.04.91.230307 KM-IP421 IPCAM_V4.04.53.210416 CVSS Vendor Equipment Vulnerabilities v3 9.1 KMW KMW CCTV Security Cameras Unverified Password Change Background Critical Infrastructure Sectors: Commercial Facilities, Government Services a…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-06cisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
Supply Chain Compromises Impact Nx Console and GitHub Repositories CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abus…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositoriescisa_alerts · tlp:amber · 5/28/2026, 12:00:00 PM
CP Plus 8 Ch. Network Video Recorder View CSAF Summary Successful exploitation of this vulnerability allows an attacker's malicious script to execute in the browser of any authenticated user or administrator who accesses the affected interface. This could lead to compromise of user sessions, execution of unauthorized actions with the victim's privileges, exposure or manipulation of sensitive data, and degradation of overall system integrity. The following versions of CP Plus…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-05unit42 · tlp:amber · 5/28/2026, 10:00:53 AM
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42 . 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Resear…
Read original ↗https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surfacetalos · tlp:amber · 5/28/2026, 10:00:52 AM
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format. Over the last decade, DICOM parsing has become an active research topic. The reason is simple: DICOM is both critical and complicated. Hospitals rely on DICOM-based PACS systems, and those systems often automatically ingest files re…
Read original ↗https://blog.talosintelligence.com/dicom-pydicom-gdcm-and-orthanc-a-technical-tour-of-what-really-happens-in-the-heapeset · tlp:amber · 5/28/2026, 8:45:00 AM
ESET APT Activity Report Q4 2025–Q1 2026 An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026 ESET APT Activity Report Q4 2025–Q1 2026 Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digit…
Read original ↗https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026unit42 · tlp:amber · 5/27/2026, 10:00:46 PM
Out of the Crypt: The Evolving Cyber Extortion Economy Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42 . Out of the Crypt: The Evolving Cyber Extortion Economy Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Out of the Crypt: The Evolving Cyber Exto…
Read original ↗https://unit42.paloaltonetworks.com/cyber-extortion-economyars_security · tlp:amber · 5/27/2026, 8:56:03 PM
Websites have a new way to spy on visitors: Analyzing their SSD activity Telltale SSD activity can be measured in the browser using simple JavaScript. Over the decades, there has been no shortage of sites using clever techniques to covertly track visitors’ browsing histories , device fingerprints , and keystrokes and mouse movements in real time. Even Meta and Yandex were recently caught joining in the privacy-invasive free-for-all . Now sites have a new way to spy on their…
Read original ↗https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activitytalos · tlp:amber · 5/27/2026, 2:00:14 PM
MediaArea heap-based buffer overflow vulnerabilities Talos researchers find 4 heap-based buffer overflow vulnerabilities in MediaArea's MediaInfoLib. Cisco Talos’ Vulnerability Discovery & Research team recently disclosed four vulnerabilities in MediaArea MediaInfoLib library. The vulnerabilities mentioned in this blog post have been patched by their respective vendor, in adherence to Cisco’s third-party vulnerability disclosure policy . For Snort coverage…
Read original ↗https://blog.talosintelligence.com/mediaarea-heap-based-buffer-overflow-vulnerabilitiescisa_alerts · tlp:amber · 5/27/2026, 12:00:00 PM
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-45321 TanStack Unspecified Vulnerability CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability These types of vulnerabilities are freq…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/27/cisa-adds-three-known-exploited-vulnerabilities-catalogchainalysis · tlp:amber · 5/27/2026, 11:55:07 AM
The New Compliance Floor: Organizations are Adopting Stronger Than Ever Monitoring Practices This blog is a preview of our forthcoming report, “The New Rails: How Digital Assets Are Reshaping the Foundations of… The post The New Compliance Floor: Organizations are Adopting Stronger Than Ever Monitoring Practices appeared first on Chainalysis . Crypto Compliance Programs in 2026 - Chainalysis Chainalysis Products Crypto Investigations Investigations Solutions Rea…
Read original ↗https://www.chainalysis.com/blog/crypto-compliance-program-benchmark-2026talos · tlp:amber · 5/27/2026, 10:00:47 AM
Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake EvidenceForge generates high-quality, realistic, and consistent datasets across multiple log formats, enabling teams to effectively train personnel and validate detection models without the need for complex manual simulations. Security teams need high-quality, labeled datasets to train threat hunters and incident responders, validate detection logic, and develop robust analytic …
Read original ↗https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-fakeeset · tlp:amber · 5/27/2026, 8:50:00 AM
What to consider before asking an AI chatbot for health advice Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe. What to consider before asking an AI chatbot for health advice Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts…
Read original ↗https://www.welivesecurity.com/en/privacy/what-consider-asking-ai-chatbot-health-advicesnyk_blog · tlp:amber · 5/27/2026, 4:00:00 AM
Continuous Offensive Security: The Line We've Been Walking Snyk's Continuous Offensive Security unifies DAST, AI pentesting, and agent red teaming to find exploitable flaws — not just bugs — before attackers do. Here's why lineage matters. Snyk Continuous Offensive Security | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure…
Read original ↗https://snyk.io/blog/continuous-offensive-securitychainalysis · tlp:amber · 5/27/2026, 1:11:23 AM
U.K. Sanctions 18 Entities and Persons for Evading Russian Trade Blockades Summary The U.K.’s Foreign, Commonwealth and Development Office (FCDO) sanctioned 18 cryptocurrency exchanges, payment providers, and individuals for helping Russia… The post U.K. Sanctions 18 Entities and Persons for Evading Russian Trade Blockades appeared first on Chainalysis . UK Sanctions Crypto Companies With Russia Ties Chainalysis Products Crypto Investigations Investigations Solutions …
Read original ↗https://www.chainalysis.com/blog/uk-sanctions-crypto-entities-russian-trade-blockade-evasion-may-2026huggingface_blog · tlp:amber · 5/27/2026, 12:00:00 AM
Reachy Mini goes fully local Reachy Mini goes fully local Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles Reachy Mini goes fully local Published May 27, 2026 Update on GitHub U…
Read original ↗https://huggingface.co/blog/local-reachy-mini-conversation