REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2281 reports · page 51 of 58
talos · tlp:amber · 5/7/2026, 6:00:40 PM
Unplug your way to better code Cybersecurity concepts — logs, packets, DNS exfiltration, and more — are usually intangible, and its practitioners are prone to mental fatigue, Amy takes a second to yell at you to go touch grass. Welcome to this week’s edition of the Threat Source newsletter. Hey, you. Yeah, you! The person endlessly scrolling or typing away at their computer. Did you touch grass today? It's just an expression, but if nature’s your thing, t…
Read original ↗https://blog.talosintelligence.com/unplug-your-way-to-better-codechainalysis · tlp:amber · 5/7/2026, 4:29:48 PM
Crypto Prediction Markets Explained: How the Blockchain Is Reshaping Forecasting TL;DR Crypto prediction markets use blockchain technology to create liquid platforms for forecasting and hedging real-world events, driving massive growth… The post Crypto Prediction Markets Explained: How the Blockchain Is Reshaping Forecasting appeared first on Chainalysis . Crypto Prediction Markets Explained Chainalysis Products Crypto Investigations Investigations Solutions Reactor I…
microsoft_mstic · tlp:amber · 5/7/2026, 4:00:00 PM
World Passkey Day: Advancing passwordless authentication This World Passkey Day, read how Microsoft is advancing passkey adoption to replace passwords, cut phishing risk, and deliver simpler, more secure sign-ins. The post World Passkey Day: Advancing passwordless authentication appeared first on Microsoft Security Blog . World Passkey Day is a chance to reflect on progress toward a shared goal: reducing our reliance on passwords and other phishable authentication methods b…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/07/world-passkey-day-advancing-passwordless-authenticationlwn_kernel · tlp:amber · 5/7/2026, 2:42:35 PM
[$] A new era for memory-management maintainership On April 21, Andrew Morton let it be known that he intends to begin stepping away from the maintainership of kernel's memory-management subsystem — a responsibility he has carried since before memory management was even seen as its own subsystem. At the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit, one of the first sessions in the memory-management track was devoted to how the maintainership would be man…
Read original ↗https://lwn.net/Articles/1070994lwn_kernel · tlp:amber · 5/7/2026, 2:10:52 PM
An update on KDE's Union style engine Arjen Hiemstra has published an article on the status of the Union project: a single system to support all of KDE's technologies used for styling applications. The work on Union's Breeze implementation has progressed to the point where it is very hard to distinguish whether or not you are running the Union version. We have also tested with a bunch of applications and made sure that any differences were fixed. So we are at a stage where w…
Read original ↗https://lwn.net/Articles/1071703lwn_kernel · tlp:amber · 5/7/2026, 1:10:37 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), Debian (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), Fedora (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns, pyOpenSSL, squid, vim, and xorg-x11-server-Xwayland), Mageia (graphicsmagick, kernel-linus, krb5-appl, libexif, libtiff, nano, nginx, ntfs-3g, opam, p…
Read original ↗https://lwn.net/Articles/1071700cisa_alerts · tlp:amber · 5/7/2026, 12:00:00 PM
MAXHUB Pivot Client Application View CSAF Summary Successful exploitation of this vulnerability may enable an attacker to access tenant email addresses and associated information in cleartext or cause a denial-of-service condition. The following versions of MAXHUB Pivot client application are affected: MAXHUB Pivot client application CVSS Vendor Equipment Vulnerabilities v3 7.3 MAXHUB MAXHUB Pivot client application Use of a Broken or Risky Cryptographic Algorithm Background…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-127-01cisa_alerts · tlp:amber · 5/7/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: …
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/07/cisa-adds-one-known-exploited-vulnerability-catalogsentinelone · tlp:amber · 5/7/2026, 10:00:17 AM
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion. Executive Summary SentinelLABS has identified PCPJack, a credential theft framework that worms across exposed cloud infrastructure and removes artifacts associated with TeamPCP, a threat actor persona who claimed several high-profile supply chain intrusions throughou…
Read original ↗https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scaleeset · tlp:amber · 5/7/2026, 8:51:19 AM
Fake call logs, real payments: How CallPhantom tricks Android users ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down Fake call logs, real payments: How CallPhantom tricks Android users Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY…
Read original ↗https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-userseset · tlp:amber · 5/7/2026, 7:00:00 AM
Fixing the password problem is as easy as 123456 How come it’s still possible to ‘secure’ an online account with a six-digit string? Fixing trivial passwords is as easy as 123456 Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital security resource c…
Read original ↗https://www.welivesecurity.com/en/cybersecurity/fixing-password-problem-as-easy-as-123456lwn_kernel · tlp:amber · 5/7/2026, 6:36:28 AM
Three stable kernel updates The 7.0.4 , 6.18.27 , and 6.12.86 stable kernels have been released; each contains another set of important fixes. Three stable kernel updates [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Three stable kernel updates [Posted May 7, 2026 by corbet] The 7.0.4 , 6.18.27 , and 6.12.86 stable kernels h…
Read original ↗https://lwn.net/Articles/1071568lwn_kernel · tlp:amber · 5/7/2026, 12:01:08 AM
[$] LWN.net Weekly Edition for May 7, 2026 Inside this week's LWN.net Weekly Edition: Front : LLMs and security; restartable sequences and TCMalloc; Fedora and GNOME bug reports; Prolly trees; Arm on s390. Briefs : NHS open source; Alpine outage; GCC 16.1; Incus 7.0 LTS; NetHack 5.0.0; PHP license; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1070466unit42 · tlp:amber · 5/7/2026, 12:00:53 AM
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42 . Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Me…
Read original ↗https://unit42.paloaltonetworks.com/captive-portal-zero-dayhuggingface_blog · tlp:amber · 5/6/2026, 7:06:55 PM
vLLM V0 to V1: Correctness Before Corrections in RL vLLM V0 to V1: Correctness Before Corrections in RL Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles vLLM V0 to V1: Correctness Before Corrections in RL Enterprise Article Published May 6, 2026 Upvote 6 Rafael Pardinas rafapi-snow Follow ServiceNow-AI Ehsan Kamalloo ehsk Follow ServiceNow-AI Migration Objective Failure Modes V1 Backend Fixes Logprob Semantics Runtime De…
Read original ↗https://huggingface.co/blog/ServiceNow-AI/correctness-before-correctionsmicrosoft_mstic · tlp:amber · 5/6/2026, 4:00:00 PM
Microsoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report Microsoft is excited to be named an Overall Leader, and the Market Leader in the Kuppinger Cole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report, as we see automation and AI as core components of the future of cybersecurity. The post Microsoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Cent…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/06/microsoft-named-an-overall-leader-in-kuppingercole-analysts-2026-emerging-ai-security-operations-center-soc-reportmicrosoft_mstic · tlp:amber · 5/6/2026, 3:20:32 PM
ClickFix campaign uses fake macOS utilities lures to deliver infostealers Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data. The post ClickFix campaign uses fake macOS utilities lures to deliver infostealers appeared first on Microsoft Security Blog . In this article Activity overview Mitigation and protection…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealerslwn_kernel · tlp:amber · 5/6/2026, 2:56:20 PM
[$] LLM-driven security reports disrupt coordinated disclosure Predictions that LLM tools would cause a surge in reports of security vulnerabilities have, unquestionably, borne out. As expected, maintainers are having to wade through more security reports than ever before; in addition, LLM tools are disrupting traditional-coordinated disclosure practices as well. The method of Copy Fail 's disclosure, in particular, left vendors, projects, and users scrambling. In addition, …
Read original ↗https://lwn.net/Articles/1070698lwn_kernel · tlp:amber · 5/6/2026, 1:53:58 PM
Incus 7.0 LTS released Version 7.0 of the Incus container and virtual-machine management system has been released. Notable changes in this release include the inclusion of a low-level backup API, the addition of basic S3 operations directly in Incus to replace the now-unmaintained MinIO project, as well as the removal of support for cgroups v1 and xtables (iptables/ip6tables/ebtables). This is a long-term-support (LTS) release, with support through June 2031. The first 2 yea…
Read original ↗https://lwn.net/Articles/1071469sentinelone · tlp:amber · 5/6/2026, 1:00:29 PM
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience Joe FitzPatrick reveals how consumer imports of networked devices pose a real security risk to small businesses and critical infrastructure alike. In this LABScon 25 presentation, Joe FitzPatrick explores how networked devices manufactured overseas have quietly become indispensable to everything from small-business prototyping labs to roadside infrastructure. He argues that the safeguard…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-please-connect-to-the-foreign-entity-to-enhance-your-user-experiencecisa_alerts · tlp:amber · 5/6/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Signi…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/06/cisa-adds-one-known-exploited-vulnerability-catalogchainalysis · tlp:amber · 5/6/2026, 11:50:40 AM
Where to Build: A Data-Driven Guide to Blockchain Infrastructure for TradFi Tokenization This blog is a preview of our forthcoming report, “The New Rails: How Digital Assets Are Reshaping the Foundations of… The post Where to Build: A Data-Driven Guide to Blockchain Infrastructure for TradFi Tokenization appeared first on Chainalysis . TradFi Tokenization: How to Choose the Right Blockchain - Chainalysis Chainalysis Products Crypto Investigations Investigations Soluti…
Read original ↗https://www.chainalysis.com/blog/blockchain-infrastructure-tradfi-tokenizationtalos · tlp:amber · 5/6/2026, 10:00:12 AM
Insights into the clustering and reuse of phone numbers in scam emails Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails. Cisco Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromis…
Read original ↗https://blog.talosintelligence.com/insights-into-the-clustering-and-reuse-of-phone-numbers-in-scam-emailstrend_micro · tlp:amber · 5/6/2026, 12:00:00 AM
Supporting the National Cyber Strategy: How TrendAI™ Helps A deeper look at the first three pillars and outlining how our capabilities directly support government agencies working to bring this strategy to life. Supporting the National Cyber Strategy: How TrendAI™ Helps | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focused portfolio of …
Read original ↗https://www.trendmicro.com/en_us/research/26/e/national-cyber-strategy.htmlhuggingface_blog · tlp:amber · 5/6/2026, 12:00:00 AM
Adding Benchmaxxer Repellant to the Open ASR Leaderboard Adding Benchmaxxer Repellant to the Open ASR Leaderboard Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Adding Benchmaxxer Repellant to the Open ASR Leaderboard Published May 6, 2026 Update on GitHub Upvote 12 +6 Eric Bezzam bezzam Follow Steven Zheng Steveeeeeeen Follow Eustache Le Bihan eustlb Follow Sergio Bruccoleri SBruccoleriAppen Follow AppenAIResearch Jea…
Read original ↗https://huggingface.co/blog/open-asr-leaderboard-private-dataunit42 · tlp:amber · 5/5/2026, 11:00:33 PM
Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42 . Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years Menu Tools ATOMs Security Consulting About Us Under Attack? …
Read original ↗https://unit42.paloaltonetworks.com/cve-2026-31431-copy-failars_security · tlp:amber · 5/5/2026, 7:46:15 PM
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack Daemon Tools users: It's time to check your machines for stealthy infections, stat. Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of its developer, researchers said Tuesday. Kaspersky, the security firm reporting the supply-chain attack, said it began on April 8 and remained active as of th…
Read original ↗https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attackcisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R Automation Runtime View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. An attacker who successfully exploited this vulnerability could cause the product to stop. The following versions of ABB B&R Automation Runtime are affected: Automation Runtime <6.5, >=6.5, =R4.93 (CVE-2025-11044, CVE-2025-11044) CVSS Vendor Equipment Vulnerabilities v3 6.8 A…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-03cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
Hitachi Energy PCM600 View CSAF Summary Hitachi Energy is aware of a vulnerability that affects the Hitachi Energy PCM600 product versions listed in this document. An attacker successfully exploiting this vulnerability can impact integrity of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy PCM600 are affected: PCM600 Legacy vers:PCM600_Legacy/<=2.11 (CVE-2018-1002208)…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-01cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
Johnson Controls CEM AC2000 View CSAF Summary Successful exploitation of this vulnerability could allow a standard user to escalate privileges on the host machine. The following versions of Johnson Controls CEM AC2000 are affected: CEM AC2000 12.0 (CVE-2026-21661) CEM AC2000 11.0 (CVE-2026-21661) CEM AC2000 10.6 (CVE-2026-21661) CVSS Vendor Equipment Vulnerabilities v3 8.7 Johnson Controls Inc. Johnson Controls CEM AC2000 Uncontrolled Search Path Element Background Critical …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-05cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R PVI View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions. The following versions of ABB B&R PVI are affected: PVI <6.5.0, 6.5.…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-02cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R Automation Studio View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol. The following versions of ABB B&R Automation Studio are affected: Aut…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-04trail_of_bits · tlp:amber · 5/5/2026, 11:00:00 AM
C/C++ checklist challenges, solved We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples : a deceptively simple Linux ping program and a Windows driver registry handler. If you found the inet_ntoa global buffer gotcha or the missing RTL_QUERY_REGISTRY_TYPECHECK flag, nice work. If not, here’s a full walkthrough of both challenges, plus a deep dive into how the Windows registry type confusion esc…
Read original ↗https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solvedtalos · tlp:amber · 5/5/2026, 10:00:30 AM
UAT-8302 and its box full of malware Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southe…
Read original ↗https://blog.talosintelligence.com/uat-8302talos · tlp:amber · 5/5/2026, 10:00:18 AM
CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.” Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented pl…
Read original ↗https://blog.talosintelligence.com/cloudz-pheno-infostealereset · tlp:amber · 5/5/2026, 8:55:27 AM
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games A rigged game: ScarCruft compromises gaming platform in a supply-chain attack Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH …
Read original ↗https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attacktrend_micro · tlp:amber · 5/5/2026, 12:00:00 AM
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads. InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Trend Micro (US) search clos…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.htmlmicrosoft_mstic · tlp:amber · 5/4/2026, 3:00:00 PM
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains. The post Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromis…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromisecheckpoint_research · tlp:amber · 5/4/2026, 1:49:31 PM
4th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 4th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Medtronic, a global medical device maker, has disclosed a cyberattack on its corporate IT systems. An unauthorized party accessed data, while the company reported no impact on products, operations, or financial systems. Threat […] The post 4th May – Threat Intelligence Report appeared first…
Read original ↗https://research.checkpoint.com/2026/4th-may-threat-intelligence-reporttrend_micro · tlp:amber · 5/4/2026, 12:00:00 AM
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, an…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.html