REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2306 reports · page 52 of 58
microsoft_mstic · tlp:amber · 5/6/2026, 4:00:00 PM
Microsoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report Microsoft is excited to be named an Overall Leader, and the Market Leader in the Kuppinger Cole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report, as we see automation and AI as core components of the future of cybersecurity. The post Microsoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Cent…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/06/microsoft-named-an-overall-leader-in-kuppingercole-analysts-2026-emerging-ai-security-operations-center-soc-reportmicrosoft_mstic · tlp:amber · 5/6/2026, 3:20:32 PM
ClickFix campaign uses fake macOS utilities lures to deliver infostealers Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data. The post ClickFix campaign uses fake macOS utilities lures to deliver infostealers appeared first on Microsoft Security Blog . In this article Activity overview Mitigation and protection…
lwn_kernel · tlp:amber · 5/6/2026, 2:56:20 PM
[$] LLM-driven security reports disrupt coordinated disclosure Predictions that LLM tools would cause a surge in reports of security vulnerabilities have, unquestionably, borne out. As expected, maintainers are having to wade through more security reports than ever before; in addition, LLM tools are disrupting traditional-coordinated disclosure practices as well. The method of Copy Fail 's disclosure, in particular, left vendors, projects, and users scrambling. In addition, …
Read original ↗https://lwn.net/Articles/1070698lwn_kernel · tlp:amber · 5/6/2026, 1:53:58 PM
Incus 7.0 LTS released Version 7.0 of the Incus container and virtual-machine management system has been released. Notable changes in this release include the inclusion of a low-level backup API, the addition of basic S3 operations directly in Incus to replace the now-unmaintained MinIO project, as well as the removal of support for cgroups v1 and xtables (iptables/ip6tables/ebtables). This is a long-term-support (LTS) release, with support through June 2031. The first 2 yea…
Read original ↗https://lwn.net/Articles/1071469sentinelone · tlp:amber · 5/6/2026, 1:00:29 PM
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience Joe FitzPatrick reveals how consumer imports of networked devices pose a real security risk to small businesses and critical infrastructure alike. In this LABScon 25 presentation, Joe FitzPatrick explores how networked devices manufactured overseas have quietly become indispensable to everything from small-business prototyping labs to roadside infrastructure. He argues that the safeguard…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-please-connect-to-the-foreign-entity-to-enhance-your-user-experiencecisa_alerts · tlp:amber · 5/6/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Signi…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/06/cisa-adds-one-known-exploited-vulnerability-catalogchainalysis · tlp:amber · 5/6/2026, 11:50:40 AM
Where to Build: A Data-Driven Guide to Blockchain Infrastructure for TradFi Tokenization This blog is a preview of our forthcoming report, “The New Rails: How Digital Assets Are Reshaping the Foundations of… The post Where to Build: A Data-Driven Guide to Blockchain Infrastructure for TradFi Tokenization appeared first on Chainalysis . TradFi Tokenization: How to Choose the Right Blockchain - Chainalysis Chainalysis Products Crypto Investigations Investigations Soluti…
Read original ↗https://www.chainalysis.com/blog/blockchain-infrastructure-tradfi-tokenizationtalos · tlp:amber · 5/6/2026, 10:00:12 AM
Insights into the clustering and reuse of phone numbers in scam emails Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails. Cisco Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromis…
Read original ↗https://blog.talosintelligence.com/insights-into-the-clustering-and-reuse-of-phone-numbers-in-scam-emailstrend_micro · tlp:amber · 5/6/2026, 12:00:00 AM
Supporting the National Cyber Strategy: How TrendAI™ Helps A deeper look at the first three pillars and outlining how our capabilities directly support government agencies working to bring this strategy to life. Supporting the National Cyber Strategy: How TrendAI™ Helps | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focused portfolio of …
Read original ↗https://www.trendmicro.com/en_us/research/26/e/national-cyber-strategy.htmlhuggingface_blog · tlp:amber · 5/6/2026, 12:00:00 AM
Adding Benchmaxxer Repellant to the Open ASR Leaderboard Adding Benchmaxxer Repellant to the Open ASR Leaderboard Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Adding Benchmaxxer Repellant to the Open ASR Leaderboard Published May 6, 2026 Update on GitHub Upvote 12 +6 Eric Bezzam bezzam Follow Steven Zheng Steveeeeeeen Follow Eustache Le Bihan eustlb Follow Sergio Bruccoleri SBruccoleriAppen Follow AppenAIResearch Jea…
Read original ↗https://huggingface.co/blog/open-asr-leaderboard-private-dataunit42 · tlp:amber · 5/5/2026, 11:00:33 PM
Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42 . Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years Menu Tools ATOMs Security Consulting About Us Under Attack? …
Read original ↗https://unit42.paloaltonetworks.com/cve-2026-31431-copy-failars_security · tlp:amber · 5/5/2026, 7:46:15 PM
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack Daemon Tools users: It's time to check your machines for stealthy infections, stat. Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of its developer, researchers said Tuesday. Kaspersky, the security firm reporting the supply-chain attack, said it began on April 8 and remained active as of th…
Read original ↗https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attackcisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R Automation Runtime View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. An attacker who successfully exploited this vulnerability could cause the product to stop. The following versions of ABB B&R Automation Runtime are affected: Automation Runtime <6.5, >=6.5, =R4.93 (CVE-2025-11044, CVE-2025-11044) CVSS Vendor Equipment Vulnerabilities v3 6.8 A…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-03cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
Hitachi Energy PCM600 View CSAF Summary Hitachi Energy is aware of a vulnerability that affects the Hitachi Energy PCM600 product versions listed in this document. An attacker successfully exploiting this vulnerability can impact integrity of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy PCM600 are affected: PCM600 Legacy vers:PCM600_Legacy/<=2.11 (CVE-2018-1002208)…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-01cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
Johnson Controls CEM AC2000 View CSAF Summary Successful exploitation of this vulnerability could allow a standard user to escalate privileges on the host machine. The following versions of Johnson Controls CEM AC2000 are affected: CEM AC2000 12.0 (CVE-2026-21661) CEM AC2000 11.0 (CVE-2026-21661) CEM AC2000 10.6 (CVE-2026-21661) CVSS Vendor Equipment Vulnerabilities v3 8.7 Johnson Controls Inc. Johnson Controls CEM AC2000 Uncontrolled Search Path Element Background Critical …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-05cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R PVI View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions. The following versions of ABB B&R PVI are affected: PVI <6.5.0, 6.5.…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-02cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R Automation Studio View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol. The following versions of ABB B&R Automation Studio are affected: Aut…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-04trail_of_bits · tlp:amber · 5/5/2026, 11:00:00 AM
C/C++ checklist challenges, solved We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples : a deceptively simple Linux ping program and a Windows driver registry handler. If you found the inet_ntoa global buffer gotcha or the missing RTL_QUERY_REGISTRY_TYPECHECK flag, nice work. If not, here’s a full walkthrough of both challenges, plus a deep dive into how the Windows registry type confusion esc…
Read original ↗https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solvedtalos · tlp:amber · 5/5/2026, 10:00:30 AM
UAT-8302 and its box full of malware Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southe…
Read original ↗https://blog.talosintelligence.com/uat-8302talos · tlp:amber · 5/5/2026, 10:00:18 AM
CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.” Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented pl…
Read original ↗https://blog.talosintelligence.com/cloudz-pheno-infostealereset · tlp:amber · 5/5/2026, 8:55:27 AM
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games A rigged game: ScarCruft compromises gaming platform in a supply-chain attack Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH …
Read original ↗https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attacktrend_micro · tlp:amber · 5/5/2026, 12:00:00 AM
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads. InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Trend Micro (US) search clos…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.htmlmicrosoft_mstic · tlp:amber · 5/4/2026, 3:00:00 PM
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains. The post Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromis…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromisecheckpoint_research · tlp:amber · 5/4/2026, 1:49:31 PM
4th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 4th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Medtronic, a global medical device maker, has disclosed a cyberattack on its corporate IT systems. An unauthorized party accessed data, while the company reported no impact on products, operations, or financial systems. Threat […] The post 4th May – Threat Intelligence Report appeared first…
Read original ↗https://research.checkpoint.com/2026/4th-may-threat-intelligence-reporttrend_micro · tlp:amber · 5/4/2026, 12:00:00 AM
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, an…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.htmlmicrosoft_mstic · tlp:amber · 5/2/2026, 3:06:08 AM
CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments A high-severity Linux vulnerability, “Copy Fail” (CVE-2026-31431), enables root privilege escalation across cloud environments and Kubernetes workloads. With a working exploit already in the wild, organizations should act quickly to detect, mitigate, and reduce risk. The post CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud env…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalationunit42 · tlp:amber · 5/2/2026, 12:10:33 AM
The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) appeared first on Unit 42 . The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) Menu Tools ATOMs Security Consulting About Us Under Attack? English English Japanese …
Read original ↗https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacksunit42 · tlp:amber · 5/1/2026, 11:00:13 PM
Essential Data Sources for Detection Beyond the Endpoint Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42 . Essential Data Sources for Detection Beyond the Endpoint Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Essential Data Sources for Detection Be…
Read original ↗https://unit42.paloaltonetworks.com/detection-beyond-the-endpointars_security · tlp:amber · 5/1/2026, 7:12:26 PM
Ubuntu infrastructure has been down for more than a day The outage has hampered communication concerning a critical vulnerability that gives root. Servers operated by Ubuntu and its parent company Canonical were knocked offline on Thursday morning and have remained down ever since, a situation that’s preventing the OS provider from communicating normally following the botched disclosure of a major vulnerability. Attempts to connect to most Ubuntu and Canonical webpages and …
Read original ↗https://arstechnica.com/security/2026/05/ubuntu-infrastructure-has-been-down-for-more-than-a-dayars_security · tlp:amber · 5/1/2026, 3:32:27 PM
GPT-5.5 matches heavily hyped Mythos Preview in new cybersecurity tests New results suggest Mythos' cyber threat isn't "a breakthrough specific to one model." Last month, Anthropic made a big deal about the supposedly outsize cybersecurity threat represented by its Mythos Preview model, leading the company to restrict the initial release to “critical industry partners.” But new research from the UK's AI Security Institute (AISI) suggests that OpenAI's GPT-5.5, which launche…
Read original ↗https://arstechnica.com/ai/2026/05/amid-mythos-hyped-cybersecurity-prowess-researchers-find-gpt-5-5-is-just-as-goodmicrosoft_mstic · tlp:amber · 5/1/2026, 3:00:00 PM
Microsoft Agent 365, now generally available, expands capabilities and integrations Today we’re announcing the general availability of Agent 365, plus previews of new capabilities to discover and manage shadow AI agents, including local agents like OpenClaw and Claude Code. The post Microsoft Agent 365, now generally available, expands capabilities and integrations appeared first on Microsoft Security Blog . Microsoft Agent 365 Now generally available for commercial custom…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrationscisa_alerts · tlp:amber · 5/1/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/1/2026, 12:00:00 PM
Careful Adoption of Agentic AI Services CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems. This guide outlines key security challenges and risks associated with agentic AI, and provides actionable steps for designing, deploying, and operating these systems safely. It helps organiza…
Read original ↗https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-servicesunit42 · tlp:amber · 4/30/2026, 10:00:57 PM
That AI Extension Helping You Write Emails? It’s Reading Them First Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42 . That AI Extension Helping You Write Emails? It’s Reading Them First Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Res…
Read original ↗https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensionsars_security · tlp:amber · 4/30/2026, 8:20:48 PM
The most severe Linux threat to surface in years catches the world flat-footed CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more. Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices. The vulnerability and exploit code that exploits i…
Read original ↗https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scramblestalos · tlp:amber · 4/30/2026, 6:00:07 PM
Great responsibility, without great power In this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity. Welcome to this week’s edition of the Threat Source newsletter.  As I’m writing this, today (April 28) is International Superhero Day. If you don’t know…
Read original ↗https://blog.talosintelligence.com/great-responsibility-without-great-powermicrosoft_mstic · tlp:amber · 4/30/2026, 4:00:00 PM
What’s new, updated, or recently released in Microsoft Security Stay ahead of emerging threats with Microsoft’s newest security innovations and updates, delivered through the In the Loop series. The post What’s new, updated, or recently released in Microsoft Security appeared first on Microsoft Security Blog . New capabilities in Microsoft Agent 365; new Microsoft Defender and GitHub integration At Microsoft, security innovations are purpose-built to help every organization…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/04/30/whats-new-updated-or-recently-released-in-microsoft-securitymicrosoft_mstic · tlp:amber · 4/30/2026, 3:00:00 PM
Email threat landscape: Q1 2026 trends and insights In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics. The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog . In this article Tycoon2FA disruption impact QR code phi…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insightscisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB AWIN Gateways View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely reboot the device or complete an unauthenticated query to reveal system configuration, including sensitive details. The following versions of ABB AWIN Gateways are affected: ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2 2.0-0 ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2 2.0-1 ABB AWIN Firmware (1.2-0) installed on A…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-05cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB Edgenius Management Portal View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to send a specially crafted message to the system node allowing the attacker to install and run arbitrary code, uninstall applications, and modify the configuration of installed applications. The following versions of ABB Edgenius Management Portal are affected: Edgenius Management Portal 3.2.0.0|3.2.1.1 CVSS Vendor Equipment Vulnerabilities v3 9.6 ABB ABB E…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-03