REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2331 reports · page 53 of 59
cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R PVI View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions. The following versions of ABB B&R PVI are affected: PVI <6.5.0, 6.5.…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-02cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R Automation Studio View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol. The following versions of ABB B&R Automation Studio are affected: Aut…
trail_of_bits · tlp:amber · 5/5/2026, 11:00:00 AM
C/C++ checklist challenges, solved We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples : a deceptively simple Linux ping program and a Windows driver registry handler. If you found the inet_ntoa global buffer gotcha or the missing RTL_QUERY_REGISTRY_TYPECHECK flag, nice work. If not, here’s a full walkthrough of both challenges, plus a deep dive into how the Windows registry type confusion esc…
Read original ↗https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solvedtalos · tlp:amber · 5/5/2026, 10:00:30 AM
UAT-8302 and its box full of malware Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southe…
Read original ↗https://blog.talosintelligence.com/uat-8302talos · tlp:amber · 5/5/2026, 10:00:18 AM
CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.” Cisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented pl…
Read original ↗https://blog.talosintelligence.com/cloudz-pheno-infostealereset · tlp:amber · 5/5/2026, 8:55:27 AM
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games A rigged game: ScarCruft compromises gaming platform in a supply-chain attack Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH …
Read original ↗https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attacktrend_micro · tlp:amber · 5/5/2026, 12:00:00 AM
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads. InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Trend Micro (US) search clos…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.htmlmicrosoft_mstic · tlp:amber · 5/4/2026, 3:00:00 PM
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains. The post Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromis…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromisecheckpoint_research · tlp:amber · 5/4/2026, 1:49:31 PM
4th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 4th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Medtronic, a global medical device maker, has disclosed a cyberattack on its corporate IT systems. An unauthorized party accessed data, while the company reported no impact on products, operations, or financial systems. Threat […] The post 4th May – Threat Intelligence Report appeared first…
Read original ↗https://research.checkpoint.com/2026/4th-may-threat-intelligence-reporttrend_micro · tlp:amber · 5/4/2026, 12:00:00 AM
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, an…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.htmlmicrosoft_mstic · tlp:amber · 5/2/2026, 3:06:08 AM
CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments A high-severity Linux vulnerability, “Copy Fail” (CVE-2026-31431), enables root privilege escalation across cloud environments and Kubernetes workloads. With a working exploit already in the wild, organizations should act quickly to detect, mitigate, and reduce risk. The post CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud env…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalationunit42 · tlp:amber · 5/2/2026, 12:10:33 AM
The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) appeared first on Unit 42 . The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) Menu Tools ATOMs Security Consulting About Us Under Attack? English English Japanese …
Read original ↗https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacksunit42 · tlp:amber · 5/1/2026, 11:00:13 PM
Essential Data Sources for Detection Beyond the Endpoint Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42 . Essential Data Sources for Detection Beyond the Endpoint Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Essential Data Sources for Detection Be…
Read original ↗https://unit42.paloaltonetworks.com/detection-beyond-the-endpointars_security · tlp:amber · 5/1/2026, 7:12:26 PM
Ubuntu infrastructure has been down for more than a day The outage has hampered communication concerning a critical vulnerability that gives root. Servers operated by Ubuntu and its parent company Canonical were knocked offline on Thursday morning and have remained down ever since, a situation that’s preventing the OS provider from communicating normally following the botched disclosure of a major vulnerability. Attempts to connect to most Ubuntu and Canonical webpages and …
Read original ↗https://arstechnica.com/security/2026/05/ubuntu-infrastructure-has-been-down-for-more-than-a-dayars_security · tlp:amber · 5/1/2026, 3:32:27 PM
GPT-5.5 matches heavily hyped Mythos Preview in new cybersecurity tests New results suggest Mythos' cyber threat isn't "a breakthrough specific to one model." Last month, Anthropic made a big deal about the supposedly outsize cybersecurity threat represented by its Mythos Preview model, leading the company to restrict the initial release to “critical industry partners.” But new research from the UK's AI Security Institute (AISI) suggests that OpenAI's GPT-5.5, which launche…
Read original ↗https://arstechnica.com/ai/2026/05/amid-mythos-hyped-cybersecurity-prowess-researchers-find-gpt-5-5-is-just-as-goodmicrosoft_mstic · tlp:amber · 5/1/2026, 3:00:00 PM
Microsoft Agent 365, now generally available, expands capabilities and integrations Today we’re announcing the general availability of Agent 365, plus previews of new capabilities to discover and manage shadow AI agents, including local agents like OpenClaw and Claude Code. The post Microsoft Agent 365, now generally available, expands capabilities and integrations appeared first on Microsoft Security Blog . Microsoft Agent 365 Now generally available for commercial custom…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrationscisa_alerts · tlp:amber · 5/1/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/1/2026, 12:00:00 PM
Careful Adoption of Agentic AI Services CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems. This guide outlines key security challenges and risks associated with agentic AI, and provides actionable steps for designing, deploying, and operating these systems safely. It helps organiza…
Read original ↗https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-servicesunit42 · tlp:amber · 4/30/2026, 10:00:57 PM
That AI Extension Helping You Write Emails? It’s Reading Them First Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42 . That AI Extension Helping You Write Emails? It’s Reading Them First Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Res…
Read original ↗https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensionsars_security · tlp:amber · 4/30/2026, 8:20:48 PM
The most severe Linux threat to surface in years catches the world flat-footed CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more. Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices. The vulnerability and exploit code that exploits i…
Read original ↗https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scramblestalos · tlp:amber · 4/30/2026, 6:00:07 PM
Great responsibility, without great power In this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity. Welcome to this week’s edition of the Threat Source newsletter. As I’m writing this, today (April 28) is International Superhero Day. If you don’t know…
Read original ↗https://blog.talosintelligence.com/great-responsibility-without-great-powermicrosoft_mstic · tlp:amber · 4/30/2026, 4:00:00 PM
What’s new, updated, or recently released in Microsoft Security Stay ahead of emerging threats with Microsoft’s newest security innovations and updates, delivered through the In the Loop series. The post What’s new, updated, or recently released in Microsoft Security appeared first on Microsoft Security Blog . New capabilities in Microsoft Agent 365; new Microsoft Defender and GitHub integration At Microsoft, security innovations are purpose-built to help every organization…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/04/30/whats-new-updated-or-recently-released-in-microsoft-securitymicrosoft_mstic · tlp:amber · 4/30/2026, 3:00:00 PM
Email threat landscape: Q1 2026 trends and insights In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics. The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog . In this article Tycoon2FA disruption impact QR code phi…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insightscisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB AWIN Gateways View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely reboot the device or complete an unauthenticated query to reveal system configuration, including sensitive details. The following versions of ABB AWIN Gateways are affected: ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2 2.0-0 ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2 2.0-1 ABB AWIN Firmware (1.2-0) installed on A…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-05cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB Edgenius Management Portal View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to send a specially crafted message to the system node allowing the attacker to install and run arbitrary code, uninstall applications, and modify the configuration of installed applications. The following versions of ABB Edgenius Management Portal are affected: Edgenius Management Portal 3.2.0.0|3.2.1.1 CVSS Vendor Equipment Vulnerabilities v3 9.6 ABB ABB E…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-03cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB PCM600 View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to send specially crafted messages to the system node resulting in execution of arbitrary code. The following versions of ABB PCM600 are affected: PCM600 >=1.5|<=2.13 CVSS Vendor Equipment Vulnerabilities v3 4.4 ABB ABB PCM600 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Critical Manufactu…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-02cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB Ability OPTIMAX View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to bypass user authentication on OPTIMAX installations that make use of the Azure Active Directory Single-Sign On integration. The following versions of ABB Ability OPTIMAX are affected: ABB Ability OPTIMAX 6.1 vers:all/* ABB Ability OPTIMAX 6.2 vers:all/* ABB Ability OPTIMAX 6.3 <6.3.1-251120 ABB Ability OPTIMAX 6.4 <6.4.1-251120 CVSS Ven…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-04cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB Ability Symphony Plus Engineering View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site’s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system. The following versions o…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-06cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-41940 WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant r…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/04/30/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB System 800xA, Symphony Plus IEC 61850 View CSAF Summary This vulnerability was privately reported relating to ABB’s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerabi…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-01eset · tlp:amber · 4/30/2026, 9:00:00 AM
This month in security with Tony Anscombe – April 2026 edition Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month This month in security with Tony Anscombe – April 2026 edition Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET R…
Read original ↗https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-april-2026trend_micro · tlp:amber · 4/30/2026, 12:00:00 AM
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond. Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia | Trend Micro (US) search close About Mission and Culture Mis…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.htmlsnyk_blog · tlp:amber · 4/30/2026, 12:00:00 AM
lightning PyPI Compromise: A Bun-Based Credential Stealer in Python A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here's what's in the package, what to rotate, and how the payload pattern connects to the Mini Shai-Hulud npm campaign one day earlier. Lightning PyPI Compromise: Bun-Based Stealer | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform…
Read original ↗https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealerhuggingface_blog · tlp:amber · 4/29/2026, 3:01:48 PM
Granite 4.1 LLMs: How They’re Built Granite 4.1 LLMs: How They’re Built Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Granite 4.1 LLMs: How They’re Built Enterprise Article Published April 29, 2026 Upvote 67 +61 Yousaf Shah yousafshah Follow ibm-granite Overview Model Architecture Pre-Training Phase 1: General Pre-Training (10T tokens) Phase 2: Math/Code Pre-Training (2T tokens) Phase 3: High-Quality Data Annealing (2…
Read original ↗https://huggingface.co/blog/ibm-granite/granite-4-1cisa_alerts · tlp:amber · 4/29/2026, 12:00:00 PM
Adapting Zero Trust Principles to Operational Technology Adapting Zero Trust Principles to Operational Technology CISA, in coordination with the Department of War, Department of Energy, Federal Bureau of Investigation, and Department of State, released Adapting Zero Trust Principles to Operational Technology , joint guidance for organizations applying zero trust (ZT) principles to operational technology (OT). Zero trust is a modern, adaptive approach to cybersecurity that el…
Read original ↗https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technologyars_security · tlp:amber · 4/29/2026, 11:00:24 AM
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden Security firms find themselves especially exposed. It has been a bad six weeks for security firm Checkmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered malware to customers on two separate occasions. Now it has been hit by a ransomware attack from prolific fame-seeking hackers. The streak of misfortunes started on March 19 with the supply-…
Read original ↗https://arstechnica.com/information-technology/2026/04/why-a-recent-supply-chain-attack-singled-out-security-firms-checkmarx-and-bitwardentrail_of_bits · tlp:amber · 4/29/2026, 11:00:00 AM
Extending Ruzzy with LibAFL LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode . Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing techniques, and libFuzzer compatibility . For these reasons, I set out to add LibAFL support to Ruzzy , our coverage-guided fuzzer for pure Ruby code and Ruby C extensions. This gives Ruby developers and security researchers access t…
Read original ↗https://blog.trailofbits.com/2026/04/29/extending-ruzzy-with-libafltalos · tlp:amber · 4/29/2026, 10:00:42 AM
AI-powered honeypots: Turning the tables on malicious AI agents Just as AI brings time-saving advantages to our lives, it brings similar advantages to threat actors. We can take the advantage back. This blog shows how generative AI can be used to rapidly deploy adaptive honeypot systems. Generative AI allows defenders to instantly create diverse honeypots, like Linux shells or Internet of Things (IoT) devices, using simple text prompts. This makes deploying c…
Read original ↗https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agentstrend_micro · tlp:amber · 4/29/2026, 12:00:00 AM
Kuse Web App Abused to Host Phishing Document Bad actors took advantage of the legitimate name and services of Kuse, a popular AI-based app designed for workplaces. The attackers exploited the users’ trust in Kuse to carry out a phishing attack. Kuse Web App Abused to Host Phishing Document | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a …
Read original ↗https://www.trendmicro.com/en_us/research/26/d/kuse-web-app-abused-to-host-phishing-document.htmlhuggingface_blog · tlp:amber · 4/29/2026, 12:00:00 AM
DeepInfra on Hugging Face Inference Providers 🔥 DeepInfra on Hugging Face Inference Providers 🔥 Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles DeepInfra on Hugging Face Inference Providers 🔥 Published April 29, 2026 Update on GitHub Upvote 7 +1 Aray Sultanbekova araikin Follow guest Shang-Pin shang-pin-deepinfra Follow guest Utemuratov Pernekhan Follow guest Yessen K yessenzhar Follow guest Oguz Vuruskaner ovuruska Fol…
Read original ↗https://huggingface.co/blog/inference-providers-deepinfra