Global Intelligence Search
Query the entire database for vulnerabilities, news articles, open-source security tools, and known threat actors.
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Researchers have identified an advanced persistent threat (APT) group for hire in China that performs both international cyber espionage and lowly cryptocurrency theft. With one hand, the mercenary group "Jewelbug"...
Belgium's eID Authentication Opens Citizen Accounts to RCE
A browser extension central to Belgium's national identity card system was built like Swiss cheese, letting hackers steal victims' identities and payment information, and even perform code execution on their local...
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
An unknown threat actor has been using a custom toolset to probe Salesforce and ServiceNow instances with overly permissive guest access and steal data for more than a year. The targets have spanned multiple sectors,...
Walmart Takes a 'Trusted Agent' Approach to Purple Teaming
Many organizations struggle with the inherent tension between red and blue teams — where offensive security testers and defensive operators often work in silos or even develop adversarial relationships. But Walmart has...
China-Linked Hacker Shows AI Capabilities in APAC Attack
A successful multi-agent AI attack on a government's agencies in the Asia-Pacific region by a Chinese-language operator has put nations and businesses on notice that near- and fully-autonomous AI-enabled attacks are now...
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
A critical-severity security vulnerability in GitLab CE/EE could allow a remote attacker with no account or login credentials to manipulate or delete publicly accessible projects and user data by exploiting the...
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The ransomware-as-a-service group Medusa has adopted fresh tactics to gain access and added hundreds of victims in a little more than a year, according to an updated U.S. government advisory published Tuesday. The gang...
Details emerge on BlackFile’s recent attacks on financial companies
A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to...
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
A company that runs AI testing labs involved in a series of breaches carried out by Anthropic and OpenAI’s cyber-focused models said the incident happened in part because they “unintentionally” provided the models with...
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
A newly-signed presidential memorandum enlisting private sector companies in federal law enforcement hacking operations against criminal organizations could present a number of legal, practical and moral pitfalls, cyber...
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
A tech worker who hatched an elaborate insider attack in late 2023 and attempted to extort Brightly Software for about $2.5 million was sentenced to two years in prison , the Justice Department said Thursday. Cameron...
AI’s ‘middle class’ has gotten dramatically better at hacking
As the White House and federal agencies grapple with frontier AI models and their hacking capabilities, researchers are warning that the industry’s “middle class” of smaller models may end up posing a greater threat...