🧠 Intelligence Threads

10 of 203 total reports

Quick Time:
Severity:
🔴 HIGHMalware & Ransomware

Akira Ransomware Claims 23GB Breach of Apache OpenOffice

Akira ransomware listed Apache OpenOffice on their leak site claiming 23GB of stolen data including employee PII (addresses, DOB, driver's licenses, SSN, credit cards), financial records, and internal bug reports. What's…

Category: Threat Alerts / Malware & Ransomware / Malware & Ransomware

#akira#ransomware#apache#open-source#data-breach#raas
🚨 CRITICALICS/SCADA

Canada: Internet-Accessible ICS Targeted by Hacktivists in Multiple Incidents

Canadian Cyber Centre and RCMP report multiple incidents where hacktivists targeted internet-exposed ICS devices. What's brutal: attackers tampered with water facility pressure values causing service degradation, manipul…

Category: Threat Alerts / Critical Infrastructure / ICS/SCADA

#ics#scada#critical-infrastructure#hacktivism#canada#water-sector#operational-technology
🚨 CRITICALVulnerabilities & Exploits

Critical Flaws in Elementor King Addons Affect 10,000 WordPress Sites

King Addons for Elementor plugin (10,000+ sites) has two critical unauthenticated vulnerabilities enabling full site takeover. CVE-2025-6327: arbitrary file upload via exposed AJAX handler—attackers can upload web shells…

Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits

#wordpress#elementor#rce#privilege-escalation#file-upload#cve-2025-6327#cve-2025-6325
⚠️ MEDIUMVulnerabilities & Exploits

Debian Patches Squid Info Disclosure Vulnerability (CVE-2025-62168)

Debian released patches for Squid proxy covering CVE-2025-62168: missing redaction of authentication data leading to information disclosure. Leonardo Giovanni discovered the flaw. Squid is a widely deployed caching proxy…

Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits

#squid#debian#information-disclosure#proxy#cve-2025-62168#credential-leak
🚨 CRITICALSupply Chain

Malicious NPM Packages Deliver Cross-Platform Infostealer to Developers

Socket discovered 10 malicious npm packages delivering infostealer malware across Windows, Linux, and macOS. What's sophisticated: 4 layers of obfuscation hide payloads, fake CAPTCHA appears legitimate, and attackers fin…

Category: Threat Alerts / Supply Chain / Supply Chain

#npm#supply-chain#typosquatting#infostealer#malware#developer-targeting#credential-theft
🚨 CRITICALSupply Chain

PhantomRaven: Hidden NPM Malware Exploits Remote Dynamic Dependencies

Koi Security discovered PhantomRaven campaign compromising 86,000+ npm downloads via Remote Dynamic Dependencies (RDD)—an obscure npm feature allowing HTTP URLs as package dependencies. What's clever: malicious code live…

Category: Threat Alerts / Supply Chain / Supply Chain

#npm#supply-chain#phantomraven#slopsquatting#ai-assisted-attacks#credential-theft#rdd
📊 LOWMobile Security

Google: Android Outperforms iOS in Mobile Scam Protection

Google published research showing Android's AI-driven scam protections outperform iOS. What's interesting: YouGov survey of 5,000 users found Android users 58% more likely to report zero scam texts vs iOS (96% advantage …

Category: Research & Analysis / Mobile Security

#mobile-security#android#ios#scam-protection#ai-security#phishing#google
Page 1 of 21(203 total reports)