Back to Blog

#Threat Intelligence

21 posts
Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root Dirty Frag is the kind of Linux bug defenders worry about because it turns a limited foot...

May 10, 2026
5 min read
TCLBANKER turns WhatsApp and Outlook into trusted malware delivery channels

TCLBANKER turns WhatsApp and Outlook into trusted malware delivery channels

TCLBANKER turns WhatsApp and Outlook into trusted malware delivery channels The most important detail in Elastic's new TCLBANKER research is not just that a Bra...

May 9, 2026
5 min read
Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root

Dirty Frag Linux kernel zero-day gives local users a fast path to root Dirty Frag deserves attention because it is not a theoretical Linux bug waiting for slow...

May 8, 2026
5 min read
CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path A critical point in the new PAN-OS warning is that defenders are not looking at a ro...

May 7, 2026
4 min read
DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path The most important part of the DAEMON Tools incident is not that malware...

May 6, 2026
5 min read
Vishing and SSO abuse are accelerating rapid SaaS extortion

Vishing and SSO abuse are accelerating rapid SaaS extortion

Vishing and SSO abuse are accelerating rapid SaaS extortion The most dangerous part of modern SaaS intrusions is not always malware. Sometimes it is speed, trus...

May 5, 2026
5 min read
CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path Executive summary A compromise of the CPUID website briefly turned trusted download links f...

April 13, 2026
5 min read
Storm-1175 turns patch gaps into rapid Medusa ransomware intrusions

Storm-1175 turns patch gaps into rapid Medusa ransomware intrusions

Storm-1175 turns patch gaps into rapid Medusa ransomware intrusions Storm-1175 is a financially motivated threat actor that Microsoft says has been using newly...

April 7, 2026
7 min read
CVE-2026-35616 puts exposed FortiClient EMS servers into the incident-response lane

CVE-2026-35616 puts exposed FortiClient EMS servers into the incident-response lane

CVE-2026-35616 puts exposed FortiClient EMS servers into the incident-response lane CVE-2026-35616 is the second serious FortiClient EMS story in less than two...

April 6, 2026
5 min read
European Commission breach shows how stolen cloud secrets can spill across shared public platforms

European Commission breach shows how stolen cloud secrets can spill across shared public platforms

European Commission breach shows how stolen cloud secrets can spill across shared public platforms The latest details on the European Commission cloud incident...

April 5, 2026
5 min read
CVE-2026-21643: FortiClient EMS exploitation puts exposed endpoint managers at immediate risk

CVE-2026-21643: FortiClient EMS exploitation puts exposed endpoint managers at immediate risk

CVE-2026-21643: FortiClient EMS exploitation puts exposed endpoint managers at immediate risk CVE-2026-21643 is the kind of flaw defenders should treat as an im...

March 31, 2026
5 min read
LeakBase arrest is a warning to review stolen credential exposure now

LeakBase arrest is a warning to review stolen credential exposure now

LeakBase arrest is a warning to review stolen credential exposure now | 2026 The reported arrest of the alleged LeakBase administrator in Russia is the kind of...

March 27, 2026
4 min read