Threat intelligence, automated.
AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.
Rejetto HFS Servers Actively Scanned for Critical RCE Flaw (CVE-2026-61500)
Threat actors are actively scanning for a critical Remote Code Execution (RCE) vulnerability, CVE-2026-61500, affecting Rejetto HFS (HTTP File Server) instances. This flaw, stemming from a weak signing key, allows for session forgery, account takeover, and arbitrary code execution on vulnerable servers. Immediate action is advised for organizations operating Rejetto HFS.
Read full report →University of Illinois Chicago College of Medicine Ransomware Incident
The University of Illinois Chicago (UIC) College of Medicine experienced a ransomware attack that resulted in the exfiltration of data from its servers. This incident underscores the persistent threat ransomware poses to educational and healthcare institutions, often leading to data theft in addition to system disruption.
TA419 Impersonates US Officials for AI Cyber Espionage
The Chinese state-sponsored threat group TA419 is actively engaged in cyber espionage, targeting US AI policy experts. The group establishes seemingly legitimate professional relationships by impersonating US officials to gather intelligence from individuals in think tanks, universities, and legal organizations. This campaign represents a significant threat to national security and intellectual property related to artificial intelligence.
Apple to Tighten macOS Full Disk Access Controls Over AI Agent Misuse
Apple plans to enhance macOS Full Disk Access (FDA) controls to mitigate risks from AI agents potentially over-accessing user data. Developers are reportedly misusing FDA, leading to unauthorized exposure of sensitive user files, communications, and browsing history. This initiative aims to prevent broad data access without explicit user awareness.
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency patches for a NetScaler SAML denial-of-service vulnerability, tracked as CVE-2026-88779, which is actively being exploited as a zero-day. While currently confirmed as a DoS, researchers are investigating its potential for remote code execution. Defenders should prioritize patching and monitoring for post-exploitation activity.
TA419 Targets U.S. AI Policy Experts with Microsoft AitM Phishing
The China-aligned APT group TA419 is conducting targeted credential phishing campaigns against U.S. AI policy experts. These attacks leverage Microsoft Adversary-in-the-Middle (AitM) techniques, impersonating prominent figures to steal credentials and potentially bypass multi-factor authentication.
Monitoring Suspicious User-Agent Strings in Web Logs
This report emphasizes the importance of analyzing unusual User-Agent strings observed in web server and honeypot logs. Such strings often indicate reconnaissance, automated scanning, or bot activity targeting web applications, serving as early indicators of potential threats.
MI5 Warns of China’s MSS Funding UK Academic Research for Intelligence
MI5 has issued an alert regarding the China General Technology Research Institute (CGTRI) funding research involving over 100 UK academics. The agency assesses CGTRI’s primary purpose is to support China’s Ministry of State Security (MSS) in intelligence gathering efforts, leveraging academic collaboration to advance Beijing’s strategic interests. This highlights a non-traditional vector for state-sponsored intelligence collection.
RemoteThreat’s Advanced Red Teaming for Post-Breach Resilience
RemoteThreat, an offensive cyber operations startup, is evolving red teaming to simulate advanced attacker capabilities, focusing on post-exploitation scenarios. Their approach aims to help security teams test and improve their resilience after initial defenses have been bypassed, addressing organizational vulnerabilities to sophisticated attacks.
Transparently AI-authored
Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.