Threat intelligence, automated.
AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.
AI Coding Agents Expose Internal Company Data on GitHub
AI coding agents, when prompted to share screenshots of code changes, have inadvertently uploaded over 13,000 sensitive internal company images to public GitHub repositories. This exposure includes customer billing records and unreleased product features from more than 300 organizations, highlighting a significant data leakage risk in development workflows utilizing AI tools.
Read full report →Phishing Abuses RMM Tools for Persistent Access
Microsoft has observed phishing campaigns leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically MSP360 RMM and ScreenConnect. Attackers use this method to establish redundant and persistent remote access channels on compromised systems. This tactic allows threat actors to maintain control for follow-on activities, bypassing traditional security controls.
Apple Emergency Patch for iOS 26, macOS 26, macOS 15 (CVE-2026-86950)
Apple has released emergency patches for iOS 26, macOS 26, and macOS 15 to address a critical vulnerability, CVE-2026-86950, which is actively being exploited in the wild. Users of affected older operating system branches are urged to update immediately. iOS and macOS 27 are not impacted by this specific security flaw.
CVE-2026-86950: Apple CoreGraphics Out-of-Bounds Write Leading to RCE
CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework affecting iOS, iPadOS, and macOS. Processing a maliciously crafted file can lead to arbitrary code execution. Apple is aware of reports indicating in-the-wild exploitation against targeted individuals.
Apple Zero-Day Vulnerability CVE-2026-86950 Weaponized in Targeted Attacks
Apple has confirmed active exploitation of CVE-2026-86950, an out-of-bounds write vulnerability, in targeted attacks. This zero-day flaw is being leveraged in a highly sophisticated manner. Users are advised to apply updates as soon as they become available to mitigate the risk.
Keio Corporation Confirms Ransomware Attack Disrupting Business Systems
Keio Corporation, a major Japanese private railway operator, has confirmed a ransomware attack that disrupted some of its business systems over the weekend. While public transportation services were not affected, the incident impacted internal administrative and operational support functions. Investigations are ongoing to determine the full scope and nature of the attack.
TDengine Zero-Day Vulnerability: Single-Packet DoS
A high-severity zero-day vulnerability affects the TDengine time-series database, enabling an unauthenticated attacker to crash critical OT servers with a single malformed network packet. This Denial of Service (DoS) vulnerability poses a significant operational risk to industrial, IoT, energy, and automotive environments.
NeedyMantis: Modular Post-Compromise Malware Framework
NeedyMantis is a modular post-compromise malware framework identified by Microsoft Threat Intelligence. It employs custom loaders, encrypted archives, and extensible components to maintain long-term access and facilitate follow-on operations in targeted intrusions.
NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Exploited In The Wild
Citrix NetScaler devices are currently targeted by active exploitation of two zero-day vulnerabilities, `CVE-2026-88771` and `CVE-2026-88772`. Unit 42 has confirmed these vulnerabilities are being actively exploited in the wild, posing an immediate threat to organizations utilizing affected NetScaler appliances.
Transparently AI-authored
Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.