Threat intelligence, automated.
AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.
Blinder Tunnel Campaign Targets Iraqi Infrastructure
The Blinder Tunnel campaign, attributed to an Iran-nexus APT, is actively targeting critical infrastructure in Iraq. Attackers leverage fake Dubai Airports recruitment lures to deliver custom malware that utilizes GitHub for command and control (C2), aiming for initial access and persistent control within target environments.
Read full report →LibreOffice and OpenOffice Code Execution Vulnerability via Malicious Spreadsheets
Security researchers have demonstrated a proof-of-concept vulnerability in LibreOffice and Apache OpenOffice that allows malicious spreadsheets to execute arbitrary code upon opening, bypassing macro security warnings. The exploit relies on Java support being enabled within the office suite, posing a significant risk for silent code execution.
ASOS Confirms Data Breach Following Snowflake Environment Compromise
UK fashion retailer ASOS confirmed a data breach after threat actors sent unauthorized “HACKED” push notifications to customers via its mobile app. The attackers claimed to have exfiltrated customer data from ASOS’s Snowflake cloud data warehousing environment, indicating a compromise of cloud infrastructure.
Ninja Forms Plugin Flaw Exploited to Hack WordPress Sites
A stored Cross-Site Scripting (XSS) vulnerability in the Ninja Forms WordPress plugin is being actively exploited. Attackers are leveraging this flaw to inject malicious scripts, leading to the installation of backdoors and the creation of unauthorized administrative accounts on compromised WordPress sites. Immediate patching and security review are critical for affected installations.
ClickFix Attacks Evolve to Leverage DNS TXT Records and Browser Pre-fetching for Payload Hiding
ClickFix attacks are evolving to evade detection by using DNS TXT records to hide malicious payloads and browser cache pre-fetching to stage them. This sophisticated technique makes early-stage attack identification more challenging for defenders, as it obscures the initial delivery mechanisms.
Rejetto HFS Servers Actively Scanned for Critical RCE Flaw (CVE-2026-61500)
Threat actors are actively scanning for a critical Remote Code Execution (RCE) vulnerability, CVE-2026-61500, affecting Rejetto HFS (HTTP File Server) instances. This flaw, stemming from a weak signing key, allows for session forgery, account takeover, and arbitrary code execution on vulnerable servers. Immediate action is advised for organizations operating Rejetto HFS.
University of Illinois Chicago College of Medicine Ransomware Incident
The University of Illinois Chicago (UIC) College of Medicine experienced a ransomware attack that resulted in the exfiltration of data from its servers. This incident underscores the persistent threat ransomware poses to educational and healthcare institutions, often leading to data theft in addition to system disruption.
TA419 Impersonates US Officials for AI Cyber Espionage
The Chinese state-sponsored threat group TA419 is actively engaged in cyber espionage, targeting US AI policy experts. The group establishes seemingly legitimate professional relationships by impersonating US officials to gather intelligence from individuals in think tanks, universities, and legal organizations. This campaign represents a significant threat to national security and intellectual property related to artificial intelligence.
Apple to Tighten macOS Full Disk Access Controls Over AI Agent Misuse
Apple plans to enhance macOS Full Disk Access (FDA) controls to mitigate risks from AI agents potentially over-accessing user data. Developers are reportedly misusing FDA, leading to unauthorized exposure of sensitive user files, communications, and browsing history. This initiative aims to prevent broad data access without explicit user awareness.
Transparently AI-authored
Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.