Related Threat Clusters
-
Critical OpenAI Codex Flaw Exposes GitHub Tokens to Attackers
A critical command injection vulnerability in OpenAI's Codex has been discovered, allowing attackers to steal GitHub OAuth tokens from developers. The flaw originated from improper input validation during the branch…
4 articles · Updated April 1, 2026 -
Microsoft Disrupts StegoAd Campaign with Malicious Edge Extensions
Microsoft has dismantled the StegoAd operation, removing 119 malicious Edge extensions that used steganography to hide malware within image and font files. The campaign, active since 2021, targeted over 2.6 million…
13 articles · Updated June 29, 2026 -
AWS Bedrock Sandbox Vulnerability Enables DNS-Based Data Exfiltration
A security flaw in AWS Bedrock's AgentCore Code Interpreter allows attackers to bypass network isolation through DNS queries. Researchers from BeyondTrust demonstrated that the sandbox mode permits outbound DNS queries…
7 articles · Updated March 17, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Gainsight Apps Breach Exposes Data of Over 200 Salesforce Customers
A significant supply chain attack has compromised Salesforce-stored data from more than 200 companies through applications published by Gainsight. Salesforce confirmed unauthorized access to customer data and is…
30 articles · Updated November 23, 2025 -
HTTP Terminator Reveals New Attack Techniques in Cybersecurity Research
PortSwigger's HTTP Terminator, developed by James Kettle, identified hundreds of websites vulnerable to HTTP request smuggling, confirming around 700 vulnerable targets. The system autonomously generated and tested…
3 articles · Updated August 12, 2026 -
Ransomware Threats Targeting Hospitals via BeyondTrust Software Flaw
U.S. federal authorities have issued a warning regarding a critical vulnerability in BeyondTrust Remote Support and Privileged Remote Access software. This flaw, if exploited, could allow ransomware hackers to gain…
2 articles · Updated February 20, 2026 -
China's Brickstorm Malware Compromises US Critical Networks
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…
10 articles · Updated December 4, 2025 -
Congressional Budget Office Hacked, Suspected Foreign Involvement
The Congressional Budget Office (CBO) confirmed it was hacked, potentially exposing sensitive government data. The agency has implemented new security measures and is investigating the incident, which may involve…
8 articles · Updated November 7, 2025
Recent Intelligence Reports
- Medusa Ransomware Tops 500 Victims as STORM-1175 Exploits Flaws Fast — Technadu · August 19, 2026
- The future of AI security research isn’t autonomous, it’s human — Csoonline · August 11, 2026
- Microsoft takes down StegoAd operation — News.Risky.Biz · June 29, 2026
- Storm-1175 Exploits Flaws in High — Infosecurity-Magazine · April 7, 2026
- Microsoft links Medusa ransomware affiliate to zero — Bleepingcomputer · April 6, 2026
- Security experts discover critical flaw in OpenAI's Codex able to compromise entire organizations — Tech.Yahoo · April 1, 2026
- AWS Bedrock tool vulnerability allows data exfiltration via DNS leaks | brief — Scworld · March 18, 2026
- Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence — Cybersecuritynews · February 28, 2026