Security & Threat Intelligence · KW30/2026
Beiträge dieser Woche
- info Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
- info Email threat landscape: Q2 2026 trends and insights
- info Defending SaaS-based applications against ShinyHunters OAuth abuse
- info Turning threat intelligence into decisive action with Defender Experts
- high KEV From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab
- info USN-8603-1: Linux kernel (Azure) vulnerabilities
- info USN-8604-1: Linux kernel (Azure) vulnerabilities
- info USN-8605-1: Linux kernel (Azure CVM) vulnerabilities
- info USN-8595-2: Linux kernel (AWS) vulnerabilities
- info USN-8606-1: Linux kernel (Azure) vulnerabilities
- info USN-8607-1: Linux kernel (Azure CVM) vulnerabilities
- info USN-8608-1: Linux kernel (Azure FIPS) vulnerabilities
- info USN-8609-1: Linux kernel (Azure CVM) vulnerabilities
- info USN-8575-3: Linux kernel vulnerabilities
- info USN-8610-1: Linux kernel (Azure CVM) vulnerabilities
- info How to catch GitHub Actions workflow injections before attackers do
- info Safeguarding VS Code against prompt injections
- info Post-quantum security for SSH access on GitHub
- medium Inside the breach that broke the internet: The untold story of Log4Shell
- info How GitHub’s agentic security principles make our AI agents as secure as possible
- info GitHub expands application security coverage with AI‑powered detections
- info GitHub for Beginners: Getting started with GitHub security
- info Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty program
- info The Risk of Exposed Cloud Functions and How to Harden
- info The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
- info CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
- high KEV Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
- info Accelerating AWS Network Firewall troubleshooting with AWS DevOps Agent
- info BGP ORIGIN attribute manipulation and its impact on the Internet
- info Why AI Needs a “Genie Coefficient”
- info Introducing Cache Response Rules
- critical KEV Don’t swing at everything
- info When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
- info What Happened Between OpenAI and Hugging Face?
- critical KEV CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
- info End-to-End Encryption and “Going Dark”
- info Preview: Cisco Talos at Black Hat USA 2026
- info Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
- high KEV What’s New in Rapid7 Products and Services: Q2 2026 in Review
- info LG to Ban Residential Proxies from Smart TV Apps
- info Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
- info The best defenders build AI agents together: Join Tenable for SWARM at Black Hat ’26
- info Do more with AWS WAF labels using dynamic label interpolation
- info R2 is now Generally Available
- info Captive Portal Detection, (Tue, Jul 21st)
- info Introducing the SpecterOps Tradecraft Academy
- info Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
- info How the 2026 World Cup affected Internet traffic
- info A new extortion cocktail: office printers, small ransoms, and BitLocker
- info MIT to Become Hotbed of AI Video Surveillance
- info New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
- info Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
- info Cloudflare Internal DNS is now generally available
- info WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
- info 2026 ISO and CSA STAR certificates are now available with two additional services
- high KEV wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
- high KEV 20th July – Threat Intelligence Report
- info On Flock License Plate Tracking Cameras
- info Introducing the SpecterOps Tradecraft Academy
- info Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
- high CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
- info Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
- info Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements
- critical KEV CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
- high KEV Begun, the Patch Wars have
- info Why “Least Privilege” Fails in Real Environments
- critical KEV CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
- info HelloNet campaign — new malicious modules launched through the ViPNet update system
- info Sunsetting the Public AttackerKB Platform
- info The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
- info GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
- info UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
- info The Hunter's Paradox: Is it time to embrace automated threat hunting?
- high KEV CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
- critical KEV Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
- info There and Back Again: An Operators Guide on NTLM Relaying Egress
- info Understanding Claude Tag’s access model in Slack and how to configure it securely
- info A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed
- info Investigating Persistence Mechanisms in AWS
- info 5 reasons to bring application security data into your exposure management platform
- info OkoBot: new sophisticated malware framework targets cryptocurrency users
- info Recent DShield SIEM Update, (Tue, Jul 14th)
- info ICYMI: June 2026 @AWS Security
- high KEV Patch Tuesday - July 2026
- high KEV Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
- high KEV Microsoft Patches a Record 570 Security Flaws
- high KEV Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
- info Security Hub adds AI workload protection and multicloud support for Microsoft Azure
- critical KEV Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
- info A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed
- info Authenticate legitimate AI agent traffic with AWS WAF Bot Control
- info [Video] Where protection starts: Cisco Talos Intelligence Integrations
- info The serpent’s tongue: Luring the Python out of its den
- info Rapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle East
- info AI Security Report 2026
- info Lessons Learned from CISA’s Recent GitHub Leak
- info Why cloud security is mission-critical for federal civilian and defense agencies
- info New compliance guidance available: HITRUST i1 on AWS
- high KEV 13th July – Threat Intelligence Report
- info Introducing Precursor: detecting agentic behavior with continuous client-side signals
- info AI Data Centers and the Concentration of Wealth
- info Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)
- info Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
- info AWS designated as a critical third party to the UK financial sector
- info Improving Smart Tiered Cache for Public Cloud Regions
- info AI Surveillance and Social Progress
- info "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)
- info Introducing OAuth Support for AWS MCP Server
- info WolfSSL, GeoVision, VTK vulnerabilities
- info Winning 54% of the time
- info Finding SOCKS with Proxywatch
- info Why we cannot wait for better post-quantum signature algorithms
- info Q2 2026 Open Source Malware Index
- info The Language of AI Could Change How Humans Speak
- info _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)
- info Designing for the inevitable: System prompt leakage and mitigations in generative AI applications
- info Building a Mental Model for Kubernetes Security Research
- info The CISO’s guide to post-quantum mandates and migrations
- info Introducing Meerkat: an experiment in global consensus
- info Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?
- info Felons, Fraudsters Flog Offensive Cybersecurity Startup
- info Cybersecurity and the Gap Between Skill and Ability
- info My Stack Simulator, (Wed, Jul 8th)
- info OMB M-26-14: Why federal agencies must fix asset visibility first
- info Enforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policies
- info More Odd DNS Records: NIMLOC, (Tue, Jul 7th)
- info Cloudflare proudly joins the UK government's Cyber Resilience Pledge
- info How to Set Red Team Objectives that Produce Value
- high KEV UAT-7810 continues building ORB networks using new malware
- info Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more
- info Threat landscape for industrial automation systems. Q1 2026
- info Offensive DPAPI With Nemesis
- info The Nemesis 2.X Development Guide
- info Emergent Architectural Leakage in Frontier Models: The Dual-Claude Phenomenon
- info Leveraging Tailscale Keys
- info BloodHound Enterprise Expands Beyond Microsoft: Mapping Identity Attack Paths Across Okta, GitHub, and Mac environments
- info Introducing Attack Path Management for GitHub in BloodHound Enterprise
- info Graph the Planet: Shai-Hulud 2.0
- info Discovering Unexpected Okta Attack Paths with BloodHound
- info RTFM: Read The Fatal Manual – When Vendor Documentation Creates Critical Attack Paths
- info Attack Paths Don’t Stop at Identity Providers
- info Leveling Up Secure Code Reviews with Claude Code
- info JamfHound v1.1 Update: SSO Attack Paths and Okta Additions
- info Expanding Attack Path Management to macOS Environments
- info Ludus SCCM Lab Expansion
- info Mythos, Machine-Speed Exploitation, and the Growing Importance of Identity Attack Paths
- info Janus: Listen to Your Logs
- info Ghostwriter v6.3.0 and CLI v1.0.0: New Activity Logging, Faster Installs, and Better Writing QA
- info BloodHound Has Changed. Your Course Probably Hasn’t.
- info BloodHound 9.0 — Product Updates
- info ghostsurf: From NTLM Relay to Browser Session Hijacking
- info AI Red Teaming Still Comes Back to Identity, Access, and Attack Paths
- info What’s New in the BloodHound Query Library: BYOL, OpenGraph, Multi-Server, and More
- info Into The Rainbow: Google’s NTLMv1 Rainbow Tables Explained in a Bit Too Much Detail
- info The Vercel Breach Explains Why Identity Attack Path Management Can’t Wait
- info SpecterOps Selected for OpenAI’s Trusted Access for Cyber Program
- info MSSQLHound Now Available in Go
- info The Accidental C2: Exploring Dev Tunnels for Remote Access
- info Shift Happens – Uncovering Two Built-in Command Injections in Windows Context Menus
- info What Comes Before Tickets
- info Spelunking through Splunk
- info Introducing TailscaleHound: Mapping Tailscale Attack Paths in BloodHound
- info How We Think about Red Teaming
- info Don’t Jump the Turnstile: Lessons from the Field
- info The Case for Practicing Response Before You Need It
- info CVE-2026-4387: StrongDM State File Reuse
- info Keeping a Short Leash: New AzureHound Least-Privilege Documentation
- info Ghostwriter v7: Safer Tokens, Scoped Access, and Better Automation
- info User-to-User Authentication: Down the Rabbit Hole – Part 1
- info Mythic Embarking on the Open Seas: Containerized Payload Delivery for Kubernetes Assessments
- info BloodHound MCP, One Year Later: What I Learned About MCPs, Models, and Context
- info SpecterOps and OpenAI: Helping to Build a New Security Frontier with Daybreak
- info Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment
- info Time Travel Debugging with Codex
- info Jailbreaker: LLM Jailbreak Testing You Can Actually Repeat
- info Accelerating EDR Evasion with LLM-Driven Analysis
- high KEV Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)
- critical KEV Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))
- info Building an Indirect Prompt Injection Workflow
- info Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)
- high KEV The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)
- high KEV A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
- medium KEV The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)
- high KEV Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)
- high KEV You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
- high KEV The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
- critical KEV More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
- high KEV CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
- high KEV It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)
- critical KEV 18th May – Threat Intelligence Report
- info Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict
- high KEV 25th May – Threat Intelligence Report
- high KEV AI Threat Landscape Digest March-April 2026
- critical KEV 1st June – Threat Intelligence Report
- info Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
- high KEV 8th June – Threat Intelligence Report
- info From SQLi to RCE – Exploiting LangGraph’s Checkpointer
- critical KEV 6th July – Threat Intelligence Report
- info Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
- info Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition
- high KEV Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape
- high KEV The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
- info M-Trends 2026: Data, Insights, and Strategies From the Frontlines
- info North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
- high KEV vSphere and BRICKSTORM Malware: A Defender's Guide
- info The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape
- info GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
- info Welcome to BlackFile: Inside a Vishing Extortion Operation
- info 2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services
- info Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
- info Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
- critical KEV ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
- info Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
- high KEV Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
- high KEV STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
- info The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem
- info Introducing GhostWorks: A Practical AI Initiative from SpecterOps
- critical KEV Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)
- info Why and how to migrate to a Transit Gateway-attached AWS Network Firewall
- info Spring 2026 SOC 1, 2, and 3 reports are now available with 188 services in scope
- info Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies
- info Identify unused AWS KMS keys and prevent accidental key deletions
- info Prompt Engineering for Security Agents: A Measurable Approach with GEPA
- critical KEV Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
- info Customize federated sign-in with new Amazon Cognito Lambda trigger
- info Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced
- info Amazon Cognito unlocks advanced capabilities with next-generation infrastructure
- info Building secure B2C applications with fine-grained access control using Amazon Cognito and Amazon Verified Permissions
- info Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)
- info Operationalizing AWS security: A maturity roadmap
- high KEV ICYMI: May 2026 @AWS Security
- info Threat tactic spotlight: Subdomain takeover
- info Introducing AWS Continuum: Security at machine speed
- info Spring 2026 SOC 1 and 2 reports are now available in OSCAL format
- info Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
- critical KEV 15th June – Threat Intelligence Report
- info Accelerate security investigations with Kiro CLI
- high KEV Prevent data exfiltration: AWS egress controls for cloud workloads
- info Restrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPs
- info What the June 2026 Threat Technique Catalog update means for your AWS environment
- info How to use the AWS Workload Credentials Provider for cross-account secret retrieval and prefetching secrets
- info Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall
- info From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker
- high KEV 29th June – Threat Intelligence Report
- info Enforce least-privilege authorization in multi-agent AI chains using Cedar
- high KEV Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
- high KEV 22nd June – Threat Intelligence Report
- high KEV Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever
- info Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
- info Identity APM Has Gone Mainstream. The Hard Work Is Just Starting.
- info Your Worker can now have its own cache in front of it
- info easy-day-js Targets Mastra, Dependency Attacks Grow
- info Miasma Returns: Leo Platform Compromise in npm
- high KEV Patch Tuesday - June 2026
- critical KEV CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
- info Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime
- info Automated Threat Hunting: Turning Threat Intelligence into Executable Hunt Plans
- info Weekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modules
- critical Beyond the Score: Using AI to Translate CVEs into Real-World Business Risk
- info Does Your Security Programme Align With NIS2 Requirements?
- info NIS2 is raising the bar. Here’s how to turn readiness into resilience.
- info Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
- info Why Security Teams Need To Start Earlier
- info Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
- info Why SIEM is Moving Toward Unified Security Operations: Rapid7 Named a Major Player in IDC MarketScape
- info Experts on Experts: Why AI and Compliance Are Forcing A New Security Operating Model
- critical KEV Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more
- high KEV Modernizing Global Vulnerability Standards For The Age Of AI
- info 5 Myths About AI in the SOC Security Teams Need to Rethink
- info Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture
- info Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more
- info A Day With Your Vector Command Red Team Pod
- info Factoring RSA Keys with Many Zeros
- info The Realities of AI Video Surveillance
- info Papa Johns Surveillance-Based Advertising
- info Cybersecurity Mission Creep in the US
- info Flock Cameras Can Surveil Cars Without License Plates
- info CISA Admin Leaked AWS GovCloud Keys on Github
- info Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
- info Lawmakers Demand Answers as CISA Tries to Contain Data Leak
- info Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
- info Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
- high KEV StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
- info Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools
- info Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk
- info The Gentlemen are knocking: сustom backdoors and evolving tactics
- info ToddyCat: your hidden email assistant. Part 2
- info OpenClaw: risks for the users and how to mitigate them
- info The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
- info Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
- info Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
- info When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website
- info Adding some Automation to the favicon.ico method of Host Recon, (Mon, Jun 29th)
- info June 2026 Apple Updates, (Tue, Jun 30th)
- info Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)
- info RCS and DNS: The NAPTR Record, (Mon, Jul 6th)
- info Tenable joins Anthropic’s Project Glasswing to advance AI-era cyber defense
- high KEV The June 2026 AI Executive Order: What federal agencies need to know and how Tenable can help
- high KEV Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
- high KEV CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive
- info Improving precision in CTEM: How continuous controls validation in Tenable One transforms exposure management
- high KEV Operationalize CISA BOD 26-04 with Tenable One
- high KEV Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)
- info What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
- high KEV How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.
- high KEV How CISA BOD 26-04 redefines vulnerability management metrics for security leaders
- info Turning Cloudflare’s threat indicators into real-time WAF rules
- info Defend against frontier cyber models: Cloudflare's architecture as customer zero
- info Route public traffic to private applications with Cloudflare
- info Scaling Security Insights: how we achieved a 10x increase in global scanning capacity
- info Growing the Cloudflare AI team with talent from Ensemble AI
- info Cloudflare DMARC Management is now generally available
- info Introducing the Cloudflare One stack: agent-powered deployment
- info Bringing more agent harnesses and frameworks to Cloudflare, starting with Flue
- info Celebrating 12 years of Project Galileo
- info Build your own vulnerability harness
- info Temporary Cloudflare Accounts for AI agents
- info How we found a bug in the hyper HTTP library
- info The White House's post-quantum executive order is an important milestone. It’s time to get to work
- info How we built saga rollbacks for Cloudflare Workflows
- info Unmasking the crawls with Attribution Business Insights
- info Your site, your rules: new AI traffic options for all customers
- info Making AI search smarter
- info Content Independence Day, one year on: building the business model for the agentic Internet
- info Announcing the Monetization Gateway: charge for any resource behind Cloudflare via x402
- info Unlocking the Cloudflare app ecosystem with OAuth for all
- critical KEV Less panic patching, more precision
- info Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting
- info Winning the cyber marathon with Tony Giandomenico
- info Reporting from Vegas: Networking, AI, and good boys
- info Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities
- info A tale of two eras
- info Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model
- info Close Encounters of the Human Kind
- info Introduction to COM usage by Windows threats
- info Beyond IOCs: AI-enabled threat intelligence
- info ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
- info Martin Lee: Running through the Arctic (and the threat landscape)
- high KEV Catan and Mouse
- info A Record-Breaking Patch Tuesday for June 2026
- info Who Runs the Ransomware Group ‘The Gentlemen?’
- info ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
- info Scattered Spider Hackers Plead Guilty on Day 1 of Trial
- info FBI Seizes NetNut Proxy Platform, Popa Botnet
- info Enterprise security at machine speed: AWS Black Hat 2026 preview
- high ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability
- high ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability
- high ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability
- high ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability
- high ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability
- medium ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability
- info Rockwell Automation ThinManager
- info MZ Automation lib60870
- info MZ Automation libIEC61850
- info Panduit IntraVUE
- info Johnson Controls XAAP Android
- info Weintek cMT3092X
- info Johnson Controls C-CURE 9000 and Victor application server
- info Email threat landscape: Q2 2026 trends and insights
- high KEV Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
- high KEV CISA Adds Two Known Exploited Vulnerabilities to Catalog
- info Real world incident response: Microsoft and AXA XL strengthen cyber resilience
- info GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
- high ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
- high ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
- info Siemens Opcenter X
- info Rockwell Automation FactoryTalk Services Platform
- high KEV Siemens CADRA
- info Rockwell Automation Studio 5000 Logix Designer
- info Rockwell Automation 1718-AENTR/1719-AENTR
- info Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
- info Rockwell Automation 1734 POINT I/O
- info Siemens IAM Client
- info Siemens SIDIS Secured SmartPlug
- info Tycon Systems TPDIN-Monitor-WEB2
- high KEV CISA Adds Four Known Exploited Vulnerabilities to Catalog
- info ACR Stealer: Two observed intrusion chains amid increased threat activity