PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...
This week’s ThreatsDay Bulletin tracks fake IT calls, abused remote tools, phishing kits, unsafe downloads, ransomware, ...
In this episode of Below the Surface, host Paul Asadoorian is joined by Eclypsium’s Vlad Babkin for a wide-ranging discussion on the latest infrastructure security risks, beginning with the August ...
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active ...
Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic ...
A newly disclosed vulnerability in the Hugging Face Transformers library can cause attacker-controlled Python code to be ...
Security researchers anticipate a rise in deep-level industrial device attacking capabilities as AI models improve, opening ...
Simon Willison, poking through his ~/.cache/ folder with OmniDiskSweeper, found that the OpenAI Codex desktop app (now rebranded as ChatGPT) ...
Fire Ant hackers, a China-linked espionage group, hacked Cisco routers and enterprise authentication servers in 2026, ...
Fire Ant compromises Cisco routers to spy on traffic, hide activity, and move toward high-value systems across networks.
Alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.