LATEST THREAT INTELLIGENCE

Next-Gen Cyber Security
Insights & Intelligence

Deep-dive analysis, hands-on tutorials, and cutting-edge threat intelligence from industry practitioners.

Featured Article

🔥 Breaking

KB5124008 update may break Windows 11 domain trust

Microsoft is investigating reports that the Windows 11 KB5124008 update can sever Active Directory trust on some Enterprise devices.

⏱️ 4 min read📅 9/17/2026

Latest Articles

Data Breach

Compromised Ribon app credentials expose shopper data on BigCommerce

Bad actors used stolen Ribon app credentials to inject malicious scripts into merchant sites, leaking personal shopper details but not payment cards.

⏱️ 4 min read📅 9/22/2026
Supply Chain

Malicious npm ‘indexed‑btree’ hides payload, exfiltrates via Slack

The npm package ‘indexed‑btree’, masquerading as ‘sorted‑btree’, runs a hidden BTree.set() routine that gathers system info and sends it to Slack, Telegram and an Ethereum contract.

⏱️ 7 min read📅 9/21/2026
Vulnerability

AI‑Assisted Exploit Chains libheif RCE with OpenAI SSO

Hacktron leveraged Claude Opus 5 to combine a libheif RCE bug in Discourse with an OpenAI SSO flaw, briefly hijacking staff ChatGPT and Codex accounts and accessing an internal repo.

⏱️ 4 min read📅 9/20/2026
Advisory

Vectra AI rolls out Ascent partner program to tackle AI‑driven threats

Vectra AI unveiled Ascent, a partner program aimed at expanding AI‑focused security services.

⏱️ 2 min read📅 9/19/2026
Threat Intelligence

NightEagle targets Russian firms, drops GhostContainer on Exchange

China‑origin APT‑Q‑95 has begun compromising Russian companies, using stolen VPN credentials to infiltrate Microsoft Exchange servers and install the GhostContainer backdoor.

⏱️ 3 min read📅 9/18/2026
Malware

13 Malicious npm Packages Deliver WeaselBiscuit Stealer

Researchers uncovered 13 npm modules that pull the WeaselBiscuit JavaScript stealer, exfiltrating Chrome extension data on Windows, macOS and Linux.

⏱️ 3 min read📅 9/18/2026