Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

general

20 articles

Security Affairs general Google Citrix Intel Sep 30

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and ...

T1190 1 IOC

Security Affairs → Details

GBHackers general Microsoft Proofpoint Sep 30

Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts With No MFA

Threat actors have targeted more than 5,700 Microsoft 365 accounts across 28 tenants in a password-spraying campaign that successfully breached seven forgott...

GBHackers → Details

SecurityWeek general Sep 30

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. The post High-Severity Vulnerabilities Patched in OpenS...

SecurityWeek → Details

Help Net Security general Sep 30

Genea brings AI agents to access control with role-based permissions

Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform. On...

Help Net Security → Details

GBHackers general Microsoft Kubernetes Sep 30

Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover

Microsoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure...

T1078

GBHackers → Details

Help Net Security general Microsoft Palo Alto Networks CrowdStrike Zscaler Cloudflare Splunk Sep 30

Security tools can now scan Claude Enterprise chats and uploads for sensitive data

More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring...

Help Net Security → Details

GBHackers general Sep 30

Unsloth Fixes Arbitrary Code Execution Flaw Triggered by Malicious Hugging Face Models

Unsloth has addressed a critical arbitrary code execution vulnerability in its Studio web interface. This flaw allowed a malicious Hugging Face model reposit...

GBHackers → Details

GBHackers general Google Sep 30

Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks

A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware. The threat uses Googl...

GBHackers → Details

GBHackers general Sep 30

SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets

A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access troj...

GBHackers → Details

Help Net Security general Sep 30

OWASP Noir: Open-source static analysis tool

OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters...

Help Net Security → Details

The Hacker News general Citrix Sep 30

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come und...

1 IOC

The Hacker News → Details

GBHackers general GitHub Sep 30

OpenAI Launches Codex Security Cloud for Always-On Application Security Scanning

OpenAI has expanded its Codex platform with Codex Security Cloud, a cloud-hosted application security feature that continuously analyzes GitHub repositories,...

GBHackers → Details

GBHackers general Sep 30

OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext

OpenSSL has announced a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation that could allow a remote peer to read uni...

1 IOC

GBHackers → Details

GBHackers general Sep 30

FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader

The FBI and Dutch National Police have announced the arrest of a 24-year-old man from Amsterdam who is suspected of playing a major role in the ShinyHunters ...

T1041

GBHackers → Details

Help Net Security general Docker Kubernetes Sep 30

EU Cyber Resilience Act requirements for containers and Kubernetes

Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements f...

Help Net Security → Details

Help Net Security general Sep 30

In this new SME cybersecurity service, the AI assists and the consultants decide

BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized ent...

Help Net Security → Details

Help Net Security general Amazon Sep 30

Most open critical and high flaws are over 90 days old

Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet...

Help Net Security → Details

Help Net Security general Microsoft GitHub Linux Docker Sep 30

WSL containers are generally available on Windows

Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls images ...

Help Net Security → Details

Help Net Security general Cisco Sep 30

Most organizations need six months or longer to roll out new security controls

Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top gro...

Help Net Security → Details

Help Net Security general Cloudflare Sep 30

Post-quantum website certificates from Cloudflare are scheduled for early 2027

Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and prov...

T1598

Help Net Security → Details

«Previous page 1 ... 44 45 46 47 48 ... 332 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA