Skip to main content

Topic

Threat Intelligence

CTI blog image

A critical, unauthenticated remote code execution vulnerability in Windows Netlogon (CVE-2026-41089, CVSS 9.8) lets a remote attacker run code as SYSTEM on a domain controller. Patch all domain controllers in the same maintenance window with the May 2026 security updates.

Blog image for Claude Mythos security risks

Anthropic's Claude Mythos Preview demonstrated significant acceleration in capabilities for autonomously identifying vulnerabilities and exploit chains across major software and operating systems. Government and industry leaders are focused on understanding the real risks the model presents, and how to leverage these advanced technologies to protect and defend against adversarial use.

Featured image for CVE-2025-47813 Wing FTP Server vulnerability blog post

CISA KEV‑listed CVE‑2025‑47813 exposes Wing FTP Server install paths used in attack chains. Learn which versions are affected and how to remediate.

Desktop featured image: CTI blog 4 - wide

The Notepad++ update process was compromised by a supply chain attack, and users are strongly advised to upgrade to version 8.8.9 or later to ensure their security.

Desktop featured image: CTI blog 1

SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

Desktop featured image: CTI blog 2

Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

Desktop featured image: CTI blog 3 - wide

Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

Desktop featured image: CTI blog 1 - wide

Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

Desktop featured image: CTI blog 2 - wide

Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

Desktop featured image: CTI blog 4 - wide

Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities

Video thumbnail for Tanium + ServiceNow integrations explained – Tanium Tech Talks #135

Discover how Tanium and ServiceNow combine forces to streamline IT operations and security workflows.

Desktop featured image: CTI blog 2 - wide

Cyber attackers exploit legitimate tools, ClickFix attacks accelerate, and BlueNoroff targets macOS devices