Skip to main content

Latest Analysis

Cybersecurity intelligence, threat analysis, and national security reporting.

Wi-Fi router on a table in a hotel lobby, surrounded by blurred travelers.

Hackers Target Hotel Wi-Fi to Steal Microsoft 365 Accounts

Hackers are targeting hotel Wi-Fi networks to steal Microsoft 365 accounts from unsuspecting travelers, with a widespread campaign affecting various industries across multiple countries. This sneaky tactic redirects visitors to attacker-controlled sites, putting business travelers at risk of having their sensitive information compromised.

Analyst 207
Person working at desk with laptop and smartphone, surrounded by papers and notes.

BlueNoroff Phishing Kit Targets Crypto Wallets with Zoom Lures

BlueNoroff's phishing kit is a masterclass in deception, using Zoom lures and compromised industry contacts to trick victims into divulging their crypto wallet info. This sophisticated scam combines social engineering and malware to selectively target high-value victims.

Analyst 207
Technicians inspect rows of computer servers and networking equipment in a brightly-lit server room.

Microsoft Outage Exposes Flaw in Automated Maintenance Process

Microsoft is launching a thorough investigation into its automated maintenance process after a recent outage, focusing on safety checks and process improvements to prevent future disruptions. The analysis comes on the heels of a significant disruption to Microsoft 365 services, affecting thousands of users.

Analyst 207
Cluttered computer workstation with code on laptop screen in dimly lit room.

Unfettered AI Fuels New Wave of Cybercrime

The alarming reality is that unregulated AI has become a cybercrime game-changer, with 6,644 openly available models labeled as "uncensored" and "unfiltered" racking up over 22 million downloads in just 30 days. This staggering statistic proves that guardrail-free AI is no longer a hypothetical threat, but a readily accessible tool for malicious use.

Analyst 207
Industrial control room with a programmable logic controller in the foreground.

FBI, CISA Warn of Iranian Cyber Exploitation Targeting US Infrastructure

A single exposed controller can be a seemingly minor issue, but in critical infrastructure, it can escalate into a major national security threat - and Iranian cyber attacks are actively targeting these vulnerabilities in US infrastructure. Stay ahead of these threats with expert guidance from trusted sources like CISA and FBI.

Analyst 207
Low-privileged user accesses restricted network area, symbolizing vulnerability.

Certighost Exploit Enables Low-Privilege AD Users to Impersonate Domain Controllers

A newly discovered exploit, dubbed Certighost, lets low-privileged Active Directory users impersonate Domain Controllers, posing a significant threat to security. This vulnerability, tracked as CVE-2026-54121, allows attackers to obtain a certificate for a Domain Controller and authenticate as that machine.

Analyst 207
Researchers in a university setting examine code with highlighted predictable names on a projected screen.

AI Coding Agents Exposed to Predictable Name Attacks

Researchers have made a startling discovery: AI coding agents are surprisingly predictable, often generating identical fake names for tasks like skill installs and repository requests, making them vulnerable to exploitation by attackers. This weakness was found across multiple popular coding tools, with identical names being hallucinated up to 85% of the time for repository requests and 100% for skill installs.

Analyst 207
Chick-fil-A restaurant interior with a tablet login screen in the foreground.

Chick-fil-A Breach Exposes 13,000 Customers' Data

Thousands of Chick-fil-A customers are reeling after a credential stuffing attack compromised 13,322 accounts, exposing sensitive customer data over just three days in June. The breach allowed hackers to access a combination of customer info linked to Chick-fil-A One accounts, including names and more.

Analyst 207
Server room with a rack of servers positioned to suggest vulnerability.

Bing Image Flaws Expose Microsoft Servers to Command Injection Attacks

Microsoft's Bing Image processing pipeline had a shocking vulnerability that allowed hackers to inject malicious commands, thanks to two critical flaws discovered by XBOW. These flaws enabled attackers to gain alarming levels of access, running commands as the system's highest authority on both Windows and Linux hosts.

Analyst 207
Europol officers in a briefing room with a large screen displaying a Europe map.

Europol Targets 4,340 URLs in Crackdown on Violent Extremist Network 'The Com

Europol has launched a crackdown on the violent extremist network 'The Com', flagging 4,340 URLs for removal after detecting sinister content that promotes self-harm and exploitation of minors. The operation, involving nine countries, aims to protect vulnerable users from coded messages and emojis that can have devastating effects.

Analyst 207
Government officials gather at a podium in a briefing room with an agency emblem in the background.

US Targets Overseas Cybercrooks with Visa Cancellations

The US is cracking down on overseas cybercrooks by cancelling their visas, a move aimed at curbing the $10 billion+ in scams that defraud American citizens every year. This targeted approach will deny visas to foreign nationals involved in cybercrime, including those behind investment scams and sextortion schemes that prey on vulnerable victims.

Analyst 207
Office computer workstation with network diagram on screen, cityscape in background.

ChatGPT Flaw Exposes Risk of Rogue AI Agents via Phishing Link

One phishing link was all it took to expose a critical flaw in ChatGPT's security, allowing hackers to create rogue AI agents with access to an employee's credentials and unchecked approvals. This vulnerability, known as AgentForger, put organizations at risk of being hijacked by autonomous AI agents controlled by attackers.

Analyst 207
Laptop on cluttered desk with faint phishing notice on screen in brightly-lit office space.

ChatGPT Enters Top 10 Most Impersonated Brands in Phishing Attacks

ChatGPT has become a hot target for phishing attacks, entering the top 10 most impersonated brands in just the second quarter of 2026, with scammers sending fake emails that mimic OpenAI's billing notices to steal sensitive info. This new trend signals where attackers are focusing their efforts next.

Analyst 207
Security professionals gather around a large screen in a brightly-lit monitoring room with multiple workstations.

Security Teams Must Enforce AI Agent Controls Beyond Visibility

Discovering AI agents across your organization is just the starting line - the real challenge lies in controlling their actions to prevent potential security threats. Simply seeing what's out there isn't enough; it's time to take charge and enforce limits on these active actors.

Analyst 207
Public Wi-Fi access point in a hotel equipment room.

Cybersecurity Experts Warn of Global Hotel Wi-Fi Credential Harvesting Campaign

Beware of hackers lurking on hotel Wi-Fi networks, as a global campaign is underway to steal sensitive credentials from unsuspecting travelers and businesses. Cyber attackers are exploiting weak spots in hotel routers and Wi-Fi systems to gain control and manipulate DNS settings.

Analyst 207
Smartphone on a plain surface with a blurred background and a hint of a computer screen.

Illinois Hacker Sentenced for Exploiting Snapchat Accounts

A 26-year-old Illinois man, Kyle Svara, has been sentenced to 76 months in prison for hacking over 750 Snapchat accounts, using social engineering tactics to phish access codes and trading stolen images online. He'll also face three years of supervised release after serving his time.

Analyst 207
Dimly lit server room with rows of equipment and a single bright laptop in the foreground.

Golden Chickens Malware Evolves With Modular Implants

The Golden Chickens malware has taken a significant leap forward with the emergence of four new, highly modular malware families, signaling a major evolution in the threat landscape. This development is a red flag, as it suggests a more sophisticated and adaptable attack strategy from the financially motivated malware-as-a-service developer behind it.

Analyst 207
Government ministry office interior with unattended workstation and server room in background.

Hackers Leverage AI Tool Hermes to Breach Thai Finance Ministry Network

A careless mistake left 585 files and 470 MB of sensitive data exposed, as hackers used an open-source AI agent called Hermes to breach Thailand's Ministry of Finance network. The breach was made possible when an operator enabled YOLO mode, which disabled the agent's normal approval requirement.

Analyst 207
University building with locked computer screens and concerned students in background.

Ransomware Attacks Intensify Against Universities Worldwide

Universities worldwide are under siege by ransomware attacks, with a single group called The Gentlemen responsible for a staggering 80% of their attacks on the education sector, and a 275% surge in attacks on education in just the first half of 2026. This alarming trend has contributed to a spike in ransomware activity against universities, despite an overall decline in recorded incidents across the broader education sector.

Analyst 207
Technicians in a server room inspect equipment amidst rows of racks and storage devices.

Redis Exposes Zero-Days, RCE Exploit in Latest Security Releases

Redis just released seven security updates to fix major vulnerabilities that could let attackers run malicious code remotely, thanks to newly published proof-of-concept exploits targeting several Redis versions. The fixes cover multiple branches, including 6.x, 7.x, and 8.x, and patch memory-corruption flaws that can be triggered using the RESTORE command and other requirements.

Analyst 207
Brightly-lit computer server room with rows of equipment and a central node.

NodeBB Fixes Flaws Exposing Admin Access, Private Chats

NodeBB has patched eight high-severity security flaws that left its forum platform vulnerable to admin access and private chat exposure, affecting all versions prior to 4.14.0. Admins should install the fixes immediately to safeguard their sites.

Analyst 207
Australian coastline with undersea cables and damaged lines, with an autonomous vehicle in the distance.

Australia's Defence Faces Urgent Test in Autonomous Systems Race

Australia's internet lifelines are under attack, with a growing number of subsea cable damages threatening the nation's digital infrastructure - and Defence Minister Richard Marles warns that the frequency and scale of these incidents is historically unprecedented. Roughly 99 percent of Australia's internet traffic relies on just 15 of these vulnerable cables.

Analyst 207
Australian-made drones sit on a table near a coastal monitoring station, with people working in the background and the…

Australia's Drone Policy Exposes National Security Gap

Australia's foreign minister, Penny Wong, has made a bold commitment to the Philippines, vowing to provide surveillance drones built in Australia and the US, shunning cheaper Chinese alternatives in favour of trusted tech. This move comes as Australia's own drone policy reveals a concerning gap in national security.

Analyst 207
Military helicopter in flight over water with a visible missile.

Helicopters Emerge as Key Players in Maritime Strike Exercises

In a display of precision firepower, AH-64 Apaches and other allied helicopters took aim at retired US Navy vessels during RIMPAC 2026's sinking exercises, showcasing their maritime strike capabilities. The US Army's Apaches even fired Spike NLOS missiles at the former cruiser ex-USS Mobile Bay with impressive results.

Analyst 207