Skip to main content

Latest Analysis

Cybersecurity intelligence, threat analysis, and national security reporting.

Defense sector office with computer workstation and blurred monitor screen.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks

The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Analyst 207
Person surrounded by cluttered financial documents holds a smartphone.

WindRelay Malware Enables Live-Call Loan Fraud via NFC Relay Attack

In just 13 minutes, a scammer can use a single phone call to trick victims into installing malware, allowing them to commit card and loan fraud - all thanks to the cunning WindRelay malware. This sneaky software uses NFC relay attacks to enable live-call loan fraud, leaving victims none the wiser.

Analyst 207
Laptop on a desk near a window with a blurred Chrome browser window on the screen.

Malicious Chrome Extensions Route Traffic Through Proxies

Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

Analyst 207
Blurred logistics management system screen in background of warehouse or shipping yard setting.

Uber Freight Probes Data Breach by Helix Extortion Group

Uber Freight is investigating a data security incident after a hacktivist group claimed to have breached its systems, but fortunately, the issue has been identified, contained, and resolved, with operations now secure and running smoothly. The breach hasn't disrupted daily operations, and the company is working to put customers' minds at ease.

Analyst 207
A brightly lit office waiting area with chairs, a coffee table, and a desk with a blurred computer screen, overlooking a…

Fake Remote Workers Exploit Hiring Process Gaps

Scammers are exploiting gaps in the hiring process to land remote jobs, using stolen credentials and impersonating others to get their hands on sensitive corporate information. They're taking advantage of the rise of remote work to gain access to company networks and exfiltrate proprietary data.

Analyst 207
Young person sits in cluttered bedroom, looking worried at laptop screen.

FBI Warns of Rising Sextortion Attacks Targeting Online Accounts

Beware: cybercriminals are on the hunt for intimate content on social media and online accounts, using stolen images and videos to blackmail victims or sell them on shady marketplaces. Once they have your secrets, they can use them to extort and exploit you, often without you even knowing.

Analyst 207
Technicians work in a network operations center with modern and legacy equipment, including a Fortinet device.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Analyst 207
Technicians walk through rows of server racks and networking equipment in a dimly lit data center with a large window in…

Enterprise Defenses Exposed to Quiet Attacks Within Network Perimeters

While defenses at the network perimeter are getting stronger, with a 69% prevention rate, the harsh reality is that attackers who breach this outer layer can still wreak havoc inside, with a surprisingly low 37% prevention rate. The latest Blue Report 2026 reveals a concerning gap in enterprise security, highlighting the need for stronger internal defenses.

Analyst 207
Modern office workspace with laptop, papers, and pen, hinting at secure networking setup.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics

Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Analyst 207
Government office interior with computer and filing cabinets in background.

UK Criminal Records Office Breach Exposes 11,000 People's Sensitive Data

A shocking data breach at the UK's Criminal Records Office has left 11,000 individuals vulnerable after sensitive information was exposed due to basic cyber security failings. The breach went undetected for seven months, highlighting the devastating consequences of neglecting online security.

Analyst 207
Modern tech facility with blurred server infrastructure and unoccupied workstation.

AI API Flaw Exposes Secrets Across OpenAI, Anthropic, Google Models

A shocking security flaw in AI APIs has been uncovered, exposing sensitive secrets like API keys, passwords, and private keys across major models from OpenAI, Anthropic, and Google. Researchers decoded hundreds of thousands of "thinking" blocks, revealing a treasure trove of confidential data.

Analyst 207
Cluttered office desk with laptop showing Windows login or blue screen, surrounded by papers and supplies near a window.

Akira Ransomware Gang Foiled by Safe Mode Reboot

In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

Analyst 207
Person in office setting examines tablet with blank screen amidst papers and database backdrop.

NIST Seeks Input on NVD Overhaul Amid AI-Driven Cybersecurity Shift

The US government's quest to modernize the National Vulnerability Database is underway, and it's seeking your input - with an October 13 deadline to share innovative ideas on how to bring this critical cybersecurity resource into the automation age. NIST wants to hear your forward-looking perspectives on how to scale the NVD and supercharge its support for automated security workflows.

Analyst 207
Corporate office interior with employees at desks, laptops, and computers under natural light.

Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks

Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

Analyst 207
Police officer stands near security camera at Victoria Station with people in background.

British Transport Police Deploys Live Facial Recognition on London Underground

The London Underground has become the latest testing ground for live facial recognition, with British Transport Police rolling out the technology at Victoria station, sparking concerns that millions of innocent faces will be scanned. This move has civil liberties groups sounding the alarm, with Big Brother Watch director Silkie Carlo calling it a "disturbing and dystopian" expansion.

Analyst 207
Modern office interior with a blank laptop screen on a desk surrounded by neutral-colored furniture.

Adobe Fixes Zero-Day Flaws in ColdFusion, Campaign Classic

Adobe has patched critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic, including a zero-day flaw with a perfect 10.0 CVSS score that could allow hackers to execute arbitrary code or escalate privileges. These high-severity flaws, including operating system command injection and eval injection, require immediate attention to prevent exploitation.

Analyst 207
Smartphone displaying Signal conversation interface with verification process on screen.

Signal Bolsters Encryption with Automatic Key Verification Feature

Say goodbye to the hassle of manually verifying safety numbers - Signal's new Automatic Key Verification feature adds an extra layer of protection to ensure your encrypted chats remain private and secure. This innovative update lets you confirm your chats haven't been intercepted, without needing to meet in person or use another channel.

Analyst 207
Windows laptop on a desk in a modern office with a blurred background and scribbled notes nearby.

Microsoft Defender Zero-Day Exploited to Gain System Privileges

A security researcher known as Nightmare Eclipse has unveiled a new exploit, ShieldBreak, which can bypass Microsoft's patch for the RoguePlanet vulnerability and grant SYSTEM privileges on fully patched Windows systems. This alarming development highlights a significant gap in Microsoft Defender's defenses, leaving users vulnerable to potential attacks.

Analyst 207
Industrial control room with scattered computer screens and panels, natural daylight through a large window.

Russian Hackers Breach Polish Power Plant via Private APN

In a chilling cyberattack, Russian hackers infiltrated a Polish power plant by breaching a wind farm's VPN and firewall, then exploited a cellular router to gain control of the plant's systems. The attackers forced a combined heat and power plant into a controlled shutdown, overriding its operations with a password-protected lock.

Analyst 207
Rows of computer servers and storage equipment in a data center with highlighted device.

VMware vCenter Vulnerability Exploited for Persistent Remote Access

Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Analyst 207
Concerned individuals in a cloud computing setting review a laptop amidst rows of servers.

Malicious LiteLLM Releases Expose Over 2,100 Organizations to Credential Theft

Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.

Analyst 207
IT professional standing in data center with server rack and open laptop.

Microsoft Patch Tuesday Disrupts 400 Vulnerabilities, Zero-Day Exploits

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 vulnerabilities, including an actively exploited zero-day threat that demands immediate attention from sysadmins. With high-risk impacts on confidentiality, integrity, and availability, these fixes should be top priority.

Analyst 207
Network equipment room with a security appliance on a rack.

Cisco ASA and FTD Flaw Exploited in Wild, Triggers Remote DoS

A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software, known as CVE-2026-20349, is being actively exploited in the wild, allowing attackers to trigger a remote denial-of-service condition with a simple crafted HTTP request. This flaw, with a CVSS score of 8.6, can cause affected devices to reload, leaving networks vulnerable to disruption.

Analyst 207
Formal meeting room with large wooden table, chairs, and blurred emblems on walls, with daylight streaming in through tall…

Australia Urged to Join Defence Bank as Rules Take Shape

Australia is being urged to join the Defence Security Bank, a proposed multilateral lender that will boost allied defence capabilities by mobilising private finance for defence manufacturers and their suppliers. By backing the bank, Australia can help strengthen its own defence industry and play a key role in supporting global security.

Analyst 207