Skip to main content

Latest Analysis

Cybersecurity intelligence, threat analysis, and national security reporting.

Network equipment and security appliances on racks with a Fortinet device centered.

FBI Warns of Ongoing FortiBleed Attacks Targeting Fortinet VPN Admins

Tens of thousands of Fortinet FortiGate firewalls and SSL VPN gateways are under active attack by hackers leveraging a massive June credential leak, putting countless networks at risk of disruption. The breach, known as FortiBleed, exposed a staggering 73,932 firewall URLs across 194 countries, giving attackers a treasure trove of vulnerable targets.

Analyst 207
Neutral background with rows of generic computer servers and monitoring equipment.

Hackers Exploit ccTLD Vulnerabilities to Hijack Google Domains

Google revealed that several top brands and online services were hit by the same attacks, following their initial mitigation efforts. Attackers exploited vulnerabilities in country-code top-level domain (ccTLD) registries and DNS to hijack Google domains, not by breaching Google's infrastructure, but by compromising third-party operators.

Analyst 207
Network operations professional surrounded by rows of servers and equipment.

Google Domains Targeted in DNS Hijacking Attacks

Google security alert: hackers hijacked DNS records, snagging unauthorized HTTPS certificates for several Google domains and others by exploiting vulnerabilities in three country-code top-level namespaces. The attacks, targeting .gh, .sl, and .as, cleverly combined DNS control with fake TLS certificates.

Analyst 207
Domain management office with computer workstations and a large map in the background.

Hackers Hijack Country-Code Domains to Obtain Google HTTPS Certificates

Hackers hijacked country-code domains to obtain unauthorized Google HTTPS certificates, putting several domains at risk between September 22 and 27. Google quickly sprang into action, revoking the certificates and blocking them in Chrome to prevent any further damage.

Analyst 207
Network appliance sits on a rack in a data center room with server racks and patch panels.

SonicWall Fixes CVSS 10.0 Flaw in SMA1000 Appliances

SonicWall has patched a critical security flaw in its SMA1000 appliances that could let attackers infiltrate internal systems and run unauthorized operations. The bug, rated 10.0 on the CVSS scale, can be exploited before login, making it a high-risk vulnerability.

Analyst 207
Software development workspace with laptop, coding books, and blurred npm registry webpage on screen.

Malicious npm Packages Deliver Overlord RAT and Stealer in Supply Chain Attack

A single malicious npm package, "function-flag," was downloaded a staggering 37,419 times in a supply-chain operation that delivered Remote Access Trojans and information stealers to Windows hosts. This was part of a larger campaign, dubbed MALFEX, where 12 packages were published to the npm registry since August 2023, with eight of them flagged as malicious and collectively downloaded over 40,767 times.

Analyst 207
Futuristic robotic form sits prominently in a bright server room with rows of computer workstations.

AWS Unveils Open-Source Sandbox to Tame Rogue AI Agents

AWS just launched Strands Box, an open-source sandbox that helps keep rogue AI agents in check by combining top-notch isolation with policy enforcement to prevent unchecked actions. This game-changing tool tackles the growing risk of AI agents running wild, approving every action without human review.

Analyst 207
Person sits at cluttered desk with laptop and papers, surrounded by reminders, conveying information overload and security…

Cybersecurity Pros Warn of Password Reliance

Relying on passwords for security is a recipe for disaster, as humans simply can't keep track of multiple complex combinations, leading to reused, shared, or poorly stored passwords. A recent survey found that nearly half of cybersecurity pros still use passwords for personal and work accounts, despite knowing they're one of the least secure authentication methods.

Analyst 207
Router on a neutral surface with scattered network cables and a blurred background.

States Sue TP-Link, Citing China Ties and Router Security Risks

Four states are taking TP-Link to court, claiming the router maker has been dishonest about its security and hiding its ties to the Chinese government, putting sensitive data and national security at risk. Iowa's Attorney General Brenna Bird warns that Iowans' personal info is vulnerable due to TP-Link's alleged deception.

Analyst 207
A dimly lit server room with rows of equipment and cables, featuring prominent servers with blank screens in the foreground.

PoeLLM Malware Expands Crypto Botnet Via 3,400 Servers

Meet PoeLLM, a sneaky malware that's rapidly expanding its crypto botnet by hijacking 3,400 servers, with its operators using a clever poem-based trick to hide its command-and-control address. This cunning tactic lets the malware derive new addresses by tweaking a few words in a public GitHub poem.

Analyst 207
Laptop screen displays GitHub repository with poem, surrounded by cluttered workspace and papers on a wooden desk.

Malware Exploits AI Systems with 'Adversarial Poetry

Meet the first-ever malware that uses a clever trick - a poem - to hijack AI systems and steer them to its command center, cleverly hidden in a forked GitHub repository. This sneaky tactic was uncovered by Lumen's Black Lotus Labs, revealing a new level of sophistication in cyber threats.

Analyst 207
Rows of computer servers and networking equipment in a data center, with one server highlighted by a visible network cable.

LMCache Flaw Exposes Servers to Remote Code Execution

A newly discovered flaw, CVE-2026-105192, allows hackers to send a single network message that can execute malicious code on vulnerable LMCache multiprocess cache servers, with no patch available yet. This vulnerability can be exploited when the multiprocess server is configured to listen on a routable address, making it a serious threat to servers that aren't properly secured.

Analyst 207
Person working at desk with laptop and scattered papers, MSIX file on desk.

Microsoft Outlook to Block MSIX Attachments in Security Push

Microsoft is bolstering security in Outlook on the web and Windows by blocking MSIX attachments, including .msix and .msixbundle file types, to protect users from potential threats. This update will be applied to the default list of blocked file types, enhancing overall security in the platform.

Analyst 207
Pakistan Navy warship underway in calm North Arabian Sea with crew engaged in routine activities.

Pakistan Navy Charts Course for Multi-Domain Operations

The Pakistan Navy is charting a bold new course, prioritizing maritime security, deterrence, and regional collaboration to safeguard commerce and ensure stability in the increasingly complex North Arabian Sea and Indian Ocean. With a focus on uninterrupted Sea Lines of Communication (SLOCs), Admiral Naveed Ashraf is driving a modernization agenda that puts protection and partnership at its core.

Analyst 207
Teenager sits somberly in a dimly lit detention room with hands on a table.

ShinyHunters' Teen Ringleader Detained Amid Extortion Attempt

A teenager known as "Rey," suspected of leading ShinyHunters, has been detained in Amman, Jordan, and is cooperating with the FBI after the group allegedly attempted to extort a Boeing business unit. The group's exploits began with a PeopleSoft vulnerability, fueling a wave of data thefts.

Analyst 207
Apple research facility interior with iPhones and camera equipment on a workbench.

Apple Unveils Image Verification System to Protect Photo Integrity

Apple's new Reference Image system verifies that an image is genuine and exactly as taken by an iPhone, without revealing the photographer's identity or linking the image to a specific device. This innovative tool protects both the image and the photographer's anonymity, giving creatives peace of mind.

Analyst 207
Dimly lit server room with blinking servers and tangled cables.

PoeLLM Malware Targets Exposed AI Servers in Global Cryptomining Campaign

Meet PoeLLM, a sneaky malware that's compromised over 2,100 AI servers worldwide, with a staggering 800 infected systems active in just one day, all part of a massive global cryptomining campaign.

Analyst 207
Romanian military helicopter, an Airbus H225M, on a base with blurred background.

Romania Bolsters Defense with Airbus H225M Helicopter Deal

Romania is taking its defense to new heights with a deal for 12 versatile Airbus H225M helicopters, perfect for tackling tough tactical protection missions and more. The multirole choppers will support attack, reconnaissance, surveillance, and airborne assault operations.

Analyst 207
Military personnel surround a transporter-erector launcher at a desert or mountainous base.

Pakistan Unveils Fatah-4 ER Cruise Missile with Extended Range Capabilities

Pakistan just took its military capabilities to the next level with the unveiling of the Fatah-4 ER cruise missile, a game-changing addition that can strike targets with pinpoint precision and devastating force at extended ranges. This powerful new missile was successfully test-fired on October 6, showcasing its impressive accuracy and survivability.

Analyst 207
Large industrial yard with construction vehicles and waterfront in background.

Anduril Expands into Shipbuilding with $6.6 Billion Navy Submarine Deal

Anduril is set to revolutionize shipbuilding with a groundbreaking $6.6 billion Navy submarine deal, partnering with the US government in a unique public-private arrangement that will see American taxpayers own a 40% stake in the new shipyard, Arsenal-2, outside Baltimore. The massive 200-acre facility, slated for construction starting in 2027, will create a new hub for submarine component manufacturing and bring jobs to the region.

Analyst 207
Rugged Coast Guard station with satellite dish and laptop overlooking mountains.

Autonomous Endpoint Management Gains Urgency in Public Sector Networks

Public sector networks are facing a daunting challenge: managing tens of thousands of endpoints scattered across diverse environments, from remote mountain sites to manned stations and mobile units. Take the Coast Guard, for instance, which operates 1,500 locations worldwide, each with its own unique connectivity and security needs.

Analyst 207
Military personnel from various countries discuss tactical operations around a large Indo-Pacific map.

US Allies Expose Gaps in Nuclear Signaling Coordination

The real challenge isn't a lack of firepower, but a lack of common language and procedures among the US, Australia, Japan, and South Korea - a gap that's becoming increasingly critical as their advanced conventional capabilities start to intersect with nuclear strategies in the Indo-Pacific.

Analyst 207
A dimly lit server room with a central server displaying a GitHub page with a poem.

PoeLLM Malware Exploits Poem to Fuel Growing Botnet

Meet PoeLLM, a sneaky malware that's hijacked over 3,400 servers since April by cleverly extracting command-and-control addresses from a harmless-sounding poem on GitHub. This cunning botnet uses a poem-based system to stay one step ahead - but its unique approach also makes it vulnerable to takedown.

Analyst 207
Government building with laptop and subtle third-party branding.

FBI Breach Exposes Third-Party Risk

A recent FBI breach was caused by a security failure at a third-party organization, Accenture, after a contractor neglected to apply a crucial security patch, exposing sensitive employee information. This incident highlights the significant risks associated with relying on outside vendors and the importance of stringent security measures.

Analyst 207