DEV Community

#threatintel

Gathering, analyzing, and applying intelligence about threats and threat actors.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Kapibala: Government Data Theft via WordPress and Active Exploitation of Zyxel CVE-2026-7273

Kapibala: Government Data Theft via WordPress and Active Exploitation of Zyxel CVE-2026-7273

1
Comments
7 min read
EvilTokens: AI-Powered PhaaS Abusing Device Code Authentication to Compromise Over 12,000 Mailboxes

EvilTokens: AI-Powered PhaaS Abusing Device Code Authentication to Compromise Over 12,000 Mailboxes

1
Comments
7 min read
TrustSink: Password Theft via a Rogue External MFA Provider in Microsoft Entra ID

TrustSink: Password Theft via a Rogue External MFA Provider in Microsoft Entra ID

1
Comments
6 min read
LLM Relay Infrastructure: Over 80,000 Nodes Obscure User Attribution and Regional Controls

LLM Relay Infrastructure: Over 80,000 Nodes Obscure User Attribution and Regional Controls

1
Comments
7 min read
Check Point CVE-2026-93616: Actively Exploited Pre-Authentication Path Traversal Leading to Script Execution

Check Point CVE-2026-93616: Actively Exploited Pre-Authentication Path Traversal Leading to Script Execution

1
Comments
9 min read
BigDiskBuster: Public PoC Claims to Block Microsoft Defender Platform and Security Intelligence Updates

BigDiskBuster: Public PoC Claims to Block Microsoft Defender Platform and Security Intelligence Updates

1
Comments
8 min read
CLOSEDQUORUM: An Autonomous Windows Implant Using Multiple LLMs for Attack Decisions

CLOSEDQUORUM: An Autonomous Windows Implant Using Multiple LLMs for Attack Decisions

1
Comments
7 min read
Three Linux Kernel Vulnerabilities Added to CISA KEV: Active Exploitation Reported in AF_ALG, ebtables, and kTLS

Three Linux Kernel Vulnerabilities Added to CISA KEV: Active Exploitation Reported in AF_ALG, ebtables, and kTLS

1
Comments
6 min read
CrowdSec Source Code Leak: GitHub OAuth Token Abused in TanStack Supply Chain Attack

CrowdSec Source Code Leak: GitHub OAuth Token Abused in TanStack Supply Chain Attack

1
Comments
7 min read
BigCommerce Third-Party App Compromise: Malicious Script Injected into Storefronts via Ribon Credentials

BigCommerce Third-Party App Compromise: Malicious Script Injected into Storefronts via Ribon Credentials

1
Comments
5 min read
Click2Shell: One-Click Chain from Automatic WordPress Theme Installation to PHP Execution

Click2Shell: One-Click Chain from Automatic WordPress Theme Installation to PHP Execution

1
Comments
6 min read
D-Link DIR-822A: Pre-authentication DHCP Buffer Overflow and L2TP Out-of-Bounds Write

D-Link DIR-822A: Pre-authentication DHCP Buffer Overflow and L2TP Out-of-Bounds Write

1
Comments
6 min read
Gemini Accessed Three Real Companies During a Security Evaluation via Password Guessing and Publicly Exposed Credentials

Gemini Accessed Three Real Companies During a Security Evaluation via Password Guessing and Publicly Exposed Credentials

1
Comments
6 min read
Colorado Small Water Utility OT Breaches: Attackers Alter Settings, Disable Alarms, and Change Pumping Cycles

Colorado Small Water Utility OT Breaches: Attackers Alter Settings, Disable Alarms, and Change Pumping Cycles

1
Comments
5 min read
indexed-btree: npm Supply Chain Malware Executes at Runtime and Uses a Smart Contract on Ethereum Sepolia for C2

indexed-btree: npm Supply Chain Malware Executes at Runtime and Uses a Smart Contract on Ethereum Sepolia for C2

1
Comments
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.