Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Priority

criticalCampaignActive

Russian Intelligence Deploys Fake Support Messages to Harvest Ukrainian Official Credentials at Scale

Russian intelligence services conducted a sustained phishing campaign using fabricated support messages to compromise messaging accounts of Ukrainian government officials, military personnel, politicians, and activists across Europe and the US. The operation highlights a persistent state-level threat to high-value targets using social engineering rather than zero-days.

Messaging platforms (specific platforms not specified in source), Ukrainian government officials, Ukrainian military personnel +2

All intelligence

Showing 19 of 728
highMalwareActive

SharkLoader malware family targets diplomatic and government networks across Indo-Pacific region

A previously undocumented loader malware called SharkLoader has been observed in a campaign tracked as StrikeShark, delivering Cobalt Strike Beacon to diplomatic organisations in Indonesia and government networks in Taiwan. The campaign represents a targeted operation against sensitive government infrastructure using commodity post-exploitation tools.

Indonesian diplomatic organisations, Taiwan government organisations
highSupply ChainEmerging

Dormant Code Injection Flaw in YouTube Ad Blocker Extension Reveals Supply Chain Risk in Chrome Web Store

Adblock for YouTube, a Chrome extension with 10M+ installs and featured status on the Chrome Web Store, contains dormant arbitrary JavaScript execution capability. The presence of this injection mechanism raises questions about extension vetting processes and potential for malicious activation.

Google Chrome, Chrome Web Store, Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk)
highVulnerabilityActive

OpenAM Liberty IDPP Anonymous SOAP Write Access – Privilege Escalation via Unauthenticated Discovery Store Manipulation

OpenAM versions ≤16.0.6 allow unauthenticated attackers to write arbitrary data to the Liberty Discovery store with admin privileges, bypassing identity ACLs. This enables persistent user profile tampering and potential service routing manipulation in deployments consuming Liberty metadata.

CVE-2026-45052
ForgeRock OpenAM Community Edition ≤16.0.6