Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 12 of 30

276–300 of 728
highCampaignResolved

Sustained Multi-Sector Phishing Campaign Targets 500+ Organisations Across Critical Infrastructure

A years-long phishing campaign has compromised over 500 organisations across aviation, energy, infrastructure, logistics, public administration, and technology sectors. The extended campaign duration and cross-sector targeting suggest either a sophisticated threat actor or multiple coordinated groups with sustained operational capability.

Aviation sector organisations, Critical infrastructure operators, Energy sector organisations +3
criticalSupply ChainResolved

Canvas LMS Supply Chain Extortion: 275M Student Records at Risk Across 9,000 Institutions

Cybercriminals breached Canvas, a learning management system serving 9,000 educational institutions, and defaced login pages with ransom demands whilst threatening to leak records for 275 million students and faculty. The attack represents a supply-chain compromise of education infrastructure affecting operational continuity at scale.

Canvas LMS, Educational institutions (schools, colleges, universities)
criticalVulnerabilityResolved

Grav CMS Multiple RCE Vectors: Unsafe Deserialization & Command Injection

Grav CMS contains five remote code execution vulnerabilities spanning unsafe unserialize() calls without class restrictions and unescaped shell parameters in git operations. This PoC is significant because it demonstrates ecosystem-wide deserialization hygiene gaps and highlights that security controls exist in the same codebase but are inconsistently applied.

GHSA-vj3m-2g9h-vm4p
getgrav/grav
criticalVulnerabilityResolved

ArcadeDB Authorization Bypass via Uninitialized Security Context and Disabled Schema Enforcement

Two compounding defects in ArcadeDB allow authenticated users to bypass database and record-level authorization controls: uninitialized fileAccessMap treated as allow-all, and newly-created databases with disabled security factories. Any authenticated principal can read/write/mutate schemas across all databases on a shared server.

CVE-2026-44221
ArcadeData/arcadedb (<26.4.2)