Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 15 of 37

351–375 of 906
highCampaignActive

Multi-vector cryptojacking campaign exploits SEO poisoning, ScreenConnect, and .NET tools to target GPU resources

Threat actors are running a coordinated cryptojacking operation that uses SEO poisoning and AI chatbot abuse to distribute malicious sites, then deploys ScreenConnect and Microsoft .NET utilities as initial access and persistence mechanisms to hijack GPU resources on high-performance systems.

ScreenConnect, Microsoft .NET utilities, High-performance computing systems
informationalToolEmerging

AppOmni's Marlin AI automates SaaS misconfiguration investigation while preserving human control over remediation

AppOmni has released Marlin AI, a tool that autonomously investigates SaaS security misconfigurations and traces their blast radius across enterprise environments, stopping short of automatic remediation. This represents incremental progress in scaling SaaS security operations but raises questions about investigation accuracy and false positive rates.

SaaS platforms (general)
highCampaignActive

Lithuania's state registry breach exposes 600,000 records: implications for EU critical infrastructure

Foreign attackers gained unauthorised access to 600,000 records from Lithuania's Centre of Registers, which manages property and legal entity data. This represents a significant compromise of state administrative infrastructure with potential implications for identity fraud and state surveillance.

Centre of Registers (Lithuania), Lithuanian state property records system, Lithuanian legal entity records system
highCampaignContained

Dutch Law Enforcement Dismantles Russian Cyberattack Infrastructure by Seizing 800 Servers and Arresting Hosting Operators

Dutch authorities arrested two co-owners of Internet hosting companies and seized approximately 800 servers used by Russian intelligence to stage cyberattacks, influence operations, and disinformation campaigns targeting the EU. The action disrupts a significant portion of Russia's operational infrastructure in Europe.

Stark Industries Solutions, EU organisations and member states
highCampaignActive

Chinese-language PhaaS ecosystem rivals Russian offerings, lowering attack barriers for regional threat actors

Google's threat intelligence team identified a dozen mature phishing-as-a-service offerings operating in Chinese-language underground forums, representing a significant shift in the geographic distribution of PhaaS infrastructure and suggesting intensified credential theft campaigns targeting organisations with Asia-Pacific exposure.

Organisations with Asia-Pacific operations, Enterprise email systems, Authentication systems