Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 3 of 30

51–75 of 728
highVulnerabilityActive

Multiple High-Impact Vulnerabilities Surface: Apple Beats Eavesdropping, GCP Config Connector Takeover, and Android TV Botnet Link

SecurityWeek reports several significant security issues including an Apple Beats eavesdropping flaw patch, an unpatched GCP Config Connector vulnerability enabling account takeover, an Android TV botnet linked to an Israeli firm, and closure of the DOT's Delta Air Lines CrowdStrike incident investigation.

Apple Beats, Google Cloud Platform Config Connector, Android TV +2
highMalwareContained

International takedown of SocGholish botnet disrupts Evil Corp's malware distribution infrastructure

Law enforcement conducted a coordinated international operation against the SocGholish botnet, a distribution mechanism linked to Russia-based cybercrime group Evil Corp. The disruption degrades Evil Corp's ability to deliver secondary payloads and conduct follow-on attacks against compromised networks.

SocGholish botnet victims, organisations compromised by Evil Corp campaigns
criticalVulnerabilityActive

Path Traversal in Crawl4AI File Downloads Enables Unauthenticated Arbitrary File Write and RCE

Crawl4AI's download handler fails to sanitize filenames from HTTP headers and page-controlled sources, allowing path traversal to write arbitrary files with attacker content. Pre-authenticated exploitation is possible via the Docker `/crawl` endpoint, enabling remote code execution through shell rc-file overwriting, SSH key injection, or cron job placement.

crawl4ai (async_crawler_strategy.py)
highMalwareActive

NetNut Residential Proxy Service Masking Four-Year Android Botnet Operation at Scale

Popa, a multi-year Android botnet compromising millions of consumer TV boxes, has been attributed to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The botnet facilitates advertising fraud, account takeovers, and mass data scraping under commercial cover.

Alarum Technologies Ltd (NASDAQ: ALAR), NetNut (residential proxy service), Android TV boxes +1
highPolicyActive

Bulgarian Export Licensing Enabled Surveillance Tool Sales to Authoritarian Regimes

Human Rights Watch obtained Bulgarian export records showing the government approved surveillance technology exports by firm Circles to law enforcement and intelligence agencies in countries with documented human rights abuse records between 2018 and 2023. This represents a systemic compliance failure in export controls for dual-use surveillance capabilities.

Circles (surveillance firm), Bulgarian government export licensing authority
criticalCampaignActive

UK Critical Infrastructure Faces Pre-positioned Nation-State Threats: NCSC Warns of Intelligence Gathering for Future Kinetic Operations

UK National Cyber Security Centre leadership has warned that hostile nation-states are behind approximately 75% of cyber attacks on British critical infrastructure and are actively pre-positioning access for use in future kinetic conflicts. This represents a shift from opportunistic compromise to strategic preparation for wartime operations.

UK critical infrastructure operators across multiple sectors
criticalVulnerabilityEmerging

Splunk Enterprise RCE via Unauthenticated File Operations: Pre-Authentication Compromise of Widely-Deployed Log Analytics Platform

CVE-2026-20253, a CVSS 9.8 critical vulnerability in Splunk Enterprise versions before 10.2.4 and 10.0.7, permits unauthenticated attackers to perform arbitrary file operations and achieve remote code execution, affecting a primary target for enterprise threat actors seeking post-compromise persistence and reconnaissance.

CVE-2026-20253
Splunk Enterprise versions below 10.2.4 and 10.0.7