Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 9 of 37

201–225 of 906
highVulnerabilityActive

OpenAM Liberty IDPP Anonymous SOAP Write Access – Privilege Escalation via Unauthenticated Discovery Store Manipulation

OpenAM versions ≤16.0.6 allow unauthenticated attackers to write arbitrary data to the Liberty Discovery store with admin privileges, bypassing identity ACLs. This enables persistent user profile tampering and potential service routing manipulation in deployments consuming Liberty metadata.

CVE-2026-45052
ForgeRock OpenAM Community Edition ≤16.0.6
criticalCampaignActive

FortiBleed: Large-Scale Credential Harvesting Campaign Targeting 430,000+ FortiGate Firewalls Globally

A Russian-speaking initial access broker has been conducting a sustained credential-harvesting campaign against FortiGate firewalls since February 2026, compromising over 430,000 devices globally and harvesting approximately 110 million credentials. This represents a significant threat to enterprise network security infrastructure and likely serves as a precursor to deeper compromise or sale of access.

Fortinet FortiGate
informationalToolEmerging

OpenAI's GPT-5.5-Cyber expansion signals shift toward AI-assisted vulnerability discovery at scale

OpenAI is expanding its Daybreak initiative by releasing an improved GPT-5.5-Cyber model to trusted defenders for identifying and patching software vulnerabilities across large codebases. This represents a maturing capability in AI-assisted security testing that could reshape how organisations approach vulnerability discovery.

OpenAI Daybreak Initiative participants
criticalSupply ChainActive

North Korean Sapphire Sleet targets npm ecosystem with Mastra AI supply chain compromise affecting 140+ packages

Microsoft attributed a compromise of over 140 npm packages to North Korean threat actor Sapphire Sleet, leveraging the Mastra AI project as an entry point. This represents a high-impact supply chain attack with potential for widespread malware distribution across the JavaScript ecosystem.

npm registry, Mastra AI, JavaScript applications using affected npm packages