Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 9 of 30

201–225 of 728
highMalwareContained

Kimwolf IoT Botnet Operator Arrested: International Prosecution Marks Escalation in Law Enforcement Against DDoS-for-Hire Operators

Canadian authorities arrested a 23-year-old suspected operator of Kimwolf, an IoT botnet that compromised millions of devices for large-scale DDoS attacks. The arrest and cross-border charges signal coordinated enforcement against botnet operators who target journalists and security researchers.

Internet-of-Things devices (millions), Online services targeted by DDoS attacks, Media and security research organisations
criticalVulnerabilityActive

Supply Chain Compromise: Malicious CAP.js Package Versions with Credential Harvesting

Compromised versions of @cap-js database packages (sqlite, postgres, db-service) published April 29, 2026 harvested credentials and attempted self-propagation. Any system with these versions installed must assume all local credentials (npm tokens, cloud keys, SSH keys, GitHub PATs) are compromised.

CVE-2026-46421
@cap-js/sqlite@2.2.2, @cap-js/postgres@2.2.2, @cap-js/db-service@2.10.1
mediumPolicyActive

FTC enforcement action reveals widespread non-compliance with Take It Down Act among major platforms

The FTC has issued warning letters to 12 major technology firms for allegedly failing to comply with the Take It Down Act, which requires platforms to provide accessible removal mechanisms for nonconsensual intimate imagery and process deletion requests within 48 hours. This represents the first significant enforcement action under the statute and signals regulatory intent to hold platforms accountable for abuse prevention infrastructure.

12 major technology companies (specific names not provided in source)
highMalwareContained

Ukrainian law enforcement dismantles infostealer operation run by 18-year-old, recovering 28,000 compromised accounts

Ukrainian cyberpolice and U.S. law enforcement identified and disrupted an infostealer malware operation run by an 18-year-old from Odesa who had compromised approximately 28,000 user accounts from a California-based online retailer. The case demonstrates effective international law enforcement coordination against financially-motivated cybercriminals operating from Eastern Europe.

Unnamed California-based online retail store
criticalSupply ChainContained

CISA Contractor Exposed AWS GovCloud Credentials and Internal CI/CD Infrastructure via Public GitHub Repository

A CISA contractor maintained a public GitHub repository containing AWS GovCloud credentials for highly privileged accounts and documentation of CISA's internal software build, test, and deployment processes. The exposure represents a significant compromise of US government infrastructure security practices and threat intelligence operations.

AWS GovCloud, CISA internal systems, Cybersecurity & Infrastructure Security Agency
criticalSupply ChainActive

GitHub Actions Tag Spoofing Attack on issues-helper Demonstrates Repository Compromise at Scale

Threat actors compromised the popular GitHub Actions workflow issues-helper by redirecting all repository tags to malicious commits, enabling CI/CD credential theft from potentially thousands of dependent workflows. This represents a sophisticated supply chain attack exploiting the trust model of GitHub Actions.

GitHub Actions, actions-cool/issues-helper, Any workflow using issues-helper at any version tag