Subscribe
Sign in
Home
Threat Intelligence
AI Research
Darknet and Hacking Forums
Data Breaches
Latest
Top
Hi Rey. This Is Why We Keep the Receipts.
I challenged the persona in 2024. The record shows why.
Oct 4
•
Tom
September 2026
ShinyHunters Says It Hacked the FBI. Which ShinyHunters?
The group wants the FBI to retract its warning. First, it has to prove its FBIjobs story.
Sep 23
•
Tom
August 2026
CVE-2026-21962 Hides Behind the WebLogic Label
CISA says CVE-2026-21962 is being exploited. Oracle scopes the affected layer to HTTP Server and the WebLogic proxy plug-in; federal civilian agencies…
Aug 25
•
Tom
Four Days Offline Inside a Resilient Grid
A cyberattack reportedly shut a small UK generator for four days without threatening the wider grid. Local operational loss still counts.
Aug 23
•
Tom
The Lock Screen Was the Credential Phish.
SynkLoader turns a Teams help-desk lure into a local Windows password prompt, reverse proxy, and remote-control stack. The useful detection point is the…
Aug 22
•
Tom
Patch the Server. Then Audit Every Installer It Served.
CISA added two exploited TrueConf flaws to KEV. Researchers found attackers replaced a client installer with a trojanized copy carrying PhantomCore…
Aug 21
•
Tom
The Charges Are New. The Credential Playbook Is Not.
DOJ's expanded Mabna Institute case describes personalized phishing, password spraying, and valid-account abuse. Credential dumps can feed the same…
Aug 20
•
Tom
The Extension ID Stayed Put. The Payload Changed.
A 77-extension Firefox corpus tied stable add-on identities, cloned code, shared infrastructure, and version histories to wallet and credential…
Aug 20
•
Tom
A Web Page Should Not Reach Your AI Control Plane
CISA's active-exploitation warning for Ray CVE-2025-62593 exposes a broader weakness: local and private compute services can still be reachable through…
Aug 18
•
Tom
Put Private Cyber Power Under Public Command
The White House is right to mobilize vetted U.S. companies against foreign cybercriminal networks—as long as target selection, legal authority, and…
Aug 13
•
Tom
The Router Was Waiting for Whoever Answered
Researchers found a root-running phone-home component embedded across 20 router models. It needs no inbound exposure, trusts any answering endpoint, and…
Aug 6
•
Tom
The Malware Arrived With Valid Provenance
A fast-moving npm compromise used a maintainer's own release workflows to ship verifiably sourced malicious builds. The attestation was valid; the…
Aug 5
•
Tom
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts