CodeAIntel

CodeAIntel

Home
Threat Intelligence
AI Research
Darknet and Hacking Forums
Data Breaches
The Ticket Queue Was Holding the Tax Files
EY says an unauthorized party accessed a third-party support platform between March 28 and April 12 and downloaded client documents before the anomaly…
Jul 18 • Tom
When a Webroot Holds the Keys
Two Boomerang flaws expose plaintext service credentials and let unauthenticated users write to the sensor database, turning device-receiver endpoints…
Jul 16 • Tom
A Federal Case Moves Down the Ransomware Stack
A newly unsealed indictment treats bulletproof hosting as part of the criminal operation—and shows why infrastructure deserves the same scrutiny as…
Jul 15 • Tom
The Webshop Wasn't Breached. The Customer Data Still Was.
Lidl's service-provider incident shows why an intact storefront does not contain the identity risk created by data held elsewhere.
Jul 14 • Tom
MCP Is Already in the Internet’s Reconnaissance Playbook
A twoweek log sample found valid MCP initialization probes, AI assistant config probes, and credentialfile checks hitting a host that ran none of them.
Jul 13 • Tom
The Calendar Invite Was the Phishing Kit
A nearly empty email slipped past filters because the real lure lived inside an .ics file, where body scanners were not looking.
Jul 12 • Tom
JadePuffer Shows Ransomware Is Becoming a Workflow
The useful signal is not that an AI agent used exotic tradecraft. It is that ordinary exposure, secrets, and weak segmentation were enough for an…
Jul 7 • Tom
The Email Auth Was Green. The Image Still Carried Malware.
A valid SPF, DKIM, and DMARC result did not stop a Windows executable from riding inside an inline PNG. The control gap is content inspection, not…
Jul 6 • Tom
The Threat Stack Is Starting To Converge
PolinRider shows developer trust under pressure, Bad Epoll puts patch cadence back on the board, and JadePuffer shows why ransomware automation now…
Jul 5 • Tom
Avalon Turns Ransomware Into A Framework Problem
The new Avalon reporting is not just about CrownX encryption. It shows how credential theft, remote access, recovery pressure, and ransomware can be…
Jul 4 • Tom
Anubis Shows Why Ransomware Detection Has To Follow Legitimate Access
The latest Citrix Bleed 2 reporting is less about one edge flaw than a familiar chain: valid sessions, RMM tools, credential access, cloud transfer, and…
Jul 3 • Tom
PolinRider Makes The Package Registry A Developer Compromise Surface
Socket's latest findings show a North Korealinked campaign spreading hidden loaders across open source ecosystems, with Git history and developer…
Jul 2 • Tom
© 2026 Tom · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture