DEV Community

#threatintel

Gathering, analyzing, and applying intelligence about threats and threat actors.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
WatchGuard Firebox CVE-2025-14733: Unauthenticated RCE via IKEv2 and Ransomware Exploitation

WatchGuard Firebox CVE-2025-14733: Unauthenticated RCE via IKEv2 and Ransomware Exploitation

1
Comments
7 min read
Microsoft 365 Session Compromise and MFA Persistence via Passkey-Themed Voice Calls and SMS

Microsoft 365 Session Compromise and MFA Persistence via Passkey-Themed Voice Calls and SMS

1
Comments
8 min read
Mantax Otax: Mobile Malware Combining Encryption, Monitoring, and Device Sabotage

Mantax Otax: Mobile Malware Combining Encryption, Monitoring, and Device Sabotage

1
Comments
7 min read
AI-Assisted Executive Impersonation and Fake Invoices: Over 1 Million ACH Payment Fraud Emails

AI-Assisted Executive Impersonation and Fake Invoices: Over 1 Million ACH Payment Fraud Emails

1
Comments
7 min read
Workflow Identity Hijacking: AI Workflows Returning Internal Data Without Checking the Requester’s Authority

Workflow Identity Hijacking: AI Workflows Returning Internal Data Without Checking the Requester’s Authority

1
Comments
6 min read
Industrial-Scale AI Distillation: Collecting Model Outputs Through Distributed Accounts and Relays

Industrial-Scale AI Distillation: Collecting Model Outputs Through Distributed Accounts and Relays

1
Comments
6 min read
Phishing Pages Built Inside the Browser: Microsoft Redirects and Blob URLs

Phishing Pages Built Inside the Browser: Microsoft Redirects and Blob URLs

1
Comments
6 min read
ShieldCrash: PoC Claims a Defender Patch Bypass and Arbitrary File Read as SYSTEM

ShieldCrash: PoC Claims a Defender Patch Bypass and Arbitrary File Read as SYSTEM

1
Comments
5 min read
Fortinet CVE-2026-84390 and CVE-2026-84388: JWT Authentication Bypass and Browser Traffic Proxying

Fortinet CVE-2026-84390 and CVE-2026-84388: JWT Authentication Bypass and Browser Traffic Proxying

1
Comments
6 min read
Chrome CVE-2026-87491: V8 Out-of-Bounds Write Exploited in the Wild

Chrome CVE-2026-87491: V8 Out-of-Bounds Write Exploited in the Wild

1
Comments
5 min read
Ivanti Neurons for ITSM and Sentry: Unauthenticated Deserialization RCE and Administrative Authentication Bypass

Ivanti Neurons for ITSM and Sentry: Unauthenticated Deserialization RCE and Administrative Authentication Bypass

1
Comments
6 min read
S4GET CVE-2026-58240: Missing Authentication in SAP Message Server Enables Cluster-Wide RCE

S4GET CVE-2026-58240: Missing Authentication in SAP Message Server Enables Cluster-Wide RCE

1
Comments
6 min read
ClearFake WebDAV Attacks: From BNB Smart Chain to Amatera, Reverse Proxies, and NetSupport

ClearFake WebDAV Attacks: From BNB Smart Chain to Amatera, Reverse Proxies, and NetSupport

1
Comments
6 min read
Multi-Hop Phishing Through Legitimate Google Services

Multi-Hop Phishing Through Legitimate Google Services

1
Comments
6 min read
StyleSmuggler: Unauthenticated RCE via Adobe Commerce Failed Payment Email Rendering

StyleSmuggler: Unauthenticated RCE via Adobe Commerce Failed Payment Email Rendering

1
Comments
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.