DEV Community

#threatintel

Gathering, analyzing, and applying intelligence about threats and threat actors.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
XCSSET v40: From Xcode Supply Chain to Memory-Resident and Browser/Telegram Hijacking

XCSSET v40: From Xcode Supply Chain to Memory-Resident and Browser/Telegram Hijacking

Comments
6 min read
Boundary Escape in Claude Evaluation Environment: Real-World Incidents at 3 Organizations and Malicious PyPI Package Publication

Boundary Escape in Claude Evaluation Environment: Real-World Incidents at 3 Organizations and Malicious PyPI Package Publication

Comments
6 min read
DeepSeek and Hermes: An Autonomous Attack Platform for Reconnaissance, PoC Acquisition, and Target Selection

DeepSeek and Hermes: An Autonomous Attack Platform for Reconnaissance, PoC Acquisition, and Target Selection

Comments
5 min read
Adform Delivery Script Compromised: Wallet Addresses Replaced on Clipboard and Screen

Adform Delivery Script Compromised: Wallet Addresses Replaced on Clipboard and Screen

Comments
5 min read
Water OT Attack Targeting Public PLCs: Locking Out Operators via Password and IP Changes

Water OT Attack Targeting Public PLCs: Locking Out Operators via Password and IP Changes

Comments
5 min read
RufRoot (CVE-2026-59726): Full Compromise of AI Agent Infrastructure via Unauthenticated MCP Bridge

RufRoot (CVE-2026-59726): Full Compromise of AI Agent Infrastructure via Unauthenticated MCP Bridge

Comments
5 min read
KindaRails2Shell (CVE-2026-66066): Arbitrary File Read and RCE via Active Storage Uploads

KindaRails2Shell (CVE-2026-66066): Arbitrary File Read and RCE via Active Storage Uploads

Comments
4 min read
TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email

TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email

Comments
5 min read
GTIG: 2026 OSS Supply Chain Compromise, Credential Theft, and Self-Propagation

GTIG: 2026 OSS Supply Chain Compromise, Credential Theft, and Self-Propagation

Comments
5 min read
STAC4749: Chaos Ransomware in Under 17 Hours via Teams IT Support Scam

STAC4749: Chaos Ransomware in Under 17 Hours via Teams IT Support Scam

Comments
5 min read
KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise

KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise

Comments 1
6 min read
CISA KEV Additions: Adobe ColdFusion RCE & Supply Chain Exploitation

CISA KEV Additions: Adobe ColdFusion RCE & Supply Chain Exploitation

Comments
5 min read
OpenAI and Hugging Face: Autonomous AI Agent Chains Zero-Day, Credentials, and Cloud Lateral Movement

OpenAI and Hugging Face: Autonomous AI Agent Chains Zero-Day, Credentials, and Cloud Lateral Movement

Comments
7 min read
ShinyHunters: Breaking Help Desks via Vishing and Bulk Stealing SaaS via SSO

ShinyHunters: Breaking Help Desks via Vishing and Bulk Stealing SaaS via SSO

Comments
6 min read
VMware VMSA-2026-0006: vCenter Authentication Bypass / RCE and ESXi VM Escape

VMware VMSA-2026-0006: vCenter Authentication Bypass / RCE and ESXi VM Escape

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.