CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 57 matching records.
AUTO-POLL // 2026-08-16 04:45 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-04 17:22 UTC
Vendor Research
TIER 2

Spring 2026 PCI DSS and PCI 3DS compliance packages for AWS now available

AWS Security Blog · Will Black · indexed 2026-08-16 02:02 UTC

Amazon Web Services (AWS) is pleased to announce the successful completion of our Payment Card Industry (PCI) Data Security Standard (DSS) and Three Domain Secure (3DS) certifications. As part of this renewal, we have expanded the scope to include three additional AWS services and one additional AWS Region: Newly added AWS services: Amazon Bedrock AgentCore […]

Cloud Security
P0
2026-08-03 10:00 UTC
Vendor Research
TIER 2

30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next

Tenable Blog · Blake Kizer · indexed 2026-08-16 02:02 UTC

Tenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs — it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team's work, what it cost, and why your program is next.Key takeaways:Now code security starts with proof, not suspicions. Frontier AI instantly builds working exploits and proves which flaws are genuinely dangerous in your source code. Now remediations are confirm…

AI SecurityCloud SecuritySecurity Research
P0
2026-07-31 19:44 UTC
Vendor Research
TIER 2

HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance

AWS Security Blog · Abdul Javid · indexed 2026-08-16 02:02 UTC

Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS. The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and […]

Cloud Security
P0
2026-07-31 11:53 UTC
Vendor Research
TIER 2

Rapid7 at Black Hat USA 2026: See preemptive security in action

Rapid7 · Emma Burdett · indexed 2026-08-16 02:02 UTC

Black Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of activities at the Border Grill.This year, our focus is preemptive security: helping security teams anticipate credible risk, respond at machine speed, and maintain an accurate view of their security and compliance posture as their environment changes.Visit the Rapid7 booth at Black Hat USAYou can find Rapid7 at booth #2…

AI SecurityCloud SecurityDFIRSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-07-30 17:22 UTC
Vendor Research
TIER 2

Extend Amazon Inspector SBOM Generator with Plugins

AWS Security Blog · Michael Long · indexed 2026-08-16 02:02 UTC

Amazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon Inspector SBOM Generator (inspector-sbomgen), a standalone command-line tool that produces a software bill of materials (SBOM) from container […]

Cloud SecurityVulnerabilities
P0
2026-07-30 16:05 UTC
Vendor Research
TIER 2

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Tenable Blog · Ashley Lukeeram · indexed 2026-08-16 02:02 UTC

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Querying for isolated, hard-to-reach process-control systems, enables operators to establish a requir…

Cloud SecurityDFIRICS / OTThreat ActorsThreat IntelligenceVulnerabilities
P10
2026-07-28 18:55 UTC
Vendor Research
TIER 2

AWS KMS or AWS CloudHSM: Choose the right key management solution

AWS Security Blog · Derek Tumulak · indexed 2026-08-16 02:02 UTC

Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is a fully managed service that integrates with all AWS […]

Cloud Security
P0
2026-07-23 07:13 UTC
Government
TIER 1

2026-009: Critical Vulnerabilities in Microsoft SharePoint

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that…

Cloud SecurityCredential ExposureMicrosoftVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-50522CVE-2026-56164CVE-2026-58644
P45
2026-07-20 09:36 UTC
Vendor Research
TIER 2

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-16 02:02 UTC

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-w…

Cloud SecurityDFIRMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-60137CVE-2026-601377CVE-2026-63030
P70
2026-07-16 12:00 UTC
Vendor Research
TIER 2

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-202…

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-07-15 14:00 UTC
Vendor Research
TIER 2

The Risk of Exposed Cloud Functions and How to Harden

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo…

AI SecurityAppleCloud SecurityInitial AccessMalwareThreat ActorsVulnerabilities
P15
2026-07-15 13:14 UTC
Vendor Research
TIER 2

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-16 02:02 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators of compromise are available and urgent patching is recommended.BackgroundSonicWall's Secure Mobile Ac…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-15409CVE-2026-15410
P100
2026-07-14 19:22 UTC
Independent Research
TIER 2

Microsoft Patches a Record 570 Security Flaws

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

AI SecurityCloud SecurityMicrosoftVulnerabilities
P0
2026-07-14 14:23 UTC
Vendor Research
TIER 2

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will …

AppleCloud SecurityLinuxMalwareMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2026-56155CVE-2026-56164
P65
2026-07-13 15:03 UTC
Independent Research
TIER 2

Lessons Learned from CISA’s Recent GitHub Leak

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.

Cloud SecurityData Breaches
P0
2026-06-15 14:00 UTC
Vendor Research
TIER 2

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration. The threat actor had broad collectio…

AI SecurityCloud SecurityDFIRInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-06-11 14:00 UTC
Vendor Research
TIER 2

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity p…

AppleCloud SecurityData BreachesLinuxMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-35273
P45
2026-06-10 11:55 UTC
Government
TIER 1

2026-008: Critical vulnerabilities in Ivanti Sentry

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.

Cloud SecurityVulnerabilities
P15
2026-06-09 14:19 UTC
Vendor Research
TIER 2

Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

32Critical166Important0Moderate0LowMicrosoft addresses 198 CVEs in the largest Patch Tuesday release, including three zero-days.Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CV…

Cloud SecurityLinuxMicrosoftMobile SecurityVulnerabilities CVE-2025-10263CVE-2026-33825CVE-2026-41091CVE-2026-42909CVE-2026-42913CVE-2026-42985CVE-2026-42992CVE-2026-42993CVE-2026-44799CVE-2026-44801CVE-2026-47289CVE-2026-47653CVE-2026-47654CVE-2026-48563CVE-2026-49160CVE-2026-50507CVE-2026-8863
P95
2026-05-29 14:19 UTC
Vendor Research
TIER 1

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues an HTTP redirect to an attacker-controlled redirect_uri. Because the identity platform evaluates th…

AppleCloud SecurityMalwarePhishingSecurity ResearchVulnerabilities
P0
2026-05-11 14:00 UTC
Vendor Research
TIER 2

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll…

AI SecurityAppleAPT / Nation-StateCloud SecurityDFIRInitial AccessMalwareMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-04-30 09:25 UTC
Government
TIER 1

2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising…

Cloud SecurityLinuxVulnerabilities CVE-2026-31431
P15
2026-04-23 14:00 UTC
Vendor Research
TIER 2

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692…

Cloud SecurityInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-04-16 14:00 UTC
Vendor Research
TIER 2

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-16 02:02 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulnerabilities. Faced with this scenario, defenders have two critical tasks: hardening the software we u…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat Actor ChatterThreat ActorsUnderground IntelligenceVulnerabilities
P60
2026-03-25 07:51 UTC
Government
TIER 1

2026-004: Critical Vulnerability in SharePoint Exploited

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release. CERT-EU strongly recommends updating SharePoint servers as soon a…

Cloud SecurityMicrosoftVulnerabilities
P55
2026-01-30 09:09 UTC
Government
TIER 1

2026-001: Critical vulnerabilities in Ivanti EPMM

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 29 January 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their EPMM products. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a limited number of cases.

Cloud SecurityVulnerabilities
P15
12