Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Priority

highVulnerabilityActive

ESAFENET CDG document management system targeted by login-bypass scanners following public XSS disclosure

Internet-wide scanning activity has been observed against ESAFENET's CDG document management platform, exploiting known weaknesses including default credentials, SQL injection, and cross-site scripting. The product, popular in Chinese markets, exhibits preventable authentication and input validation flaws despite being marketed as a secure data leakage prevention solution.

ESAFENET CDG (Content Data Guard)

All intelligence

Showing 19 of 879
highVulnerabilityEmerging

Aggregated threat briefing reveals convergence of AI-powered malware, industrial vulnerabilities, and kernel flaws across multiple attack vectors

SecurityWeek's aggregate report covers multiple concurrent threats including Dolphin X AI-assisted malware, Siemens industrial switch vulnerabilities, a Russian Zimbra campaign, Linux kernel flaws, and ransomware extortion attempts. The breadth suggests attackers are expanding their targeting across consumer, industrial, and infrastructure domains simultaneously.

Siemens ROX II, Linux kernel, Zimbra webmail +2
highCampaignActive

BlueNoroff Operationalises Crypto-Targeted Phishing Through Compromised Industry Contacts and Typosquatted Domains

North Korean threat actor BlueNoroff is running a sophisticated phishing campaign that impersonates Zoom and Microsoft Teams via typosquatted domains to profile cryptocurrency wallet holders before delivering malware. The operation combines trusted industry contact compromise with social engineering to increase success rates.

Zoom, Microsoft Teams, Cryptocurrency wallet users
informationalPolicyActive

UK Cyber Policy Continuity Under Labour: Strategic Retention of Lloyd Signals Institutional Stability

The UK's new Prime Minister Keir Starmer has retained Liz Lloyd in a cyber policy role despite dissolving her previous ministry, indicating continuity in national cyber governance rather than substantive policy change. This retention of a key Starmer ally in a reduced capacity suggests cyber remains a government priority whilst undergoing organisational restructuring.

informationalToolEmerging

Frontier AI Models Struggle with Autonomous Malware Analysis When Evidence Invalidates Initial Conclusions

SentinelOne Labs benchmarked whether large frontier AI models can maintain investigative integrity during long-horizon malware analysis tasks when new evidence contradicts prior reasoning. The research highlights fundamental reliability gaps in autonomous AI-driven security analysis.

Frontier AI models (general category), AI-augmented malware analysis tools
informationalPolicyActive

CISA 2015 Information-Sharing Framework Extended by a Decade in Congressional Defence Bill

The US House of Representatives has approved a 10-year renewal of the Cybersecurity Information Sharing Act (CISA 2015) as part of the fiscal 2027 National Defence Authorisation Act. This extends protections for voluntary threat intelligence sharing between private sector organisations and government agencies.

US private sector organisations, CISA, US federal cybersecurity programmes