Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 3 of 36

51–75 of 879
highCampaignActive

Abbott's dual breach exposes risks in legacy healthcare infrastructure and cloud portals

Abbott Laboratories is investigating two concurrent cybersecurity incidents: unauthorised access to legacy Exact Sciences systems in its Cancer Diagnostics division and a separate breach of its LabCentral portal with alleged data theft. The incidents highlight vulnerabilities in healthcare IT infrastructure spanning both legacy systems and modern cloud platforms.

Abbott Laboratories, Exact Sciences Cancer Diagnostics, LabCentral portal
highPolicyActive

OT vulnerability disclosure dilemma: balancing safety against transparency in legacy industrial systems

SecurityWeek examines the structural tension in operational technology security where legacy systems, safety dependencies, and critical infrastructure protection create barriers to standard vulnerability disclosure practices. The piece highlights how OT environments differ fundamentally from IT, complicating the security research and patching ecosystem.

OT systems broadly, legacy industrial control systems
highCampaignResolved

Scattered Spider operatives sentenced for £29M TfL ransomware attack demonstrating persistent threat from young, organised cybercriminals

Two members of the Scattered Spider cybercriminal group, Owen Flowers (18) and Thalha Jubair (20), received 5.5-year sentences for orchestrating a 2024 ransomware attack against Transport for London that disabled 148 systems and forced 27,000 employees to reset credentials in person. The sentencing marks a significant law enforcement victory but group's capacity to cause infrastructure-level disruption.

Transport for London
highPolicyEmerging

US-Canada surveillance legislation dispute highlights encryption backdoor risks in Five Eyes alliance

Senator Ron Wyden opposes Canada's proposed lawful access legislation, arguing it would repurpose US technology infrastructure for surveillance and set a dangerous precedent. The dispute reflects ongoing tensions within the Five Eyes alliance over encryption backdoors and government access capabilities.

US technology infrastructure providers, Canadian telecommunications operators
informationalPolicyEmerging

Gold Eagle: US government centralises AI-driven vulnerability coordination across critical infrastructure

The Trump administration has launched Gold Eagle, a clearinghouse programme that uses artificial intelligence to help industry and government detect, prioritise and remediate cybersecurity vulnerabilities at scale. This represents a significant policy shift toward centralised vulnerability intelligence sharing.

Critical infrastructure operators, US government agencies, Private sector industry participants
criticalVulnerabilityActive

FacturaScripts Path Traversal in File Upload Handler — Unauthenticated RCE via Directory Escape and .htaccess Write

Authenticated users can bypass file upload restrictions in FacturaScripts by injecting `../` sequences into client-supplied filenames, enabling arbitrary file writes outside the intended `MyFiles/` directory. Combined with `.htaccess` exclusion bypass, this escalates to remote code execution via executable file placement in web-accessible directories.

facturascripts/facturascripts
highVulnerabilityActive

Microsoft's AI-Assisted Vulnerability Discovery Drives 570-Patch Record, Signalling Acceleration in Patch Volume

Microsoft released 570 security patches in a single Patch Tuesday cycle, triple the previous month's record, with the vendor attributing the surge to artificial intelligence-aided vulnerability discovery. This represents a significant shift in patch cadence and raises questions about remediation capacity across enterprise environments.

Microsoft Windows, Microsoft Office, Microsoft other software products
highPolicyActive

US prosecutes Russian bulletproof hosting operators: infrastructure enablers face indictment

The US Department of Justice has unsealed charges against alleged operators of Media Land and ML Cloud, St. Petersburg-based companies accused of providing hosting infrastructure and technical support specifically to cybercriminals. This represents a significant enforcement action targeting the operational backbone of organised cybercrime.

Cybercriminals using bulletproof hosting services
criticalVulnerabilityActive

Microsoft's Record 622-Vulnerability Patch Cycle Reveals Active Exploitation of Directory and Collaboration Tiers

Microsoft released patches for 622 vulnerabilities in a single cycle, including two zero-days already exploited in the wild affecting Active Directory and SharePoint Server, plus a publicly disclosed BitLocker flaw. The scale and active exploitation indicate broad attack surface across enterprise authentication and document collaboration infrastructure.

Microsoft Active Directory, Microsoft SharePoint Server, Microsoft BitLocker