Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 5 of 17

101–125 of 401
highPolicyActive

Google's 2029 PQC Migration Deadline: Crypto-Agility Crisis Looming for Enterprise Infrastructure

Google has committed to migrating its infrastructure to post-quantum cryptography by 2029, signalling that the cryptographically-relevant quantum computer threat window is closing faster than many organisations anticipated. This accelerates industry pressure to inventory and remediate legacy systems before quantum capabilities render current encryption obsolete.

Google, Enterprise organisations dependent on Google Cloud, Organisations using TLS/PKI infrastructure
highVulnerabilityEmerging

Multi-tenant SMS data exposure via parameter tampering in OpenCode messaging platform

OpenCode Systems OC Messaging and USSD Gateway versions 6.32.2 contain an insecure direct object reference (IDOR) vulnerability allowing authenticated users to access SMS messages from other tenants by manipulating company or tenant identifiers. This affects multi-tenant deployments handling sensitive communications.

CVE-2025-70614
OpenCode Systems OC Messaging 6.32.2, OpenCode Systems USSD Gateway 6.32.2
highMalwareContained

RedLine Infostealer Administrator Arrested: Law Enforcement Disrupts Malware-as-a-Service Operation

Hambardzum Minasyan, an Armenian national allegedly involved in developing and administering the RedLine infostealer, has been extradited to the United States. This arrest represents a significant enforcement action against a malware-as-a-service operation that has compromised thousands of organisations globally.

Organisations using compromised credentials, Enterprise networks, Financial institutions
criticalVulnerabilityActive

OpenTelemetry RMI Deserialization RCE - Unsafe Gadget Chain Exploitation Vector

OpenTelemetry Java instrumentation versions <2.26.1 fail to apply serialization filters on RMI deserialization, allowing unauthenticated remote code execution when RMI endpoints are network-accessible and gadget chains are present. This affects production observability infrastructure with potential for supply-chain compromise.

CVE-2026-33701
OpenTelemetry/opentelemetry-java-instrumentation (<2.26.1)