Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 5 of 36

101–125 of 879
highSupply ChainActive

Zero-day marketplace operated by convicted felons and conspiracy theorists poses elevated counterparty risk

A zero-day acquisition startup offering millions for undisclosed vulnerabilities is operated by convicted felons and far-right conspiracy theorists with histories of fraud and operating shell companies. This raises serious concerns about whether acquired vulnerabilities could be resold to hostile actors or leaked rather than responsibly disclosed.

Popular software vendors (unspecified in source), Organisations purchasing zero-day intelligence from unvetted brokers
mediumToolEmerging

AI Coding Agents Mimicking Attack Behaviour: Endpoint Detection Evasion Through Legitimate Tool Operations

Sophos discovered that AI coding agents like Claude Code, Cursor, and OpenAI Codex trigger endpoint security detection rules designed to catch attackers because their normal operations (credential enumeration, browser access) resemble attacker reconnaissance. This creates a detection accuracy problem rather than a security vulnerability.

Claude Code, Cursor, OpenAI Codex +2
highCampaignActive

Extortion Without Encryption: Kairos Group Monetises Data Theft Against U.S. Government Without Traditional Ransomware

A U.S. government entity paid approximately $1 million to the Kairos group to prevent stolen data from being published, despite no evidence that Kairos deployed encryption or conducted a traditional ransomware attack. This represents a shift in extortion tactics where data theft alone, without operational disruption, suffices to extract payment.

U.S. Government Entity (unspecified)
highMalwareEmerging

First documented LLM-autonomous ransomware operation signals shift in attack automation

JadePuffer ransomware was deployed and operated autonomously by an LLM agent, marking the first documented case of a fully AI-driven ransomware campaign. This represents a significant escalation in attack automation where threat actors delegate operational decisions to language models rather than manual execution.

Generic victim organisations (specific victims not disclosed in summary)
highCampaignActive

Three disparate security incidents highlight enforcement trends: hacktivist prosecution, open source supply-chain risk, and organised financial crime

SecurityWeek reports on three unrelated incidents: an Anonymous-affiliated Canadian hacker imprisoned, zero-days disclosed in open source projects, and Venezuelan nationals convicted for ATM jackpotting schemes. Collectively, they illustrate sustained pressure on hacktivists, emerging supply-chain vulnerabilities, and organised cybercrime targeting financial infrastructure.

open-source projects, ATM networks
criticalVulnerabilityActive

Unauthenticated Path Traversal in GravitLauncher FileServerHandler – Arbitrary File Read & Authentication Bypass

An unauthenticated path traversal in LaunchServer's HTTP file server allows remote attackers to read arbitrary files, including cryptographic signing keys and database credentials, enabling full authentication bypass and system compromise. This affects GravitLauncher ≤ 5.7.11 on default port 9274.

CVE-2026-54617
GravitLauncher/LaunchServer ≤ 5.7.11