Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 6 of 36

126–150 of 879
highMalwareContained

FBI Dismantles NetNut Residential Proxy Operation Linked to Popa Botnet Infrastructure

US federal law enforcement seized NetNut, an Israeli residential proxy service operated by publicly-traded Alarum Technologies, following security research linking it to the Popa botnet comprising at least two million compromised devices. The action represents significant progress in disrupting a major abuse infrastructure that enabled attackers to mask malicious traffic through residential IP addresses.

Alarum Technologies (NetNut), NetNut proxy platform users
highCampaignActive

Google Disrupts NetNut Residential Proxy Network: Law Enforcement Success Against Distributed Infrastructure Abuse

Google's Threat Intelligence Group, working with the FBI and Lumen, significantly degraded the NetNut residential proxy network by reducing its device pool by millions. This coordinated action targets infrastructure used for credential stuffing, ad fraud, and anonymised malicious activity across compromised home devices.

NetNut (Popa), Home broadband subscribers, Online services targeted by fraud
highCampaignActive

Pegasus Spyware Deployed Against European Parliament Investigator: Targeting of Oversight Creates Political Vulnerability

Stelios Kouloglou, a European Parliament member investigating commercial spyware abuses, was infected with Pegasus spyware twice during his tenure on the PEGA committee. This represents a direct attack on parliamentary oversight mechanisms and suggests threat actors are targeting those scrutinising spyware exports.

Pegasus (NSO Group), European Parliament
highCampaignActive

Scattered Spider operative extradited: teenage member faces US charges for luxury retail breach

A 19-year-old suspect linked to Scattered Spider has been extradited to the US and faces charges for participating in breaches including a luxury jewellery retailer compromise in 2025. This marks a significant law enforcement action against an active criminal collective known for social engineering and supply chain targeting.

Luxury jewellery retailers, Organisations targeted by Scattered Spider
criticalVulnerabilityActive

Fission Environment CRD podspec passthrough enables Kubernetes host escape via privileged pod injection

Fission's Environment CRD failed to validate or filter dangerous Kubernetes pod security fields (`hostPID`, `hostNetwork`, `privileged`), allowing namespace users with basic create/update RBAC to spawn host-privileged pods and escape to node compromise. Pod Security Admission bypass due to missing namespace labels amplified the risk.

CVE-2026-50564
fission/fission < v1.24.0
highSupply ChainEmerging

LLM Domain Hallucinations Enable Phantom Squatting Attacks on Software Supply Chains

Attackers are exploiting large language models' tendency to generate non-existent domain names and registering these hallucinated domains to intercept developer traffic and compromise software supply chains. This technique bridges AI model weaknesses with domain squatting to create plausible but fake package repositories and dependencies.

Developers using LLM assistants for code discovery, Package managers relying on domain-based package sourcing, Software development organisations +1
highCampaignActive

Large-scale password spray campaign targets Azure CLI with 81M+ attempts, compromising 78+ Microsoft accounts

A sustained password spray attack originating from an IPv6 range controlled by LSHIY LLC has targeted Azure CLI with over 81 million login attempts between mid-June and late June 2026, successfully compromising at least 78 Microsoft accounts. This represents a significant threat to organisations using Azure command-line tooling without robust account protection measures.

Microsoft Azure CLI, Microsoft Azure accounts
highCampaignActive

Email account compromise as identity system attack vector: why attackers prioritise inbox access

Cybercriminals target email accounts as a primary objective because inbox control grants access to password resets, financial accounts, and identity verification across an individual's digital footprint. This represents a fundamental shift in attack prioritisation from specific services to the authentication hub itself.

Email service users (all providers), Identity verification systems
highMalwareContained

Perplexity Impersonation Attack Exploited Chrome Web Store Trust to Intercept Search Queries

A malicious Chrome extension masquerading as the Perplexity AI search engine intercepted all user searches and address bar input, routing them through an attacker-controlled server before delivering results. Google removed the extension after Microsoft's responsible disclosure, but the attack demonstrates how supply chain compromises in browser extension marketplaces can enable large-scale data harvesting.

Google Chrome, Chrome Web Store, Perplexity (brand/reputation)
informationalPolicyResolved

U.S. Supreme Court mandates warrant requirement for geofence data, reshaping law enforcement digital surveillance

The U.S. Supreme Court ruled that police must obtain a warrant before accessing geofence location data from cellphones, extending Fourth Amendment protections to digital tracking. This represents a significant legal victory for privacy advocates and establishes new constraints on law enforcement digital surveillance practices.

Law enforcement agencies, Technology companies storing location data, Mobile carriers