Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 6 of 26

126–150 of 632
criticalSupply ChainContained

CISA Contractor Exposed AWS GovCloud Credentials and Internal CI/CD Infrastructure via Public GitHub Repository

A CISA contractor maintained a public GitHub repository containing AWS GovCloud credentials for highly privileged accounts and documentation of CISA's internal software build, test, and deployment processes. The exposure represents a significant compromise of US government infrastructure security practices and threat intelligence operations.

AWS GovCloud, CISA internal systems, Cybersecurity & Infrastructure Security Agency
criticalSupply ChainActive

GitHub Actions Tag Spoofing Attack on issues-helper Demonstrates Repository Compromise at Scale

Threat actors compromised the popular GitHub Actions workflow issues-helper by redirecting all repository tags to malicious commits, enabling CI/CD credential theft from potentially thousands of dependent workflows. This represents a sophisticated supply chain attack exploiting the trust model of GitHub Actions.

GitHub Actions, actions-cool/issues-helper, Any workflow using issues-helper at any version tag
highCampaignContained

Interpol-led takedown disrupts Middle East scam infrastructure; 200+ arrests and hundreds of compromised devices recovered

Interpol-coordinated law enforcement operations arrested over 200 individuals operating cybercriminal scam networks across the Middle East and recovered hundreds of compromised devices used in the scheme. This represents a significant disruption to a regional fraud operation, though the technical sophistication and scale suggest similar networks remain active.

Hundreds of end-user devices (specific platforms not disclosed)
criticalVulnerabilityEmerging

Multi-vendor RCE patch wave signals coordinated disclosure cycle with Ivanti Xtraction critical flaw leading

Ivanti, Fortinet, SAP, VMware, and n8n have released patches for multiple remote code execution and privilege escalation vulnerabilities, with Ivanti Xtraction's CVE-2026-8043 (CVSS 9.6) enabling arbitrary code execution through external file name control. This coordinated patch release suggests these flaws were likely discovered through vulnerability coordination channels.

CVE-2026-8043
Ivanti Xtraction, Fortinet, SAP +2
criticalVulnerabilityEmerging

MiniPlasma 0-Day Exposes Systemic Patching Failure in Windows Cloud Files Driver

Researcher Chaotic Eclipse has released a working exploit for MiniPlasma, a Windows privilege escalation zero-day in the Cloud Files Mini Filter Driver (cldflt.sys) that grants SYSTEM access on fully patched systems. This represents a complete bypass of Windows security controls and poses immediate risk to all affected Windows installations.

Microsoft Windows, Windows Cloud Files Mini Filter Driver (cldflt.sys)