Skip to main content

Cyber Intelligence

Curated cybersecurity news and threat intelligence

productSecurityWeek1 Oct

Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders

Google has launched Gemini 4 Argon, a frontier AI model with guardrail-free access for vetted security defenders. The model has demonstrated the ability to identify critical vulnerabilities in widely-used hospital software.

productInfosecurity29 Sept

Kiteworks Urges Customers to Restart Systems After Shutdown Notice

Kiteworks has lifted a temporary shutdown recommendation that was previously issued following federal intelligence concerns. Customers are being urged to restart their systems following the resolution of the security incident.

Kiteworks
Read original
productDarkReading28 Sept

Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions

A malicious browser extension disguised as an ad-blocker named 'Poper Blocker' was discovered stealing sensitive user data while being hosted on the Chrome Web Store with millions of downloads. The extension continued to operate despite researcher warnings and Google's official endorsement, highlighting risks in the official app marketplace.

productDarkReading15 Sept

VectraRAT Can Hack Windows Enterprises for $250 per Month

VectraRAT is a malware-as-a-service platform offering comprehensive Windows enterprise hacking capabilities including C2 infrastructure and operator panels for $250 per month. This represents a significant threat to enterprises as it commoditizes advanced remote access attacks.

productBleepingComputer31 Aug

Microsoft Exchange Online outage causes email failures, auth issues

Microsoft is investigating a widespread outage affecting Exchange Online that is causing authentication failures, email delays, and service disruptions for customers. This is a critical infrastructure issue impacting enterprise communication and security systems.

productDarkReading26 Aug

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

NovaCookies is an adversary-in-the-middle phishing service offered as a subscription for $320 per month that steals Microsoft 365 session cookies, enabling attackers to bypass authentication. This threat lowers the barrier to entry for cybercriminals to conduct sophisticated attacks beyond simple credential theft.

Microsoft
Read original
productDarkReading19 Aug

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

A no-filter AI platform called 'Kriminal' is being offered for cryptocurrency payment, enabling users to conduct social engineering attacks, offensive cybercrime operations, and OSINT scanning despite official prohibitions against illicit use. The platform's accessibility and lack of safeguards present significant cybercrime and security threat concerns.

productBleepingComputer14 Aug

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

Apple is sending threat notifications to iPhone users warning them of targeted mercenary spyware attacks. The alerts indicate detection of sophisticated spyware campaigns aimed at compromising individual devices.

productInfosecurity28 Jul

Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats

Microsoft has introduced a new agentic security system designed to assist cyber defenders and released its first AI model specifically focused on cybersecurity. These initiatives aim to help organizations combat increasingly sophisticated AI-enabled threats.

Microsoft
Read original
productBleepingComputer24 Jul

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft experienced a major outage affecting Azure and Microsoft 365 services caused by a bug in its automated network maintenance system that mistakenly removed IP routes from more devices than intended. The company has identified the root cause as an error in the maintenance request automation process.

productBleepingComputer23 Jul

Microsoft working to fix Exchange Online mailbox quarantine issue

Microsoft is addressing a significant Exchange Online issue that has been incorrectly quarantining customer mailboxes since Sunday, impacting email availability. The company is actively working to resolve the service disruption affecting enterprise customers relying on the platform.

productBleepingComputer22 Jul

Microsoft to stop Exchange 2016 / 2019 security updates in October

Microsoft is ending security updates for Exchange 2016 and 2019 in October through its Extended Security Update program. Organizations still running these versions will lose access to critical security patches after this date.

Microsoft
Read original
productDarkReading2 Jul

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

IBM and Red Hat are launching Project Lightwell, dedicating 20,000 engineers to secure the open-source software supply chain in response to vulnerability findings from Anthropic's Mythos research. This represents a significant industry investment in addressing supply chain security concerns through a new managed service offering.

IBMRed HatAnthropic
Read original
productBleepingComputer30 Jun

Microsoft accelerates quantum-safe roadmap as risks grow

Microsoft is accelerating its quantum-safe security roadmap due to advancing quantum computing threats that are expected to compromise current encryption standards sooner than anticipated. The company is prioritizing the replacement of existing cryptographic standards to address emerging quantum computing risks.

Microsoft
Read original
productSecurityWeek13 Jun

NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

NPM 12 will implement a security change that disables automatic script execution from dependencies by default, requiring explicit user permission to run such scripts. This change is designed to mitigate supply chain attack risks, a significant vulnerability vector in the JavaScript ecosystem.

productInfosecurity12 Jun

GitHub to Update npm to Thwart Software Supply Chain Attacks

GitHub announced a new version of npm package manager with enhanced security features designed to prevent software supply chain attacks. The update includes disabling install scripts by default to reduce the risk of malicious code execution during package installation.

productBleepingComputer1 Jun

Microsoft investigates Office Apps, Teams file access issues

Microsoft is investigating a widespread incident affecting Teams and Office for the web that is preventing users from accessing files. This represents a significant service disruption impacting Microsoft's core productivity and collaboration platforms.

productBleepingComputer1 Jun

Microsoft fixes outage affecting MFA setup, MySignIn service

Microsoft is addressing an ongoing outage that is preventing customers from setting up multi-factor authentication (MFA) and accessing the My Sign-Ins service. This incident impacts critical authentication infrastructure affecting numerous Microsoft customers.

productBleepingComputer1 Jun

Microsoft confirms outage affecting MFA, My Sign-Ins platform

Microsoft is experiencing an outage affecting multi-factor authentication (MFA) setup and the My Sign-Ins platform, preventing customers from accessing these critical security services. The company is actively working to resolve the ongoing incident.

productThe Register Security1 Jun

Password manager Dashlane suspends customer accounts amid brute-force attacks

Dashlane suspended customer accounts as a security measure in response to brute-force attack attempts, triggering its automatic protection systems. The incident impacted users over the weekend as the platform's defensive mechanisms activated to prevent unauthorized access.

productInfosecurity26 May

BTMOB Android RAT Spreads Through No-Code Builder Tooling

BTMOB is an Android Remote Access Trojan being sold as a service with a no-code builder tool that enables attackers to rapidly create region-specific phishing campaigns. This malware-as-a-service offering significantly lowers the barrier to entry for cybercriminals to develop and deploy Android-targeting attacks.

productBleepingComputer4 May

Microsoft confirms April Windows updates cause backup failures

Microsoft has confirmed that April 2026 security updates are causing failures in third-party backup applications that use the psmounterex.sys driver. This issue affects critical backup functionality across multiple vendor solutions.

productBleepingComputer3 May

Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha

Microsoft Defender is incorrectly flagging legitimate DigiCert root certificates as malware, causing false-positive detections and certificate removal on Windows systems. This widespread issue affects the reliability of Microsoft's security product and DigiCert's certificate infrastructure.

MicrosoftDigiCert
Read original
productBleepingComputer30 Apr

New Bluekit phishing service includes an AI assistant, 40 templates

A new phishing kit called Bluekit has emerged that includes over 40 templates for targeting popular services and incorporates AI capabilities to automate campaign generation. This represents an evolution in phishing attack infrastructure that lowers the barrier for threat actors to conduct sophisticated social engineering attacks.

productBleepingComputer29 Apr

Microsoft says backend change broke Teams Free chat and calls

Microsoft experienced a backend service disruption affecting Teams Free users' ability to chat and calls due to a configuration change. The company is actively working to resolve the issue.

productSecurityWeek28 Apr

The Mythos Moment: Enterprises Must Fight Agents with Agents

The article discusses the emergence of AI-powered agentic systems as a new cybersecurity threat landscape, advocating that enterprises need agentic, AI-driven defense platforms to protect themselves. It emphasizes the need for advanced defensive strategies to counter autonomous AI agents in what is termed the 'agentic era.'

productBleepingComputer28 Apr

Microsoft to deprecate legacy TLS in Exchange Online starting July

Microsoft will deprecate legacy TLS connections for POP and IMAP clients in Exchange Online beginning July 2026. This security hardening measure aims to eliminate outdated encryption protocols and improve email security posture.