Cyber Intelligence
Curated cybersecurity news and threat intelligence
Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
Google has launched Gemini 4 Argon, a frontier AI model with guardrail-free access for vetted security defenders. The model has demonstrated the ability to identify critical vulnerabilities in widely-used hospital software.
Kiteworks Urges Customers to Restart Systems After Shutdown Notice
Kiteworks has lifted a temporary shutdown recommendation that was previously issued following federal intelligence concerns. Customers are being urged to restart their systems following the resolution of the security incident.
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A malicious browser extension disguised as an ad-blocker named 'Poper Blocker' was discovered stealing sensitive user data while being hosted on the Chrome Web Store with millions of downloads. The extension continued to operate despite researcher warnings and Google's official endorsement, highlighting risks in the official app marketplace.
VectraRAT Can Hack Windows Enterprises for $250 per Month
VectraRAT is a malware-as-a-service platform offering comprehensive Windows enterprise hacking capabilities including C2 infrastructure and operator panels for $250 per month. This represents a significant threat to enterprises as it commoditizes advanced remote access attacks.
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread outage affecting Exchange Online that is causing authentication failures, email delays, and service disruptions for customers. This is a critical infrastructure issue impacting enterprise communication and security systems.
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
NovaCookies is an adversary-in-the-middle phishing service offered as a subscription for $320 per month that steals Microsoft 365 session cookies, enabling attackers to bypass authentication. This threat lowers the barrier to entry for cybercriminals to conduct sophisticated attacks beyond simple credential theft.
No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
A no-filter AI platform called 'Kriminal' is being offered for cryptocurrency payment, enabling users to conduct social engineering attacks, offensive cybercrime operations, and OSINT scanning despite official prohibitions against illicit use. The platform's accessibility and lack of safeguards present significant cybercrime and security threat concerns.
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
Apple is sending threat notifications to iPhone users warning them of targeted mercenary spyware attacks. The alerts indicate detection of sophisticated spyware campaigns aimed at compromising individual devices.
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has introduced a new agentic security system designed to assist cyber defenders and released its first AI model specifically focused on cybersecurity. These initiatives aim to help organizations combat increasingly sophisticated AI-enabled threats.
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft experienced a major outage affecting Azure and Microsoft 365 services caused by a bug in its automated network maintenance system that mistakenly removed IP routes from more devices than intended. The company has identified the root cause as an error in the maintenance request automation process.
Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft is addressing a significant Exchange Online issue that has been incorrectly quarantining customer mailboxes since Sunday, impacting email availability. The company is actively working to resolve the service disruption affecting enterprise customers relying on the platform.
Microsoft to stop Exchange 2016 / 2019 security updates in October
Microsoft is ending security updates for Exchange 2016 and 2019 in October through its Extended Security Update program. Organizations still running these versions will lose access to critical security patches after this date.
Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM and Red Hat are launching Project Lightwell, dedicating 20,000 engineers to secure the open-source software supply chain in response to vulnerability findings from Anthropic's Mythos research. This represents a significant industry investment in addressing supply chain security concerns through a new managed service offering.
Microsoft accelerates quantum-safe roadmap as risks grow
Microsoft is accelerating its quantum-safe security roadmap due to advancing quantum computing threats that are expected to compromise current encryption standards sooner than anticipated. The company is prioritizing the replacement of existing cryptographic standards to address emerging quantum computing risks.
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
NPM 12 will implement a security change that disables automatic script execution from dependencies by default, requiring explicit user permission to run such scripts. This change is designed to mitigate supply chain attack risks, a significant vulnerability vector in the JavaScript ecosystem.
GitHub to Update npm to Thwart Software Supply Chain Attacks
GitHub announced a new version of npm package manager with enhanced security features designed to prevent software supply chain attacks. The update includes disabling install scripts by default to reduce the risk of malicious code execution during package installation.
Microsoft investigates Office Apps, Teams file access issues
Microsoft is investigating a widespread incident affecting Teams and Office for the web that is preventing users from accessing files. This represents a significant service disruption impacting Microsoft's core productivity and collaboration platforms.
Microsoft fixes outage affecting MFA setup, MySignIn service
Microsoft is addressing an ongoing outage that is preventing customers from setting up multi-factor authentication (MFA) and accessing the My Sign-Ins service. This incident impacts critical authentication infrastructure affecting numerous Microsoft customers.
Microsoft confirms outage affecting MFA, My Sign-Ins platform
Microsoft is experiencing an outage affecting multi-factor authentication (MFA) setup and the My Sign-Ins platform, preventing customers from accessing these critical security services. The company is actively working to resolve the ongoing incident.
Password manager Dashlane suspends customer accounts amid brute-force attacks
Dashlane suspended customer accounts as a security measure in response to brute-force attack attempts, triggering its automatic protection systems. The incident impacted users over the weekend as the platform's defensive mechanisms activated to prevent unauthorized access.
BTMOB Android RAT Spreads Through No-Code Builder Tooling
BTMOB is an Android Remote Access Trojan being sold as a service with a no-code builder tool that enables attackers to rapidly create region-specific phishing campaigns. This malware-as-a-service offering significantly lowers the barrier to entry for cybercriminals to develop and deploy Android-targeting attacks.
Microsoft confirms April Windows updates cause backup failures
Microsoft has confirmed that April 2026 security updates are causing failures in third-party backup applications that use the psmounterex.sys driver. This issue affects critical backup functionality across multiple vendor solutions.
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
Microsoft Defender is incorrectly flagging legitimate DigiCert root certificates as malware, causing false-positive detections and certificate removal on Windows systems. This widespread issue affects the reliability of Microsoft's security product and DigiCert's certificate infrastructure.
New Bluekit phishing service includes an AI assistant, 40 templates
A new phishing kit called Bluekit has emerged that includes over 40 templates for targeting popular services and incorporates AI capabilities to automate campaign generation. This represents an evolution in phishing attack infrastructure that lowers the barrier for threat actors to conduct sophisticated social engineering attacks.
Microsoft says backend change broke Teams Free chat and calls
Microsoft experienced a backend service disruption affecting Teams Free users' ability to chat and calls due to a configuration change. The company is actively working to resolve the issue.
The Mythos Moment: Enterprises Must Fight Agents with Agents
The article discusses the emergence of AI-powered agentic systems as a new cybersecurity threat landscape, advocating that enterprises need agentic, AI-driven defense platforms to protect themselves. It emphasizes the need for advanced defensive strategies to counter autonomous AI agents in what is termed the 'agentic era.'
Microsoft to deprecate legacy TLS in Exchange Online starting July
Microsoft will deprecate legacy TLS connections for POP and IMAP clients in Exchange Online beginning July 2026. This security hardening measure aims to eliminate outdated encryption protocols and improve email security posture.