Cyber Security Intelligence
Real-time aggregation of the most critical cybersecurity news, vulnerabilities, and threat warnings.
Latest Intel Feed
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting victims before the attacks become public and claiming it can provide decryption keys and delete stolen data...
OpenAI confirms ChatGPT is down as logins and signups fail
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. The outage started at approximately 8 PM ET on Wednesday, August 19, and is...
Microsoft says August Windows updates may cause gaming issues
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. The confirmation follows user reports that a...
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
A Chinese-nexus cyber-espionage operation is actively targeting government organizations across Central Asia with a collection of mostly previously unidentified remote access Trojans (RATs) from seven different malware...
A California county wants to hire Tina Peters to help run its elections
Clint Curtis, the registrar for voters in Shasta County, Calif. said he plans to hire convicted felon and election denialist Tina Peters as one of his top deputies. Curtis said he plans to hire Peters next month as an...
US charges Iranian hackers over $3.4 billion intellectual property theft
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. Nine of the defendants were...
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
Executive Summary The security of the npm ecosystem reached a critical inflection point in September 2025. The Shai-Hulud worm, a self-replicating malware that automated the compromise and redistribution of malicious...
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
Unit 42’s 2026 Global Incident Response Report offers frontline intelligence drawn directly from global investigations. The report spotlights four defining trends shaping the threat landscape. We’ll take a closer look...
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Executive Summary We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical,...
Russian Global Webmail Espionage
Executive Summary Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and...
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Executive Summary Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven...
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Executive Summary After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. This version’s advanced architecture hides its core logic in memory space,...