Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Aug 6

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm cred...

Elastic Security Labs → Details

Recorded Future research Aug 6

Emerging Threats to Neurotechnology

Explore the evolving security landscape of neurotechnology, including risks like IP theft, data extortion, and regulatory challenges in this emerging field.

Recorded Future → Details

Elastic Security Labs research Aug 6

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm cred...

Elastic Security Labs → Details

PortSwigger Research research Aug 5

CRLF-Powered Desync Attacks: Beheading HTTP Streams

Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated.

PortSwigger Research → Details

PortSwigger Research research Aug 5

Can AI do novel security research? Meet the HTTP Terminator

Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use ...

PortSwigger Research → Details

PortSwigger Research research Aug 5

Can AI do novel security research? Meet the HTTP Terminator

Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use ...

PortSwigger Research → Details

Trail of Bits research Amazon Aug 5

A few notes on AWS Nitro Enclaves: KMS integration

Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers...

Trail of Bits → Details

Recorded Future research Aug 5

Hype vs. Reality: What the Hugging Face Incident Means for AI Safety

Discover the security lessons from the recent incident where autonomous AI agents breached Hugging Face infrastructure.

Recorded Future → Details

Elastic Security Labs research Aug 4

Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows

Public leaderboards can't tell you which LLM to trust in your SOC, so Elastic built an evaluation framework that grades models on the work (tool calls, execu...

Elastic Security Labs → Details

Unit 42 research Aug 4

The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software

Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.

T1195

Unit 42 → Details

Unit 42 research Aug 4

Almost Half of Malware Samples Communicate Direct to IP

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.

Unit 42 → Details

Kaspersky Securelist research Cloudflare GitHub Aug 4

How legitimate cloud platforms enable phishers to bypass MFA

We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms lik...

T1566 T1557

Kaspersky Securelist → Details

Elastic Security Labs research Aug 4

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

LLMs made it cheap to flood bug bounty programs with submissions.

Elastic Security Labs → Details

Elastic Security Labs research Aug 4

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

LLMs made it cheap to flood bug bounty programs with submissions.

Elastic Security Labs → Details

Check Point Research research Check Point Intel Aug 3

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota ...

Check Point Research → Details

Kaspersky Securelist research Aug 3

An analysis of incidents at Brazilian educational institutions

Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and un...

Kaspersky Securelist → Details

Unit 42 research Aug 3

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The...

Unit 42 → Details

Elastic Security Labs research Aug 3

Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows

Public leaderboards can't tell you which LLM to trust in your SOC, so Elastic built an evaluation framework that grades models on the work (tool calls, execu...

Elastic Security Labs → Details

Elastic Security Labs research Aug 3

SOC case management and detection rule history in Elastic Security

Elastic Security now tracks every detection rule change with one-click rollback and makes case data queryable out of the box, so SOC teams get audit trails a...

Elastic Security Labs → Details

Recorded Future research Intel Aug 3

8 Ways AI is Changing Threat Intelligence

Explore eight key ways that AI is reshaping the threat intelligence landscape, from creating speed and stealth advantages for adversaries to helping defender...

Recorded Future → Details

«Previous page 1 ... 5 6 7 8 9 ... 37 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA