Threat Intelligence Feed
Aggregating 4895 articles from trusted cybersecurity sources
Latest News
Hole in GitHub’s browser-based VSCode editor could lead to stolen token
A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher. The is...
Enterprise Spotlight: Rethinking cloud strategy in the age of AI
Cloud computing has reached a crossroads. The high cost and data sensitivity of AI workloads are raising the appeal of private clouds, even as neoclouds and ...
Threats to the 2026 FIFA World Cup
Threat assessment for the 2026 FIFA World Cup (US, Mexico, Canada) covering organized crime, AI-powered cyber fraud, state espionage, and political influence...
Threats to the 2026 FIFA World Cup
Threat assessment for the 2026 FIFA World Cup (US, Mexico, Canada) covering organized crime, AI-powered cyber fraud, state espionage, and political influence...
Remembering Sir Alex Younger
A personal tribute to Sir Alex Younger, former head of MI6, on the friendship, lessons, and clarity he brought to Recorded Future and to those who knew him.
Smashing Security podcast #470: This AI security flaw might be impossible to fix
A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were a...
Microsoft Edge retires master password feature, adopts passkeys and biometrics
As of June 4, Microsoft will disable the master password feature in Edge, replacing it with device-based authentication such as Windows Hello, which includes...
Spanish hacker Alcasec sentenced to prison for stealing banking details
Spanish hacker José Luis Huertas, known online as Alcasec, has been sentenced to two years and seven months in prison after accepting a plea deal.
Google rolls out scam call detection for Android
The fake call detection feature works automatically when both the caller and recipient are using the Phone by Google app.
WP Engine adds bot management to Global Edge Security
The new bot management features, integrated with Cloudflare Inc., allow website teams to create and implement rules for blocking or permitting bot traffic ba...
Russia FSB claims foreign intelligence used malware on officials' phones
The FSB stated that the operation exploited the capabilities of unspecified "major international IT corporations" to extract sensitive information from targe...
Data Breaches
Maine Shuts Down Breach Reporting Portal Following Fake VRChat and Discord Submissions
The Office of the Maine Attorney General has temporarily taken its public data breach reporting portal offline following the discovery of fraudulent submissi...
Iran-Linked Handala Breached a California Water Utility. It Could Have Done Worse, and It Knows That.
Pro-Iran group Handala breached Cal Water via an exposed GPS tool, reaching billing data for 2M customers. 5GB leaked.
Novo Nordisk discloses data breach affecting patient and healthcare professional information
Attackers gained access to Novo Nordisk's internal IT systems, copying non-public data without authorization.
Maine disables data breach notification portal after fake disclosures
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review...
Privacy own-goal: World Cup blunder leaks Lionel Messi’s passport details
Argentina's World Cup squad had their passport numbers leaked before a ball was kicked - not by hackers, but by someone who failed to redact a document prope...
Bankruptcy admin approves settlement fund of $47 million for 23andMe data breach victims
About 7 million customers of the genetics testing company had their data stolen by hackers starting in April 2023, and many had their information posted on t...
South Korea hits Coupang with record $409 million fine over data breach
The penalty is the largest ever issued by the commission for a personal data breach, surpassing the record 134.8 billion won ($88.
How Security Debt Can Accumulate Faster Than Technical Debt
Security debt sounds like a tidy metaphor until the first breach turns it into a billing department with teeth. Technical debt behaves like clutter.
Kyushu Electric Power Co. reports data breach affecting over 10 million customers
On April 27, Kyushu Electric Power Co. utilized an external storage device for data backups due to capacity constraints.
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
GitHub access sales, leaked repositories, and stolen API keys can all become supply-chain attack footholds. Flare explores how underground forums expose earl...
Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign
ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available. Mandiant an...
Pharma giant Novo Nordisk discloses breach of clinical trials data
Danish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical t...