Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Defense

20 articles

GBHackers general Aug 17

ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token

The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm inst...

GBHackers → Details

Help Net Security general Microsoft Aug 17

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without phy...

Help Net Security → Details

Security Affairs general Google Aug 16

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers...

Security Affairs → Details

SC Media general Aug 14

California launches AI cybersecurity initiative amid growing threats

The initiative mandates the creation of an AI cybersecurity officer role within every state agency and establishes an AI cyber defense program housed in the ...

SC Media → Details

BleepingComputer general Google Aug 14

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems.

T1566

BleepingComputer → Details

CSO Online enterprise Microsoft Aug 14

Akira ransomware reboots into Windows Safe Mode to knock EDR offline

Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system ...

CSO Online → Details

GBHackers general Aug 14

PATCHCORD Infrastructure Hosts SuperShell C2 for Remote Commands and Webshell Management

A newly uncovered espionage operation targeting Afghan telecom providers and South Asian critical infrastructure has exposed a layered attacker ecosystem bui...

T1190

GBHackers → Details

CSO Online enterprise Aug 13

Attackers target zero-day vulnerability in geospatial data platform GeoServer

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-sour...

CSO Online → Details

GBHackers general Microsoft Aug 13

Armored Likho Turns Windows Microphones Into Automated Eavesdropping Devices

Armored Likho, also tracked as Eagle Werewolf, has expanded its espionage capability with a Rust-based toolkit that can hijack Telegram sessions and transfor...

GBHackers → Details

CSO Online enterprise Microsoft Aug 13

Microsoft wants you to rethink your approach to cyber defense

Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-acc...

CSO Online → Details

Kaspersky Securelist research Aug 13

Armored Likho expands its cyber-espionage toolkit

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram dat...

Kaspersky Securelist → Details

Security Affairs general Microsoft Check Point Aug 13

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Po...

Security Affairs → Details

The Hacker News general Microsoft Check Point Aug 12

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Wi...

The Hacker News → Details

Cisco Advisories advisories Cisco Intel Aug 12

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along wi...

Cisco Advisories → Details

BleepingComputer general Microsoft Aug 12

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream...

1 IOC

BleepingComputer → Details

Help Net Security general Microsoft Check Point Aug 12

Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense secto...

Help Net Security → Details

The Hacker News general Aug 12

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none.

The Hacker News → Details

GBHackers general Microsoft Google Aug 12

Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks

Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that dynamically b...

GBHackers → Details

GBHackers general Microsoft Check Point Aug 12

Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access

Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level access a...

1 IOC

GBHackers → Details

The Hacker News general Cisco Aug 12

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Softw...

1 IOC

The Hacker News → Details

«Previous page 1 ... 8 9 10 11 12 ... 18 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA