DEV Community

#threatintel

Gathering, analyzing, and applying intelligence about threats and threat actors.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
ShinyHunters Hacks Clop Leak Site: Claims an Unauthenticated File Upload Led to Tor Private Key Theft

ShinyHunters Hacks Clop Leak Site: Claims an Unauthenticated File Upload Led to Tor Private Key Theft

1
Comments
7 min read
Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

1
Comments
5 min read
Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1
Comments
5 min read
WaterPlum: North Korean Campaign Infects 30,000 Devices via Fake Interview Tasks

WaterPlum: North Korean Campaign Infects 30,000 Devices via Fake Interview Tasks

1
Comments
5 min read
RatHat: AI-Powered Mobile Threat Steals Android Shell

RatHat: AI-Powered Mobile Threat Steals Android Shell

1
Comments
9 min read
Brevo Supply Chain Attack: Edge Injection of ClickFix via Cloudflare Workers

Brevo Supply Chain Attack: Edge Injection of ClickFix via Cloudflare Workers

1
Comments
8 min read
Cisco ISE CVE-2026-76460: Pre-authentication Auth Bypass Actively Exploited

Cisco ISE CVE-2026-76460: Pre-authentication Auth Bypass Actively Exploited

1
Comments
7 min read
SparroWocky: A New Backdoor for Latin American Governments by FamousSparrow

SparroWocky: A New Backdoor for Latin American Governments by FamousSparrow

1
Comments
10 min read
Agentic Self-Modification: Maintenance AI Retraining, Weight Updating, and Deploying Its Own Model Weights

Agentic Self-Modification: Maintenance AI Retraining, Weight Updating, and Deploying Its Own Model Weights

1
Comments
8 min read
OpenAI Model Misalignment Disclosure Framework and Six Unauthorized Actions

OpenAI Model Misalignment Disclosure Framework and Six Unauthorized Actions

1
Comments
9 min read
Orkes Conductor CVE-2026-58138: Exploitation Activity Observed Against Unauthenticated Workflow RCE

Orkes Conductor CVE-2026-58138: Exploitation Activity Observed Against Unauthenticated Workflow RCE

1
Comments 1
5 min read
BragJack: Prompt-Forcing In-Browser AI Agents via Browser Extensions

BragJack: Prompt-Forcing In-Browser AI Agents via Browser Extensions

1
Comments
8 min read
The Events Calendar: Two Unauthenticated RCE Chains via Unapproved Comments

The Events Calendar: Two Unauthenticated RCE Chains via Unapproved Comments

1
Comments
7 min read
CHOSEN BRICK: Iranian Windows Surveillance Malware Using Telegram C2

CHOSEN BRICK: Iranian Windows Surveillance Malware Using Telegram C2

1
Comments
7 min read
Google Pixel CVE-2026-58704: Limited Active Exploitation of Modem Authorization Bypass

Google Pixel CVE-2026-58704: Limited Active Exploitation of Modem Authorization Bypass

1
Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.