Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
On July 24, 2026, researchers H0j3n and Aniq Fakhrul published a working exploit for a Microsoft Active Directory Certificate Services (AD CS)…
Most organizations focus on protecting Non-Human Identities (NHIs) from theft, but a more insidious threat is emerging: fabricated machine identities. Unlike stolen…
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Identity lifecycle management (ILM) was architected around human principals with employment records, managers, and departure dates. AI agents have none of these,…
Threat actors are actively exploiting three security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. The flaws include CVE-2026-39813…
At the Gartner Security & Risk Management Summit, Zur Ulianitzky, SVP Product and Security Research at XM Cyber, detailed how attackers are…
Active Directory was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
A Russian-speaking initial access broker (IAB) has been linked to a large-scale credential-harvesting operation dubbed FortiBleed, targeting over 430,000 FortiGate firewalls globally…