DEV Community

#threatintel

Gathering, analyzing, and applying intelligence about threats and threat actors.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Supabase Misconfiguration: Readable Tables in 16,326 Databases, Sensitive Data Confirmed in Some Cases

Supabase Misconfiguration: Readable Tables in 16,326 Databases, Sensitive Data Confirmed in Some Cases

2
Comments
9 min read
Storm-3168 (JADEPUFFER): Azure Resources Mass-Deleted in Seven Minutes Using Compromised Service Principals

Storm-3168 (JADEPUFFER): Azure Resources Mass-Deleted in Seven Minutes Using Compromised Service Principals

1
Comments
9 min read
Kiteworks Advanced Forms: Precautionary Shutdown Following Critical Vulnerability and Conditional Resumption

Kiteworks Advanced Forms: Precautionary Shutdown Following Critical Vulnerability and Conditional Resumption

1
Comments
8 min read
Bitget: $387.5M Stolen via Wallet Backend Compromise and Transaction Data Tampering

Bitget: $387.5M Stolen via Wallet Backend Compromise and Transaction Data Tampering

2
Comments
8 min read
Mini Shai-Hulud Re-Exposure: Re-Enabled GitHub Action Repositories Trigger Malicious Code Execution in CI

Mini Shai-Hulud Re-Exposure: Re-Enabled GitHub Action Repositories Trigger Malicious Code Execution in CI

1
Comments
10 min read
Oracle PeopleSoft CVE-2026-35273: WAF Bypassed via URL Normalization Mismatch to Deploy Web Shells and SIDEEYE

Oracle PeopleSoft CVE-2026-35273: WAF Bypassed via URL Normalization Mismatch to Deploy Web Shells and SIDEEYE

1
Comments
11 min read
SalesBleed: Zero-Click DNS Data Exfiltration from Agentforce Through Indirect Prompt Injection

SalesBleed: Zero-Click DNS Data Exfiltration from Agentforce Through Indirect Prompt Injection

1
Comments
5 min read
Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

1
Comments
5 min read
CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

1
Comments
6 min read
SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

1
Comments
6 min read
SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites Allowing Anonymous Access

SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites Allowing Anonymous Access

1
Comments 3
9 min read
Cloudflare Containers: Vulnerability Allowing Reading of Residual Data from Other Tenants via Reused Blocks

Cloudflare Containers: Vulnerability Allowing Reading of Residual Data from Other Tenants via Reused Blocks

1
Comments 3
7 min read
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Two Pre-Authentication RCE Zero-Days Under Active Exploitation

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Two Pre-Authentication RCE Zero-Days Under Active Exploitation

1
Comments 3
8 min read
RemControl: Android Banking Trojan Uses AI-Assisted Overlays and a Local VPN

RemControl: Android Banking Trojan Uses AI-Assisted Overlays and a Local VPN

1
Comments
6 min read
Kapibala: Government Data Theft via WordPress and Active Exploitation of Zyxel CVE-2026-7273

Kapibala: Government Data Theft via WordPress and Active Exploitation of Zyxel CVE-2026-7273

1
Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.