DEV Community

#threatintel

Gathering, analyzing, and applying intelligence about threats and threat actors.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

Comments
4 min read
PaperCut Authentication Bypass and Dynamic Class Loading: Pre-authentication RCE Chain Actively Exploited

PaperCut Authentication Bypass and Dynamic Class Loading: Pre-authentication RCE Chain Actively Exploited

Comments
5 min read
GiveWP CVE-2026-82222: RCE Chain from Unauthenticated Registration to PHP Object Injection

GiveWP CVE-2026-82222: RCE Chain from Unauthenticated Registration to PHP Object Injection

Comments
5 min read
Citrix NetScaler CVE-2026-8452: SAML Heap Overflow to Root RCE and Web Shell Deployment

Citrix NetScaler CVE-2026-8452: SAML Heap Overflow to Root RCE and Web Shell Deployment

Comments 2
7 min read
Nearly 700 Rogue AI Agents Coordinated in the Hugging Face Attack: Lateral Movement from Artifactory Across Multiple Regions

Nearly 700 Rogue AI Agents Coordinated in the Hugging Face Attack: Lateral Movement from Artifactory Across Multiple Regions

Comments 2
5 min read
Safely Analyzing Obfuscated JavaScript: Step-by-Step Phishing Kit Restoration

Safely Analyzing Obfuscated JavaScript: Step-by-Step Phishing Kit Restoration

Comments 2
5 min read
SPEAKINGSTONE and DARKLANTERN in ZBT-Based White-Label Routers: WAN-Accessible Root Shell and DNS Hijacking

SPEAKINGSTONE and DARKLANTERN in ZBT-Based White-Label Routers: WAN-Accessible Root Shell and DNS Hijacking

Comments 2
5 min read
TA4922 PackClient Attacks: From Tax Documents to DLL Side-Loading and RAT Deployment

TA4922 PackClient Attacks: From Tax Documents to DLL Side-Loading and RAT Deployment

Comments 2
5 min read
When AI Infrastructure Becomes the Target: Attacks Observed on LiteLLM, RAGFlow, and Kestra

When AI Infrastructure Becomes the Target: Attacks Observed on LiteLLM, RAGFlow, and Kestra

Comments
6 min read
NovaCookies: Microsoft 365 AiTM Exploiting Trusted Docusign and Microsoft Redirects

NovaCookies: Microsoft 365 AiTM Exploiting Trusted Docusign and Microsoft Redirects

Comments
6 min read
Gitea CVE-2026-60004: Active Exploitation of RCE via diffpatch API to Install Git Hooks

Gitea CVE-2026-60004: Active Exploitation of RCE via diffpatch API to Install Git Hooks

Comments
5 min read
Attacks on Water OT: Over 100 Internet-Exposed Systems Targeted in July

Attacks on Water OT: Over 100 Internet-Exposed Systems Targeted in July

Comments
5 min read
Dark Caracal's New Malware GoCaracal: From SVG Phishing to Ethereum Backup C2

Dark Caracal's New Malware GoCaracal: From SVG Phishing to Ethereum Backup C2

Comments
6 min read
SharePoint Authentication Bypass and RCE Chain Attack Observed: CVE-2026-55040 / CVE-2026-63520

SharePoint Authentication Bypass and RCE Chain Attack Observed: CVE-2026-55040 / CVE-2026-63520

Comments
5 min read
CISA "A Tale of Two SOCs": Detection and Containment from Two Red Team Assessments

CISA "A Tale of Two SOCs": Detection and Containment from Two Red Team Assessments

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.