All posts
Topic
Threat Intelligence
15 articles on threat intelligence.
AI-Enabled Cyberattacks: How Attackers Misuse LLMs
AI-enabled cyberattacks are real but bounded. Learn how attackers misuse LLMs for phishing and recon, why guardrails limit uplift, and how to defend.
September 11, 2026
AI Influence Operations: Spotting LLM Disinformation
How AI-scaled influence operations and LLM sockpuppets really work, the detection signals that expose them, and how comms teams and platforms defend.
September 11, 2026
AI Surveillance: The Risks and How to Safeguard Against It
How AI supercharges surveillance and profiling, the privacy and security risks it creates, and the governance safeguards a CISO or DPO can put in place.
September 11, 2026
AI Biosecurity: How Frontier Model Safeguards Work
Why frontier AI labs restrict dangerous dual-use biology, how layered safeguards and responsible scaling work, and what security leaders should know.
September 11, 2026
AI and Weapons: How Dual-Use AI Safeguards Work
How frontier AI labs restrict weapons and CBRN uplift: dual-use risk, export controls, responsible scaling, and layered safeguards for security leaders.
September 11, 2026
How AI Labs Detect and Disrupt Misuse: Lessons for CISOs
How AI labs detect AI misuse with monitoring, classifiers and threat intelligence, plus the AI trust and safety lessons CISOs can apply to their own AI.
September 11, 2026
Cl0p Leak-Site Claims Four New Victims: A Defender's Brief on the Claim
Cl0p's dark-web leak site has listed four organizations as alleged victims. These are unverified extortion claims, not confirmed breaches. Here is how to read a leak-site listing, why Cl0p keeps hitting file-transfer software, and the defensive steps that actually matter.
September 10, 2026
Where Ransomware Crews Gather: A Defender's Map of the Underground
A defensive threat-intelligence explainer on the venue types that power the ransomware economy - forums, RaaS portals, initial-access brokers, leak sites - and how defenders and law enforcement monitor and disrupt them.
September 10, 2026
How Ransomware Crews Recruit: The Red Flags That Mean You're Being Groomed
A defensive awareness briefing for CISOs and staff on how ransomware operations recruit affiliates and insiders, the traits they hunt for as red flags, the manipulation tactics they use, the legal and personal consequences, and how to recognize and avoid being pulled in.
September 10, 2026
How Ransomware Crews Get Paid: Inside the Ransom Economy
An analytical look at the ransomware business: the RaaS affiliate model and revenue splits, how demands are sized and negotiated, the crypto rails crews use -- and how blockchain analysis and law enforcement follow and seize the money.
September 10, 2026
How Ransomware Crews Hide - And How They Get Caught
Inside the operational security ransomware operators use to stay anonymous, and the recurring OPSEC mistakes, blockchain tracing, infrastructure seizures and leaks that keep unmasking them anyway.
September 10, 2026
Critical Langflow Flaw (CVE-2026-0768) Now Exploited en Masse to Steal OpenAI & AWS Keys
Attackers are mass-exploiting CVE-2026-0768, a CVSS 9.8 unauthenticated RCE in the Langflow AI app builder, to run code as root and harvest OpenAI API keys and cloud secrets. What the flaw is, why AI gateways are the target, and what to do today.
September 4, 2026
OpenVuln: Z.ai Turned an AI Model That Outgrew Its Own Safety Training Into a Public Vulnerability Scanner
Z.ai released OpenVuln, a free public tool that points its GLM-5.3 model at any GitHub repo to hunt vulnerabilities โ built on a model whose exploitation reasoning reportedly advanced faster than its developers expected. Here is how it actually works, the numbers behind it, and what it means for anyone maintaining open-source code.
August 14, 2026
The LiteLLM Supply Chain Attack: What TeamPCP Stole, Who It Hit, and What to Do Now
Backdoored LiteLLM 1.82.7 and 1.82.8 stayed on PyPI for 40 minutes in March 2026 โ long enough to compromise over 2,400 organizations. A 153GB archive of the stolen data has now surfaced. Here is exactly what happened, the IOCs, and the remediation checklist.
August 13, 2026
Enter, Evade, Escape: The Anatomy of AI Agent Hijacking Attacks
From RovoBlast to EchoLeak โ a single click can now turn your enterprise AI assistant into a data exfiltration tool. Here is how the attacks work, a timeline of every known incident, and what security leaders should do about it.
August 10, 2026