threat-intel That AI Extension Helping You Write Emails? It’s Reading Them First Palo Alto Unit 42 has identified 18 AI-powered browser extensions posing significant security risks. These extensions, masquerading as productivity tools, are actually delivering malicious payloads such as remote access… Palo Alto Unit 42 · Apr 30, 2026 High USaibrowser extensionsgenai
threat-intel Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber This article reports on Anthropic’s release of Claude, dubbed ‘Mythos,’ an AI model capable of rapidly identifying and exploiting software vulnerabilities, including zero-day bugs, across major operating systems and web… Dark Reading · Apr 30, 2026 High aivulnerabilitycybersecurity
threat-intel Great responsibility, without great power This article from Cisco Talos discusses the importance of empathy and understanding in cybersecurity, particularly in recognizing and responding to attacker behavior. It highlights five critical priorities for defenders… Cisco Talos · Apr 30, 2026 High CVE-2026-42208identityanomalythreat-hunting
threat-intel Anti-DDoS Firm Heaped Attacks on Brazilian ISPs A Brazilian DDoS protection firm, Huge Networks, was found to be running a botnet that launched massive DDoS attacks against Brazilian ISPs. This activity stemmed from a security breach in January 2026 that compromised t… Krebs on Security · Apr 30, 2026 High CVE-2023-1389BRUSddosbotnetdns
threat-intel Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions This podcast episode discusses a recent corporate hack stemming from an individual attempting to cheat at the Roblox game. The incident involved a developer gaining unauthorized access to a Microsoft 365 tenant, disablin… Graham Cluley · Apr 29, 2026 High microsoft 365security breachcorporate hack
threat-intel AI-powered honeypots: Turning the tables on malicious AI agents This article details a new approach to cybersecurity utilizing generative AI to create dynamic honeypots. By leveraging AI to simulate vulnerable systems and respond to attacker actions, defenders can actively manipulate… Cisco Talos · Apr 29, 2026 Medium CVE-2014-6271aihoneypotgenerative-ai
threat-intel NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later This Dark Reading Confidential episode features a retrospective discussion with Chris Inglis, former NSA Deputy Director during the Edward Snowden affair, 13 years after the events. The conversation focuses on the misund… Dark Reading · Apr 28, 2026 Low USRUnsasnowdenmetadata
threat-intel Five defender priorities from the Talos Year in Review This Cisco Talos report, part of their Year in Review, highlights five key priorities for cybersecurity defenders in the current threat landscape. The report emphasizes the increasing ease of attack due to readily availa… Cisco Talos · Apr 28, 2026 High USidentityvulnerabilityanomaly detection
threat-intel The calm before the ransom: What you see is not all there is This article highlights a common cybersecurity pitfall: organizations can become overly confident in their security posture due to a period of stability, leading to complacency and a failure to adequately assess current… WeLiveSecurity · Apr 24, 2026 High UScomplacencyrisk assessmentcybersecurity
threat-intel Frontier AI and the Future of Defense: Your Top Questions Answered This article from Palo Alto Networks Unit 42 analyzes the emerging threat posed by frontier AI models, particularly Anthropic’s Mythos, to cybersecurity. The rapid capabilities of these models – including vulnerability i… Palo Alto Unit 42 · Apr 23, 2026 High frontier aivulnerabilityexploit chaining
threat-intel It pays to be a forever student This article from Cisco Talos highlights the importance of broad knowledge beyond traditional cybersecurity for threat intelligence professionals. It emphasizes the need to understand diverse fields like economics and in… Cisco Talos · Apr 23, 2026 High CVE-2025-20333CVE-2025-20362aiphishingindustrial espionage
threat-intel Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System This report details a proof-of-concept (PoC) developed by Palo Alto Unit 42 demonstrating the potential of autonomous AI agents in launching offensive attacks against cloud environments. The PoC, utilizing a multi-agent… Palo Alto Unit 42 · Apr 23, 2026 High USaiautonomouscloud
threat-intel Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not A data breach occurred at Rockstar Games, stemming from a hacker gaining access to the company's systems. The stolen data, initially believed to be embarrassing, ultimately revealed sensitive internal communications, inc… Graham Cluley · Apr 22, 2026 Medium data breachrockstar gamesinternal communications
threat-intel When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks This report details a novel attack technique, dubbed AirSnitch, that exploits vulnerabilities in Wi-Fi encryption protocols (WPA2 and WPA3-Enterprise) to bypass client isolation and intercept network traffic. The attack… Palo Alto Unit 42 · Apr 22, 2026 High wpa2wpa3wi-fi
threat-intel Fracturing Software Security With Frontier AI Models This report from Palo Alto Unit 42 highlights the emerging threat posed by advanced AI models, particularly "frontier AI models," which demonstrate autonomous vulnerability discovery and exploitation capabilities. The ra… Palo Alto Unit 42 · Apr 20, 2026 High UNNOaivulnerabilityzero-day
threat-intel Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) This report from Palo Alto Unit 42 details a significant escalation of cyber risk originating from Iran following a 47-day internet outage. Iranian threat actors, identified as CL-STA-1128 (Cyber Av3ngers), are now aggre… Palo Alto Unit 42 · Apr 17, 2026 High USIRILoticsphishing
threat-intel A Deep Dive Into Attempted Exploitation of CVE-2023-33538 This report details an ongoing attempt to exploit CVE-2023-33538, a vulnerability in older TP-Link Wi-Fi router models (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Automated scans, utilizing Mirai-like malware p… Palo Alto Unit 42 · Apr 16, 2026 High CVE-2023-33538USiotvulnerabilitymirai
threat-intel Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying This article discusses a concerning trend where AI companies are inadvertently leaking their own code and becoming targets for malicious actors. Tanya Janca highlights the vulnerability of software developers, particular… Graham Cluley · Apr 15, 2026 High CAsupply chaindeveloper securitycredential theft
threat-intel Patch Tuesday, April 2026 Edition Microsoft released a substantial update, Patch Tuesday, addressing 167 vulnerabilities across its operating systems and software, including several zero-days. This update focused on critical flaws in SharePoint Server, W… Krebs on Security · Apr 14, 2026 High CVE-2026-32201CVE-2026-33825CVE-2026-34621zero-daypatch tuesdayvulnerability
threat-intel Recovery scammers hit you when you’re down: Here’s how to avoid a second strike This article discusses the growing problem of ‘recovery fraud,’ where scammers target individuals who have already been victims of fraud, exploiting their desperation to get their stolen funds back. These scams typically… WeLiveSecurity · Apr 10, 2026 High USfraudscamrecovery