Beyond IOCs: AI-enabled threat intelligence
Welcome to this week’s Threat Source newsletter. The issue of AI in cybersecurity is often portrayed as a binary choice: either a force multiplier for our adversaries, or a tool…
Welcome to this week’s Threat Source newsletter. The issue of AI in cybersecurity is often portrayed as a binary choice: either a force multiplier for our adversaries, or a tool…
Executive Summary Update (June 19, 2026): We have confirmed that the NinjaOne-related artifact referenced in this report is no longer accessible. Our investigation did not identify a vulnerability or compromise in NinjaOne’s platform. The campaign relied…
Introduction CVE-2026-9082 is a critical pre-authentication SQL injection vulnerability in Drupal Core’s JSON:API module, carrying a CVSS score of 9.8. Published on May 20, 2026, it was added to the…
Anyone who has seen the impressive frame of Stonehenge against the morning’s sunrise cannot help but be struck by its resilience, how it has withstood time and the unpredictable impact…
Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates. Key Takeaways The June 2026 Critical Security Patch Update (CSPU) contains…
At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education. The…
For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed…
The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit,…
Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded “ARToken,” that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early…
A CVE lands in the morning. Hours later, attackers are exploiting it in the wild. The patch is not ready, the change window is days away, and the clock is…