Topic
Reports

Claude Mythos security risks: What the Anthropic System Card tells us
Anthropic's Claude Mythos Preview demonstrated significant acceleration in capabilities for autonomously identifying vulnerabilities and exploit chains across major software and operating systems. Government and industry leaders are focused on understanding the real risks the model presents, and how to leverage these advanced technologies to protect and defend against adversarial use.

CVE‑2025‑47813: Wing FTP Server vulnerability flagged by CISA
CISA KEV‑listed CVE‑2025‑47813 exposes Wing FTP Server install paths used in attack chains. Learn which versions are affected and how to remediate.

Tanium named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Management Tools
Tanium CTO shares a perspective on the 2026 Gartner Magic Quadrant for Endpoint Management Tools.

CTI roundup: SantaStealer, BlackForce, Ink Dragon
SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

CTI roundup: Shanya, GrayBravo, Storm-0249
Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

CTI roundup: Hybrid 2FA phishing, RomCom, MuddyWater
Hybrid 2FA phishing threatens enterprises, RomCom uses SocGholish to deploy Mythic Agent malware, and MuddyWater targets critical infrastructure with evolving tactics

CTI roundup: Whisper Leak, @acitons/artifact, Quantum Route Redirect
Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

CTI roundup: RMM abuse, SesameOp, Google’s 2026 Cybersecurity Forecast
Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

CTI roundup: DragonForce, Qilin, Water Saci
Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

CTI roundup: Famous Chollima, COLDRIVER, Vidar Stealer 2.0
Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities

CTI roundup: Astaroth, TA585, Microsoft tech support scams
Astaroth trojan uses GitHub to host malware configurations, TA585 delivers MonsterV2 malware in phishing campaigns, and threat actors exploit Microsoft’s logo in tech support scams

CTI roundup: XWorm, Microsoft Teams, Storm-1175
XWorm malware reemerges with ransomware, Microsoft disrupts multiple threats targeting Teams, and Storm-1175 exploits a critical GoAnywhere MFT vulnerability