AuraInspector: Auditing Salesforce Aura for Data Exposure

AuraInspector: Auditing Salesforce Aura for Data Exposure

• AuraInspector: Auditing Salesforce Aura for Data Exposure Mandiant Written by: Amine Ismail, Anirudha Kanodia Introduction Mandiant is releasing AuraInspector, a new open-source

Threat Intelligence · January 12, 2026 (updated February 24, 2026) · 2 min · 249 words

12th January - Threat Intelligence Report

• JavaScript is disabled In order to continue, we need to verify that you’re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.

Threat Intelligence · January 12, 2026 (updated February 24, 2026) · 1 min · 121 words
Breaking Down the Attack Surface of the Kenwood DNR1007XR - Part One

Breaking Down the Attack Surface of the Kenwood DNR1007XR - Part One

• Breaking Down the Attack Surface of the Kenwood DNR1007XR - Part One For the upcoming Pwn2Own Automotive contest, a total of 3 head units have been selected. • One of these is th

Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns

• JavaScript is disabled In order to continue, we need to verify that you’re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.

5th January - Threat Intelligence Report

• JavaScript is disabled In order to continue, we need to verify that you’re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.

Detect Go's silent arithmetic bugs with go-panikint

Detect Go's silent arithmetic bugs with go-panikint

• Go’s arithmetic operations on standard integer types are silent by default, meaning overflows ‘wrap around’ without panicking. • This behavior has hidden an entire class of secur

Threat Intelligence · December 31, 2025 (updated February 24, 2026) · 2 min · 238 words
Can chatbots craft correct code?

Can chatbots craft correct code?

• Can chatbots craft correct code? • I recently attended the AI Engineer Code Summit in New York, an invite-only gathering of AI leaders and engineers. • One theme emerged repeated

Threat Intelligence · December 19, 2025 (updated February 24, 2026) · 2 min · 217 words
Use GWP-ASan to detect exploits in production environments

Use GWP-ASan to detect exploits in production environments

• Use GWP-ASan to detect exploits in production environments Memory safety bugs like use-after-free and buffer overflows remain among the most exploited vulnerability classes in pr

Threat Intelligence · December 16, 2025 (updated February 24, 2026) · 2 min · 237 words

Welcome to the new Project Zero Blog

• While on Project Zero, we aim for our research to be leading-edge, our blog design was ⦠not so much. • We welcome readers to our shiny new blog! • For the occasion, we asked me

Threat Intelligence · December 16, 2025 (updated February 24, 2026) · 2 min · 229 words

Thinking Outside The Box [dusted off draft from 2017]

• Preface Hello from the future! • This is a blogpost I originally drafted in early 2017. • I wrote what I intended to be the first half of this post (about escaping from the VM to

Threat Intelligence · December 16, 2025 (updated February 24, 2026) · 2 min · 294 words

Windows Exploitation Techniques: Winning Race Conditions with Path Lookups

• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second

Threat Intelligence · December 16, 2025 (updated February 24, 2026) · 2 min · 246 words
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)

Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)

• Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most. •

Threat Intelligence · December 12, 2025 (updated February 24, 2026) · 2 min · 247 words
Catching malicious package releases using a transparency log

Catching malicious package releases using a transparency log

• Catching malicious package releases using a transparency log We’re getting Sigstore’s rekor-monitor ready for production use, making it easier for developers to detect tampering

Threat Intelligence · December 12, 2025 (updated February 24, 2026) · 2 min · 251 words

A look at an Android ITW DNG exploit

• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl

Threat Intelligence · December 12, 2025 (updated February 24, 2026) · 2 min · 216 words
Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis

Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis

• Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis In 2023 GitHub introduced CodeQL multi-repository variant analysis (MRVA). • This functionality

Threat Intelligence · December 11, 2025 (updated February 24, 2026) · 2 min · 259 words
The December 2025 Security Update Review

The December 2025 Security Update Review

• It’s the final patch Tuesday of 2025, but that doesn’t make it any less exciting. • Put aside your holiday planning for just a moment as we review the latest security offering fr

Threat Intelligence · December 9, 2025 (updated February 24, 2026) · 3 min · 439 words
A method to assess 'forgivable' vs 'unforgivable' vulnerabilities

A method to assess 'forgivable' vs 'unforgivable' vulnerabilities

• You need to enable JavaScript to run this app.

Threat Intelligence · December 8, 2025 (updated February 24, 2026) · 1 min · 101 words
Sanctioned but Still Spying: Intellexa's Prolific Zero-Day Exploits Continue

Sanctioned but Still Spying: Intellexa's Prolific Zero-Day Exploits Continue

• Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats tha

Threat Intelligence · December 3, 2025 (updated February 24, 2026) · 1 min · 206 words
Introducing constant-time support for LLVM to protect cryptographic code

Introducing constant-time support for LLVM to protect cryptographic code

• Introducing constant-time support for LLVM to protect cryptographic code Trail of Bits has developed constant-time coding support for LLVM, providing developers with compiler-lev

Threat Intelligence · December 2, 2025 (updated February 24, 2026) · 2 min · 221 words
Beyond the Watering Hole: APT24's Pivot to Multi-Vector Attacks

Beyond the Watering Hole: APT24's Pivot to Multi-Vector Attacks

• Beyond the Watering Hole: APT24’s Pivot to Multi-Vector Attacks Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most

Threat Intelligence · November 20, 2025 (updated February 24, 2026) · 2 min · 266 words
We found cryptography bugs in the elliptic library using Wycheproof

We found cryptography bugs in the elliptic library using Wycheproof

• We found cryptography bugs in the elliptic library using Wycheproof Trail of Bits is publicly disclosing two vulnerabilities in elliptic, a widely used JavaScript library for ell

Threat Intelligence · November 18, 2025 (updated February 24, 2026) · 2 min · 236 words
Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem

Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem

• Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem Mandiant Written by: Mohamed El-Banna, Daniel Lee, Mike

Threat Intelligence · November 17, 2025 (updated February 24, 2026) · 2 min · 287 words
Level up your Solidity LLM tooling with Slither-MCP

Level up your Solidity LLM tooling with Slither-MCP

• We’re releasingSlither-MCP, a new tool that augments LLMs with Slither’s unmatched static analysis engine. • Slither-MCP benefits virtually every use case for LLMs by exposing Sl

Threat Intelligence · November 15, 2025 (updated February 24, 2026) · 2 min · 261 words
How we avoided side-channels in our new post-quantum Go cryptography libraries

How we avoided side-channels in our new post-quantum Go cryptography libraries

• How we avoided side-channels in our new post-quantum Go cryptography libraries The Trail of Bits cryptography team is releasing our open-source pure Go implementations of ML-DSA

Threat Intelligence · November 14, 2025 (updated February 24, 2026) · 2 min · 274 words
Time Travel Triage: An Introduction to Time Travel Debugging using a .NET Process Hollowing Case Study

Time Travel Triage: An Introduction to Time Travel Debugging using a .NET Process Hollowing Case Study

• Time Travel Triage: An Introduction to Time Travel Debugging using a .NET Process Hollowing Case Study Mandiant Google Threat Intelligence Visibility and context on the threats t

Threat Intelligence · November 13, 2025 (updated February 24, 2026) · 2 min · 270 words
Building checksec without boundaries with Checksec Anywhere

Building checksec without boundaries with Checksec Anywhere

• Since its original release in 2009,checksechas become widely used in the software security community, proving useful in CTF challenges, security posturing, and general binary ana

Threat Intelligence · November 13, 2025 (updated February 24, 2026) · 2 min · 225 words
The November 2025 Security Update Review

The November 2025 Security Update Review

• I’ve made it through Pwn2Own Ireland, and while many are celebrated those who served their country in the armed services, patch Tuesday stops for no one. • So affix your poppy ac

Threat Intelligence · November 11, 2025 (updated February 24, 2026) · 2 min · 240 words
No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480

No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480

• No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480 Mandiant Written by: Stallone D’Souza, Praveeth DSouza, Bill Glynn, Kevin O’Flynn,

Threat Intelligence · November 10, 2025 (updated February 24, 2026) · 2 min · 277 words
Balancer hack analysis and guidance for the DeFi ecosystem

Balancer hack analysis and guidance for the DeFi ecosystem

• Balancer hack analysis and guidance for the DeFi ecosystem TL;DR - The root cause of the hack was a rounding direction issue that had been present in the code for many years. • -

Threat Intelligence · November 7, 2025 (updated February 24, 2026) · 2 min · 276 words
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools

GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools

• GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter m

Threat Intelligence · November 5, 2025 (updated February 24, 2026) · 2 min · 302 words
Preparing for Threats to Come: Cybersecurity Forecast 2026

Preparing for Threats to Come: Cybersecurity Forecast 2026

• Preparing for Threats to Come: Cybersecurity Forecast 2026 Blog and Content Manager Visibility and context on the threats that matter most. • Every November, we make it our missi

Threat Intelligence · November 4, 2025 (updated February 24, 2026) · 2 min · 218 words
The cryptography behind electronic passports

The cryptography behind electronic passports

• The cryptography behind electronic passports Did you know that most modern passports are actually embedded devices containing an entire filesystem, access controls, and support f

Threat Intelligence · October 31, 2025 (updated February 24, 2026) · 2 min · 275 words
Vulnerabilities in LUKS2 disk encryption for confidential VMs

Vulnerabilities in LUKS2 disk encryption for confidential VMs

• Trail of Bits is disclosing vulnerabilities in eight different confidential computing systems that use Linux Unified Key Setup version 2 (LUKS2) for disk encryption. • Using thes

Threat Intelligence · October 30, 2025 (updated February 24, 2026) · 2 min · 275 words
Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring

Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring

• Keys to the Kingdom: A Defender’s Guide to Privileged Account Monitoring Mandiant Written by: Bhavesh Dhake, Will Silverstone, Matthew Hitchcock, Aaron Fletcher The Criticality o

Threat Intelligence · October 28, 2025 (updated February 24, 2026) · 2 min · 304 words
Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials

Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials

• Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials Visibility and context on the threats that matter most. • Google Threat I

Threat Intelligence · October 23, 2025 (updated February 24, 2026) · 2 min · 241 words
Pwn2Own Ireland 2025: Day Three and Master of Pwn

Pwn2Own Ireland 2025: Day Three and Master of Pwn

• Pwn2Own Ireland 2025: Day Three and Master of Pwn Welcome to the third and final day of Pwn2Own Ireland 2025. • So far, we’ve awarded $792,750 for 56 unique 0-day bugs, and we st

Threat Intelligence · October 23, 2025 (updated February 24, 2026) · 1 min · 212 words
Prompt injection to RCE in AI agents

Prompt injection to RCE in AI agents

• Prompt injection to RCE in AI agents Modern AI agents increasingly execute system commands to automate filesystem operations, code analysis, and development workflows. • While so

Threat Intelligence · October 22, 2025 (updated February 24, 2026) · 2 min · 283 words
Pwn2Own Ireland 2025: Day One Results

Pwn2Own Ireland 2025: Day One Results

• Pwn2Own Ireland 2025: Day One Results Welcome to Day One of Pwn2Own Ireland 2025! • We have 17 attempts today with some exciting research on display. • We’ll be posting results h

Threat Intelligence · October 21, 2025 (updated February 24, 2026) · 2 min · 296 words
Pwn2Own Ireland 2025: The Full Schedule

Pwn2Own Ireland 2025: The Full Schedule

• Pwn2Own Ireland 2025: The Full Schedule Welcome to Pwn2Own Ireland 2025! • We have some amazing spooky entries for this year’s contest, and a potential of up to $2,000,000 - incl

Threat Intelligence · October 20, 2025 (updated February 24, 2026) · 2 min · 234 words
Pwn2Own Automotive Returns to Tokyo with Expanded Chargers and More!

Pwn2Own Automotive Returns to Tokyo with Expanded Chargers and More!

• If you just want to read the rules, click here. • Updated as of November 21 to expand the Alpitronic target scope and to clarify the model of the ChargePointHome Flex model numbe

Threat Intelligence · October 16, 2025 (updated February 24, 2026) · 2 min · 216 words
The October 2025 Security Update Review

The October 2025 Security Update Review

• I’m currently in Cork, Ireland as we prepare for Pwn2Own Ireland, but that doesn’t stop patch Tuesday from coming. • Take a break from your scheduled activities and let’s take a

Threat Intelligence · October 14, 2025 (updated February 24, 2026) · 2 min · 284 words
Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing

Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing

• In April of 2025, my colleague Mat Powell was hunting for vulnerabilities in Autodesk Revit 2025. • While fuzzing RFA files, he found the following crash (CVE-2025-5037 / ZDI-CAN

Taming 2,500 compiler warnings with CodeQL, an OpenVPN2 case study

Taming 2,500 compiler warnings with CodeQL, an OpenVPN2 case study

• Taming 2,500 compiler warnings with CodeQL, an OpenVPN2 case study Why are implicit integer conversions a problem in C? • During our security review of OpenVPN2, we faced a daunt

Threat Intelligence · September 25, 2025 (updated February 24, 2026) · 2 min · 250 words
CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin

CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin

• CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin While investigating the security posture of various machine learning (ML) and artificial intelligence (AI) framewor

Threat Intelligence · September 24, 2025 (updated February 24, 2026) · 2 min · 287 words
Supply chain attacks are exploiting our assumptions

Supply chain attacks are exploiting our assumptions

• Supply chain attacks are exploiting our assumptions Every time you run cargo add or pip install , you are taking a leap of faith. • You trust that the code you are downloading co

Threat Intelligence · September 24, 2025 (updated February 24, 2026) · 2 min · 224 words
The September 2025 Security Update Review

The September 2025 Security Update Review

• There’s a crispness in the air - at least here in North America - and with it comes the latest security patches from Adobe and Microsoft. • Take a break from your scheduled activ

Threat Intelligence · September 9, 2025 (updated February 24, 2026) · 2 min · 247 words
Active Cyber Defence (ACD) - The Third Year

Active Cyber Defence (ACD) - The Third Year

• You need to enable JavaScript to run this app. • You need to enable JavaScript to run this app.

Impact of AI on cyber threat from now to 2027

Impact of AI on cyber threat from now to 2027

• AI is accelerating threat sophistication, enabling attackers to craft more convincing phishing campaigns. • Machine‑learning models are used to generate polymorphic malware that

Vendor Security Assessment

Vendor Security Assessment

• Identify vendor security posture through comprehensive risk assessment. • Evaluate compliance with industry standards and regulatory requirements. • Assess data protection, acces

Threat report on application stores

Threat report on application stores

• Malware increasingly hides in legitimate app store listings, exploiting user trust for widespread infection. • Supply‑chain attacks target third‑party libraries, enabling attacke

The threat from commercial cyber proliferation

The threat from commercial cyber proliferation

• Commercial software proliferation expands attack surface, increasing vulnerability exposure across enterprises. • Open-source components in commercial stacks introduce hidden bac

The near-term impact of AI on the cyber threat

The near-term impact of AI on the cyber threat

• AI accelerates threat detection, enabling faster identification of malicious activity. • Adversarial AI allows attackers to craft evasive malware that bypasses traditional defens

The cyber threat to Universities

The cyber threat to Universities

• Universities face rising ransomware attacks targeting research data and student records. • Phishing campaigns exploit faculty credentials to gain network access. • Supply‑chain v

The Cyber Threat to UK Business

The Cyber Threat to UK Business

• Ransomware remains the top threat, targeting critical UK business data. • Phishing campaigns exploit remote working, increasing credential theft. • Supply‑chain attacks grow, com

The cyber threat to sports organisations

The cyber threat to sports organisations

• Sports organisations increasingly targeted by ransomware, phishing, and credential‑stealing attacks. • High‑profile events like the Olympics and World Cup attract sophisticated t

Summary of the NCSC analysis of May 2020 US sanction

Summary of the NCSC analysis of May 2020 US sanction

• US sanctions in May 2020 targeted Russian cyber actors and infrastructure. • NCSC identified increased threat actor activity following sanction announcements. • Sanctions disrupt

Summary of NCSC's security analysis for the UK telecoms sector

Summary of NCSC's security analysis for the UK telecoms sector

• UK telecoms face rising cyber threats, including ransomware targeting network infrastructure. • NCSC highlights supply chain risks from overseas vendors in 5G equipment. • Vulner

Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking

Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking

• BGP is critical for inter-ISP routing, requiring strict policy enforcement to prevent leaks and hijacks. • Implement prefix filtering and route origin validation to ensure only l

Organisational use of Enterprise Connected Devices

Organisational use of Enterprise Connected Devices

• Enterprise connected devices expand attack surface, enabling lateral movement across corporate networks. • Insider threats amplified as employees use personal devices for work, b

Joint report on publicly available hacking tools

Joint report on publicly available hacking tools

• Joint report reveals surge in publicly available hacking toolkits targeting critical infrastructure. • Analysts highlight increased ease of access via dark web marketplaces and o