For Banks
For Government Agencies
For Enterprise
For Service Providers
Learn
Partner
About
Contact
Solutions
For Banks
For Government Agencies
For Enterprise
For Service Providers
Learn
Partner
About
Contact
Sign up
Intelligence
How initial access brokers operate in the MENA region
Pioneer Kitten highlights a growing MENA cyber threat: where espionage, ransomware, and access brokers increasingly overlap.
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
Credential Leak Monitoring: A Complete Guide for Security Teams
How credential leak monitoring works, what it detects, and how security teams should act on alerts. Includes 2025 DBIR and IBM breach data.
Marouane Sabri
Defendis Co-founder
ALL
EXPLAINERS
GUIDES
News
Usurpation de Marque en 2026 : Anatomie des Attaques, Montée en Puissance des Domaines Frauduleux et Rôle de la Surveillance Continue
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Shadow IT, Repos Git Ouverts, Backups Exposés : Ce que les Attaquants Voient de Votre Organisation Sans Même Essayer
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Logs, Markets, Brokers : Comment les Identifiants Volés par Infostealers Deviennent un Service à la Demande sur le Dark Web
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
PamStealer : Le Faux Gestionnaire de Presse-Papier qui Détourne l'Authentification macOS pour Voler les Mots de Passe
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
The Credential Economy in 2026: What 16 Billion Dark Web Records Tell You About Your Organisation's Real Exposure
Sami Malik
Copywriter
News
The 2026 Attack Surface Reality: 60% of Organisations Expose Admin Panels, and Most Don't Know What Attackers Can See
Sami Malik
Copywriter
News
Phantom Squatting: How Attackers Are Registering Domains That AI Models Invent Before Defenders Know They Exist
Sami Malik
Copywriter
News
ACR Stealer and the ClickFix Credential Pipeline: How an Infostealer Is Walking Out of Enterprise Microsoft 365 Environments
Sami Malik
Copywriter
News
LSHIY : 81 Millions de Tentatives en 14 Jours, l'Anatomie d'une Campagne de Password Spraying contre Microsoft 365 via Azure CLI
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
InfernoGrabber v9.0 : Comment DeepSeek a Généré le Premier Ransomware de Navigateur Fonctionnel sur Windows, Linux, macOS et Android
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Abbott Laboratories : ShinyHunters et ShadowByt3$ Revendiquent Deux Intrusions Simultanées et 22 Millions de Dossiers Médicaux Exposés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Avalon et CrownX : Le Framework Ransomware Assisté par IA qui Cible les Sauvegardes Avant de Chiffrer
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Google and FBI Dismantle NetNut: Inside the Residential Proxy Botnet Used by 316 Threat Clusters to Hide Attack Traffic
Sami Malik
Copywriter
News
Helix: The Data-Extortion Group Using Voice Phishing and Microsoft's Own OAuth Flow to Steal SharePoint Files Without Deploying Malware
Sami Malik
Copywriter
News
wp2shell (CVE-2026-63030): How Two Chained WordPress Core Bugs Enable Unauthenticated Remote Code Execution on Default Installations
Sami Malik
Copywriter
News
GhostLock (CVE-2026-43499): The 15-Year Linux Kernel Flaw That Delivers Root Access in Under Five Seconds
Sami Malik
Copywriter
News
TELEPUZ : Le Malware MaaS en C qui Exploite ClickFix, Telegram, Steam et la Blockchain pour Cacher son C2
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
OkoBot : Le Framework Malware qui Injecte du Phishing de Seed Phrase Directement dans Ledger Live et Trezor Suite
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Scattered Spider: Owen Flowers and Thalha Jubair Sentenced to 5.5 Years for the £29 Million TfL Attack
Sami Malik
Copywriter
News
SharePoint Server Zero-Day CVE-2026-58644 (CVSS 9.8) Under Active Exploitation: What On-Premises Deployments Need to Do Now
Sami Malik
Copywriter
News
Forg365 PhaaS : 400 Dollars par Mois pour Voler les Sessions Microsoft 365 via Device Code et AitM
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
148 Paquets npm Déguisés en Proxies Étudiants pour Transformer des Navigateurs en Botnet DDoS
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
LabubaRAT : le Cheval de Troie Rust qui se Fait Passer pour NVIDIA pour Contrôler des Hôtes Windows
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
MemGhost : Un Email Piégé Plante de Faux Souvenirs Persistants dans un Agent IA
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
CrashStealer: The Notarised macOS Info-Stealer That Passes Gatekeeper and Empties 80 Crypto Wallet Extensions
Sami Malik
Copywriter
News
Eleven Old Microsoft-Signed Linux UEFI Shims Still Trusted by Secure Boot — Now Revoked After Six-Month Disclosure
Sami Malik
Copywriter
News
SAP July 2026 Security Day: CVE-2026-44747 (CVSS 9.9) and Two More Critical Flaws Across NetWeaver ABAP, Approuter, and Commerce Cloud
Sami Malik
Copywriter
News
Two SonicWall SMA 1000 Zero-Days Under Active Exploitation: CVE-2026-15409 and CVE-2026-15410
Sami Malik
Copywriter
Guides
How to Choose a Dark Web Monitoring Solution: 8 Criteria That Actually Matter
Noha Moussaddak
Cybersecurity enthusiast and writer
News
XSS Stockée dans Zimbra Classic Web Client : Exécution de Code via Email Piégé
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
RedWing MaaS : la Fraude Bancaire Android en Location sur Telegram
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Ghostcommit : des Instructions Malveillantes Cachées dans des Images PNG pour Voler les Secrets via des Agents IA
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
GodDamn Ransomware et PoisonX : le Driver BYOVD Signé Microsoft qui Désactive les EDR avant le Chiffrement
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
GigaWiper (BLUERABBIT): Iran-Linked Go Backdoor That Wipes Disks and Fakes Ransomware With No Decryption Key
Sami Malik
Copywriter
News
OpenClaw: Three Flaws Chain a WhatsApp Message to Full Host Escape With No Prior Foothold
Sami Malik
Copywriter
News
Progress ShareFile Storage Zone Controller Shutdown: What the Credible Threat Advisory Means for Your Organisation
Sami Malik
Copywriter
News
GhostLock (CVE-2026-43499): The 15-Year-Old Linux Futex Flaw That Gives Root in Five Seconds
Sami Malik
Copywriter
News
RoguePlanet (CVE-2026-50656): The Microsoft Defender Race Condition That Hands Any User SYSTEM Privileges
Sami Malik
Copywriter
News
EtherRAT : le RAT distribué via de faux appels support Teams avec Ethereum pour le C2
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
QuimaRAT : le RAT Java multiplateforme vendu en MaaS avec 74 modules Windows et plugins dynamiques chiffrés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
TrojPix : exfiltration de données depuis un système isolé à 8,1 Mbps via le câble vidéo
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Cavern Manticore : le framework C2 iranien qui compromet les organisations israéliennes via SysAid
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Januscape (CVE-2026-53359): The 16-Year-Old Linux KVM Flaw That Lets a Guest VM Escape to the Host
Sami Malik
Copywriter
News
CVE-2026-48282: Adobe ColdFusion RCE Exploited in the Wild Within Two Hours of Disclosure
Sami Malik
Copywriter
News
BeyondTrust Patches Four Vulnerabilities Including Two CVSS 9.2 Pre-Auth Bypasses Found With AI Assistance
Sami Malik
Copywriter
News
CVE-2026-11405: The Hidden Admin Backdoor in Tenda Router Firmware That Nobody Patched
Sami Malik
Copywriter
News
ARToken PhaaS : quand un kit de phishing Microsoft 365 expose toute l'architecture d'EvilTokens
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Armored Likho : l'acteur malveillant qui cible gouvernements et secteur électrique avec le stealer BusySnake
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Avalon : le framework malveillant modulaire qui combine vol de données, mouvement latéral et ransomware CrownX
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
PolinRider : la campagne nord-coréenne qui a compromis 1 951 dépôts GitHub pour infecter développeurs et projets crypto
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Bad Epoll (CVE-2026-46242): The Linux Kernel Race Condition That Hands Any User Root and Escapes Chrome's Sandbox
Sami Malik
Copywriter
News
No Encryption Required: How Kairos Extorted $1 Million From a US County Using Only Stolen Data
Sami Malik
Copywriter
News
SkillCloak: The AI Agent Skill Packer That Passes Every Scanner and What Security Teams Can Do About It
Sami Malik
Copywriter
News
Opera GX's Silent Mod Attack: How a Gaming Browser Flaw Let Any Website Extract Your Gmail Address Without a Click
Sami Malik
Copywriter
News
Umbrij : le malware de ToddyCat qui détourne OAuth pour espionner les emails Gmail d'entreprises
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
NetNut : Google et le FBI dégradent un réseau de 2 millions d'appareils domestiques transformés en proxies pour cybercriminels
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
JADEPUFFER: The AI Agent That Ran a Complete Ransomware Attack Without Human Operators
Sami Malik
Copywriter
News
PamStealer: The macOS Infostealer That Hid Inside a Fake Clipboard Manager
Sami Malik
Copywriter
News
81 Million Login Attempts: The Microsoft 365 Credential Attack Organisations Need to Understand
Sami Malik
Copywriter
News
ChocoPoC : quand les chercheurs en sécurité deviennent les cibles de faux exploits piégés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Scattered Spider : un suspect de 19 ans extradé aux États-Unis pour piratage d'entreprises mondiales
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
CVE-2026-45659: SharePoint Deserialization Flaw Added to CISA KEV as Active Exploitation Confirmed
Sami Malik
Copywriter
Guides
What Actually Happens When a Phishing Campaign Hits Your Org
Noha Moussaddak
Cybersecurity enthusiast and writer
News
INC Ransomware : 830 victimes en trois ans, des hôpitaux aux cabinets d'avocats
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Tata Electronics : une cyberattaque expose les secrets industriels d'Apple et Tesla
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
The Klue Supply Chain Attack: How Icarus Used a 2022 Credential to Breach LastPass, Recorded Future, Jamf and Nine Others via Stolen Salesforce OAuth Tokens
Sami Malik
Copywriter
News
DragonForce Ransomware Hid Inside Microsoft Teams for Two Months: How Backdoor.Turn Tunnelled C2 Through TURN Relays
Sami Malik
Copywriter
News
INSEE : l'annuaire interne trombi.insee.fr compromis, 12 800 agents exposés par Saturne
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
RATP : les données professionnelles de 62 208 agents diffusées sur le dark web par le pirate Misere
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
CVE-2026-47291: The HTTP.sys Kernel RCE That Gives Unauthenticated Attackers SYSTEM on Every Windows Version
Sami Malik
Copywriter
News
CVE-2026-42271: How a LiteLLM MCP Endpoint Chained with a Starlette Bug Became a CVSS 10.0 AI Gateway Takeover
Sami Malik
Copywriter
News
Cegedim Santé : les données administratives de 15 millions de patients français ont fuité
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Tchap : 643 000 messages de la messagerie d'État exfiltrés, 90 documents Diffusion Restreinte exposés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Cisco SD-WAN CVE-2026-20245: Nation-State Actor Gained Root via CSV Upload Two Months Before Patch
Sami Malik
Copywriter
News
Cordyceps: The CI/CD Flaw That Let Any GitHub User Compromise Microsoft, Google and Apache
Sami Malik
Copywriter
News
Squidbleed CVE-2026-47729 : un bug de 1997 dans Squid expose les requêtes HTTP des autres utilisateurs
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Campagne WhatsApp : des VBScript installent ManageEngine RMM Central sur les machines des victimes
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Fake AI Agent Skill Bypassed Every Security Scanner and Reportedly Reached 26,000 Agents
Sami Malik
Copywriter
News
DoJ Seizes HuiOne Group Cloud Infrastructure Behind $31 Billion Fraud Marketplace
Sami Malik
Copywriter
News
ShapedPlugin : trois plugins WordPress Pro compromis dans une attaque de supply chain
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Cisco Unified CM CVE-2026-20230 : faille SSRF exploitée pour élever les privilèges en root
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Malicious npm Packages Mimic PostCSS Tools to Deliver Windows RAT
Sami Malik
Copywriter
Intelligence
FortiBleed: How 430,000 FortiGate Firewalls Were Turned Into Credential Harvesters
Sami Malik
Copywriter
Intelligence
How initial access brokers operate in the MENA region
Noha Moussaddak
Cybersecurity enthusiast and writer
Intelligence
The Expert View: Quantum Readiness Before It's Too Late
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
Ransomware-as-a-service: how attacks are launched without technical skills
Noha Moussaddak
Cybersecurity enthusiast and writer
Intelligence
GreatXML : le zero-day qui contourne BitLocker via Windows Defender
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Langflow CVE-2026-5027: Path Traversal Flaw Exploited for RCE
Sami Malik
Copywriter
Intelligence
Oracle PeopleSoft Zero-Day CVE-2026-35273 Exploited by ShinyHunters
Sami Malik
Copywriter
News
Adobe corrige 123 vulnérabilités en juin 2026 dont plusieurs critiques
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Veeam Backup RCE Flaw CVE-2026-44963: Domain Users Can Execute Remote Code
Sami Malik
Copywriter
Intelligence
Google Chrome corrige 74 failles dont un zero-day V8 exploité en conditions réelles
Sami Malik
Copywriter
News
Un ver informatique autonome propulsé par IA compromet 75 % d'un réseau en sept jours
Sami Malik
Copywriter
Intelligence
Vidar Infostealer Spreads via Fake Spotify Tutorials on TikTok and Instagram
Sami Malik
Copywriter
News
Check Point VPN CVE-2026-50751: IKEv1 Flaw Exploited by Qilin Ransomware
Sami Malik
Copywriter
Intelligence
CVE-2026-23111 : un seul caractère dans le kernel Linux ouvre la porte au root
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Le ver Miasma force GitHub à désactiver 73 dépôts Microsoft en 105 secondes
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Hacktivists Expand Beyond Politics: Agriculture, Hospitality, and C2 Frameworks
Sami Malik
Copywriter
News
WinRAR Flaw CVE-2025-8088 Fuels GiftedCrook Stealer Attacks on Ukraine
Sami Malik
Copywriter
Intelligence
C0XMO : le botnet Gafgyt qui cible vos vieux routeurs DD-WRT
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Malicious npm Packages Mimic PostCSS Tools to Deliver Windows RAT
Sami Malik
Copywriter
Intelligence
FortiBleed: How 430,000 FortiGate Firewalls Were Turned Into Credential Harvesters
Sami Malik
Copywriter
Intelligence
How initial access brokers operate in the MENA region
Noha Moussaddak
Cybersecurity enthusiast and writer
Intelligence
The Expert View: Quantum Readiness Before It's Too Late
Noha Moussaddak
Cybersecurity enthusiast and writer
Intelligence
GreatXML : le zero-day qui contourne BitLocker via Windows Defender
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Oracle PeopleSoft Zero-Day CVE-2026-35273 Exploited by ShinyHunters
Sami Malik
Copywriter
Intelligence
Veeam Backup RCE Flaw CVE-2026-44963: Domain Users Can Execute Remote Code
Sami Malik
Copywriter
Intelligence
Google Chrome corrige 74 failles dont un zero-day V8 exploité en conditions réelles
Sami Malik
Copywriter
Intelligence
Vidar Infostealer Spreads via Fake Spotify Tutorials on TikTok and Instagram
Sami Malik
Copywriter
Intelligence
CVE-2026-23111 : un seul caractère dans le kernel Linux ouvre la porte au root
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Hacktivists Expand Beyond Politics: Agriculture, Hospitality, and C2 Frameworks
Sami Malik
Copywriter
Intelligence
C0XMO : le botnet Gafgyt qui cible vos vieux routeurs DD-WRT
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Everest Forms Pro CVE-2026-3300: RCE Flaw Used to Hijack WordPress Sites
Sami Malik
Copywriter
Intelligence
CVE-2025-8088: WinRAR Path Traversal Under Active Exploit
Sami Malik
Copywriter
Intelligence
Gamaredon CVE-2025-8088: GammaWorm Against Ukraine
Sami Malik
Copywriter
Intelligence
Miasma : 32 paquets npm Red Hat compromis par un ver furtif
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Dashlane : attaque par force brute sur les codes 2FA
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
CISA Flags Critical Magento RCE Vulnerability in KEV Catalog
Sami Malik
Copywriter
Intelligence
CVE-2026-49975 : la faille HTTP/2 Bomb paralyse nginx et IIS
Sami Malik
Copywriter
Intelligence
JINX-0164 Targets Crypto Firms via Fake Teams and npm Backdoor
Sami Malik
Copywriter
Intelligence
FROST : votre SSD trahit vos habitudes de navigation
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
CVE-2026-48710 : un caractère bypass l'auth Starlette
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Taphouse 1.5 : scanner CVE pour les paquets Homebrew
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
CVE-2026-35616: FortiClient EMS Flaw Used to Drop EKZ Stealer
Sami Malik
Copywriter
Intelligence
CVE-2026-5426: KnowledgeDeliver LMS Zero-Day Drops Cobalt Strike
Sami Malik
Copywriter
Intelligence
Microsoft Patches Critical SharePoint RCE CVE-2026-45659
Sami Malik
Copywriter
Intelligence
CVE-2026-26980: Ghost CMS Exploited to Hijack 700+ Sites
Sami Malik
Copywriter
Intelligence
The Gentlemen : ransomware bâti sur les identifiants volés
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
CVE-2026-9082 : injection SQL critique dans Drupal sur PostgreSQL
Sami Malik
Copywriter
Intelligence
CVE-2022-0543: Redis Lua Sandbox Escape Exploited in the Wild
Sami Malik
Copywriter
Intelligence
CVE-2026-46333 : faille kernel Linux, root via ptrace
Sami Malik
Copywriter
Intelligence
PHP & Apache CVEs Exploited Actively Across Four Vulnerabilities
Sami Malik
Copywriter
Intelligence
Microsoft Patches BitLocker Bypass Vulnerability CVE-2026-45585
Sami Malik
Copywriter
Intelligence
Four Malicious npm Packages Distribute Infostealers and DDoS Malware
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
CVE-2026-0300 : buffer overflow non authentifié dans PAN-OS donne un accès root
Sami Malik
Copywriter
Intelligence
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Multiples vulnérabilités dans les produits Cisco
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Cisco Catalyst SD-WAN Controller Auth Bypass to Gain Admin Access
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Fragnesia (CVE-2026-46300) : escalade root via IPsec Linux
Sami Malik
Copywriter
Intelligence
Cisco SD-WAN CVE-2026-20182: Critical Zero-Day Under Attack
Sami Malik
Copywriter
Intelligence
Nitrogen vole 8 To de données chez Foxconn et ses partenaires technologiques
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Premier exploit zero-day créé par une IA : Google stoppe une attaque de masse
Sami Malik
Copywriter
Intelligence
First AI-Built Zero-Day: How Google Stopped a Mass 2FA Exploitation Campaign
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
CVE-2026-45185: Critical Exim Zero-Day Puts GnuTLS Mail Servers at Risk
Sami Malik
Copywriter
Intelligence
Les robots Unitree vulnérables à une backdoor persistante
Sami Malik
Copywriter
Intelligence
Botnet Exploiting Source Engine to Target Game Servers
Sami Malik
Copywriter
Intelligence
Covert Hacker Group Exploits Critical cPanel Vulnerability After Six Years
Sara Amin
Marketing Student • Content & Writing Enthusiast
Intelligence
Needle C2: Crypto-Stealing Malware-as-a-Service Operation
Sami Malik
Copywriter
Intelligence
How Cyber Threat Intelligence Protects Your Business
Noha Moussaddak
Cybersecurity enthusiast and writer
Intelligence
An Analysis of Dark Web Monitoring
Defendis
Simplified Threat Intelligence
Explainers
Ransomware-as-a-service: how attacks are launched without technical skills
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
What is dark web monitoring? A plain-language guide for security teams
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
MITRE ATT&CK Explained: A Practical Guide for Security Leaders
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
Deepfake Job Interview Scams Explained
Marouane Sabri
Defendis Co-founder
Explainers
What are indicators of compromise and why they matter
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
What does ‘Attack Surface’ really mean for a business
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
What is ISO 27001 and why it matters
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
Understanding Insider Threats: Why Internal Access Is Your Biggest Security Risk
Noha Moussaddak
Cybersecurity enthusiast and writer
Explainers
Understanding and Preventing Man-in-the-Middle (MitM) Attacks
Defendis
Simplified Threat Intelligence
Explainers
Understanding and Preventing DDoS Attacks
Defendis
Simplified Threat Intelligence
Explainers
What is a Brute Force Attack?
Defendis
Simplified Threat Intelligence
Explainers
Understanding the role of CVEs in Cybersecurity
Defendis
Simplified Threat Intelligence
No items found.
Guides
How to Choose a Dark Web Monitoring Solution: 8 Criteria That Actually Matter
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
What Actually Happens When a Phishing Campaign Hits Your Org
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
Credential Leak Monitoring: A Complete Guide for Security Teams
Marouane Sabri
Defendis Co-founder
Guides
How to Align Threat Intelligence With Your Business Strategy
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
How to Identify Suspicious Activity Before It Becomes an Attack
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
What to do when your company's credentials are found leaked
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
How to Prioritize the CVEs That Actually Get Exploited
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
How to Build a Security-First Culture without Affecting Productivity
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
How To Achieve Cyber Resilience With Continuous Learning
Noha Moussaddak
Cybersecurity enthusiast and writer
Guides
Insider Threats Explained: Types, Detection, and Prevention
Sara Amin
Marketing Student • Content & Writing Enthusiast
Guides
Protect Yourself Against Social Engineering Attacks
Defendis
Simplified Threat Intelligence
Guides
Threat Intelligence : 4 critères pour bien choisir
Sara Amin
Marketing Student • Content & Writing Enthusiast
Guides
Zero-Day Attack and How to Prevent It
Defendis
Simplified Threat Intelligence
News
Usurpation de Marque en 2026 : Anatomie des Attaques, Montée en Puissance des Domaines Frauduleux et Rôle de la Surveillance Continue
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Shadow IT, Repos Git Ouverts, Backups Exposés : Ce que les Attaquants Voient de Votre Organisation Sans Même Essayer
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Logs, Markets, Brokers : Comment les Identifiants Volés par Infostealers Deviennent un Service à la Demande sur le Dark Web
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
PamStealer : Le Faux Gestionnaire de Presse-Papier qui Détourne l'Authentification macOS pour Voler les Mots de Passe
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
The Credential Economy in 2026: What 16 Billion Dark Web Records Tell You About Your Organisation's Real Exposure
Sami Malik
Copywriter
News
The 2026 Attack Surface Reality: 60% of Organisations Expose Admin Panels, and Most Don't Know What Attackers Can See
Sami Malik
Copywriter
News
Phantom Squatting: How Attackers Are Registering Domains That AI Models Invent Before Defenders Know They Exist
Sami Malik
Copywriter
News
ACR Stealer and the ClickFix Credential Pipeline: How an Infostealer Is Walking Out of Enterprise Microsoft 365 Environments
Sami Malik
Copywriter
News
LSHIY : 81 Millions de Tentatives en 14 Jours, l'Anatomie d'une Campagne de Password Spraying contre Microsoft 365 via Azure CLI
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
InfernoGrabber v9.0 : Comment DeepSeek a Généré le Premier Ransomware de Navigateur Fonctionnel sur Windows, Linux, macOS et Android
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Abbott Laboratories : ShinyHunters et ShadowByt3$ Revendiquent Deux Intrusions Simultanées et 22 Millions de Dossiers Médicaux Exposés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Avalon et CrownX : Le Framework Ransomware Assisté par IA qui Cible les Sauvegardes Avant de Chiffrer
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Google and FBI Dismantle NetNut: Inside the Residential Proxy Botnet Used by 316 Threat Clusters to Hide Attack Traffic
Sami Malik
Copywriter
News
Helix: The Data-Extortion Group Using Voice Phishing and Microsoft's Own OAuth Flow to Steal SharePoint Files Without Deploying Malware
Sami Malik
Copywriter
News
wp2shell (CVE-2026-63030): How Two Chained WordPress Core Bugs Enable Unauthenticated Remote Code Execution on Default Installations
Sami Malik
Copywriter
News
GhostLock (CVE-2026-43499): The 15-Year Linux Kernel Flaw That Delivers Root Access in Under Five Seconds
Sami Malik
Copywriter
News
TELEPUZ : Le Malware MaaS en C qui Exploite ClickFix, Telegram, Steam et la Blockchain pour Cacher son C2
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
OkoBot : Le Framework Malware qui Injecte du Phishing de Seed Phrase Directement dans Ledger Live et Trezor Suite
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Scattered Spider: Owen Flowers and Thalha Jubair Sentenced to 5.5 Years for the £29 Million TfL Attack
Sami Malik
Copywriter
News
SharePoint Server Zero-Day CVE-2026-58644 (CVSS 9.8) Under Active Exploitation: What On-Premises Deployments Need to Do Now
Sami Malik
Copywriter
News
Forg365 PhaaS : 400 Dollars par Mois pour Voler les Sessions Microsoft 365 via Device Code et AitM
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
148 Paquets npm Déguisés en Proxies Étudiants pour Transformer des Navigateurs en Botnet DDoS
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
LabubaRAT : le Cheval de Troie Rust qui se Fait Passer pour NVIDIA pour Contrôler des Hôtes Windows
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
MemGhost : Un Email Piégé Plante de Faux Souvenirs Persistants dans un Agent IA
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
CrashStealer: The Notarised macOS Info-Stealer That Passes Gatekeeper and Empties 80 Crypto Wallet Extensions
Sami Malik
Copywriter
News
Eleven Old Microsoft-Signed Linux UEFI Shims Still Trusted by Secure Boot — Now Revoked After Six-Month Disclosure
Sami Malik
Copywriter
News
SAP July 2026 Security Day: CVE-2026-44747 (CVSS 9.9) and Two More Critical Flaws Across NetWeaver ABAP, Approuter, and Commerce Cloud
Sami Malik
Copywriter
News
Two SonicWall SMA 1000 Zero-Days Under Active Exploitation: CVE-2026-15409 and CVE-2026-15410
Sami Malik
Copywriter
News
XSS Stockée dans Zimbra Classic Web Client : Exécution de Code via Email Piégé
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
RedWing MaaS : la Fraude Bancaire Android en Location sur Telegram
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Ghostcommit : des Instructions Malveillantes Cachées dans des Images PNG pour Voler les Secrets via des Agents IA
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
GodDamn Ransomware et PoisonX : le Driver BYOVD Signé Microsoft qui Désactive les EDR avant le Chiffrement
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
GigaWiper (BLUERABBIT): Iran-Linked Go Backdoor That Wipes Disks and Fakes Ransomware With No Decryption Key
Sami Malik
Copywriter
News
OpenClaw: Three Flaws Chain a WhatsApp Message to Full Host Escape With No Prior Foothold
Sami Malik
Copywriter
News
Progress ShareFile Storage Zone Controller Shutdown: What the Credible Threat Advisory Means for Your Organisation
Sami Malik
Copywriter
News
GhostLock (CVE-2026-43499): The 15-Year-Old Linux Futex Flaw That Gives Root in Five Seconds
Sami Malik
Copywriter
News
RoguePlanet (CVE-2026-50656): The Microsoft Defender Race Condition That Hands Any User SYSTEM Privileges
Sami Malik
Copywriter
News
EtherRAT : le RAT distribué via de faux appels support Teams avec Ethereum pour le C2
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
QuimaRAT : le RAT Java multiplateforme vendu en MaaS avec 74 modules Windows et plugins dynamiques chiffrés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
TrojPix : exfiltration de données depuis un système isolé à 8,1 Mbps via le câble vidéo
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Cavern Manticore : le framework C2 iranien qui compromet les organisations israéliennes via SysAid
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Januscape (CVE-2026-53359): The 16-Year-Old Linux KVM Flaw That Lets a Guest VM Escape to the Host
Sami Malik
Copywriter
News
CVE-2026-48282: Adobe ColdFusion RCE Exploited in the Wild Within Two Hours of Disclosure
Sami Malik
Copywriter
News
BeyondTrust Patches Four Vulnerabilities Including Two CVSS 9.2 Pre-Auth Bypasses Found With AI Assistance
Sami Malik
Copywriter
News
CVE-2026-11405: The Hidden Admin Backdoor in Tenda Router Firmware That Nobody Patched
Sami Malik
Copywriter
News
ARToken PhaaS : quand un kit de phishing Microsoft 365 expose toute l'architecture d'EvilTokens
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Armored Likho : l'acteur malveillant qui cible gouvernements et secteur électrique avec le stealer BusySnake
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Avalon : le framework malveillant modulaire qui combine vol de données, mouvement latéral et ransomware CrownX
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
PolinRider : la campagne nord-coréenne qui a compromis 1 951 dépôts GitHub pour infecter développeurs et projets crypto
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Bad Epoll (CVE-2026-46242): The Linux Kernel Race Condition That Hands Any User Root and Escapes Chrome's Sandbox
Sami Malik
Copywriter
News
No Encryption Required: How Kairos Extorted $1 Million From a US County Using Only Stolen Data
Sami Malik
Copywriter
News
SkillCloak: The AI Agent Skill Packer That Passes Every Scanner and What Security Teams Can Do About It
Sami Malik
Copywriter
News
Opera GX's Silent Mod Attack: How a Gaming Browser Flaw Let Any Website Extract Your Gmail Address Without a Click
Sami Malik
Copywriter
News
Umbrij : le malware de ToddyCat qui détourne OAuth pour espionner les emails Gmail d'entreprises
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
NetNut : Google et le FBI dégradent un réseau de 2 millions d'appareils domestiques transformés en proxies pour cybercriminels
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
JADEPUFFER: The AI Agent That Ran a Complete Ransomware Attack Without Human Operators
Sami Malik
Copywriter
News
PamStealer: The macOS Infostealer That Hid Inside a Fake Clipboard Manager
Sami Malik
Copywriter
News
81 Million Login Attempts: The Microsoft 365 Credential Attack Organisations Need to Understand
Sami Malik
Copywriter
News
ChocoPoC : quand les chercheurs en sécurité deviennent les cibles de faux exploits piégés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Scattered Spider : un suspect de 19 ans extradé aux États-Unis pour piratage d'entreprises mondiales
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
CVE-2026-45659: SharePoint Deserialization Flaw Added to CISA KEV as Active Exploitation Confirmed
Sami Malik
Copywriter
News
INC Ransomware : 830 victimes en trois ans, des hôpitaux aux cabinets d'avocats
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Tata Electronics : une cyberattaque expose les secrets industriels d'Apple et Tesla
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
The Klue Supply Chain Attack: How Icarus Used a 2022 Credential to Breach LastPass, Recorded Future, Jamf and Nine Others via Stolen Salesforce OAuth Tokens
Sami Malik
Copywriter
News
DragonForce Ransomware Hid Inside Microsoft Teams for Two Months: How Backdoor.Turn Tunnelled C2 Through TURN Relays
Sami Malik
Copywriter
News
INSEE : l'annuaire interne trombi.insee.fr compromis, 12 800 agents exposés par Saturne
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
RATP : les données professionnelles de 62 208 agents diffusées sur le dark web par le pirate Misere
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
CVE-2026-47291: The HTTP.sys Kernel RCE That Gives Unauthenticated Attackers SYSTEM on Every Windows Version
Sami Malik
Copywriter
News
CVE-2026-42271: How a LiteLLM MCP Endpoint Chained with a Starlette Bug Became a CVSS 10.0 AI Gateway Takeover
Sami Malik
Copywriter
News
Cegedim Santé : les données administratives de 15 millions de patients français ont fuité
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Tchap : 643 000 messages de la messagerie d'État exfiltrés, 90 documents Diffusion Restreinte exposés
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Cisco SD-WAN CVE-2026-20245: Nation-State Actor Gained Root via CSV Upload Two Months Before Patch
Sami Malik
Copywriter
News
Cordyceps: The CI/CD Flaw That Let Any GitHub User Compromise Microsoft, Google and Apache
Sami Malik
Copywriter
News
Squidbleed CVE-2026-47729 : un bug de 1997 dans Squid expose les requêtes HTTP des autres utilisateurs
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Campagne WhatsApp : des VBScript installent ManageEngine RMM Central sur les machines des victimes
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Fake AI Agent Skill Bypassed Every Security Scanner and Reportedly Reached 26,000 Agents
Sami Malik
Copywriter
News
DoJ Seizes HuiOne Group Cloud Infrastructure Behind $31 Billion Fraud Marketplace
Sami Malik
Copywriter
News
ShapedPlugin : trois plugins WordPress Pro compromis dans une attaque de supply chain
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Cisco Unified CM CVE-2026-20230 : faille SSRF exploitée pour élever les privilèges en root
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Langflow CVE-2026-5027: Path Traversal Flaw Exploited for RCE
Sami Malik
Copywriter
News
Adobe corrige 123 vulnérabilités en juin 2026 dont plusieurs critiques
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
Un ver informatique autonome propulsé par IA compromet 75 % d'un réseau en sept jours
Sami Malik
Copywriter
News
Check Point VPN CVE-2026-50751: IKEv1 Flaw Exploited by Qilin Ransomware
Sami Malik
Copywriter
News
Le ver Miasma force GitHub à désactiver 73 dépôts Microsoft en 105 secondes
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
WinRAR Flaw CVE-2025-8088 Fuels GiftedCrook Stealer Attacks on Ukraine
Sami Malik
Copywriter
News
Cisco SD-WAN CVE-2026-20245 : un septième zero-day exploité, toujours sans correctif
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
justsstop.ru: Inside the Infrastructure Flagged as an Active Threat Campaign
Sami Malik
Copywriter
News
CVE-2025-34054 and Multi-CVE Campaign Targeting Edge Devices
Sami Malik
Copywriter
News
RAlord bannit un affilié pour avoir ciblé la zone CEI
Sami Malik
Copywriter
News
Unpatched Gogs Zero-Day Allows RCE on 2,400+ Exposed Servers
Sami Malik
Copywriter
News
Kali365 : le kit de phishing qui vole vos tokens OAuth M365
Sami Malik
Copywriter
News
CVE-2025-11953: Active Exploitation Tracked Across Five IPs
Sami Malik
Copywriter
News
Firefox 151 : 27 CVE corrigées, dont 5 de sévérité haute
Sami Malik
Copywriter
News
CVE-2026-9082: Drupal SQL Injection Hits PostgreSQL Sites
Sami Malik
Copywriter
News
Pizza Hut : un franchisé réclame 100 M$ pour un outil IA imposé
Sami Malik
Copywriter
News
Active Threat: IOCs Linked to Suspicious Hosts and IP Activity
Sami Malik
Copywriter
News
CVE-2026-46640 : exécution de code PHP arbitraire dans Twig contourne le sandbox Symfony
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
GLPI : sept vulnérabilités corrigées dont SSRF et XSS
Sara Amin
Marketing Student • Content & Writing Enthusiast
News
CVE-2026-39987: Marimo Python Notebook Pre-Auth RCE Exploited in Under 10 Hours
Sami Malik
Copywriter
News
CVE-2026-31431: Linux Kernel LPE Lets Unprivileged Users Gain Root via Page Cache Corruption
Sara Amin
Marketing Student • Content & Writing Enthusiast
Discover simplified
Cyber Risk Management
Learn how to prevent cyberattacks proactively with a free trial of Defendis.
Sign up
©
2026
. Defendis
Service Status
No items found.