Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type cve · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:the_hacker_news, report:trend_micro, report:unit42
tags: report:checkpoint_research, report:securityweek, report:the_hacker_news
tags: report:checkpoint_research, report:securityweek, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news, report:trend_micro
tags: report:checkpoint_research, report:securityweek, report:the_hacker_news
tags: report:the_hacker_news, report:unit42
tags: report:securityweek, report:the_hacker_news
tags: report:checkpoint_research, report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the age
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deployin
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used,
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer We tracked a cryptocurrency-mining campaign exploiting CVE-2026-33017, which revealed how threat actors are now scanning exposed AI application infrastructure for their next foothold. From Langflow to Monero: Inside CVE
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM A pre-authentication remote code execution (RCE) chain in Oracle PeopleSoft PeopleTools abuses the Integration Broker's PSIGW gateway to execute code inside the application server's Ja
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ai's own platfor
From stored enrichment entities only.
Deduped connector weight from graph context.