Canadian Tire – 38,306,562 breached accounts

In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email...

Abusing Windows File Explorer and WebDAV for Malware Delivery

By: Kahng An, Intelligence TeamCofense Intelligence has been tracking how threat actors are abusing Windows File Explorer’s ability to retrieve remote files over Web-based...

Elastic AutoOps is now free: Investing in our community

We're making AutoOps free for every self-managed Elasticsearch user. It analyzes your clusters, identifies what's wrong, and tells you how to fix it. It’s...

The Ghost in the Shell: Why Agentic AI is a Corporate Security Nightmare

Autonomous AI agents blur security boundaries, enabling data exfiltration, privilege abuse, and insider‑level risk in enterprises. - Read more

Google Alerts Users to Serious Chrome Bugs With Takeover Risk

Google released a Chrome security update patching three high-severity vulnerabilities, including memory flaws that could enable remote attacks. The post Google Alerts Users to Serious...

Cost of Insider Incidents Surges 20% to Nearly $20m

DTEX claims insider incidents cost $19.5m in 2025, with employee negligence most expensive - Read more

InSAT MasterSCADA BUK-TS

View CSAF Summary Successful exploitation of these vulnerabilities may allow remote code execution. The following versions of InSAT MasterSCADA BUK-TS are affected: MasterSCADA BUK-TS vers:all/* (CVE-2026-21410, CVE-2026-22553) CVSS Vendor Equipment Vulnerabilities v3 9.8 InSAT InSAT...

Punchbowl Phishing Attack Explained: How Digital Invites Are Used to Steal Credentials

By: Adriane Andaya, Cofense Phishing Defense CenterIn today's digital age, receiving online invitations to events has become commonplace. Sending and receiving invites has never...

Shorter Certificate Lifetimes and Rate Limits

As previously announced, over the next two years we will be switching the default certificate lifetime from 90 days to 64 days, and then...

Latest article

Looking at the SmarterMail API Vulnerability CVE-2026-24423

Sensor Intel Series: February 2026 CVE Trends - Read more

Security Flaw in WordPress Plugin Puts 400,000 Websites at Risk

A security flaw in the Ally WordPress plugin used on more than 400,000 sites could allow attackers to extract sensitive data without logging in. The...

Medical giant Stryker crippled after Iranian hackers remotely wipe computers

A major cyberattack on US medical supplies giant Stryker has resulted in thousands of devices being remotely wiped, after a...

This one’s for you, Mom

Welcome to this week’s edition of the Threat Source newsletter. I am the product of a single parent, my mom, who along with my grandparents...