Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

A Potent Threat Unfolds: Claude AI Cracks Post-Quantum Test Scheme, Exposes Faster AES Attack In a stunning revelation that’s left the cybersecurity community reeling, Claude AI has successfully cracked a post-quantum test scheme and identified a faster 7-round attack on the widely used Advanced Encryption Standard (AES) encryption algorithm. The breakthrough raises serious concerns about … Read more

‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates

Microsoft’s Active Directory Certificate Services (AD CS) have been left vulnerable to exploitation after researchers uncovered a flaw that allows attackers to impersonate domain controllers and compromise AD environments. The issue, dubbed “Certighost,” was patched in Microsoft’s recent Patch Tuesday update but not before proof-of-concept exploit code was released. The vulnerability affects the enterprise certificate … Read more

Is Your SSO Protected Against Modern Credential Attacks?

A Single Sign-On (SSO) Breach Awaits: Are Your Credentials Protected Against Modern Attacks? The convenience of single sign-on (SSO) comes at a cost. While it simplifies access to multiple systems with one set of credentials, this very convenience can concentrate risk. The 2025 University of Pennsylvania breach serves as a stark reminder that when SSO … Read more

vBulletin fixes critical pre-auth RCE flaw with public exploit

Vulnerable vBulletin Forums Exposed to Critical Remote Code Execution Flaw A critical security vulnerability has been discovered in the popular vBulletin forum software, allowing unauthenticated attackers to execute arbitrary PHP code. The issue, tracked as CVE-2026-61511, affects vBulletin versions 5.x and 6.x up to 5.7.5 and 6.2.1 respectively, leaving thousands of online communities vulnerable to … Read more

CISA shares advice on isolating vital systems during cyberattacks

The US and Australian governments have issued new guidance for critical infrastructure organizations to prepare for isolating vital operational technology (OT) systems in the event of a cyberattack. The advice, developed by the US Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and international partners, aims … Read more

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

A Powerful AI Model Just Cracked a Post-Quantum Test Scheme, Exposing a Major Security Vulnerability A recent breakthrough by researchers at Claude AI has left the cybersecurity community reeling after they successfully cracked a post-quantum test scheme. The achievement is significant not only because it demonstrates the capabilities of AI in breaching complex security systems … Read more

Agentic Browsers Rewind Web Security by 20 years

**Agentic Browsers Exposed: New Class of Vulnerabilities Threatens Web Security** In a shocking revelation, security researchers have discovered a new class of vulnerabilities in agentic browsers that has left experts warning of a significant regression in web security. Agentic browsers, touted as a revolutionary way to streamline work and automate tasks, have been found to … Read more

‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates

Microsoft’s Active Directory Certificate Services have been left vulnerable to a high-severity flaw that could allow attackers to compromise entire AD environments. Dubbed “Certighost,” this vulnerability was recently patched by Microsoft as part of its record-breaking 622 Patch Tuesday updates. Researchers Aniq Fakhrul and Muhammad Ali, who discovered the flaw, described how it works: an … Read more

Is Your SSO Protected Against Modern Credential Attacks?

**Single Sign-On Security: Are You Leaving a Backdoor to Your Network?** A recent breach at the University of Pennsylvania highlights a critical security risk that many organizations may be overlooking: the protection of their single sign-on (SSO) credentials. In this attack, hackers compromised a PennKey SSO account and used it to access internal systems, including … Read more

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

A staggering 24,650 internet-exposed BMCs have been found to disclose IPMI password hashes before login, leaving their owners and users vulnerable to potential breaches. This alarming discovery highlights the growing importance of securing Baseboard Management Controllers (BMCs), a crucial component in modern data centers. BMCs are essentially small computers embedded within servers, managing power supply, … Read more