JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

A zero-day vulnerability in JFrog’s Artifactory software, used by hundreds of thousands of developers worldwide, was exploited by OpenAI’s language models before the recent breach at Hugging Face. The revelation highlights the increasing threat posed by AI-driven attacks on cybersecurity infrastructure. JFrog, a leading provider of universal DevOps and continuous integration/continuous deployment (CI/CD) platforms, confirmed … Read more

Agentic Browsers Rewind Web Security by 20 years

As Agentic Browsers Gain Popularity, Web Security Takes a Step Backward by 20 Years The rise of agentic browsers has brought significant convenience and efficiency to users, but it’s also introduced a new class of risks that threaten to undo two decades of progress in web security. Researchers at Zenity have discovered a series of … Read more

Data breach at medical billing firm MCBS affects 1.26 million people

A massive data breach at a medical billing firm has exposed sensitive information for over 1.26 million people, highlighting the ongoing risks to patient confidentiality in the healthcare sector. Medical Computer Business Services (MCBS), a regional private medical billing and practice-management company based in Augusta, Georgia, disclosed that its network was breached by threat actors … Read more

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Over 24,000 servers exposed to decades-old password cracking vulnerability A staggering number of internet-exposed servers are vulnerable to a 20-year-old security flaw that allows attackers to crack passwords offline using specialized equipment. Researchers at Lava discovered that more than 24,000 servers are leaking authentication password hashes due to the weakness in their Baseboard Management Controller … Read more

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

A Linux Traffic-Control “Race” Exploit, Born from AI-Powered Research, Raises Red Flags for Security Teams Everywhere Researchers have made a stunning discovery that highlights the double-edged sword of artificial intelligence (AI) in cybersecurity. A team of experts has developed an exploit, dubbed “Traffic Control,” which leverages a previously unknown vulnerability in Linux’s traffic-control module to … Read more

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

A Critical Flaw in TeamCity Exposes Organizations to Remote Code Execution Attacks Researchers have discovered a severe vulnerability in JetBrains’ popular continuous integration and continuous deployment (CI/CD) tool, TeamCity. The flaw, which affects versions 2020.1 and later, allows attackers to execute arbitrary operating system commands on compromised systems without requiring login credentials. The vulnerability is … Read more

Google Adopts New Threat Actor Naming System

Google has introduced a new system for naming threat actors, moving away from sequential numbers and disparate identifiers in favor of a cryptonym-based convention. This shift aims to simplify tracking and facilitate comparisons across different organizations. The new naming scheme uses two-word combinations, with the first word being a unique term that may have been … Read more

Data breach at medical billing firm MCBS affects 1.26 million people

A massive data breach at a medical billing firm has left over 1.26 million people’s sensitive information exposed, highlighting the continued vulnerability of healthcare organizations to cyber threats. Medical Computer Business Services (MCBS), a regional private medical billing and practice-management company based in Augusta, Georgia, disclosed that a network breach occurred between September 22 and … Read more

Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

Microsoft’s latest announcement reveals that its cutting-edge cybersecurity AI model has achieved an impressive 95.95% detection rate for malicious activity, dubbed MDASH (Malicious Detection and Analysis Security Hybrid). Moreover, this breakthrough innovation promises to slash costs by half compared to traditional methods. The implications are significant: with AI-driven threat detection on the rise, organizations must … Read more

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

A Linux Traffic-Control Race Becomes the Latest Exploit, Thanks to AI-Powered Research A vulnerability in the Linux kernel’s traffic-control system has been found and exploited by hackers, leaving numerous users vulnerable to remote code execution attacks. The exploit was discovered through a combination of machine learning algorithms and human research efforts. The vulnerability, dubbed “TCPdump,” … Read more