Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

A Powerful AI Model Just Cracked a Post-Quantum Test Scheme, Exposing a Major Security Vulnerability A recent breakthrough by researchers at Claude AI has left the cybersecurity community reeling after they successfully cracked a post-quantum test scheme. The achievement is significant not only because it demonstrates the capabilities of AI in breaching complex security systems … Read more

Agentic Browsers Rewind Web Security by 20 years

**Agentic Browsers Exposed: New Class of Vulnerabilities Threatens Web Security** In a shocking revelation, security researchers have discovered a new class of vulnerabilities in agentic browsers that has left experts warning of a significant regression in web security. Agentic browsers, touted as a revolutionary way to streamline work and automate tasks, have been found to … Read more

‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates

Microsoft’s Active Directory Certificate Services have been left vulnerable to a high-severity flaw that could allow attackers to compromise entire AD environments. Dubbed “Certighost,” this vulnerability was recently patched by Microsoft as part of its record-breaking 622 Patch Tuesday updates. Researchers Aniq Fakhrul and Muhammad Ali, who discovered the flaw, described how it works: an … Read more

Is Your SSO Protected Against Modern Credential Attacks?

**Single Sign-On Security: Are You Leaving a Backdoor to Your Network?** A recent breach at the University of Pennsylvania highlights a critical security risk that many organizations may be overlooking: the protection of their single sign-on (SSO) credentials. In this attack, hackers compromised a PennKey SSO account and used it to access internal systems, including … Read more

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

A staggering 24,650 internet-exposed BMCs have been found to disclose IPMI password hashes before login, leaving their owners and users vulnerable to potential breaches. This alarming discovery highlights the growing importance of securing Baseboard Management Controllers (BMCs), a crucial component in modern data centers. BMCs are essentially small computers embedded within servers, managing power supply, … Read more

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new and highly resilient botnet, dubbed Tengu, has been discovered targeting Linux devices with a unique approach that allows it to reboot compromised systems when defenders attempt to kill its process. This sophisticated tactic has significant implications for organizations reliant on Linux servers, making it essential to understand what’s happening and why. Tengu is … Read more

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

**Nimbus Manticore Deploys NightLedger, Hijacking Millions of Devices Worldwide** A devastating cyberattack has been unleashed on an unprecedented scale, with millions of devices worldwide compromised and turned into unwitting accomplices for malicious activities. The attack, attributed to a group known as Nimbus Manticore, leverages a sophisticated technique called “NightLedger” – a cunning method that hijacks … Read more

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

A Critical OpenWrt DHCPv6 Flaw Exposes Millions of Devices to Root Access Attacks Millions of internet-connected devices are vulnerable to a critical security flaw that could allow unauthenticated attackers to run code as root, thanks to an OpenWrt DHCPv6 vulnerability. The issue was discovered by a researcher and has already been patched by the OpenWrt … Read more

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

A Zero-Day Exploit, Hitting Multiple Targets: How JFrog and OpenAI’s AI Models Unleashed Chaos A shocking revelation has surfaced involving OpenAI’s models, which appear to have been used to exploit a zero-day vulnerability in Artifactory, a popular software repository management tool. JFrog, the company behind Artifactory, confirmed that its system was compromised before Hugging Face, … Read more

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

A staggering number of nearly 25,000 Internet-facing Blade Management Controllers (BMCs) have been found to be disclosing IPMI password hashes before login, leaving their sensitive data vulnerable to unauthorized access. This significant security lapse affects various organizations worldwide, including government agencies, educational institutions, and private companies. The BMC is a crucial component in data centers, … Read more