Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A Malicious Botnet’s Cunning Defense Mechanism Leaves Linux Defenders Baffled In a concerning trend, researchers have discovered that the Tengu botnet is exploiting a clever tactic to evade detection and maintain its grip on compromised Linux devices. When security teams attempt to terminate the botnet’s process, it rebooted the device instead of shutting down cleanly, … Read more

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Over 24,000 Exposed Servers Leak Passwords via Decades-Old Flaw, Leaving Critical Infrastructure at Risk A staggering 24,650 servers worldwide have been found to be vulnerable to a well-known security flaw that allows attackers to steal authentication passwords. The issue, which has been lingering for two decades, affects the Baseboard Management Controller (BMC) interface, a critical … Read more

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

A new and highly sophisticated attack vector has emerged, dubbed Nimbus Manticore, which exploits vulnerabilities discovered by artificial intelligence models to turn victim systems into covert relays for malicious activities. The attackers behind this operation have been using a tool called NightLedger to compromise networks, leaving organizations vulnerable to further breaches. Nimbus Manticore is a … Read more

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

A Critical Flaw in OpenWrt’s DHCPv6 Service Exposes Devices to Unauthenticated Attacks A severe vulnerability has been discovered in the popular open-source firmware, OpenWrt, which could allow unauthenticated attackers to run code as root on affected devices. The flaw, affecting the DHCPv6 service, was disclosed by security researchers and is already being exploited in the … Read more

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

A zero-day vulnerability in JFrog’s Artifactory software, used by hundreds of thousands of developers worldwide, was exploited by OpenAI’s language models before the recent breach at Hugging Face. The revelation highlights the increasing threat posed by AI-driven attacks on cybersecurity infrastructure. JFrog, a leading provider of universal DevOps and continuous integration/continuous deployment (CI/CD) platforms, confirmed … Read more

Agentic Browsers Rewind Web Security by 20 years

As Agentic Browsers Gain Popularity, Web Security Takes a Step Backward by 20 Years The rise of agentic browsers has brought significant convenience and efficiency to users, but it’s also introduced a new class of risks that threaten to undo two decades of progress in web security. Researchers at Zenity have discovered a series of … Read more

Data breach at medical billing firm MCBS affects 1.26 million people

A massive data breach at a medical billing firm has exposed sensitive information for over 1.26 million people, highlighting the ongoing risks to patient confidentiality in the healthcare sector. Medical Computer Business Services (MCBS), a regional private medical billing and practice-management company based in Augusta, Georgia, disclosed that its network was breached by threat actors … Read more

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

Over 24,000 servers exposed to decades-old password cracking vulnerability A staggering number of internet-exposed servers are vulnerable to a 20-year-old security flaw that allows attackers to crack passwords offline using specialized equipment. Researchers at Lava discovered that more than 24,000 servers are leaking authentication password hashes due to the weakness in their Baseboard Management Controller … Read more

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

A Linux Traffic-Control “Race” Exploit, Born from AI-Powered Research, Raises Red Flags for Security Teams Everywhere Researchers have made a stunning discovery that highlights the double-edged sword of artificial intelligence (AI) in cybersecurity. A team of experts has developed an exploit, dubbed “Traffic Control,” which leverages a previously unknown vulnerability in Linux’s traffic-control module to … Read more