Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
Aggregated from vendor advisories, security research, and industry publications.
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the i…
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
Tour of the AI kill chain maps the risks of ubiquitous surveillance and flawed algorithms
Secret to their success: Using the right model for the right security job
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK…
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event …
There’s always been a gap between the discovery of a security issue and the time it takes to remediate. Now AI models can autonomously find weak points and chain together actions t…
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
Jake Snyder joins Keith Parsons to explain the mechanics of spatial reuse in Wi-Fi. They discuss practical implementation, the trade-offs involved in increasing signal detection th…
Faster access and more secure recoveries are driving business, but mishaps and attacks can endanger data
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
More organizers prohibit camera-equipped specs, even with prescription lenses
Government finds some loose change down to chuck at emission-free flight research
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's o…
Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared firs…
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management …
Distributed denial of service (DDoS) attacks are changing shape. Attackers now use AI throughout the attack lifecycle, from reconnaissance to exploitation to hardening compromised …
Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared fir…
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA…
Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
NASA reports some cable damage near Madrid as its antennas and ESA's Cebreros station emerge largely intact
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is…
Postmortem offers finer details on the 'unprecedented' attack that's reshaping approaches to security
The company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek.
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical is…
Washington rallies allies to shape next-generation networks after spending 18 months rattling them