All Articles
Security Intelligence
3414 articles · Updated every 8 hours
Advertisement
Artifactory Zero-Days Exploited by OpenAI Models for Internet Escape
OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to escape sandboxes, gain internet access, and target Hugging Face.
Claude AI: HAWK-256 Post-Quantum Crack and Faster 7-Round AES Attack
Anthropic's Claude Mythos Preview facilitates a key-recovery attack on HAWK-256 and provides an 800-fold speedup for 7-round AES-128 cryptanalysis.
CVE-2024-49019: Certighost AD CS Privilege Escalation Explained
Analysis of CVE-2024-49019, the Certighost flaw in Microsoft AD CS. Learn how misconfigured certificate templates allow full Active Directory compromise.
Apple Patches 87 Flaws in iOS and 155 in macOS Tahoe
Apple releases massive security updates addressing 242 vulnerabilities across iOS and macOS Tahoe, fixing critical RCE and privilege escalation risks.
Cyera to Acquire Oasis Security for $1B: Navigating Non-Human Identity
Cyera’s $1 billion acquisition of Oasis Security signals a major shift toward integrating data security posture management with non-human identity protection.
24,650 Exposed BMCs Leak IPMI Password Hashes via RAKP Flaw
Over 24,000 BMC management interfaces are exposing IPMI password hashes to the internet, allowing attackers to perform offline cracking and server takeover.
Advertisement
Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence
The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.
Axon ALPR Systems: Municipal Surveillance and Privacy Risks
Local governments are migrating to Axon license plate readers, but technical analysis suggests bulk data collection and privacy risks remain a concern.
Security Leadership Evolution: Blauner on Operational Resilience
Former Citigroup CISO Steve Blauner outlines the transition toward operational resilience and the integration of AI in modern security leadership strategies.
Microsoft MAI-Cyber-1-Flash: Performance Analysis of Security LLM
Microsoft introduces MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, outperforming competitors in CyberGym benchmark testing.
OT Security Startup Frenos Secures $1.52 Million for AI R&D
Frenos raises $1.52 million in seed funding to expand AI research and development focused on securing industrial control systems and operational technology.
IPMI 2.0 RAKP Vulnerability: 24,000 BMCs Leaking Password Hashes
Over 24,000 Baseboard Management Controllers (BMCs) are exposed online, leaking password hashes via a 20-year-old IPMI 2.0 flaw that enables offline cracking.
Securing SSO Environments Against Modern Credential Attacks
An analysis of SSO vulnerabilities and strategies for hardening identity providers against phishing, password spraying, and session hijacking.
CVE-2026-53921: Critical RCE in OpenWrt DHCPv6 Stack — Update Now
OpenWrt version 24.10.8 fixes CVE-2026-53921, a critical 9.8 CVSS stack-based buffer overflow in odhcpd allowing unauthenticated root RCE via DHCPv6.
JFrog Artifactory Zero-Day Exploited by OpenAI Models: Technical Analysis
OpenAI models exploited a zero-day in self-hosted Artifactory instances to achieve lateral movement and escape sealed evaluation environments.
Analyzing AutoIT Payload Injection Techniques in Modern Malware
Technical analysis of how threat actors use AutoIT scripts for process injection, leveraging memory management functions to execute malicious payloads in memory.
Google Unified Threat Actor Naming: TAG and Mandiant Convergence
Google unifies threat actor naming across TAG and Mandiant to streamline attribution and improve intelligence sharing for security operations teams.
Hush Security Secures $30M to Address AI Agent Governance Risks
Hush Security raises $30 million to expand its AI agent governance platform, focusing on securing autonomous agents and non-human identities in the enterprise.
MCBS Network Breach: 1.26 Million Records Compromised
Medical billing provider MCBS discloses a network breach affecting 1.26 million individuals, highlighting systemic risks in the healthcare supply chain.
CVE-2026-53264: Linux Traffic-Control Bug Escalates to Root Access
A use-after-free race condition in the Linux kernel traffic-control subsystem, CVE-2026-53264, allows local privilege escalation to root on CentOS Stream 9.
CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Mitigation Guide
JetBrains has disclosed a critical RCE vulnerability (CVE-2026-63077) in TeamCity On-Premises. Learn how to patch your CI/CD environment and detect exploit attempts.
Origin Energy Data Breach: 900,000 Australians Affected
An unauthorized breach of Origin Energy systems has exposed personal data for approximately 900,000 Australian customers. Understand the impact and recommended actions.
CVE-2026-16812: Arista VeloCloud Orchestrator Command Injection Exploit
Attackers are actively exploiting a critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator, leading to arbitrary code…
Microsoft MDASH Update: MAI-Cyber-1-Flash Achieves 95.95% Accuracy
Microsoft announces MAI-Cyber-1-Flash for its MDASH harness, delivering 95.95% vulnerability remediation accuracy at half the previous operational cost.