SECURITY NEWS

Security Feed

118 articles from top security sources· Updated 12:17:57 AM

vulnerabilitiesDark Reading2h ago

Ghost Credentials Expose Cloud Systems to Hidden Identity Risks

Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths.

Read article
vulnerabilitiesBleepingComputer3h ago

CubePilot drone software dev hit by DNS hijacking to intercept traffic

CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]

Read article
investigationsDark Reading3h ago

Thousands of Data Center Controllers Open to Takeover

A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.

Read article
investigationsDark Reading3h ago

Flaw From 2002 Exposes Data Centers to Server Takeover

Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.

Read article
vulnerabilitiesBleepingComputer3h ago

OpenAI models used Artifactory zero-days to escape to the internet

JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]

Read article
threat-intelDark Reading3h ago

When AI Agents Escape Sandboxes, Old Security Rules Apply

OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.

Read article
threat-intelDark Reading4h ago

Stronger AI Safety Requires Peeking Inside the 'Black Box'

Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.

Read article
vulnerabilitiesThe Hacker News5h ago

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server

Read article
vulnerabilitiesBleepingComputer5h ago

CISA shares advice on isolating vital systems during cyberattacks

The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]

Read article
vulnerabilitiesBleepingComputer6h ago

vBulletin fixes critical pre-auth RCE flaw with public exploit

A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]

Read article
Page 1 of 12

118 articles total