Aggregator
Code at AI Speed, Risk at AI Scale
AI-generated code is transforming software development, but it is also introducing new security risks. Learn how a real-world penetration test uncovered a critical authentication flaw that exposed sensitive customer data and what security teams can do to prevent similar issues.
The post Code at AI Speed, Risk at AI Scale appeared first on Sygnia.
当安全研究进入 AI 时代
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Дженсен Хуанг начал войну за открытые нейросети ради спасения империи Nvidia
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. That controller runs underneath the operating system. It power-cycles the host, mounts virtual media, opens a remote console, and flashes firmware. Host security tools watch the layer above it. Example BMC web … More →
The post Exposed BMCs hand out password hashes before login appeared first on Help Net Security.
When cyber attacks happen: helping organisations recover
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang. […]
The post CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Левые, либертарианцы, противники евгеники: политический портрет 16 ведущих нейросетей
Confidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in Use
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
Список чертежей в простом .txt. Хакеры Cl0p теперь сортируют украденное прямо на взломанном сервере
Introducing the abuse.ch Community Hub: recognition matters
DSRC | 平台维护通知
【安全圈】Fastjson2紧急修复远程代码执行漏洞
【安全圈】AI智能体攻陷泰国财政部
【安全圈】俄罗斯黑客Turla:欧洲20年潜伏帝国
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers. The issue impacts every version of the self-hosted continuous integration and continuous delivery platform, making it urgent for organizations that expose TeamCity instances over HTTP or HTTPS to […]
The post Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.