Aggregator
Code at AI Speed, Risk at AI Scale
AI-generated code is transforming software development, but it is also introducing new security risks. Learn how a real-world penetration test uncovered a critical authentication flaw that exposed sensitive customer data and what security teams can do to prevent similar issues.
The post Code at AI Speed, Risk at AI Scale appeared first on Sygnia.
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence
Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale, security teams must use their own AI capabilities to make intelligence more accessible, allowing them to pinpoint what is relevant to their organization and pair it with internal telemetry. The Verity471 platform turns adversary tradecraft into pre-attack intelligence and proactive threat hunting, helping security teams act on any threat before … More →
The post Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence appeared first on Help Net Security.
SpecterOps brings AWS attack path management and AI to hybrid identity security
SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the ability to proactively eliminate pathways before they can be abused. BloodHound Enterprise adds support for Amazon Web Services and Microsoft Entra Agent ID, expanding the reach of attack path management. A new purpose-built AI agent interface, BloodHound Hunter, brings that same adversary intelligence into AI-assisted security workflows, letting teams incorporate the power of the … More →
The post SpecterOps brings AWS attack path management and AI to hybrid identity security appeared first on Help Net Security.
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response
Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence. Command unlocks Team Cymru’s globally observed threat intelligence data by connecting telemetry, investigative and attack surface management capabilities, expert analysis, and machine-native access within a common architecture. The result is a continuous path from discovery to action, eliminating fragmented workflows, preserving investigative context, and accelerating active … More →
The post Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response appeared first on Help Net Security.
Как внутренний мир коровы меняет атмосферу всей Земли
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of […]
The post Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Former Citigroup CISO Blauner on What Makes A Great Security Leader
当安全研究进入 AI 时代
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Дженсен Хуанг начал войну за открытые нейросети ради спасения империи Nvidia
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. That controller runs underneath the operating system. It power-cycles the host, mounts virtual media, opens a remote console, and flashes firmware. Host security tools watch the layer above it. Example BMC web … More →
The post Exposed BMCs hand out password hashes before login appeared first on Help Net Security.
When cyber attacks happen: helping organisations recover
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang. […]
The post CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.