Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to

BY The Hacker News
MIN READ 1 MIN READ
EXPLORE north_east
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Is Your SSO Protected Against Modern Credential Attacks?
CYBERSECURITY

Is Your SSO Protected Against Modern Credential Attacks?

A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect.

1 MIN READ arrow_forward
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
CYBERSECURITY

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

1 MIN READ arrow_forward
BlackCloak extends deepfake protection to the executive’s trusted circle
CYBERSECURITY

BlackCloak extends deepfake protection to the executive’s trusted circle

Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive Protection (DEP), built Impersonation Protection to focus on validating the authenticity of communications. Circle of trust functionality is the most significant expansion of that capability to date — giving executives and high-profile individuals a new … More → The post BlackCloak extends deepfake protection to the executive’s trusted circle appeared first on Help Net Security.

1 MIN READ arrow_forward
Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation
CYBERSECURITY

Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation

Bugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it onto the pentest schedule, while providing the evidence to prove that the findings are genuinely exploitable. Security teams are attempting both deep and broad coverage, and getting the worst of each. Crown-jewel assets sit exposed for months … More → The post Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation appeared first on Help Net Security.

1 MIN READ arrow_forward
Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting
CYBERSECURITY

Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting

Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll out through summer 2026 add attack surface management (ASM), new asset testing types and expanded environment support, extending Cait’s reach well beyond its initial web application focus. The announcements follow Cait’s general availability launch earlier this year, which introduced an autonomous, context-aware pentester that explores applications before attacking them and delivers … More → The post Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting appeared first on Help Net Security.

1 MIN READ arrow_forward
Cyberhaven launches Flow to secure data across human and AI workflows
CYBERSECURITY

Cyberhaven launches Flow to secure data across human and AI workflows

Cyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage, identity, and behavior to protect data as it is created, copied, fragmented, and shared, marking a shift in how protection adapts to the changing context of work in the AI era. Flow secures data across every human and agentic workflow, wherever people and AI agents work: on endpoints, in browsers, and in the … More → The post Cyberhaven launches Flow to secure data across human and AI workflows appeared first on Help Net Security.

1 MIN READ arrow_forward
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
CYBERSECURITY

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt’s GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6

1 MIN READ arrow_forward
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence
CYBERSECURITY

Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence

Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale, security teams must use their own AI capabilities to make intelligence more accessible, allowing them to pinpoint what is relevant to their organization and pair it with internal telemetry. The Verity471 platform turns adversary tradecraft into pre-attack intelligence and proactive threat hunting, helping security teams act on any threat before … More → The post Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence appeared first on Help Net Security.

1 MIN READ arrow_forward