SecurityTicks

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login 2026-07-28 at 18:41 By Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose […]

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login Read More »

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process 2026-07-28 at 18:01 By A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process Read More »

Cyera Acquiring Oasis Security in $1 Billion Deal

Cyera Acquiring Oasis Security in $1 Billion Deal 2026-07-28 at 17:55 By Eduard Kovacs Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cyera Acquiring Oasis Security in $1 Billion Deal Read More »

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root 2026-07-28 at 17:29 By OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root Read More »

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe 2026-07-28 at 17:19 By Eduard Kovacs Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Read More »

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach 2026-07-28 at 16:33 By JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach Read More »

BlackCloak extends deepfake protection to the executive’s trusted circle

BlackCloak extends deepfake protection to the executive’s trusted circle 2026-07-28 at 16:15 By Industry News Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive

BlackCloak extends deepfake protection to the executive’s trusted circle Read More »

Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation

Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation 2026-07-28 at 16:14 By Industry News Bugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it

Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation Read More »

PayPal expands stablecoin push as crypto assets factor into Q2 results

PayPal expands stablecoin push as crypto assets factor into Q2 results 2026-07-28 at 16:11 By Cointelegraph by Helen Partz PayPal highlighted growth of stablecoins and AI-driven payment tools in Q2 while reporting $8.68 billion in revenue and an $81 million crypto-related earnings adjustment. This article is an excerpt from Cointelegraph.com News View Original Source

PayPal expands stablecoin push as crypto assets factor into Q2 results Read More »

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays 2026-07-28 at 16:10 By The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays Read More »

Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting

Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting 2026-07-28 at 16:10 By Industry News Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll out through summer 2026 add attack surface management (ASM), new asset testing types and

Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting Read More »

OT Security Startup Frenos Raises $1.52 Million

OT Security Startup Frenos Raises $1.52 Million 2026-07-28 at 16:05 By Ionut Arghire The company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

OT Security Startup Frenos Raises $1.52 Million Read More »

Cyberhaven launches Flow to secure data across human and AI workflows

Cyberhaven launches Flow to secure data across human and AI workflows 2026-07-28 at 16:03 By Industry News Cyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage, identity, and behavior to protect data as it is created, copied, fragmented, and shared, marking a

Cyberhaven launches Flow to secure data across human and AI workflows Read More »

Ethereum, Solana led crypto hack losses in H1 2026: Blockaid

Ethereum, Solana led crypto hack losses in H1 2026: Blockaid 2026-07-28 at 16:00 By Cointelegraph by Helen Partz Blockaid found Ethereum remained the hardest-hit blockchain in H1 2026, while Solana replaced Arbitrum as the network with the second-highest losses, driven largely by key compromises. This article is an excerpt from Cointelegraph.com News View Original Source

Ethereum, Solana led crypto hack losses in H1 2026: Blockaid Read More »

Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence

Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence 2026-07-28 at 15:55 By Industry News Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale, security teams must use their own AI capabilities to make intelligence

Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence Read More »

SpecterOps brings AWS attack path management and AI to hybrid identity security

SpecterOps brings AWS attack path management and AI to hybrid identity security 2026-07-28 at 15:48 By Industry News SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the ability to proactively eliminate pathways before they can be abused. BloodHound Enterprise adds support for Amazon

SpecterOps brings AWS attack path management and AI to hybrid identity security Read More »

Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response

Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response 2026-07-28 at 15:36 By Industry News Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence. Command unlocks Team Cymru’s globally observed threat

Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response Read More »

Exposed BMCs hand out password hashes before login

Exposed BMCs hand out password hashes before login 2026-07-28 at 15:00 By Sinisa Markovic An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced

Exposed BMCs hand out password hashes before login Read More »

Scroll to Top