Swati KhandelwalJul 28, 2026Linux / Endpoint Security A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware […]
Category: Security
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform […]
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Swati KhandelwalJul 28, 2026Vulnerability / Artificial Intelligence JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while […]
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws […]
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Ravie LakshmananJul 28, 2026Malware / Cyber Espionage The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, […]
Microsoft AI Releases MAI-Cyber-1-Flash: A 5B-Active-Parameter Cyber Model That Pushes MDASH to 95.95% on CyberGym
Microsoft AI has released MAI-Cyber-1-Flash, its first model built specifically for cyber defense. The model does not ship as a […]
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Ravie LakshmananJul 28, 2026Vulnerability / Enterprise Security JetBrains is urging customers of on-premise versions of TeamCity to update to the […]
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Swati KhandelwalJul 28, 2026Vulnerability / Linux STAR Labs has published a Linux kernel exploit that turns an ordinary local user […]
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Swati KhandelwalJul 28, 2026AI Security / Vulnerability Management Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability […]
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Ravie LakshmananJul 28, 2026Vulnerability / Threat Intelligence A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has […]
