generalnews.media
All World Business Technology Science Health Sports Entertainment Security
311 stories
Exclusive

Claude AI breaks post-quantum test scheme and finds faster AES attack

Claude AI successfully cracked a post-quantum cryptographic test scheme and discovered a more efficient 7-round attack on AES encryption. This achievement highlights AI's growing role in security research and raises concerns about future cryptographic vulnerabilities. The finding could accelerate efforts to develop stronger encryption standards.

Exclusive

Over 24,650 Internet-Exposed BMCs Leak IPMI Password Hashes

Researchers found that 24,650 baseboard management controllers (BMCs) are accessible online and reveal IPMI password hashes before any login is required. Attackers could potentially crack these hashes to gain unauthorized remote control of servers. This widespread exposure poses a serious risk to the security of critical infrastructure and data centers globally.

security

Critical OpenWrt DHCPv6 Flaw Allows Unauthenticated Root Code Execution

A critical security vulnerability has been discovered in OpenWrt's DHCPv6 implementation, allowing unauthenticated attackers to execute arbitrary code as root. The flaw affects many routers and IoT devices running the open-source firmware, potentially giving attackers full device control without any credentials. This is significant because it could lead to widespread exploitation, compromising network security and privacy.

Exclusive

Nimbus Manticore Uses NightLedger to Turn Systems into Covert Relays

The threat actor known as Nimbus Manticore has deployed a new tool called NightLedger that converts compromised systems into covert communication relays. This technique allows attackers to hide command-and-control traffic and expand their network access stealthily. Security teams must monitor for unusual relay behavior to detect this evolving threat.

Exclusive

Critical TeamCity Flaw Lets Attackers Execute OS Commands Without Authentication

A critical security vulnerability in JetBrains TeamCity, a popular CI/CD server, allows unauthenticated attackers to execute arbitrary operating system commands. This flaw could enable full server compromise, putting sensitive data and build pipelines at risk. Immediate patching is advised to prevent exploitation.

Exclusive

Attackers Exploit Command Injection Flaw in Arista VeloCloud Orchestrator

Threat actors are actively exploiting a command injection vulnerability in Arista Networks' VeloCloud Orchestrator, a component of their SD-WAN solution. The flaw could allow remote attackers to execute arbitrary commands on affected systems. This matters because it puts enterprise networks using VeloCloud at risk of compromise, requiring urgent patching.

security technology

Microsoft unveils its first cybersecurity model and new agentic system

Microsoft announced the launch of its first proprietary cybersecurity model, alongside a new agentic cybersecurity system designed to automate threat detection and response. This move aims to strengthen enterprise defenses by leveraging AI to handle complex security operations more efficiently. The release signals Microsoft's deeper push into AI-driven security solutions.

Exclusive

NVIDIA Launches 37-Member Open Secure AI Alliance, Open-Sources NOOA Framework

NVIDIA has formed a 37-member alliance called the Open Secure AI Alliance and open-sourced its NOOA framework. The initiative aims to improve security in AI systems through shared tools and standards. This collaboration could accelerate the adoption of secure AI practices across the industry.

Exclusive

Sandbox Escape in n8n Lets Workflow Editors Execute OS Commands

A security vulnerability in n8n, a workflow automation tool, allows users with editor access to escape the sandbox and run arbitrary operating system commands as the n8n process. This could enable privilege escalation and unauthorized system access. Organizations using n8n should apply patches or restrict editor permissions immediately.