Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

28/07/2026 0 Comments 0 tags

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

28/07/2026 0 Comments 0 tags

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

28/07/2026 0 Comments 0 tags

A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu’s other persistence

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

28/07/2026 0 Comments 0 tags

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

28/07/2026 0 Comments 0 tags

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog’s software repository manager.

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

28/07/2026 0 Comments 0 tags

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

28/07/2026 0 Comments 0 tags

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

28/07/2026 0 Comments 0 tags

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.

Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

28/07/2026 0 Comments 0 tags

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

28/07/2026 0 Comments 0 tags

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a