Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitatio… Continue reading Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Posted in Uncategorized

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers.

They… Continue reading Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Posted in Uncategorized

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment also hacked multiple third-party accounts and services as part of the attack.

T… Continue reading OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

Posted in Uncategorized

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128.

The HAWK attack exploits a previously unused symmetry in the lattice behind the … Continue reading Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Posted in Uncategorized

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.

If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Ne… Continue reading Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Posted in Uncategorized

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.

Artifactory is JFrog’s software repository manager. OpenAI says the models then escala… Continue reading JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

Posted in Uncategorized

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.

The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt’s Gi… Continue reading Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Posted in Uncategorized