BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 27m agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 1h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 1h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 1h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 2h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 2h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 2h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 3h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 3h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 3h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 3h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 3h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 3h agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 4h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 27m agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 1h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 1h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 1h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 2h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 2h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 2h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 3h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 3h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 3h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 3h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 3h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 3h agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 4h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

1372 results in Vulnerability

VulnerabilityFortinet PSIRT·14d ago
Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00

VulnerabilityThe Hacker News·14d ago
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In

VulnerabilityThe Hacker News·14d ago
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a single browsing domain. The

VulnerabilityThe Hacker News·15d ago
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. When it works, the person reads an ordinary-looking reply and never learns their assistant was tampered with. The

VulnerabilityThe Hacker News·15d ago
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing

VulnerabilityCISA·15d ago
CISA Adds One Known Exploited Vulnerability to Catalog

p CISA has added one new vulnerability to its a href="https://edit.cisa.gov/known-exploited-vulnerabilities-catalog" Known Exploited Vulnerabilities (KEV) Catalog /a , based on evidence of active exploitation. /p ul type="square" li a href="https://www.cve.org/CVERecord?id=CVE-2008-4128" target="_blank" CVE-2008-4128 /a Cisco IOS Cross-Site Request Forgery Vulnerability /li /ul p This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. /p p a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk /a establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. /p p While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" KEV Catalog vulnerabilities /a . CISA will continue to add vulnerabilities to the catalog that meet the a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities" specified criteria /a . /p p Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s a class="ext" href="https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w" target="_blank" KEV Nomination Form /a . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. nbsp; /p

VulnerabilityCISA·15d ago
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

p Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors /p h2 strong Executive summary /strong /h2 p Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s a href="https://www.ic3.gov/PSA/2025/PSA250820" target="_blank" Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure /a Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. [ a href="#Work1" 1 /a ] nbsp; /p p This CSA is being released by the following authoring and co-sealing agencies: nbsp; /p ul type="square" li United States National Security Agency (NSA) /li li United States Cybersecurity and Infrastructure Security Agency (CISA) /li li United States Federal Bureau of Investigation (FBI) /li li United States Department of Defense Cyber Crime Center (DC3) /li li Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) /li li Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre) /li li New Zealand National Cyber Security Centre (NCSC-NZ) /li li United Kingdom National Cyber Security Centre (NCSC-UK) /li li Czech Republic National Cyber and Information Security Agency (NÚKIB) a href="#Foot1" sup 1 /sup /a nbsp; /li li Danish Defence Intelligence Service (DDIS) a href="#Foot2" sup 2 nbsp; /sup /a /li li Estonian Foreign Intelligence Service (EFIS) a href="#Foot3" sup 3 /sup /a nbsp; /li li Estonian Information System Authority (RIA) a href="#Foot4" sup 4 /sup /a /li li Finnish Defence Intelligence (FDI) a href="#Foot5" sup 5 /sup /a /li li Finnish Security and Intelligence Service (SUPO) a href="#Foot6" sup 6 /sup /a /li li French National Cybersecurity Agency (ANSSI) a href="#Foot7" sup 7 /sup /a /li li Italian External Intelligence and Security Agency (AISE) a href="#Foot8" sup 8 nbsp; /sup /a /li li Italian Internal Intelligence and Security Agency (AISI) a href="#Foot9" sup 9 /sup /a /li li The Military Counterintelligence Service of Poland (SKW) a href="#Foot10" sup 10 nbsp; /sup /a /li li Sweden National Cyber Security Centre (NCSC-SE) a href="#Foot11" sup 11 nbsp; /sup /a /li /ul p The authoring and co-sealing agencies strongly urge device owners and network defenders to take mitigation and remediation actions against Russian government-sponsored exploitation of vulnerable routers. /p figure class="c-figure c-figure--image" role="group" div class="c-figure__media" img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%201%20FSB%20Center%2016%20activity%20and%20recommended%20mitigation%20actions.png?itok

VulnerabilityThe Hacker News·15d ago
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling

Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day; others would

VulnerabilityThe Hacker News·15d ago
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they were building

VulnerabilityThe Hacker News·15d ago
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the

VulnerabilityThe Hacker News·15d ago
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse, French security firm Lexfo lifted the operator's entire toolkit and pivoted through it to two more

VulnerabilitySANS ISC·15d ago
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)

The setup I pulled 14 days of Apache and ModSecurity logs from a single small web host. Nothing special about it. A handful of low-traffic virtual hosts. A WordPress site, a couple of custom application backends, a static devotional site. The kind of server that exists by the millions and that nobody would call a high-value target. Server IP and hostnames are anonymized throughout this diary. The point of looking was not to find a breach. It was to see what the background radiation of internet scanning looks like in 2026. Most of it is exactly what you would expect. WordPress xmlrpc floods. Endless .env probing. Git config fishing. But mixed into the noise was a category of scanning I had not seen documented before. Someone is systematically looking for Model Context Protocol servers, AI assistant configuration files, and locally exposed LLM endpoints. On a server that runs none of those things. The overall picture Figure 1 breaks down the reconnaissance categories that ModSecurity flagged over the two-week window. I split them into two groups. The classic cloud and application recon that every server sees, and the newer AI-agent recon that is the subject of this diary. ??????? Spring Boot Actuator scanning dominates by request volume. That is not new. The full set of actuator endpoints including /actuator/heapdump and /actuator/env gets hit hundreds of times from dozens of sources. The interesting part is the group below it. MCP handshakes, LLM API probes, AI assistant secret fishing, and MCP config files together account for roughly 200 requests. And the MCP protocol handshake category came from 49 distinct source IPs, more spread than any other category in the dataset. This is not one researcher. It is a broad, distributed scan. The Part That Stood Out: A Real MCP Handshake Most scanning is dumb. A bot requests a path, checks the status code, moves on. The POST /mcp probes were different. Every one of them carried a valid JSON-RPC 2.0 body performing a Model Context Protocol initialize call. POST /mcp HTTP/1.1 Content-Type: application/json { id :1, jsonrpc : 2.0 , method : initialize , params :{ capabilities :{}, clientInfo :{ name : client , version : 0 }, protocolVersion : 2025-03-26 }} This matters. The scanner is not blindly requesting a URL. It is speaking the protocol. It sends a correctly formed handshake with a real MCP protocol version and waits to see if something on the other end answers like an MCP server. If your server responds to that initialize call then the next steps are to enumerate the tools the server exposes, the data sources it connects to, and whatever it can be convinced to do. Figure 2 shows the flow. For readers who have not deployed one yet: an MCP server is the bridge that lets an AI agent call tools and read data sources. It is the thing that gives a model access to your database, your file system, your ticketing system, your internal APIs. An exposed and unauthenticated MCP server is close to the worst case. It