BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Rapid7 · 49m agovBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 1h agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 1h agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 2h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 4h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 4h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 4h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 4h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 4h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 5h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 5h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 5h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 6h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 6h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Rapid7 · 49m agovBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 1h agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 1h agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 2h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 4h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 4h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 4h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 4h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 4h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 5h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 5h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 5h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 6h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 6h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

1372 results in Vulnerability

VulnerabilityThe Hacker News·19d ago
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the

VulnerabilitySANS ISC·19d ago
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)

[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program] Every so often a honeypot hit comes along that is less about the exploit and more about the intent behind it. While reviewing DShield logs I ran into a scanning bot that caught my eye: a URI string that appeared to be a plea for help. On 2026-06-06 my DShield honeypot logged back-to-back HTTP requests from the same source IP hitting two different ports with both carrying an identical, oddly formatted request path: The request path itself /?_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ is not a known exploit path, it appeared to be a plain-text message in the URL. Searching my logs for that particular string returned around a dozen similar HTTP requests over a 2 months period. These came from various IPs from around the globe with no discernible pattern which pointed to a self-propagating bot rather than a single attacker. Further research showed that this bot was first reported to ISC in May 2026. The number of reports peaked shortly after the first report before a sharp drop and has remained steady since. [ 1 ] I was unable to locate much more information about this bot other than a reddit thread on r/selfhosted describing the same requests hitting a Traefik reverse proxy. According to that thread, the user emailed the address embedded in the User-Agent and received a reply pointing to a page on a free web-hosting service. The page is a static HTML document with no scripts and it lays out what the bot is why it exists. The author, who identifies himself only as Alex, claims to be based in Belarus and writes that the bot is intentionally limited: no exploits, no command-and-control, no persistence. In his words, paraphrased and summarized from the page: The bot scans random IP addresses for open HTTP ports (80, 8000, 8080) and SSH ports (22, 2222). If it finds an open HTTP port it sends a single request (GET, CONNECT, or HEAD) If it finds an open SSH port it attempts a brute force with a small, fixed list of default credential pairs (admin:admin, root:root, etc.) It runs fully autonomously with no C2 channel; discovered IP/credential pairs are reported back to a loader only. It does not establish persistence, typically running from /tmp, and it is designed to self-terminate roughly six months after release. The stated purpose is to draw attention to conditions in Belarus. They describe it as a performance piece, saying they are not seeking funding and only asking for non-financial help leaving the country (job leads, advice, connections). Disregarding the origin and supposed intent of the bot, this is a straightforward scan-and-brute-force bot and it should be treated like any other hitting a honeypot. The HTTP request is reconnaissance/fingerprinting that tells the operator a host is alive and reachable on that port. The risk is on the SSH side: any host reachable on TCP 22/2222 that still uses a default or weak credential pair is exposed, regardless of the crea

VulnerabilityThe Hacker News·20d ago
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack. Decrypting browser credentials, listing what sits in Windows' credential store,

VulnerabilityRapid7·20d ago
Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?

The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit , we surveyed attendees to better understand where security leaders and practitioners stand today, what is shaping their priorities, and what they need to move forward. Their responses offer a candid view into the current state of security operations: ambitious, increasingly AI-aware, and ready for change, but still working through the practical challenges of getting there. For many teams, the direction is clear: security needs to become more proactive, more connected, and more resilient. Attackers are moving quickly, environments are expanding, and teams are under pressure to reduce risk before it turns into business disruption. But the survey results show that most organizations are still somewhere in the middle of that journey. Where organizations are today One of the clearest findings is that security operations are increasingly collaborative. According to the survey, 57% of respondents operate in a hybrid internal and MDR model. That reflects a reality many teams know well: internal expertise remains essential, but external support can help extend coverage, add specialist knowledge, and support faster response when internal resources are stretched. This hybrid model also speaks to the complexity security teams are managing. Modern environments span cloud, identity, endpoints, applications, third parties, and expanding attack surfaces. Keeping watch across all of it requires more than tooling alone. It requires the right mix of people, process, visibility, and support. At the same time, many organizations are still working to connect the dots across their security ecosystem. Two-thirds of respondents said their security capabilities are only partially integrated. For analysts, partial integration often means more manual work: switching between tools, stitching together context, and making decisions with an incomplete picture. When teams are jumping between systems, manually stitching together context, or working from incomplete data, it becomes harder to act at the speed modern threats demand. The survey also showed that only 10% of respondents describe their organization as “highly proactive” in predicting and preventing threats, which points to the reality of where many teams are today. The ambition is there, but becoming truly preemptive takes time, integration, and operational maturity. Most organizations are still balancing the day-to-day demands of reactive response with the longer-term work of building a more proactive security model. Confidence levels tell a similar story. 59% of respondents said they are only somewhat confident in their organization’s ability to prevent attacks before impact. Security teams understand what is at stake, but many still lack full confidence that they can consistently stop threats before they aff

VulnerabilityThe Hacker News·20d ago
New Ghost Phishing Wave Is Breaking Traditional Email Security

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time

VulnerabilityThe Hacker News·20d ago
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters

VulnerabilityThe Hacker News·20d ago
The Verification Step Is the New ATO Battleground in 2026

For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not because attackers gave up, but because the front door finally got harder to kick in. Passkeys are now mainstream.

VulnerabilityThe Hacker News·20d ago
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple. The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused

VulnerabilitySANS ISC·20d ago
My Stack Simulator, (Wed, Jul 8th)

The stack is a memory region where a program stores temporary data - like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plate to the top, and you can only take one away from the top too. Programs use this same last in, first out principle to keep track of what they're doing. Every time a function is called, the program pushes a new plate onto the stack containing things like local variables and the address to return to once the function finishes. When the function is done, that plate is popped off the top, and execution resumes exactly where it left off. This simple mechanism is what allows programs to call functions within functions within functions, and always find their way back - but it's also precisely why a stack that grows too large, or gets overwritten with unexpected data, becomes a favorite target for attackers looking to hijack a program's execution flow. In the SANS class FOR610[ 1 ] (malware analysis), there is an introduction to assembly and, when students learn how functions work, they have to understand how the stack also works. If you ve no prior experience, it could be a bit challenging. To help students to vizualise how the stack works, I created a stack simulator that allows to see what s happening when code is executed. How does it work? Select the architecture (32-64 bits) in the assembly editor Select a predefined set of instructions ( lesson , call , prologue , ). Click on Step to you can see the impact on the stack and registers (like in a debugger). Note that you can modify the predefined ASM code and add your own instructions. The stack simulator is available on my website[ 2 ]. If you re interested in malware analysis, my next classes will be: SANS Tokyo Autumn 2026 [ 3 ] SANS Paris November 2026 [ 4 ] [1] https://www.sans.org/cyber-security-courses/reverse-engineering-malware-malware-analysis-tools-techniques [2] https://xameco.be/stack-simulator.html [3] https://www.sans.org/cyber-security-training-events/tokyo-autumn-2026 [4] https://www.sans.org/cyber-security-training-events/paris-november-2026 Xavier Mertens (@xme) Xameco Senior ISC Handler - Freelance Cyber Security Consultant PGP Key (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

VulnerabilityThe Hacker News·20d ago
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network

VulnerabilityThe Hacker News·20d ago
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the

VulnerabilitySANS ISC·21d ago
More Odd DNS Records: NIMLOC, (Tue, Jul 7th)

Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another odd record that shows up in my DNS logs. This one isn't new, but I don't think I ever covered it: NIMLOC. At least that is what Zeek calls it. But let's see what it is all about. At first, it looks like NIMLOC records are no longer used. Google's AI overview explains: A NIMLOC (Nimrod Locator) DNS record is an obsolete resource record type (Type 32) originally designed for the Nimrod routing architecture to map names to network locators. Because Nimrod was an experimental protocol, NIMLOC records are considered historic and are not used in modern, standard network operations. While I do have one or the other odd IOT device in my network, I doubt any of them speak Nimrod . On the other hand, the queries originate from my macOS systems. This turns out to be an older standard, replaced by a newer (but still old) standard, with the newer standard becoming obsolete before the even older standard is phased out. DNS defines several resource record types. The official list is maintained by IANA [1] and I am including a sample below: TYPE Value Meaning References A 1 IPv4 Address RFC1035 NS 2 Name Server RFC1035 PTR 12 Domain Name Pointer RFC1035 MX 15 Mail Server RFC1035 TXT 16 Text String RFC1035 AAAA 28 IPv6 Address RFC3596 NIMLOC 32 Nimrod Locator (no RFC) SRV 33 Server Selection RFC2782 NAPTR 35 Naming Authority Pointer RFC3403 There is a range of unassigned RR types, so one would think that it is not necessary to reuse RR Types. But this is exactly what happened here. RR Type 32 was originally assigned for the old NetBIOS over TCP/UDP (RFC 1002, [2]). This actually became one of the few Internet Standards (STD 19). RR Type 32 is assigned ot NB (NetBIOS General Name Service) and 33 to NBSTAT , the NetBIOS Node Status. If you search for it in the RFC, look for the hex values 0x0020 and 0x0021 (took me a while to find them). NetBIOS is long gone, and modern Windows networks use DNS and SMB over TCP, eliminating the NetBIOS layer. But macOS is still holding on to it and broadcasting name announcements on port 137 using these records. Zeek (which I used to collect the logs), translates RR Type 32 to NIMLOC , which conforms to the current IANA assignment for this type. But in reality, you are probably going to see NetBIOS and not the never-quite-implemented Nimrod routing scheme. [1] https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml#dns-parameters-4 [2] https://www.rfc-editor.org/info/rfc1002/ -- Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu Twitter | (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.