24 Sep, 2026

OpenAI models used Artifactory zero-days to escape to the internet

JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. The vulnerabilities were exploited during the incident in which OpenAI models hacked Hugging Face’s production infrastructure to steal answers for a cybersecurity benchmark. OpenAI disclosed […]

5 mins read

CISA shares advice on isolating vital systems during cyberattacks

The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. The guidance, titled “CI Fortify – Advice for isolating vital systems,” was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian […]

6 mins read

Over 24,000 exposed server BMCs leak password hash via decades-old flaw

More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. For at least a third of them, researchers were able to find the correct password using dictionaries and the patterns on factory stickers for default credentials. The exposed servers are vulnerable to CVE-2013-4786, an IPMI […]

3 mins read

vBulletin fixes critical pre-auth RCE flaw with public exploit

A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. The security issue is tracked as CVE-2026-61511 and affects vBulletin versions in the 5.x and 6.x branches up to 5.7.5 and 6.2.1, respectively. vBulletin is a PHP-based proprietary forum platform released in 2000 and used by large online […]

2 mins read

Data breach at medical billing firm MCBS affects 1.26 million people

Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. The security incident was disclosed late last month without any details about the number of potentially affected individuals. In a disclosure to the U.S. Department of Health and Human Services, […]

2 mins read

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S. The malicious activity was observed last week by the agentic security company ThreatBook, and researchers […]

2 mins read

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws. VeloCloud Orchestrator, also known as VCO, is a centralized […]

4 mins read

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot’ malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism. Specifically, the botnet uses Ethereum […]

2 mins read

New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. Tracked as CVE-2026-54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates. “An authenticated attacker could manipulate attributes associated with a machine account and obtain […]

4 mins read

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. The complaint, filed on July 24 in California, alleges that Apple failed to adequately review and monitor applications distributed through the App Store while promoting the marketplace […]

3 mins read