Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-28 08:00 PDT
- Is Your SSO Protected Against Modern Credential Attacks?
BleepingComputer • 2026-07-28 07:00 • www.bleepingcomputer.com
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. […]
https://www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/ - JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
The Hacker News • 2026-07-28 06:33 • thehackernews.com
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud
https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html - Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
The Hacker News • 2026-07-28 05:56 • thehackernews.com
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt’s GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6
https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html - Over 24,000 exposed server BMCs leak password hash via decades-old flaw
BleepingComputer • 2026-07-28 05:10 • www.bleepingcomputer.com
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. […]
https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/ - Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Hacker News • 2026-07-28 04:55 • thehackernews.com
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,
https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html - Axon Is Another License Plate Surveillance Company
Schneier on Security • 2026-07-28 04:06 • www.schneier.comGovernments are switching, but I’m not sure it makes a difference:
…some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings.
[…]
Despite what you may read on the Flock website, Axon cameras are pretty effectiv…
https://www.schneier.com/blog/archives/2026/07/axon-is-another-license-plate-surveillance-company.html - Data breach at medical billing firm MCBS affects 1.26 million people
BleepingComputer • 2026-07-28 02:10 • www.bleepingcomputer.com
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. […]
https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
