
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.

Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.

Attackers seized CubePilot’s domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.

Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via

Three individuals sued Apple over a fake iOS Sparrow Wallet app that stole $1.8 million in Bitcoin by harvesting seed

ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed

Origin Energy disclosed a breach affecting 900,000 Australian customers, exposing names, bank account fragments, and addresses amid unconfirmed ransom claims.

DentaQuest’s breach notification confirms up to 23.4 million Medicaid dental enrollees potentially affected, with SSNs and dental PHI stolen in

PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at

Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims

Trend Micro documented Russian actor ‘bandcampro’ using Gemini CLI as a hacking assistant in a dental clinic botnet attack on
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.