
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.

Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.

More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting

Attackers seized CubePilot’s domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.

Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.

Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by

Dysphoria, successor to the disrupted JackSkid botnet, infected 200,000 IoT devices worldwide and adopted Ethereum and Solana Name Service to

Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern

CISA added CVE-2026-25089 and CVE-2026-39808 in Fortinet FortiSandbox to KEV, ordering FCEB agencies to patch by July 19 amid confirmed

F5 released an out-of-band patch for CVE-2026-42533, a CVSS 9.2 heap buffer overflow in NGINX Plus and Open Source requiring

Palo Alto Networks Unit 42 exposed TuxBot v3, an Iranian-linked IoT botnet targeting 17 CPU architectures with DDoS-for-hire capabilities and
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.