CHECKLEAKED.CC

กำลังโหลด

เว็บไซต์แบบคลาสสิก

สรุปข่าวประจำวัน

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Today's briefing covers thousands of exposed server management interfaces disclosing hashes, a novel Linux botnet watchdog tactic, and critical patches for vBulletin.

System administrators and operational technology defenders must prioritize isolating vulnerable management interfaces and applying emergency patches. Exposed administration channels—from server BMCs to forum software—continue to serve as primary entry points for threat actors.

Meanwhile, novel research into AI-driven cryptanalysis demonstrates advancing techniques against cryptographic standards, reinforcing the need for long-term defensive planning alongside immediate perimeter hardening.

vBulletin fixes critical pre-auth RCE flaw with public exploit

vBulletin patched a critical pre-authentication remote code execution flaw that allows unauthenticated attackers to execute arbitrary PHP code through template rendering, with public exploit code available.

เหตุใดจึงสำคัญ
Unauthenticated remote code execution allows attackers to gain total control over vBulletin server environments.
  • vBulletin
  • PHP
อ่านต้นฉบับ

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

The Mirai-derived Tengu botnet abuses hardware watchdogs on compromised Linux devices to trigger system reboots if its main process is terminated, allowing backup persistence mechanisms to relaunch it.

  • Tengu
  • Linux
  • Botnet
อ่านต้นฉบับ

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.

  • BMC
  • IPMI
อ่านต้นฉบับ

CISA shares advice on isolating vital systems during cyberattacks

The U.S. and Australian governments released joint security guidance urging critical infrastructure operators to prepare to isolate vital operational technology systems during cyberattacks or major disruptions.

เหตุใดจึงสำคัญ
Critical infrastructure organizations risk prolonged outages or malware spreading across IT and OT boundaries if isolation procedures are not tested.
  • OT
  • Infrastructure
อ่านต้นฉบับ

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Anthropic revealed its Claude Mythos Preview AI helped derive an end-to-end key-recovery attack against HAWK-256 and accelerated a 7-round AES-128 attack. Anthropic stated that neither result affects production software or systems.

  • Anthropic
  • AI
  • Encryption
อ่านต้นฉบับ

ประเด็นสำคัญ

  • Over 24,000 internet-exposed BMCs expose IPMI password hashes via RAKP message responses (CVE-2013-4786), enabling offline cracking attacks.
  • The Tengu botnet leverages hardware watchdogs on Linux devices to trigger reboots when its main process is terminated by defenders.
  • vBulletin released patches for a critical pre-authentication remote code execution vulnerability that allows arbitrary PHP code execution.
  • Tengu
  • Botnet
  • CVE20134786
  • IPMI
  • vBulletin