ЩОДЕННИЙ ОГЛЯД
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Today's briefing covers thousands of exposed server management interfaces disclosing hashes, a novel Linux botnet watchdog tactic, and critical patches for vBulletin.
5 новин2 хв читання

System administrators and operational technology defenders must prioritize isolating vulnerable management interfaces and applying emergency patches. Exposed administration channels—from server BMCs to forum software—continue to serve as primary entry points for threat actors.
Meanwhile, novel research into AI-driven cryptanalysis demonstrates advancing techniques against cryptographic standards, reinforcing the need for long-term defensive planning alongside immediate perimeter hardening.
vBulletin fixes critical pre-auth RCE flaw with public exploit
vBulletin patched a critical pre-authentication remote code execution flaw that allows unauthenticated attackers to execute arbitrary PHP code through template rendering, with public exploit code available.
- Чому це важливо
- Unauthenticated remote code execution allows attackers to gain total control over vBulletin server environments.
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
The Mirai-derived Tengu botnet abuses hardware watchdogs on compromised Linux devices to trigger system reboots if its main process is terminated, allowing backup persistence mechanisms to relaunch it.
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.
CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments released joint security guidance urging critical infrastructure operators to prepare to isolate vital operational technology systems during cyberattacks or major disruptions.
- Чому це важливо
- Critical infrastructure organizations risk prolonged outages or malware spreading across IT and OT boundaries if isolation procedures are not tested.
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic revealed its Claude Mythos Preview AI helped derive an end-to-end key-recovery attack against HAWK-256 and accelerated a 7-round AES-128 attack. Anthropic stated that neither result affects production software or systems.
Основні висновки
- Over 24,000 internet-exposed BMCs expose IPMI password hashes via RAKP message responses (CVE-2013-4786), enabling offline cracking attacks.
- The Tengu botnet leverages hardware watchdogs on Linux devices to trigger reboots when its main process is terminated by defenders.
- vBulletin released patches for a critical pre-authentication remote code execution vulnerability that allows arbitrary PHP code execution.