Cybersecurity
When the internet’s plumbing catches fire
Critical VMware vCenter Flaw Is Exploited for Reverse SSH Access — The Hypervisor Butler Has Opened a Private Service Elevator
VMware vCenter administrators received another exquisitely unpleasant reminder this week that “patched recently” and “safe now” are two different concepts, separated by a moat full…
Read moreA Compromised AI Package Reportedly Exposed Terabytes of Credentials — The Developer Supply Chain Has Misplaced the Crown Jewels in a Python Gift Bag
A reported supply-chain compromise involving LiteLLM, an open source tool used to streamline AI-driven development workflows, allegedly exposed terabytes of credentials tied to thousands of…
Read moreChrome Ties Session Cookies to the Device — The Stolen Biscuit Has Been Denied Its Luxury Travel Privileges
🤚 The Open-Palm Cookie Jar Google Chrome is adopting a new defense against one of the internet’s most vulgar little crimes: stealing session cookies and…
Read moreDEF CON Builds a Water Watch Center for Rural Utilities — The Pump House Finally Gets a Security Concierge
DEF CON Franklin and the National Rural Water Association have announced a new Water Watch Center program to help small U.S. water utilities get actual…
Read moreAtlassian Rovo Can Be Tricked Into Mailing the Silverware to Attackers — The Collaboration Butler Has Discovered Prompt Injection
🤚 The Open-Palm Exfiltration Atlassian Rovo, the company’s AI assistant for products such as Jira and Confluence, can be manipulated into collecting data a signed-in…
Read moreWater System Controllers Are Still on the Internet After Suspected Iran-Linked Attacks — The Pump Room Has Entered Its Geopolitical Influencer Era
🤚 The Open-Palm Valve Retired General Paul Nakasone, the former NSA chief, used DEF CON to say the quiet infrastructure sentence out loud: water system…
Read moreRansomware Attacks Jump Nearly 20 Percent While Everyone Stares at AI — The Old Extortion Boutique Is Still Accepting Victims
While executives were busy asking whether AI agents might one day autonomously schedule a meeting about synergy, ransomware gangs spent July doing the unfashionable thing:…
Read moreChina Opens a Security Probe Into Palo Alto Networks — The Firewall Has Been Invited to a Sovereignty Interview
China’s Cyberspace Administration has launched a security review of Palo Alto Networks products, offering only the kind of official explanation that arrives wrapped in fog…
Read moreThousands of Servers Can Be Backdoored Through Buggy Motherboard Controllers — The Datacenter’s Secret Computer Would Like Administrative Privileges
Baseboard management controllers — the tiny management computers embedded in enterprise servers — are once again reminding everyone that “out-of-band management” is Latin for “a…
Read moreCISA Gives Federal Agencies Three Days to Patch an Exploited N-able N-central Flaw — The MSP Master Console Has Entered Its God-Mode Incident Era
The US Cybersecurity and Infrastructure Security Agency has added an actively exploited N-able N-central vulnerability to its Known Exploited Vulnerabilities catalog, giving federal agencies just…
Read more