Cybersecurity

When the internet’s plumbing catches fire

Critical VMware vCenter Flaw Is Exploited for Reverse SSH Access — The Hypervisor Butler Has Opened a Private Service Elevator

VMware vCenter administrators received another exquisitely unpleasant reminder this week that “patched recently” and “safe now” are two different concepts, separated by a moat full…

Read more

A Compromised AI Package Reportedly Exposed Terabytes of Credentials — The Developer Supply Chain Has Misplaced the Crown Jewels in a Python Gift Bag

A reported supply-chain compromise involving LiteLLM, an open source tool used to streamline AI-driven development workflows, allegedly exposed terabytes of credentials tied to thousands of…

Read more

Chrome Ties Session Cookies to the Device — The Stolen Biscuit Has Been Denied Its Luxury Travel Privileges

🤚 The Open-Palm Cookie Jar Google Chrome is adopting a new defense against one of the internet’s most vulgar little crimes: stealing session cookies and…

Read more

DEF CON Builds a Water Watch Center for Rural Utilities — The Pump House Finally Gets a Security Concierge

DEF CON Franklin and the National Rural Water Association have announced a new Water Watch Center program to help small U.S. water utilities get actual…

Read more

Atlassian Rovo Can Be Tricked Into Mailing the Silverware to Attackers — The Collaboration Butler Has Discovered Prompt Injection

🤚 The Open-Palm Exfiltration Atlassian Rovo, the company’s AI assistant for products such as Jira and Confluence, can be manipulated into collecting data a signed-in…

Read more

Water System Controllers Are Still on the Internet After Suspected Iran-Linked Attacks — The Pump Room Has Entered Its Geopolitical Influencer Era

🤚 The Open-Palm Valve Retired General Paul Nakasone, the former NSA chief, used DEF CON to say the quiet infrastructure sentence out loud: water system…

Read more

Ransomware Attacks Jump Nearly 20 Percent While Everyone Stares at AI — The Old Extortion Boutique Is Still Accepting Victims

While executives were busy asking whether AI agents might one day autonomously schedule a meeting about synergy, ransomware gangs spent July doing the unfashionable thing:…

Read more

China Opens a Security Probe Into Palo Alto Networks — The Firewall Has Been Invited to a Sovereignty Interview

China’s Cyberspace Administration has launched a security review of Palo Alto Networks products, offering only the kind of official explanation that arrives wrapped in fog…

Read more

Thousands of Servers Can Be Backdoored Through Buggy Motherboard Controllers — The Datacenter’s Secret Computer Would Like Administrative Privileges

Baseboard management controllers — the tiny management computers embedded in enterprise servers — are once again reminding everyone that “out-of-band management” is Latin for “a…

Read more

CISA Gives Federal Agencies Three Days to Patch an Exploited N-able N-central Flaw — The MSP Master Console Has Entered Its God-Mode Incident Era

The US Cybersecurity and Infrastructure Security Agency has added an actively exploited N-able N-central vulnerability to its Known Exploited Vulnerabilities catalog, giving federal agencies just…

Read more