Private security firms will soon be allowed to hack overseas cybercriminals

Trump memo is first time gov’t has authorized private sector to perform cyberattacks.  The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyberattacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities. In a National Security Presidential Memorandum issued…

Terabytes of credentials leaked in massive supply-chain attack

The data was scraped and exfiltrated from 2,500 users of a compromised AI package.  Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco,…

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Baseboard management controllers from the world’s biggest manufacturers are a security mess.  Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday. Baseboard management controllers are…

Claude published malicious code to the Internet and attacked 3 real companies

Had the hacks used conventional methods, someone would likely go to prison.  Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities. The events, which Anthropic revealed Thursday, are the…

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Exploits can give persistent server access that survives credential rotation and disk re-imaging.  Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488,…