❌

Reading view

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar

submitted by /u/Pale_Fly_2673
[link] [comments]
  •  

CFP Open – Looking for Technical AI & Security Research for AprΓ¨s Slopes Summit 2027

I'm helping organize Après-Cyber Slopes Summit 2027, and our CFP is now open.

We're particularly interested in technical presentations and original research involving AI and modern cybersecurity.

Topics we're hoping to see include:

  • AI red teaming
  • LLM security
  • Prompt injection research
  • Agent security
  • Offensive tooling
  • Detection engineering
  • Reverse engineering
  • Malware analysis
  • Cloud exploitation and defense
  • Identity attacks
  • Threat intelligence
  • AI-assisted security tooling
  • Novel attack techniques
  • Defensive research

We especially appreciate talks that include demonstrations, technical depth, or research that attendees can reproduce themselves.

Conference: February 24–26, 2027
Location: Park City, Utah

CFP:
https://sessionize.com/apres-cyber-slopes-summit-2027

Conference website:
https://www.aprescyber.com

Happy to answer questions about the CFP or conference.

submitted by /u/PilotSmooth9439
[link] [comments]
  •  

The way AI voice phishing gets demonstrated is making people worse at spotting it

AI voice phishing isn't a cloned voice with a bot doing the talking. It's a human operator running a real time voice changer. Which matters, because every "how to spot a voice phishing / deepfake" tell is a text to speech artifact and none of them survive voice conversion.

Disclosure .. I build voice phishing simulation for a living, so I have a horse in this race. But to show exactly how a real time voice changer works, I built a free demo so people can hear one for themselves ..

Speak into it and you come back as someone else, live. No signup, capped at 60 seconds, and there's 8 cloud GPUs behind it doing the conversion so expect a queue. Five fixed identities to pick from .. deliberately not your own voice cloned back at you, because that's not the threat. You're hearing what an operator sounds like wearing someone else's voice. We've also seeded artifacts into the output audio so it cant be lifted and used for anything real.

submitted by /u/gyanchawdhary
[link] [comments]
  •  

Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled

Caught this in three open directories on a Hong Kong server, exposed July 9 to 13. The agent is Hermes, open source, and the recovered logs show it running LinPEAS and walking a ministry web root without a human in the loop. Target was Thailand's Ministry of Finance.

submitted by /u/Straight-Practice-99
[link] [comments]
  •  
❌