433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

Exposed BMCs hand out password hashes before login

An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. That controller runs underneath the operating system. It power-cycles the host, mounts virtual media, opens a remote console, and flashes firmware. Host security tools watch the layer above it. Example BMC web … More → The post Exposed BMCs hand out password hashes before login appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBJl

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Solutions Engineering Lead at JetBrains. TeamCity as a possible target JetBrains TeamCity is a widely used continuous integration and continuous delivery (CI/CD) server solution. It’s available as a JetBrains-hosted option (TeamCity Cloud) or can be … More → The post JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBJW

VERITAS project could change the way scientists secure AI

The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establishing AI Assurance as a core function of scientific research infrastructure. Led by Anita Nikolich, research scientist and director of research and technology innovation at the University of Illinois School of Information Sciences, the initiative … More → The post VERITAS project could change the way scientists secure AI appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBHc

Grafana Assistant expands with AI agents for investigations, automation, and observability

Grafana Labs has announced the general availability of six AI capabilities, extending Grafana Assistant into an agentic operations layer that detects, investigates, and remediates production issues. The releases include Grafana Assistant Investigations, Grafana Assistant Workspace, Grafana Assistant Automations, the Grafana Cloud MCP server, gcx, and Grafana Agent Observability. Observability has traditionally started after code reaches production: instrument it, dashboard it, alert on it, and hope you notice issues before your customers do. That timeline is … More → The post Grafana Assistant expands with AI agents for investigations, automation, and observability appeared first on Help Net Security.
http://news.poseidon-us.com/TTl3qC

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition preserves traffic flow and runs alongside existing L7 automatic mitigation and AWS WAF rules. The rule group is available to all AWS WAF customers, and is included with AWS Shield Advanced subscriptions. Migration timeline Between July 27 and … More → The post AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 appeared first on Help Net Security.
http://news.poseidon-us.com/TTl3qB

Coca-Cola confirms hackers stole data in Fairlife ransomware attack

Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and protein drinks, with annual retail sales that have topped $1 billion. In a statement published on Monday, Coca-Cola said Fairlife has resumed the majority of production across its four US manufacturing facilities. “The company previously … More → The post Coca-Cola confirms hackers stole data in Fairlife ransomware attack appeared first on Help Net Security.
http://news.poseidon-us.com/TTl3pp

AutoIT Payload Injector , (Tue, Jul 28th)

For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it&#x27s easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you&#x27ll see below.
http://news.poseidon-us.com/TTkwqV

Shadow AI incident response begins with logs that may already be gone

In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough. Wityak also discusses the gap between an AI policy in a wiki and a control … More → The post Shadow AI incident response begins with logs that may already be gone appeared first on Help Net Security.
http://news.poseidon-us.com/TTktt8