433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

SpecterOps brings AWS attack path management and AI to hybrid identity security

SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the ability to proactively eliminate pathways before they can be abused. BloodHound Enterprise adds support for Amazon Web Services and Microsoft Entra Agent ID, expanding the reach of attack path management. A new purpose-built AI agent interface, BloodHound Hunter, brings that same adversary intelligence into AI-assisted security workflows, letting teams incorporate the power of the … More → The post SpecterOps brings AWS attack path management and AI to hybrid identity security appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBJq

Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response

Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence. Command unlocks Team Cymru’s globally observed threat intelligence data by connecting telemetry, investigative and attack surface management capabilities, expert analysis, and machine-native access within a common architecture. The result is a continuous path from discovery to action, eliminating fragmented workflows, preserving investigative context, and accelerating active … More → The post Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBJm

Exposed BMCs hand out password hashes before login

An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. That controller runs underneath the operating system. It power-cycles the host, mounts virtual media, opens a remote console, and flashes firmware. Host security tools watch the layer above it. Example BMC web … More → The post Exposed BMCs hand out password hashes before login appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBJl

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Solutions Engineering Lead at JetBrains. TeamCity as a possible target JetBrains TeamCity is a widely used continuous integration and continuous delivery (CI/CD) server solution. It’s available as a JetBrains-hosted option (TeamCity Cloud) or can be … More → The post JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBJW

VERITAS project could change the way scientists secure AI

The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establishing AI Assurance as a core function of scientific research infrastructure. Led by Anita Nikolich, research scientist and director of research and technology innovation at the University of Illinois School of Information Sciences, the initiative … More → The post VERITAS project could change the way scientists secure AI appeared first on Help Net Security.
http://news.poseidon-us.com/TTlBHc

Grafana Assistant expands with AI agents for investigations, automation, and observability

Grafana Labs has announced the general availability of six AI capabilities, extending Grafana Assistant into an agentic operations layer that detects, investigates, and remediates production issues. The releases include Grafana Assistant Investigations, Grafana Assistant Workspace, Grafana Assistant Automations, the Grafana Cloud MCP server, gcx, and Grafana Agent Observability. Observability has traditionally started after code reaches production: instrument it, dashboard it, alert on it, and hope you notice issues before your customers do. That timeline is … More → The post Grafana Assistant expands with AI agents for investigations, automation, and observability appeared first on Help Net Security.
http://news.poseidon-us.com/TTl3qC

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition preserves traffic flow and runs alongside existing L7 automatic mitigation and AWS WAF rules. The rule group is available to all AWS WAF customers, and is included with AWS Shield Advanced subscriptions. Migration timeline Between July 27 and … More → The post AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 appeared first on Help Net Security.
http://news.poseidon-us.com/TTl3qB

Coca-Cola confirms hackers stole data in Fairlife ransomware attack

Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and protein drinks, with annual retail sales that have topped $1 billion. In a statement published on Monday, Coca-Cola said Fairlife has resumed the majority of production across its four US manufacturing facilities. “The company previously … More → The post Coca-Cola confirms hackers stole data in Fairlife ransomware attack appeared first on Help Net Security.
http://news.poseidon-us.com/TTl3pp