More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
FortiBleed has exposed more than 86,000 valid credentials for Fortinet firewalls and VPNs in 194 countries. Attackers ran 1.16 billion login attempts against 320,000 FortiGate devices, cracked password hashes on a 45-GPU cluster, then moved into internal Active Directory environments. Organizations that left management interfaces internet-facing without multi-factor authentication or network isolation paid the price. Meanwhile, a Texas vendor for hunting and fishing licenses leaked driver’s license and passport numbers for 3.09 million people, and a threat actor tied to a Virginia wildlife breach is already hawking the data. On the hardware side, the “usbliter8” BootROM exploit for Apple A12/A13 chips lets attackers install a restart-persistent handler that downgrades security and boots unsigned code. It can’t be patched because the flaw sits in mask ROM, so iPhone XS through iPhone 11 remain permanently exposed.
GitHub rolled out context-aware LLM checks to cut secret-scanning false positives by over 75%. Instead of scanning entire files, it isolates code paths where secrets actually feed into API calls, auth headers or database clients. That keeps coverage the same while silencing placeholder tokens and random UUIDs. A related FortiBleed brief shows how credential spraying, privilege escalation and offline cracking work together in large-scale password attacks. The advice: audit remote-access logs after high-volume failures, require MFA, adopt zero-trust jump boxes, rotate defaults and disable unused accounts. In pharma, FulcrumSec used a stolen GitHub PAT to exfiltrate 1.3 TB from Novo Nordisk, including the exact Ozempic formula and clinical-trial records for 11,500 patients. The intruders cloned hundreds of repos over months without detection, then spilled 264 GB after a refused \$25 million ransom. Companies need short-lived tokens, IP allowlists, SSO-backed credentials, plus alerts for bulk clones and high-volume data transfers.
On the emerging-tech front, Delinea’s whitepaper argues identity controls and just-in-time privilege limit AI-driven post-exploit damage. Quantum Bridge launched a crypto-agile key distribution service combining PQC, QKD and its DSKE protocol for government and finance. Visa published VVAH, an open-source harness that uses multi-agent voting with frontier models to focus vulnerability scans and cut false positives. VaultSort V4 now binds file encryption on macOS to hardware through Secure Enclave and Touch ID, sealing per-file keys with AES-KWP and closing gaps from its last version. Researchers also detailed how attackers silence or poison cloud logs—deleting destinations, encrypting entries with attacker keys or rerouting streams to their own accounts. Finally, Microsoft warned of Crypto Clipper, a USB-propagated worm that hijacks clipboards to swap cryptocurrency addresses and exfiltrate data over Tor.
Questions about this article
No questions yet.