
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Wednesday, July 29, 2026. I'm Rich Stroffelino. Thousands of server BMCs leak password hashes Researchers at Lava report that over 24,000 Internet exposed servers are leaking password hashes through a vulnerability in their baseboard management controller, or BMC interface that dates back to 2013. The vulnerability is in an IPMI 2.0 authentication weakness and allows attackers to request an authentication response that can be used to crack a password offline. On top of that, the researcher found that many of the exposed BMCs are super microsystems that still use a 10 character uppercase password printed on an attached label with the default username of admin, and over 6,000 hosts accepted an empty username during authentication. While the researchers didn't find widespread proof of active exploitation, they found at least one instance of an Internet exposed server displaying a ransomware note on its login page. Claude finds flaws in encryption we've known LLMs can be effective at finding flaws in encryption implementation, but Anthropic just published research showing they can be effective at finding flaws in the underlying encryption technology itself. Using Claude Metho's preview, Anthropic researchers were able to improve the attack methodology on the post Quantum Digital Signature Scheme hawk using about 60 hours of work, cutting its key strength in half. This is largely academic at this point, as Hawk is only a NIST candidate standard and has not really deployed anywhere yet, but Mytho shows that its proposed key sizes would need to be doubled to keep its desired level of security. The researchers also found a way to break a seven round reduced version of AES 128, effectively eliminating one of the guesses an attacker needs to make and improving the speed of attacks significantly. To be clear, this was on a weakened academic version of AES, not something that would ever be used in production. Each of these research approaches cost about $100,000 in tokens, with the LLM running largely unsupervised for several days before landing on an effective approach. Google gives Old Threat Actors new names Google's Threat Intelligence Group is adopting a new crypto NIM based naming taxonomy for tracking threat groups. Until now, Google has used sequential numbers to identify groups. This new system will use a unique and memorable term linked to public reporting to represent a threat actor or use a random word if they're talking about new groups. The second word is meant to place the threat actor into a category based on either motivation, attribution or type of activity. So, for example, Google will use castle as the second word for threat actors from China or relic from those originating from Russia. Comet will be used for cybercrime gangs. Under this scheme, APT44, which refers to the notorious Sandworm group from Russia, would be called Sandworm Relic. Google will keep its previous naming conventions indexed and searchable in its Google Threat Intelligence platform and says we are intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies. Dysphoria Botnet is growing up researchers at Qianxin XLAB report that this botnet has grown to over 200,000 compromised devices recently, adding the ability to use blockchain based C2 resolution mechanisms. The group conceals C2 addresses and fake IPv6 strings while using Ethereum ENS and Solana SNS domains to retrieve actual infrastructure information. Dysphoria was first spotted on March 25 and has received several meaningful updates since then. The botnet also seems to be shifting focus, going from using compromised devices for DDoS attacks to using them as network proxies. In other botnet news, researchers at Nozomi Network Labs found a new Mirai derived botnet called Tengu that features a novel persistence feature. When defenders kill the botnet's main process on a compromised Linux device, Tengu triggers a reboot on restart, Tengu's other persistent mechanisms have another chance to kick in. This kind of self defense mechanism stood out to the researchers as unique among Mirai derived variants and now a huge thanks to our sponsor Pindrop AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up? Deepfake and synthetic voices are slipping through a channel. Your defenses were never built to cover stealing credentials and exposing data with no visibility until after the incident report. Pin drop closes that gap with under 1% false positives. Go to pindrop.com to learn more. Nimbus Manticore uses a New backdoor Researchers at Kaspersky documented a new campaign by the Iranian state backed threat group that uses a previously undocumented Windows backdoor dubbed Knightledger as well as two custom websocket tunnelers to target entities across the Middle East, Africa and South Asia. Overall, the goal seems to be maintaining covert access. The victims are pretty widespread, ranging from SMBs and government environments in Jordan to aviation organizations in Pakistan and telcos in Ethiopia. While the initial access method for this particular campaign isn't known, Nimbus Manticore has previously used highly tailored job opportunity themed phishing lures to pose as trusted brands and then gain access through job applications. Sierra to Acquire Oasis Security the data security company Sierra announced it reached an agreement to acquire Oasis Security in a deal worth $1 billion. In its announcement, Sierra said the acquisition would allow it to integrate Oasis, non human identity and access government solutions into their product portfolio in order to create a next generation security platform. Oasis launched in 2022 and has raised a total of $195 million in funding since then. We don't cover a ton of acquisition announcements on this show, but given Oasis focus on nonhuman identities and leaning into agentic governance, this seemed like a particularly timely acquisition and likely we'll see similar ones going forward. NVD sees vulnerabilities surge in 2026 the US National Vulnerability Database recorded 45,207 software vulnerabilities since the start of 2026. This total approaches the total number of vulnerabilities it cataloged in all of 2025. This also comes after we've seen repeated record setting vulnerability disclosures from individual companies. For example, Microsoft hit another all time high in its latest patch Tuesday in July with 642 security vulnerabilities. Oracle in its July update patched 1,449. These totals aren't surprising if you've been even remotely following the ongoing news with the voltanpocalypse, but probably another reason the NVD is struggling to properly enrich vulnerabilities going forward. Agents used to augment cyberattack on Thai Ministry Researchers at Huntio documented a cyber attack against Thailand's Ministry of Finance last week. While the goal of this attack appears to have been garden variety cyber espionage, the researchers found signs that the attack was supported by AI agents using the open source tool Hermes. The agent was operating in what appeared to be an unrestricted YOLO mode. I guess that's an official designation which allows it to function without any human approval. While the attackers didn't appear to use the agents to write any malware, they do appear to have been used extensively in support activities, performing system enumeration, escalating privileges, discovering files and services, and conducting network reconnaissance. This may have been more of a proof of concept for the attackers, as there doesn't appear to have been any evidence of data exfiltration. Remember to register for this Friday's Super Cyber Friday at 1pm this Friday we're going to be talking about hacking the SMB security gap. We know small businesses are always tempted to ignore security. It used to be that they just weren't worth the time of your average threat actor to pop, but agentic AI has changed the math. So how do we start to address that chasm? Register@SuperCyberFriday.com for the event and join in the conversation. And if you have some thoughts about the news from today, or about the show in general, be sure to reach out to us. Feedback@cisoseries.com we'd love to hear from you. Reporting for the CISO series, I'm Rich Stroffelino reminding you to have a super sparkly day.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Podcast Summary: Cybersecurity Headlines
Episode: Leaky BMCs, Claude finds encryption flaws, Google's new names
Date: July 29, 2026
Host: Rich Stroffelino (CISO Series)
This episode covers several pressing cybersecurity topics, including a new wave of exposed server management vulnerabilities, breakthroughs in encryption analysis using AI, changes to Google’s threat actor naming taxonomy, evolving botnet tactics, a major acquisition in the non-human identity space, a surge in vulnerability counts, and the use of agentic AI in cyberattacks on critical infrastructure. The tone balances urgency with clarity and occasional humor, making critical topics approachable for security professionals and the concerned public alike.
[For more episodes and details, visit cisoseries.com.]