lithos Twitter
Lithos Header
Last Updated
Age in hrs 
1
2
3
5
8
13
21
34
55

 Over 24,000 exposed server BMCs leak password hash via decades-old flaw  - More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface.

 Tribeca Film Festival data leak exposes Hollywood stars, including Angelina Jolie and Robert De Niro  - Thousands of Hollywood contacts were exposed – and no one knows for how long.

 Ernst & Young data breach claimed by ShinyHunters extortion gang  - The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.

 Russian Hackers Steal Emails Via Zimbra Exploit  - Russian state-linked hacking group Laundry Bear targeted previously unknown exploit to steal emails from corporate servers, say authorities

 MY TAKE: Big Tech is funding the AI race by cutting the skilled employees it needs to win it  - Big Tech isn’t buying the AI future with profits. It’s buying it with payroll.

 Discord settles with Texas, agrees to stronger online protection for minors  - Evidence showed predators target children on the platform.

 Arista patches VeloCloud Orchestrator zero-day exploited in attacks  - Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.

 NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework  - NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft,...

 Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update  - Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management ( RMM ) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that...

 Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In  - JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions....

 CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security  - AI is changing the speed and scale of cyber defense, and the speed and scale of the adversary. As AI becomes embedded across government, critical infrastructure, and enterprise environments, defenders[…]

 Nvidia weighs funding massive Ohio data center for OpenAI  - The project is expected to cost half a trillion dollars in total.

 SourTrade Malvertising Campaign Secretly Builds Malware in the Browser  - Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims

 Hacker who targeted over 500 Snapchat accounts sentenced to over 6 years in prison  - Svara used two-factor authentication to lock victims out of their Snapchat accounts.

 GitHub, PyPI add time-absed defenses against supply chain attacks  - GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.


In the shadows of Arrakis lie many secrets. But the darkest of them all may remain... the end of House Atreides. -Princess Irulan