Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
Cybersecurity researchers have discovered over 36,000 Baseboard Management Controller (BMC) interfaces exposing the Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of these, 24,650 were found to disclose password-derived authentication hashes before…
CVE-2013-4786 is a high-severity information disclosure flaw in the IPMI v2.0 specification that allows remote attackers to obtain password hashes for valid…
CVE-2026-53921 is a critical stack overflow vulnerability in OpenWrt's odhcpd DHCPv6 server, rated 9.8 CVSS 3.1. An unauthenticated attacker can send a…
CVE-2026-62948 is a DHCPv6 hostname-injection flaw in OpenWrt that can produce stored cross-site scripting (XSS) when an administrator opens the LuCI leases…
CVE-2026-62947 is a path traversal vulnerability in OpenWrt's cgi-io component that can expose arbitrary root-readable files. It requires an authenticated session with…
Anthropic announced that its Claude AI model, Mythos Preview, has achieved two significant cryptanalytic results: a full key-recovery attack against the HAWK-256…
NVIDIA, along with 36 other organizations including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux…
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
CTM360 Research has uncovered a sophisticated evolution in insurance phishing campaigns, where attackers now hijack accounts in real time rather than harvesting…
An attacker installed the open-source Hermes AI assistant on a rented server, disabled its permission-requesting YOLO mode, and directed it at Thailand's…
AI-assisted attackApacheBob DiachenkoChinese-speaking threat actor
Iranian state-backed hacking group Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been linked to…
Nimbus Manticore, also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549, is an Iranian state-backed hacking group known for…
TA4922 is a Chinese-speaking cybercrime actor associated with tax-themed phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams. The group…
NightLedger is a previously undocumented Windows backdoor deployed by Nimbus Manticore. It supports reconnaissance, command execution, file operations, process discovery, and screenshot…
The vulnerability CVE-2026-53264 was independently reported by Kyle Zeng (KyleBot) shortly before the TyphoonPwn 2026 competition. Lee Jia Jie later published a…
Coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026 targeted JackSkid and three other IoT botnets. Court documents attributed…
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
Common CriteriaEAL6+secure elementsecurity certification
HPE iLO is a server management interface that provides out-of-band management capabilities. It was found to be vulnerable to CVE-2013-4786, with factory…
Supermicro BMC is a management processor embedded in Supermicro servers. It was found to expose IPMI password hashes, with factory passwords recoverable…
Lava is a cybersecurity company that identified the widespread exposure of BMC interfaces leaking IPMI password hashes. Their research highlighted the risks…
HPE is a global enterprise IT company that manufactures servers with Integrated Lights-Out (iLO) management interfaces. Their iLO products were found to…
The Python Package Index is the official repository for third-party Python packages, providing a platform for developers to publish and install software.…