Topic: brute-force attacks

  • Middle East Brute-Force Attacks Surge in 2026

    Middle East Brute-Force Attacks Surge in 2026

    A sharp rise in brute-force attacks targeting network security appliances like firewalls and VPNs was observed in early 2026, with a dominant share of malicious traffic originating from the Middle East. These attacks highlight the critical targeting of internet-exposed edge devices, with over hal...

    Read More »
  • BruteForceAI: Free AI-Powered Login Security Testing Tool

    BruteForceAI: Free AI-Powered Login Security Testing Tool

    BruteForceAI is a free automated penetration testing tool that uses large language models to identify login vulnerabilities without manual configuration. It intelligently scans webpages to detect login forms, then executes multi-threaded attacks mimicking user behavior to evade security defenses....

    Read More »
  • $30,000 GPU Password Cracking Test: Results

    $30,000 GPU Password Cracking Test: Results

    A benchmark test found that high-end consumer GPUs, like the Nvidia RTX 5090, significantly outperform expensive AI accelerators (Nvidia H200, AMD MI300X) in password-cracking speed, making specialized AI hardware a poor investment for this purpose. The primary organizational risk is not advanced...

    Read More »
  • New FortiBleed campaign uses custom sniffer to steal FortiGate credentials

    New FortiBleed campaign uses custom sniffer to steal FortiGate credentials

    The FortiBleed campaign has targeted over 430,000 Fortinet FortiGate firewalls since February 2026, using custom Golang-based sniffers to intercept authentication traffic and steal credentials. Attackers exploit FortiOS's legitimate "diagnose sniffer packet" feature via SSH to capture data from 2...

    Read More »
  • AES 128 Encryption Remains Secure Post-Quantum

    AES 128 Encryption Remains Secure Post-Quantum

    AES 128 encryption remains secure against quantum computers, as emphasized by cryptography engineer Filippo Valsorda, and is not obsolete. The 128-bit variant of the Advanced Encryption Standard is highly secure, with no practical vulnerabilities found in three decades; a brute-force attack using...

    Read More »
  • SystemBC Malware Hijacks VPS Servers as Proxy Gateways

    SystemBC Malware Hijacks VPS Servers as Proxy Gateways

    The SystemBC proxy botnet targets vulnerable commercial virtual private servers, maintaining around 1,500 daily compromised systems to route malicious traffic and mask cybercriminal activities. It is widely used by ransomware groups and other threat actors, leveraging unpatched security flaws in ...

    Read More »
  • UK Slaps LastPass With Fine for 2022 Data Breach Affecting Millions

    UK Slaps LastPass With Fine for 2022 Data Breach Affecting Millions

    The UK's Information Commissioner's Office fined LastPass £1.2 million for failing to protect the personal data of up to 1.6 million users during a 2022 breach, where encrypted password vaults were stolen. The breach occurred in stages, starting with a compromised employee laptop and escalating w...

    Read More »
  • $35M Crypto Theft Linked to LastPass Breach

    $35M Crypto Theft Linked to LastPass Breach

    A cryptocurrency theft exceeding $35 million has been linked to the 2022 LastPass breach, where hackers exploited stolen password vault backups over several years in a prolonged campaign. The thefts, traced to Russian cybercriminals, targeted users with weak master passwords, which allowed for of...

    Read More »
  • SonicWall SMA100 Update Eradicates Rootkit Malware

    SonicWall SMA100 Update Eradicates Rootkit Malware

    SonicWall has released a critical firmware update for its SMA 100 series appliances that can eradicate the OVERSTEP rootkit malware, which enables persistent unauthorized access and data theft. The update is urgent due to active attacks by threat actor UNC6148, who uses the rootkit to steal sensi...

    Read More »
  • Fortinet warns of critical FortiCloud SSO auth bypass flaw

    Fortinet warns of critical FortiCloud SSO auth bypass flaw

    Fortinet has patched two critical authentication bypass vulnerabilities (CVE-2025-59718 & CVE-2025-59719) in several products, which could allow attackers to gain unauthorized access via a crafted SAML message. The affected FortiCloud SSO feature is not enabled by default on new devices, but it i...

    Read More »