The Signal

The strongest items concern defensive boundaries: infrastructure below the operating system, malware designed to frustrate static analysis, and AI-related workflows or research assets that may sit outside conventional security coverage. [1][2][3][4]

Must Know

Exposed BMC password-hash retrieval

Identity · Security

What happened

An attacker reaching UDP port 623 on a server’s baseboard management controller can request and receive a password hash before authenticating, as part of the IPMI 2.0 handshake. [1]

The affected controller operates beneath the operating system and can power-cycle the host, mount virtual media, open a remote console, and flash firmware. [1]

Why it matters

Host security tools monitor the layer above the baseboard management controller. [1]

Cruciferra malware crypter service

Exploitation · Supply Chain

What happened

Proofpoint identified Cruciferra as a crypter-as-a-service used to evade antivirus detection and deliver malware across multiple campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams. [2]

Proofpoint’s report describes Cruciferra as written in Mono and using indirect system calls, API and IAT unhooking, BYOVD-based EDR tampering, privilege escalation, persistence, and customized Process Ghosting. [2]

Why it matters

Cruciferra’s payload-protection system uses varied custom encryption routines, apparently assembled from cryptographic components, making samples differ substantially and complicating static analysis and signature-based defenses. [2]

Shadow AI incident-response logging

AI & Agents · Policy

What happened

In a Help Net Security interview, Brandy Wityak of LevelBlue describes response after a shadow AI incident, including rapidly rolling logs and outbound-firewall records to AI platforms that may be unavailable before responders arrive. [3]

Wityak discusses the gap between having an AI policy in a wiki and having a control in place, but the supplied excerpt truncates the explanation. [3]

Why it matters

The interview addresses what regulators look for when assessing whether a company did enough after a shadow AI incident. [3]

VERITAS AI security research project

AI & Agents · Research

What happened

AI models, datasets, and automated systems used by researchers can be compromised in ways conventional cybersecurity tools are not designed to detect. [4]

The VERITAS project aims to establish AI Assurance as a core function of scientific research infrastructure to address this security gap. [4]

Why it matters

Treating AI assurance as research infrastructure frames models, datasets, and automated systems as security-relevant assets rather than assuming conventional controls cover them. [4]

Also Worth Knowing

Microsoft MDASH cybersecurity model evaluation

AI & Agents · Vulnerability

What happened

Microsoft launched its first cybersecurity-specific model inside MDASH, a multi-model vulnerability-identification and remediation harness. [5]

The reported benchmark and cost figures are Microsoft claims within a stated evaluation harness, so teams should distinguish model-evaluation results from operational assurance. [5]

SpecterOps AWS attack-path capabilities

Cloud · Identity

What happened

SpecterOps announced capabilities intended to help defenders understand adversary traversal of hybrid environments and proactively eliminate attack paths before abuse. [6]

Coverage across AWS and Entra Agent ID makes this relevant to teams assessing attack paths that cross identity and cloud boundaries. [6]

Bugcrowd Savant Pathseeker testing platform

Security · AI & Agents

What happened

Bugcrowd introduced Savant Pathseeker as the first solution in its Agentic Offensive Testing line. [7]

The stated emphasis on exploitability evidence distinguishes a testing claim from mere asset enumeration, while the broader coverage promise warrants practitioner scrutiny. [7]

Sources (7)
  1. [1] Exposed BMCs hand out password hashes before login

    helpnetsecurity · July 28, 2026

  2. [2] New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide

    securityaffairs · July 28, 2026

  3. [3] Shadow AI incident response begins with logs that may already be gone

    helpnetsecurity · July 28, 2026

  4. [4] VERITAS project could change the way scientists secure AI

    helpnetsecurity · July 28, 2026

  5. [5] Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

    the hacker news · July 28, 2026

  6. [6] SpecterOps brings AWS attack path management and AI to hybrid identity security

    helpnetsecurity · July 28, 2026

  7. [7] Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation

    helpnetsecurity · July 28, 2026