by admin | Jul 24, 2026 | Uncategorized
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to...
by admin | Jul 24, 2026 | Uncategorized
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller...
by admin | Jul 24, 2026 | Uncategorized
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a...
by admin | Jul 24, 2026 | Uncategorized
A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITYSYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s testing got the same result on workers across different...
by admin | Jul 24, 2026 | Uncategorized
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many...
by admin | Jul 24, 2026 | Uncategorized
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection. The...