Tag: access
-
Chinese-Speaking Hacker Uses DeepSeek Agent to Launch Autonomous Cyberattacks
Chinese-speaking threat actor “knaithe” (aka KnYuan) has been caught running an AI-enabled autonomous attack stack built around DeepSeek and the Hermes Agent framework, proving that large language models can now drive end”‘to”‘end offensive operations with minimal human oversight. Hermes provided terminal access, skills orchestration, and Model Context Protocol (MCP) integrations. At the same time, DeepSeek…
-
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, including potentially those managed internally by Microsoft. The issue specifically affected the service’s Gremlin API. It exposed a cross-tenant attack path that could bypass customer network isolation controls. CosmosEscape Vulnerability According…
-
Laufzeitautorisierung für KI-Agenten: Warum Zugriffskontrolle innerhalb der Sitzung wichtiger wird
KI-Agenten verändern die Sicherheitsarchitektur in Unternehmen. Sie greifen autonom auf Datenbanken, Cloud-Konsolen, Kubernetes-Cluster oder SSH-Hosts zu und führen dort Aktionen mit hoher Geschwindigkeit aus. Klassische Identitäts- und Zugangskontrollen reichen dafür nur bedingt aus: Sie prüfen häufig, ob ein Zugriff erlaubt ist, aber nicht granular genug, was während der Sitzung tatsächlich geschieht. Laufzeitautorisierung setzt genau an……
-
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Exploits can give persistent server access that survives credential rotation and disk re-imaging. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/
-
Breach Roundup: OpenAI Models on a Hacking Tear
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production. This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department and Angola teleco breached, SonicWall credential stuffing, Telegram founder charged in Russia, hidden prompt turns Microsoft Copilot into an AI worm. First seen on govinfosecurity.com…
-
Kremlin hackers are exploiting Exchange flaw to backdoor unpatched networks
Exploits can give persistent server access that survives credential rotation and disk re-imaging. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/
-
Why brand impersonation is becoming an initial access vector
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing…
-
Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices
Apple’s latest iPhone, iPad and Mac updates patch 194 unique security flaws involving root access, kernel code execution and protected data. The post Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apple-security-updates-194-vulnerabilities/
-
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
-
When AI Agents Escape Sandboxes, Old Security Rules Apply
OpenAI’s recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply
-
Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability
Silver Spring, MD, USA, July 28th, 2026, CyberNewswire To reduce identity risk when third-party AI agents access business systems, Aembit is launching a new integration with Snowflake to help enterprises securely govern third-party agents across platforms. Aembit, the identity and access management company for agentic AI, today announced a new integration with Snowflake, the AI…
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/
-
From Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global Investing
See how stablecoins, tokenized stocks and fractional investing lower costs and expand global access to US markets through modern financial super apps worldwide. First seen on hackread.com Jump to article: hackread.com/financial-super-app-rewrite-global-investing-economics/
-
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations First seen on hackread.com Jump to article: hackread.com/fake-it-calls-microsoft-teams-gogrpc-backdoor/
-
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR’s Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/ir-trends-q2-2026/
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate…
-
Top 10 Best VPN Alternatives For Secure Remote Access in 2026
In the rapidly evolving landscape of 2026, the traditional VPN is increasingly showing its age. While a VPN creates a secure, encrypted tunnel to a private network, it often functions like an >>all-access key,<< granting users broad, undifferentiated access once connected. This model presents a significant security risk, as a single compromised endpoint can give…
-
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed…
-
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved First seen…
-
Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access
Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone 11 and later models, as well as supported iPads. It should be prioritized for deployment…
-
Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed
A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed phishing email delivering a “secure document” lure. Victims are redirected through compromised infrastructur to a…
-
Wyden Calls for Edge Device Annihilation in US Government
US Senator Says Zero Trust Must Replace Legacy Edge Devices in 2028. Network devices conversion into nation-state hackers’ favorite initial access vector has a U.S. senator urging the federal government to phase out legacy, public-facing remote access systems in favor of zero trust architecture. Security experts have long flagged network edge devices as a risk.…
-
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers’ access controls. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure
-
UK court rejects Bahrain immunity claim in spyware case
The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court opinion. First seen on therecord.media Jump to article: therecord.media/uk-court-rejects-bahrain-immunity-claim-spyware-case
-
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user.SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not…

