Tag: control
-
Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used to obtain root access, establish persistent control, and collect mailbox authentication secrets. The issue resides in Zimbra’s SNMP notification processing path. An attacker can send a specially crafted SMTP request containing shell metacharacters, allowing attacker-controlled input to reach…
-
US sanctions 10 over ATM malware scheme tied to Tren de Aragua
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs. First seen on therecord.media Jump to article: therecord.media/us-sanctions-10-atm-jackpotting-tren-de-aragua
-
Trump, Tech Giants Strike Voluntary AI Safety Accord
The new White House Accord on so-called Super Intelligence calls on companies to implement greater controls and oversight over AI safety. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/trump-tech-giants-strike-voluntary-ai-safety-accord
-
Trump, Six AI Giants Sign ‘Super Intelligence’ Safety Accord
Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/trump-ai-giants-super-intelligence/
-
Saudi Arabia’s next AI challenge is turning infrastructure into capability
Magna AI executive says governance, operational ownership and sovereign control will determine whether organisations can scale artificial intelligence beyond pilots First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651211/Saudi-Arabias-next-AI-challenge-is-turning-infrastructure-into-capability
-
Saudi Arabia’s next AI challenge is turning infrastructure into capability
Magna AI executive says governance, operational ownership and sovereign control will determine whether organisations can scale artificial intelligence beyond pilots First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651211/Saudi-Arabias-next-AI-challenge-is-turning-infrastructure-into-capability
-
RSA Agent ID Secures AI Agents and MCP Servers With Identity-Based Access Controls
RSA has launched RSA Agent ID, an identity security platform that discovers, secures, and governs AI agents and Model Context Protocol (MCP) servers in highly regulated environments. The company states that this offering addresses a growing “agentic identity” gap by applying workforce-style identity governance, authorization controls, and auditability to non-human AI actors. Announced at The…
-
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
-
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
-
WSL containers are generally available on Windows
Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls images from. WSL … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/microsoft-wsl-containers-available/
-
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/
-
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/
-
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/
-
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/
-
How Cybersecurity Can Help Rein In Surging AI Token Costs: Experts
The same cybersecurity tools and services that are now being deployed to protect increasing AI usage may also provide the visibility needed to bring AI spending under control, solution and service provider experts tell CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/how-cybersecurity-can-help-rein-in-surging-ai-token-costs-experts
-
Catch threats before they escalate with real-time Identity Telemetry
Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity before it escalates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/catch-threats-before-they-escalate-with-real-time-identity-telemetry/
-
Webinar: Closing the accountability gap in AI-assisted delivery
Source control records who committed code. It does not record who made the decisions behind it, and that gap is widening as AI agents take on more of the delivery process. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/29/cleverbit-webinar-ai-assisted-delivery-accountability/
-
AI Agents Are Becoming Privileged Identities. Is IAM Ready?
Royal Bank of Canada, Ping Identity on Privilege, Runtime Control and AI Governance. AI agents can act independently at machine speed, creating new identity and privilege risks. Melissa Carvalho of Royal Bank of Canada and Gaurav Sharma of Ping Identity discuss how enterprises can discover shadow agents, enforce least privilege, authorize actions at runtime and…
-
Proof of Concept: When AI Agents Get More Authority
Royal Bank of Canada, Ping Identity on Privilege, Runtime Control and AI Governance. AI agents can act independently at machine speed, creating new identity and privilege risks. Melissa Carvalho of Royal Bank of Canada and Gaurav Sharma of Ping Identity discuss how enterprises can discover shadow agents, enforce least privilege, authorize actions at runtime and…
-
New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits
Tags: ai, api, botnet, control, credentials, cyber, ddos, infrastructure, intelligence, malware, service, theft, threat, windowsA newly identified Windows botnet dubbed x47.c is marketing a blend of conventional DDoS tooling, credential theft, SOCKS5 proxying, fast-flux command-and-control infrastructure, and an “AI API drain” capability designed to exhaust victims’ paid artificial-intelligence service credits. Qrator Research Labs identified the previously undocumented malware platform during threat hunting. They traced its sale to an operator…
-
Palo Alto Networks and NVIDIA want tighter control over AI agents
Palo Alto Networks is expanding its work with NVIDIA to help companies control what AI agents can access and do. The collaboration covers agent activity, network traffic and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/29/palo-alto-networks-nvidia-ai-agent-security/
-
DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new Ethereum-based recovery channel dubbed HashHiding. The technique stores an active C2 IP address and port inside the recipient address of ordinary Ethereum transfers, allowing infected systems to recover attacker infrastructure without relying on domains, smart contracts, or transaction…
-
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions.”An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…

