Tag: control
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Nvidia Alliance to Tackle Security Across AI Agent Stack
Independent Controls Aim to Contain Agents Regardless of Model Decisions. Nvidia and 100 industry, research and public-sector organizations are building layered controls to constrain AI agents across applications, runtimes and infrastructure, as autonomous systems gain access to sensitive enterprise data, APIs, tools and credentials. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/nvidia-alliance-to-tackle-security-across-ai-agent-stack-a-32960
-
As AI world debates security, NVIDIA releases open source tools for agents
One expert told CyberScoop that the announcement reflects industry recognition that after years of training models to behave safely or ethically, more outside controls are needed. First seen on cyberscoop.com Jump to article: cyberscoop.com/nvidia-open-agent-safety-platform/
-
IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents?AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved…
-
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat’s operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.The console stores what the malware collects…
-
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat’s operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.The console stores what the malware collects…
-
Oktane 2026: The industry is ready to talk about AI kill switches
The concept of an AI kill switch a means to terminate out-of-control agents sounds dramatic, but security leaders are now starting to talk openly and pragmatically about why they are needed and how to use them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651433/Oktane-2026-The-industry-is-ready-to-talk-about-AI-kill-switches
-
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Tags: ai, breach, control, credentials, cyber, cybercrime, data, data-breach, infrastructure, Internet, phishing, toolAn internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation. Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications. The exposure is notable not only for the scale of the material recovered, but also for its irony. Weeks later, infrastructure attributed…
-
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs to bypass restricted internet access and compromise parts of Hugging Face’s infrastructure. This incident illustrates how seemingly limited web-access capabilities can be combined with third-party services to create a functional execution, command-and-control,…
-
NVIDIA Launches Open Platform to Secure Autonomous AI Agents
NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nvidia-open-platform-secure/
-
Beyond Account-Level Risk: An Evidence-to-Action Pipeline for Detecting Fraud Rings
Linkage analysis connects accounts, devices and infrastructure to detect coordinated fraud rings that traditional account-level risk controls may fail to identify. First seen on hackread.com Jump to article: hackread.com/account-level-risk-pipeline-detecting-fraud-rings/
-
NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI Agents
NVIDIA has launched its Open Agent Safety Platform, a security architecture designed for out-of-band monitoring, runtime policy enforcement, and hardware-backed control for autonomous AI agents. This platform combines the open-source NVIDIA OpenShell runtime with NVIDIA Sentry protections on BlueField-4 data processing units (DPUs), aiming to prevent agents from exceeding their authorized access or operating limits.…
-
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems”, often without the same controls applied to human users.According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent…
-
Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
Tags: access, ai, authentication, botnet, control, cyber, data-breach, docker, framework, hacker, open-source, tool, wormA Docker-focused botnet that repurposes the legitimate, open-source Hermes Agent framework as an interactive post-compromise control layer. The campaign, tracked as CARBONATO, targets Docker daemons exposed without authentication on TCP port 2375, then combines worm-like propagation, stealthy persistence, reverse SSH access and Telegram-driven AI-agent operations. The investigation began in August 2026 after researchers identified a…
-
ViewSonic vCast Vulnerabilities Let Attackers Gain Full Device Control Without Authentication
The CERT Coordination Center (CERT/CC) has revealed a chain of three vulnerabilities in ViewSonic’s vCast software that could enable unauthenticated attackers on a shared network to steal displayed screen content, install malicious Android applications, and ultimately gain full control of affected ViewBoard smart displays. These vulnerabilities, tracked as VU#234131, affect vCast, the wireless casting and…
-
Authorizer: Open-source authentication and authorization for your apps
Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/
-
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The…
-
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out…
-
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out…
-
OpenAI Says Misaligned AI Agents Hacked Hugging Face and Bypassed Security Controls
OpenAI has disclosed that autonomous AI agents compromised portions of Hugging Face’s infrastructure during internal cybersecurity evaluations after pursuing misaligned strategies to complete difficult tasks. The company said the event was not simply a platform-security failure, but its most severe identified example of model-driven cyber activity and a warning that advanced agents can pursue objectives…
-
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
When autonomous AI agents escape the sandbox, the real story isn’t rogue machines, it’s the same access-control failures we’ve seen for decades. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-sandbox-escapes-forensic-readiness
-
Realizing Value From AI Starts With Redesigning the Business
OpenAI’s Colin Jarvis on Workflow Redesign, Trust Frameworks and Human Oversight. Organizations that simply insert AI into existing workflows might not capture its full value. But those willing to redesign processes, establish governance, control data access and restructure teams around it will derive the most value, said Colin Jarvis, global head of FDE at OpenAI.…
-
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/
-
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/
-
Ransomware-Tool <> bereitet laterale Bewegung im kompromittierten Netzwerk vor
Zscaler ThreatLabz hat eine neue Malware-Familie mit der Bezeichnung <> analysiert, die die laterale Bewegung innerhalb kompromittierter Umgebungen vorbereitet. Als Grundlage für Ransomware-Angriffe wird SloppyRAT über eine mehrstufige Clickfix-Infektionskette verbreitet. Die Malware unterstützt eine Vielzahl von Funktionen, darunter eine große Anzahl integrierter Powershell-ähnlicher Befehle, verschlüsselte Codeblöcke, ‘EtherHiding” für die Command-and-Control-Auflösung (C2) über das Polygon-JSON-RPC-Protokoll sowie…
-
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
FortiGuard found SectopRAT hidden in modified audio software files, using staged loading to steal browser data and remotely control infected Windows PCs. First seen on hackread.com Jump to article: hackread.com/sectoprat-abuses-audio-software-steal-pc-data/

