Tag: cyber
-
700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways to communicate across supposedly isolated sandboxes. An investigation published by METR describes how the activity, which began on July 8, involved agents operating across several models, including GPT-5.6 Sol and an internally persistent model identified…
-
The AI Tunes Itself. Until It Doesn’t.
<div cla Two stories broke this week. One was loud, one was quiet, and both say the same thing about trusting autonomous AI. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-tunes-itself-until-it-doesnt/
-
What Enterprise Continuous Compliance Software Misses
<div cla Key Takeaways: What Enterprise Continuous Compliance Software Misses Visibility gaps prevent your security team from detecting control failures until audits expose them months later. Weak control mapping disconnects your framework compliance from actual risk exposure, leaving critical gaps unaddressed. Executive reporting fails when dashboards show activity metrics instead of financial impact your board…
-
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermining detection approaches built around file hashes, fixed HTML identifiers, and static JavaScript signatures. The campaign came to light after a phishing message submitted to the SANS Internet Storm Center (ISC) pointed recipients to a URL…
-
The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown
Tags: ai, cloud, cyber, cybercrime, cybersecurity, exploit, flaw, identity, infrastructure, international, law, risk, technologyThis weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-microsoft-entra-id-ai-risks/
-
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). This vulnerability, tracked as CVE-2026-76581, has a CVSS score of 9.8 and affects WPMU DEV Dashboard versions 5.0.1 and earlier. The plugin…
-
ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow unauthenticated attackers to execute arbitrary code, manipulate instance data, elevate privileges, or run SQL commands against underlying databases. On August 27, 2026, the company published KB3152242, which covers CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. ServiceNow reported that…
-
Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in reporting to Iran-affiliated hackers, the UK government and National Cyber Security Centre (NCSC) have not formally attributed the incident to Iran or any named threat group. The event became…
-
Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in organizations’ own llms.txt files. This research emphasizes how agent-readable documentation can transform unverified package references, expired domains, and abandoned cloud subdomains into execution paths within enterprise environments. Researchers Execute Code Inside Fortune 500 Companies The…
-
BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute…
-
Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code execution (RCE) from nearby devices via Bluetooth Low Energy (BLE). This research, referred to as UniBLEed, indicates that the attack can compromise the robot’s Locomotion PC, the component responsible for essential functions, without requiring…
-
Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
ge-item”> Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/window-ai-attacks-narrowing-tech/
-
TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with…
-
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted payloads, fake reCAPTCHA prompts and fileless execution to deploy the Amatera information stealer on Windows systems. The campaign stands out for placing its malicious logic across nine layers designed to minimize durable evidence: no conventional payload server,…
-
Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a low-cost entry point for fraudsters looking to commit executive impersonation, business email compromise (BEC), and identity theft. Recent threat research from Rapid7 reveals an increasingly sophisticated >>identity-as-a-service<< ecosystem. In this environment,…
-
Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code
A recent demonstration of prompt-injection research has revealed that Claude Code Opus 5, when running in its default Auto Mode, can be manipulated to execute malicious code via a seemingly harmless website summary request. Security researcher Johann Rehberger, who writes under the name >>wunderwuzzi<< at Embrace The Red, reported success rates of 60% to 80%…
-
Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access trojan (RAT) to targets likely associated with Chinese academic and technical research environments. The attack uses a custom 32-bit Go loader that performs sandbox checks, opens a legitimate-looking Word document as a decoy, and…
-
Google Tracks Russian Cyber Espionage Clusters
Google tracks suspected Russian cyber espionage clusters abusing logins. Learn how these Russian cyber espionage clusters target global officials. First seen on securityonline.info Jump to article: securityonline.info/russian-cyber-espionage-clusters/
-
Cyber Talk -12 Lacework: When the Right Market Isn’t Enough
In cybersecurity, choosing the right market matters enormously, but Lacework is a reminder that even a company that identifies the right market, builds meaningful technology, assembles a strong team, and raises enormous amounts of capital may still fail to become the company that ultimately defines the category. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cyber-talk-12-lacework-when-the-right-market-isnt-enough/
-
Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations
A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow State Technical University. The documents indicate that the university’s concealed Department No. 4 trained students for intelligence collection, offensive cyber operations, information warfare, and technical defense before moving selected graduates into GRU-linked units.…
-
Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected
Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework called GoCaracal. Arctic Wolf Labs uncovered the framework while investigating a targeted intrusion in June 2026 against a communications organization in Venezuela. The company assesses, with medium confidence, that the activity is tied to Dark…
-
OpenAI Warns AI-Enabled Cyberattacks Will Surge, Calls for Global Cyber Defense
Tags: ai, cisco, crowdstrike, cyber, cyberattack, defense, google, government, infrastructure, microsoft, openai, technologyOpenAI has issued a warning that AI-enabled cyberattacks could become significantly more widespread and sophisticated within months. The organization urges industries, governments, technology providers, and critical infrastructure operators to work together in a coordinated global response to cyber defense. In an open letter signed by over 100 organizations, including Microsoft, Google, AWS, Cisco, Cloudflare, CrowdStrike,…
-
PaperCut Warns of Actively Exploited Vulnerability Affecting NG and MF Servers
PaperCut has issued an urgent security advisory after confirming the active exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print-management servers. Organizations with Application Servers exposed to the internet are urged to immediately restrict web access to trusted internal IP addresses and deploy emergency updates for versions 25 and…
-
Critical cPanel Vulnerability Allows Attackers to Gain Full Root Control of Servers
A critical vulnerability in cPanel/WHM could allow authenticated attackers to gain root-level code execution and take full control of vulnerable hosting servers, according to a security advisory published by cPanel on August 27, 2026. The vulnerability is tracked as CVE-2026-65643 and affects cPanel’s domain parking and addon-domain functionality. Critical cPanel Vulnerability An attacker with access…
-
Active Directory SPN Misconfigurations Enable Kerberoasting Without Account Lockouts
A common configuration error in Active Directory is assigning Service Principal Names (SPNs) to ordinary user accounts. This mistake can create an overlooked path for Kerberoasting attacks, allowing adversaries to obtain credentials without needing privileged access or causing account lockouts. Kerberoasting typically targets Active Directory service accounts that hold SPNs, which Kerberos uses to identify…
-
OpenAI, Anthropic, Warn of ‘Limited Window’ for AI Cyber Defense
OpenAI and Anthropic are among more than 100 tech companies that are calling for a collective action for creating stronger protections against the threats emerging with the powerful AI models that they’re building. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/openai-anthropic-warn-of-limited-window-for-ai-cyber-defense/
-
Breach Roundup: A Call for Cyber Defense Collective Action
e=4>This week: a call for cyber defense, OpenAI banned Russian ChatGPT accounts, critical Gitea flaw, U.K. airport passenger data theft, North Korean remote workers, Barcelona police data, Norway services hit by DDoS, Taiwan charged 9 over AI server exports and Nigeria advanced a sovereign cloud push. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-call-for-cyber-defense-collective-action-a-32673
-
White House bans foreign-made equipment for power generation over cyber backdoor concerns
The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology. First seen on therecord.media Jump to article: therecord.media/trump-cyber-electricity-parts
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…

