Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

24/07/2026 0 Comments 0 tags

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

24/07/2026 0 Comments 0 tags

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

24/07/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

24/07/2026 0 Comments 0 tags

A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITYSYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

24/07/2026 0 Comments 0 tags

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

24/07/2026 0 Comments 0 tags

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

24/07/2026 0 Comments 0 tags

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

24/07/2026 0 Comments 0 tags

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

23/07/2026 0 Comments 0 tags

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

23/07/2026 0 Comments 0 tags

Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders