Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

24/07/2026 0 Comments 0 tags

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

24/07/2026 0 Comments 0 tags

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

24/07/2026 0 Comments 0 tags

A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITYSYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

24/07/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

24/07/2026 0 Comments 0 tags

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

24/07/2026 0 Comments 0 tags

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

24/07/2026 0 Comments 0 tags

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

23/07/2026 0 Comments 0 tags

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

23/07/2026 0 Comments 0 tags

Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

23/07/2026 0 Comments 0 tags

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with