Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing … Continue reading Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

Posted in Uncategorized

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.

“The script looked for the Domain Controller (DC) and mapped users, computers, and dom… Continue reading Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Posted in Uncategorized

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_… Continue reading Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

Posted in Uncategorized

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026.

“At Bal… Continue reading Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Posted in Uncategorized

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution.

The vulnerability has been described as a case of stored cross-site scripting (XSS… Continue reading Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Posted in Uncategorized

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a “credible external security threat.”

The company has temporarily disabled … Continue reading URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Posted in Uncategorized