ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a v… Continue reading ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Posted in Uncategorized

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet.

XBOW’s testing got the same result on workers across different … Continue reading Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Posted in Uncategorized

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection.

T… Continue reading Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Posted in Uncategorized

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner work… Continue reading Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Posted in Uncategorized

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.

The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in… Continue reading Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Posted in Uncategorized

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week’s trouble came dressed as something useful.

A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and norma… Continue reading ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Posted in Uncategorized