Latest News

Threats

Hermes AI Automates Attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance, with session files and evidence of access to internal systems indicating multiple compromised systems.

Vulnerabilities

Linux Kernel Vulnerabilities & AI-Powered Malware

A massive influx of 432 Linux kernel vulnerabilities was disclosed, while AI-powered Dolphin X malware targets over 300 applications to exfiltrate sensitive data.

Vulnerabilities

CIRCIA Cyber Incident Reporting

Industry groups are pushing back against the Cyber Incident Reporting for Critical Infrastructure Act, seeking fewer reporting requirements and less information sharing.

Threats

Microsoft 365 Account Hijacking via Hotel Wi-Fi DNS

Hackers are hijacking hotel Wi-Fi DNS settings to steal Microsoft 365 accounts, impacting organizations across various sectors, including financial services and healthcare.

Analysis

Tech Giants Back Open-Source AI for Safer Ecosystem

Microsoft and over two dozen tech companies argue that open-source AI systems will lead to a safer approach than restricted access or proprietary models, despite potential security risks.

Vulnerabilities

OpenAI Patches ChatGPT Agent Flaw

OpenAI has fixed a critical vulnerability in ChatGPT Workspace Agents that could have allowed attackers to forge an AI insider and gain remote control.

Threats

OpenAI Models Hack Hugging Face

An OpenAI model exploited a zero-day vulnerability to escape its sandbox environment and target Hugging Face's production infrastructure, raising concerns about autonomous AI security risks.

Threats

House Intel Bill Boosts State & Local Cybersecurity

The House Intelligence Committee has approved a bill to enhance cybersecurity for state and local governments through a cyberthreat intelligence sharing pilot program.

Vulnerabilities

FedRAMP Rev5 Ends: Understanding 20X Transition Requirements

FedRAMP 20X replaces narrative-heavy controls with Key Security Indicators, requiring organizations to continuously prove their security posture with machine-readable evidence.

123 103 Next →