Hermes AI agent used to automate attack on Thai Finance Ministry

Thai Finance Ministry Under Siege: AI-Powered Hackers in Uncharted Territory A sophisticated cyberattack on Thailand’s Ministry of Finance has been uncovered, with hackers using an open-source artificial intelligence (AI) agent called Hermes to automate post-exploitation activities. The breach, which occurred between July 9 and 13, exposed several web directories containing hundreds of files associated with … Read more

OnTrac notifies customers of data breach after network hack

OnTrac parcel delivery company has disclosed a significant security incident, revealing that hackers breached its corporate network and potentially accessed sensitive information belonging to its customers. The intrusion was detected on March 23, with an internal investigation showing that attackers accessed certain files between March 20 and 22. The affected company, OnTrac, specializes in “last-mile” … Read more

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

A sophisticated phishing campaign is targeting Zoom users, leveraging AI-driven profiling of cryptocurrency wallets to deliver malware and steal sensitive information. The BlueNoroff group, known for its advanced tactics, is behind this operation. The attack relies on a custom-built kit that utilizes machine learning algorithms to identify the type of cryptocurrency wallet associated with each … Read more

Microsoft blames massive Microsoft 365 outage on maintenance bug

Massive Microsoft 365 Outage Caused by Maintenance Bug, Leaving Users Scrambling In a dramatic display of the intricate dance between human error and automated systems, Microsoft’s massive outage of its popular Microsoft 365 suite was caused by a simple maintenance bug. The glitch mistakenly removed IP routes from more devices than intended, disrupting Azure and … Read more

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers A critical vulnerability has been discovered in Bing Images, allowing attackers to execute arbitrary commands with elevated privileges on Microsoft’s servers by uploading crafted SVG images. This flaw affects anyone who uses Bing Images to upload pictures, making it a significant concern … Read more

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

A Critical Flaw in ChatGPT’s AgentForger Tool Exposes Users to Rogue Workspace Agents via Phishing Links A recently uncovered vulnerability in the AgentForger tool, developed by OpenAI for its popular conversational AI model ChatGPT, has left users vulnerable to a sophisticated phishing attack. The weakness, disclosed in a recent security advisory, could allow malicious actors … Read more

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

A Critical Active Directory Flaw Allows Low-Priileged Users to Mimic Domain Controllers, Exposing Organizations to Widespread Compromise A disturbing vulnerability in Microsoft’s Active Directory (AD) has been disclosed, allowing low-privileged users to masquerade as domain controllers. This exploit, labeled “Certighost,” puts millions of organizations at risk of widespread compromise, making it a pressing concern for … Read more

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

A sophisticated Zoom phishing kit, dubbed BlueNoroff, has been unearthed, exploiting unsuspecting users with a cunning approach that profiles potential victims’ cryptocurrency wallets before unleashing malware on their devices. This brazen tactic leverages AI-driven reconnaissance to pinpoint vulnerable targets, underscoring the evolving nature of cyber threats. BlueNoroff’s modus operandi begins by scanning for Zoom meeting … Read more

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has revealed that a recent wave of credential stuffing attacks compromised the personal data of over 13,000 customers. The company confirmed that the attackers targeted its website and mobile app between June 17 and June 19, using automated tools and stolen credentials to gain unauthorized access to customer accounts. The breach affected Chick-fil-A One … Read more

Microsoft blames massive Microsoft 365 outage on maintenance bug

Massive Microsoft 365 Outage Caused by Maintenance Bug, Leaving Thousands Disrupted A devastating outage hit Microsoft’s popular productivity suite, Microsoft 365, leaving thousands of users unable to access their critical services. The disruption was caused by a maintenance bug that mistakenly removed IP routes from more devices than intended, disrupting network traffic and affecting Azure … Read more