OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

A Critical Flaw in OpenAI’s ChatGPT Workspace Agents Exposes Organizations to Insider Threats Cybersecurity researchers have uncovered a severe vulnerability in OpenAI’s ChatGPT Workspace Agents, which could allow attackers to create an invisible autonomous agent that can be remotely controlled and used for malicious activities. The flaw, dubbed “AgentForger,” is a tailored cross-site request forgery … Read more

Flaws in Passkey Implementation Show Old Attacks Still Work

As Microsoft gears up to make passkeys the default authentication method for its cloud-based identity and access management service, a closer look at their implementation has revealed some unsettling vulnerabilities. Researchers from SpecterOps have found three nearly exploitable zero-day flaws in Windows 11 and Microsoft Entra ID that could allow attackers to impersonate privileged users, … Read more

Agentic AI Challenges Progress in Confidential Computing

As Confidential Computing Hits Mainstream, Agentic AI Presents New Security Challenges The adoption of confidential computing has been gaining momentum in recent years, thanks to significant advancements in technology. However, a new threat model is emerging as artificial intelligence (AI) becomes increasingly prevalent in enterprises. Agentic AI, which refers to AI agents that can think … Read more

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian State-Sponsored Hackers Exploit Zimbra Zero-Day in Sophisticated Phishing Campaign A highly sophisticated phishing campaign has been uncovered, targeting Western governments and enterprises through a vulnerability in the popular email management system, Zimbra Collaboration Suite (ZCS). The attack, attributed to a Russian state-sponsored threat group dubbed “Laundry Bear,” has compromised networks of US and Ukrainian … Read more

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

A New Era of Stealthy Malware: msaRAT Uses Browsers to Route C2 Traffic Cybersecurity researchers have uncovered a sophisticated new backdoor dubbed msaRAT that is being used by the Chaos ransomware gang to evade detection and maintain control over compromised systems. What’s particularly noteworthy about this malware is its ability to route command-and-control (C2) communication … Read more

New RefluXFS Linux flaw lets attackers gain root privileges

A new Linux vulnerability has been discovered that allows attackers to gain root privileges on systems with an XFS filesystem. Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), this security flaw affects millions of Linux users worldwide and poses a significant threat to system integrity. The vulnerability, tracked as CVE-2026-64600, has been present in … Read more

Australian energy provider Origin says data breach exposes client data

Australian Energy Provider Origin Confirms Data Breach Exposing Client Information to Threat Actors A significant data breach has been confirmed by Australian energy provider Origin Energy, exposing the personally identifiable information (PII) of an unknown number of its 4.8 million customers. The company is currently investigating the scope of the breach and will notify affected … Read more

New Dolphin X malware uses AI to rank high-value targets

A New Malware Threat Emerges with AI-Powered Profiling Feature Cybercriminals have been exploiting artificial intelligence (AI) in various ways, from launching spam campaigns to conducting autonomous cyberattacks. The latest development in this trend is a new malware called Dolphin X, which uses an AI-powered profiling feature to identify high-value targets among infected users. This remote … Read more

Microsoft working to fix Exchange Online mailbox quarantine issue

A major issue is unfolding for Microsoft’s Exchange Online users, with thousands of mailboxes mistakenly quarantined since Sunday. The problem, which has been ongoing for four days, has left users unable to receive and send emails, access their calendars, or even send emails to those whose mailboxes are incorrectly marked as quarantined. At the heart … Read more