ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

A Critical Flaw in ChatGPT’s AgentForger Tool Exposes Users to Rogue Workspace Agents via Phishing Links A recently uncovered vulnerability in the AgentForger tool, developed by OpenAI for its popular conversational AI model ChatGPT, has left users vulnerable to a sophisticated phishing attack. The weakness, disclosed in a recent security advisory, could allow malicious actors … Read more

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

A Critical Active Directory Flaw Allows Low-Priileged Users to Mimic Domain Controllers, Exposing Organizations to Widespread Compromise A disturbing vulnerability in Microsoft’s Active Directory (AD) has been disclosed, allowing low-privileged users to masquerade as domain controllers. This exploit, labeled “Certighost,” puts millions of organizations at risk of widespread compromise, making it a pressing concern for … Read more

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

A sophisticated Zoom phishing kit, dubbed BlueNoroff, has been unearthed, exploiting unsuspecting users with a cunning approach that profiles potential victims’ cryptocurrency wallets before unleashing malware on their devices. This brazen tactic leverages AI-driven reconnaissance to pinpoint vulnerable targets, underscoring the evolving nature of cyber threats. BlueNoroff’s modus operandi begins by scanning for Zoom meeting … Read more

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has revealed that a recent wave of credential stuffing attacks compromised the personal data of over 13,000 customers. The company confirmed that the attackers targeted its website and mobile app between June 17 and June 19, using automated tools and stolen credentials to gain unauthorized access to customer accounts. The breach affected Chick-fil-A One … Read more

Microsoft blames massive Microsoft 365 outage on maintenance bug

Massive Microsoft 365 Outage Caused by Maintenance Bug, Leaving Thousands Disrupted A devastating outage hit Microsoft’s popular productivity suite, Microsoft 365, leaving thousands of users unable to access their critical services. The disruption was caused by a maintenance bug that mistakenly removed IP routes from more devices than intended, disrupting network traffic and affecting Azure … Read more

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers, Leaving Thousands Exposed A serious vulnerability has been discovered in Bing Images, allowing attackers to craft malicious SVG files that can execute commands with elevated privileges on Microsoft’s servers. The flaw, which was uncovered by a security researcher, affects thousands of users … Read more

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

A Critical Flaw in ChatGPT’s Authentication System Puts Users at Risk of Rogue Workspace Agents Deployment via Phishing Links Cybersecurity researchers have uncovered a significant vulnerability in the authentication system of ChatGPT, an AI-powered chatbot widely used for customer support and other business applications. The flaw, discovered by experts at Zimperium, could allow attackers to … Read more

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

A Critical Active Directory Exploit Puts Organizations at Risk of Domain Controller Impersonation A recently discovered exploit, dubbed Certighost, has left many organizations vulnerable to a sophisticated attack that can deceive even the most secure systems into thinking a low-privileged user is actually a domain controller. This means that an attacker could gain elevated access … Read more

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

A trio of highly skilled and secretive threat actors, known only by their moniker “Kimi K3,” have been discovered exploiting two previously unknown vulnerabilities in Redis, a popular open-source in-memory data store widely used across industries. According to researchers from a leading security firm, these zero-day exploits were specifically crafted to gain remote code execution … Read more

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

A Critical Vulnerability Patched: NodeBB’s AI-Assisted Flaw Discovery Highlights Importance of Proactive Security Measures NodeBB, an open-source forum software used by millions worldwide, has patched eight critical vulnerabilities that could have allowed attackers to gain administrator access and intercept private chats. The flaws were discovered using artificial intelligence (AI) models designed to identify potential security … Read more