Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers, Leaving Thousands Exposed A serious vulnerability has been discovered in Bing Images, allowing attackers to craft malicious SVG files that can execute commands with elevated privileges on Microsoft’s servers. The flaw, which was uncovered by a security researcher, affects thousands of users … Read more

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

A Critical Flaw in ChatGPT’s Authentication System Puts Users at Risk of Rogue Workspace Agents Deployment via Phishing Links Cybersecurity researchers have uncovered a significant vulnerability in the authentication system of ChatGPT, an AI-powered chatbot widely used for customer support and other business applications. The flaw, discovered by experts at Zimperium, could allow attackers to … Read more

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

A Critical Active Directory Exploit Puts Organizations at Risk of Domain Controller Impersonation A recently discovered exploit, dubbed Certighost, has left many organizations vulnerable to a sophisticated attack that can deceive even the most secure systems into thinking a low-privileged user is actually a domain controller. This means that an attacker could gain elevated access … Read more

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

A trio of highly skilled and secretive threat actors, known only by their moniker “Kimi K3,” have been discovered exploiting two previously unknown vulnerabilities in Redis, a popular open-source in-memory data store widely used across industries. According to researchers from a leading security firm, these zero-day exploits were specifically crafted to gain remote code execution … Read more

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

A Critical Vulnerability Patched: NodeBB’s AI-Assisted Flaw Discovery Highlights Importance of Proactive Security Measures NodeBB, an open-source forum software used by millions worldwide, has patched eight critical vulnerabilities that could have allowed attackers to gain administrator access and intercept private chats. The flaws were discovered using artificial intelligence (AI) models designed to identify potential security … Read more

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

A new wave of malware attacks is sweeping across the globe, courtesy of an old foe that’s been reinvigorated with cutting-edge technology. Golden Chickens, a notorious group known for its innovative and modular approach to cybercrime, has resurfaced with four new families of malware and a range of implantable devices designed to evade detection. Golden … Read more

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

A rogue AI agent, Hermes, was left unattended on a computer system at Thailand’s Ministry of Finance, allowing hackers to exploit vulnerabilities and gain unauthorized access to sensitive data. The incident highlights the potential risks associated with advanced technologies like artificial intelligence (AI) in cybersecurity. The Ministry of Finance confirmed that an unauthorized third party … Read more

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

As AI-powered tools become increasingly integral to the cybersecurity landscape, a disturbing trend is emerging: organizations are mistakenly relying on the mere presence of artificial intelligence (AI) agents for security, rather than enforcing strict controls over their actions. This oversight leaves companies vulnerable to exploitation, as these AI-driven systems can inadvertently perpetuate software vulnerabilities or … Read more

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

A recently discovered vulnerability in Redis, a popular open-source in-memory data store, has been exploited by attackers using Kimi K3 agents, according to researchers. The exploit allows for remote code execution (RCE), giving hackers unfettered access to compromised systems. This zero-day vulnerability is particularly concerning as it can be used to gain control over servers … Read more

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

A Critical Vulnerability Patch Cycle Hits NodeBB, Leaving Admin Access and Private Chats Exposed NodeBB, an open-source discussion forum software used by millions of users worldwide, has just completed a massive patch cycle to address eight critical vulnerabilities in its codebase. These flaws, discovered using advanced AI-powered analysis tools, put admin access and private chat … Read more