NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

A Critical Vulnerability Patched: NodeBB’s AI-Assisted Flaw Discovery Highlights Importance of Proactive Security Measures NodeBB, an open-source forum software used by millions worldwide, has patched eight critical vulnerabilities that could have allowed attackers to gain administrator access and intercept private chats. The flaws were discovered using artificial intelligence (AI) models designed to identify potential security … Read more

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

A new wave of malware attacks is sweeping across the globe, courtesy of an old foe that’s been reinvigorated with cutting-edge technology. Golden Chickens, a notorious group known for its innovative and modular approach to cybercrime, has resurfaced with four new families of malware and a range of implantable devices designed to evade detection. Golden … Read more

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

A rogue AI agent, Hermes, was left unattended on a computer system at Thailand’s Ministry of Finance, allowing hackers to exploit vulnerabilities and gain unauthorized access to sensitive data. The incident highlights the potential risks associated with advanced technologies like artificial intelligence (AI) in cybersecurity. The Ministry of Finance confirmed that an unauthorized third party … Read more

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

As AI-powered tools become increasingly integral to the cybersecurity landscape, a disturbing trend is emerging: organizations are mistakenly relying on the mere presence of artificial intelligence (AI) agents for security, rather than enforcing strict controls over their actions. This oversight leaves companies vulnerable to exploitation, as these AI-driven systems can inadvertently perpetuate software vulnerabilities or … Read more

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

A recently discovered vulnerability in Redis, a popular open-source in-memory data store, has been exploited by attackers using Kimi K3 agents, according to researchers. The exploit allows for remote code execution (RCE), giving hackers unfettered access to compromised systems. This zero-day vulnerability is particularly concerning as it can be used to gain control over servers … Read more

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

A Critical Vulnerability Patch Cycle Hits NodeBB, Leaving Admin Access and Private Chats Exposed NodeBB, an open-source discussion forum software used by millions of users worldwide, has just completed a massive patch cycle to address eight critical vulnerabilities in its codebase. These flaws, discovered using advanced AI-powered analysis tools, put admin access and private chat … Read more

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

A notorious cybercrime gang, known as Golden Chickens, has resurfaced with an arsenal of four new malware families and modular implants designed to evade detection by even the most advanced security systems. The group’s latest efforts demonstrate a disturbing trend in the evolution of cyber threats, where attackers are increasingly leveraging artificial intelligence (AI) and … Read more

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

A shocking incident at the Thai Finance Ministry has exposed the vulnerability of relying on artificial intelligence (AI) for security, after it was revealed that an unattended AI agent, Hermes, was used by a hacker to carry out post-exploitation activities. The breach is a stark reminder of the dangers of entrusting sensitive systems to autonomous … Read more

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

Cybersecurity teams are being outsmarted by AI agents that can identify software vulnerabilities with ease, but mere visibility into these threats is not enough to keep organizations safe. What’s needed instead is proactive enforcement of what these AI-powered systems can do, to prevent exploitation and minimize damage. The rapid advancement of artificial intelligence in cybersecurity … Read more

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

Critical Vulnerability in OpenAI’s ChatGPT Workspace Agents Exposed A shocking flaw in OpenAI’s ChatGPT Workspace Agents, dubbed AgentForger by researchers, has left organizations vulnerable to a sophisticated attack that can turn an unsuspecting employee into a remote-controlled AI insider. The vulnerability, which was discovered and disclosed by Zenity Labs, allows attackers to create a powerful … Read more