AI Agent Drives Espionage Attack on Thai Ministry of Finance

Thai Ministry of Finance Hit with Sophisticated AI-Driven Espionage Attack Threat actors have launched a brazen cyber-espionage operation against Thailand’s Ministry of Finance (MOF), leveraging an autonomous artificial intelligence (AI) agent to gather sensitive information. The attack, which unfolded from July 9 to 13, highlights the growing threat posed by large language models (LLMs) and … Read more

Shadow AI agents are multiplying. Here’s how to find and secure them.

A Silent Threat Multiplies: Shadow AI Agents Proliferate Across Organizations, Leaving IT and Security Teams Scrambling to Keep Up Shadow AI agents are rapidly multiplying across organizations, often without the knowledge or approval of IT and security teams. These autonomous software entities can be created in minutes using various tools, connected to sensitive systems with … Read more

Ernst & Young data breach claimed by ShinyHunters extortion gang

Ernst & Young’s Data Breach Exposes Client Tax Information, Raises Concerns Over Supply-Chain Attacks A major cybersecurity incident has unfolded at Ernst & Young (EY), one of the world’s largest professional services firms. The company disclosed a data breach earlier this month, where an attacker compromised its third-party support ticket system, potentially exposing sensitive client … Read more

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

A critical vulnerability in Arista’s VeloCloud Orchestrator has been actively exploited by attackers, leaving organizations with potentially compromised networks and sensitive data at risk. The flaw, designated as CVE-2026-16812, is a maximum-severity command injection vulnerability that allows remote attackers to access privileged functionality without authentication. VeloCloud Orchestrator (VCO) is a centralized management platform used for … Read more

Hackers target US firms in FastJson RCE zero-day attacks

US Companies Under Attack as Hackers Exploit Vulnerability in Popular Java Library A critical vulnerability is being actively exploited by hackers to target US-based organizations, with a few reported cases in Singapore and Canada. The issue lies in FastJson, an open-source Java library used for serializing data between Java objects and JSON formats. This widely-used … Read more

‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure

Significant security vulnerabilities have been discovered in two of the world’s leading cloud platforms, Microsoft Azure and Google Cloud Platform (GCP), allowing attackers to bypass critical access controls. These “confused deputy” flaws, which can be exploited to acquire administrative level permissions, have left enterprise and government resources at risk. Justin O’Leary, an independent security researcher, … Read more

New Certighost PoC exploit lets attackers hijack Windows domains

Windows Domains Left Vulnerable by Unpatched Certighost Exploit A potentially devastating vulnerability has been unearthed in Windows Active Directory Certificate Services, allowing authenticated attackers to hijack entire domains. The proof-of-concept exploit, dubbed “Certighost,” can be used to compromise even the most secure of networks. This critical flaw was patched as part of Microsoft’s July Patch … Read more

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A Devastating DDoS Botnet Has Emerged, Threatening Global Stability A massive and highly resilient distributed denial of service (DDoS) botnet has been spreading rapidly across the globe, compromising over 200,000 devices in its wake. Dubbed Dysphoria, this botnet is using a novel combination of blockchain-based command-and-control (C2) resolution mechanisms and sophisticated networking techniques to evade … Read more

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

A critical vulnerability in Arista’s VeloCloud Orchestrator (VCO) platform has been exploited by attackers, prompting the company to issue an emergency patch. The flaw, tracked as CVE-2026-16812, is a maximum-severity command injection bug that allows unauthenticated attackers to access privileged functionality and potentially compromise the confidentiality, integrity, and availability of the orchestrator and its managed … Read more

Hackers target US firms in FastJson RCE zero-day attacks

US Firms Under Attack as Hackers Exploit Critical Vulnerability in FastJson Library Hackers have been targeting US-based organizations with a devastating zero-day attack that leverages a critical vulnerability in the widely used FastJson Java library. The malicious activity, which has been observed by security researchers at ThreatBook and Imperva, affects various industries including finance, healthcare, … Read more