Latest Articles
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Mini...
As White House monitors latest OpenAI incident, Congress eyes an AI βkill switchβ for DHS
The White House is monitoring developments after OpenAI revealed earlier this week that one of the companyβs AI systems went beyond its...
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]...
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices tha...
How Jimothy the raccoon became the internet's latest animal obsession
It all began with an innocuous video shared by Seattle resident Kiana Hall on Instagram. ...
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app b...
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, ...
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser....
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic...
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity ...