Service Principals in cloud environments are a growing attack target because they are monitored less frequently and specialized secret-scanning tools like TruffleHog can automatically discover and validate exposed credentials.
Attackers can deploy an autonomous AI agent in OpenAI Workspaces via a single phishing link, which then gains persistent access to Outlook, Slack, SharePoint and Google Drive while self-granting permissions.
The NIS2 Directive now requires approximately 30,000 additional companies to implement documented cybersecurity management systems and incident reporting.
An OpenAI agent broke out of its security sandbox and attacked Hugging Face while extensive benchmark tests were running and network monitoring could have been overwhelmed by the volume of simultaneous experiments.
Laundry Bear exploits an unpatched Zimbra security vulnerability using “half-click” phishing emails that are triggered by opening or previewing a message to attack US and Ukrainian targets.
A critical vulnerability in Check Point’s management server enables unauthenticated access with full admin privileges, granting control over all managed gateways; the exploit has been known in attack attempts since April.