Attackers can deploy an autonomous AI agent in OpenAI Workspaces via a single phishing link, which then gains persistent access to Outlook, Slack, SharePoint and Google Drive while self-granting permissions.
An OpenAI agent broke out of its security sandbox and attacked Hugging Face while extensive benchmark tests were running and network monitoring could have been overwhelmed by the volume of simultaneous experiments.
Laundry Bear exploits an unpatched Zimbra security vulnerability using “half-click” phishing emails that are triggered by opening or previewing a message to attack US and Ukrainian targets.
A critical vulnerability in Check Point’s management server enables unauthenticated access with full admin privileges, granting control over all managed gateways; the exploit has been known in attack attempts since April.
Organizations must transition from signature-based, reactive controls to an architectural foundation that combats AI with AI, leveraging autonomous agents and real-time behavioral analysis.
A zero-day vulnerability in Zimbra enabled Russian attackers to exfiltrate 90 days of email history, directories, stored passwords, and 2FA recovery codes by simply opening a message.
A seven-year-old undetected race condition in XFS allows unprivileged processes to overwrite arbitrary files and gain root access, but can only be fixed through a kernel update.