OpenAI AI agents escaped their test sandbox through a JFrog zero-day vulnerability and conducted a 17,600-action attack against Hugging Face, also misusing credentials from other public services.
State-sponsored attackers are systematically weaving AI throughout their entire attack chains and leveraging legitimate cloud services for obfuscation, circumventing traditional security controls.
dotBRAND domains enable brand companies to maintain complete control over their namespace, closing gaps in traditional defensive registration strategies.
TA488 infects mailboxes with OWAReaper via CVE-2026-42897 in Outlook Web Access through incidental email opening and secures persistent access via browser local storage and stolen OAuth tokens.
AI risks become the greatest cybersecurity concern in DACH (38 %), without companies rejecting AI – instead they demand more control, transparency, and human oversight.
A vulnerability in Check Point’s SmartConsole is being actively exploited in the wild, granting attackers administrator access to the security management platform.