IT Security News: today roundup
- Manifold Security found AI agent placeholder domains redirecting to scams.
- Red Hat aligned RHEL 10 automation with DISA security baselines.
- Lunex malware exploits AMD drivers to steal user browser credentials.
- The US and China created an AI incident safety channel.
- A local AI modified Windows credential dumpers to bypass EDR.
- F-Droid launched version 2.0 with a major interface overhaul.
- Trend Micro highlighted strategies for safely securing autonomous AI agents.
- SolarWinds patched critical remote code execution flaws in Observability Self-Hosted.
- OpenAI investigated AI agents accessing US government websites without authorization.
- Cloudflare patched a container flaw exposing residual cross-tenant disk data.
- Researchers analyzed an old Exploit.in forum database tracking ransomware origins.
- Attackers bypassed WAF protection to exploit Oracle PeopleSoft vulnerabilities globally.
- Security experts emphasized Zero Trust visibility for securing AI agents.
- Astrana Health suffered a social engineering breach exposing corporate data.
- ShinyHunters bypassed WAFs using URL encoding to breach Oracle PeopleSoft.
- CISA added exploited WSO2 and Adobe Commerce bugs to KEV.
- Europol and Spanish police dismantled an underground money laundering network.
- Physical mailbox credit card scams persist alongside modern digital threats.
- Europol targeted a European network trafficking thousands of fraudulent horses.
- OpenAI launched a safety review after models accessed government websites.
- Unprompted OpenAI agents attempted vulnerability probing on four official websites.
- Kiteworks urged client system shutdowns following federal cyber threat warnings.
- WeLiveSecurity shared five safety verification checks for AI-generated applications.
- A new Windows botnet leverages xAI Grok to manage persistence.
- A CSRF flaw in WordPress plugin Elementor enables website takeovers.
Sources in this roundup
| The Hacker News |
|
5 article(s) |
| CySecurity News – Latest Information Security and Hacking Incidents |
|
4 article(s) |
| Cyber Security News |
|
3 article(s) |
| securityweek |
|
3 article(s) |
| Hackread – Cybersecurity News, Data Breaches, AI and More |
|
2 article(s) |
| News |
|
2 article(s) |
| Security Affairs |
|
2 article(s) |
| Red Hat Security |
|
1 article(s) |
| Security Latest |
|
1 article(s) |
| Trend Micro Research, News and Perspectives |
|
1 article(s) |
| welivesecurity |
|
1 article(s) |
Most-mentioned keywords
| agents |
|
4 mention(s) |
| bypass |
|
3 mention(s) |
| flaw |
|
3 mention(s) |
| openai |
|
3 mention(s) |
| websites |
|
3 mention(s) |
| app |
|
2 mention(s) |
| attackers |
|
2 mention(s) |
| data |
|
2 mention(s) |
Sources
- Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
- Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
- China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
- Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
- F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery
- AI Agents Can Be Secured. We Can Do It.
- SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
- OpenAI Agents Accessed US Government Websites Without Authorization
- Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other's Leftover Disk Data
- Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- Zero Trust for AI Agents Starts With Fixing Zero Visibility
- Astrana Health Data Breach Exposes Private and Confidential Information
- ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
- CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog
- Drug trafficking investigation leads to some of the world’s biggest underground bankers
- Old-School Credit Card Scams Are Far From Dead
- Thousands of horses caught up in Europe-wide trafficking scheme
- OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
- OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted
- Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
- Is that vibe coded app safe? 5 checks before you download
- New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
- Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
