Hackers Use Hermes AI Agent to Automate Cyberattack on Thailand’s Finance Ministry

Cybersecurity researchers have uncovered a sophisticated cyber operation in which an attacker used the open-source Hermes AI agent to carry out post-exploitation activities against Thailand’s Ministry of Finance. Instead of manually controlling every step of the attack, the operator allowed the AI agent to work on its own with approval prompts disabled. This discovery highlights … Continued

Golden Chickens Returns With Four New Malware Families Targeting Sensitive Data

Golden Chickens, also known as Venom Spider, has once again come under the spotlight after cybersecurity researchers discovered four new malware families and updated modular implants linked to the group’s Malware-as-a-Service (MaaS) platform. The latest findings show that the group is actively improving its cyber tools to help criminals steal sensitive information and gain unauthorized … Continued

Hackers Abuse GitHub Actions to Attack cPanel and WHM Servers

A new cyber campaign has been uncovered in which attackers are abusing GitHub Actions runners and compromised GitHub repositories to launch attacks against internet-facing cPanel and WebHost Manager (WHM) servers. Instead of directly attacking victims from their own systems, the threat actors are using GitHub’s cloud infrastructure to perform scanning, exploitation, and data theft. Security … Continued

EU Fines Google $1 Billion for Search and Play Store Antitrust Violations

The European Union has fined Google €890 million (around $1 billion) after finding that the company violated the Digital Markets Act (DMA). According to the European Commission, Google used its strong position in online search and the Play Store in ways that gave its own services an unfair advantage over competitors. This is one of … Continued

Adobe Chrome Extension Flaw Exposed Private WhatsApp Chats to Malicious Websites

A serious security flaw was discovered in the Adobe Acrobat extension for Google Chrome that could allow malicious websites to access information displayed in WhatsApp Web. The issue did not affect WhatsApp’s end-to-end encryption directly, but instead abused the browser extension’s permissions. Security researchers from Guardio Labs named the attack HermeticReader and reported the problem … Continued

CISA Warns of Active Langflow AI Flaw That Lets Hackers Take Over Systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently fix a critical security vulnerability in Langflow after confirming that attackers are actively exploiting it in real-world attacks. The flaw, tracked as CVE-2026-0770, affects Langflow, a popular open-source platform used to build AI agents and AI-powered workflows. CISA has added the … Continued

New Bit2Watt Research Reveals How Cloud GPU Workloads Could Disrupt Power Grids Without Exploits

A new cybersecurity study has introduced a technique called Bit2Watt, showing how a cloud customer could potentially affect power infrastructure without exploiting any software vulnerability. Instead of breaking into systems, the attacker simply runs specially designed GPU workloads that remain within normal cloud permissions. Researchers say this creates a new type of cyber-physical risk where … Continued

US Seizes Over 1,000 Websites in Massive FIFA World Cup Piracy Crackdown

The U.S. Department of Justice has carried out one of its biggest anti-piracy operations during the 2026 FIFA World Cup by shutting down more than 1,000 websites that were illegally streaming tournament matches. Authorities also blocked access to 1,970 related internet domains that allowed users to watch games without official broadcasting rights. The operation was … Continued

Russian Hackers Hijack IP Cameras to Spy on NATO Military Supply Routes

Russian intelligence agencies have been accused of hacking internet-connected IP cameras across several NATO countries and Ukraine to secretly monitor military logistics and the movement of aid. According to a joint advisory released by Dutch intelligence and international security partners, the campaign focused on watching transportation routes used to deliver military equipment to Ukraine. Officials … Continued

Newsletter line