New ‘Confused Deputy’ Flaws in Google Cloud and Microsoft Azure Could Lead to Privilege Escalation

Security researchers have discovered two new ″Confused Deputy″ vulnerabilities affecting Microsoft Azure and Google Cloud Platform (GCP). The flaws could allow attackers to misuse trusted cloud services and gain higher privileges than they should normally have. The findings were reported by independent security researcher Justin O’Leary. A Confused Deputy vulnerability happens when a trusted cloud … Continued

Hackers Used an AI Agent to Spy on Thailand’s Finance Ministry

Cybersecurity researchers have uncovered a sophisticated cyber-espionage campaign targeting Thailand’s Ministry of Finance. The investigation revealed that attackers used an open-source AI assistant called Hermes to automate many post-exploitation activities after gaining access to the ministry’s systems. Researchers discovered the operation while analyzing exposed attacker infrastructure that accidentally revealed valuable evidence about the ongoing attack. … Continued

Fake Microsoft Teams Update Used to Deploy Remote Access Tools in Operation BlueDash Attack

Cybersecurity researchers have uncovered a new phishing campaign called Operation BlueDash that tricks users into installing legitimate remote management tools through a fake Microsoft Teams update. The attackers send phishing emails containing a so-called secure document that appears genuine. When victims try to open the file, they are redirected to a fake Microsoft Store page. … Continued

Critical n8n Vulnerability Lets Workflow Editors Execute System Commands

A critical security vulnerability has been discovered in n8n, a popular open-source workflow automation platform used by organizations to automate business tasks and connect applications. Security researchers found that users with permission to create or edit workflows could escape the platform’s security sandbox and execute operating system commands on the server running n8n. This issue … Continued

Hackers Use Hermes AI Agent to Automate Cyberattack on Thailand’s Finance Ministry

Cybersecurity researchers have uncovered a sophisticated cyber operation in which an attacker used the open-source Hermes AI agent to carry out post-exploitation activities against Thailand’s Ministry of Finance. Instead of manually controlling every step of the attack, the operator allowed the AI agent to work on its own with approval prompts disabled. This discovery highlights … Continued

Golden Chickens Returns With Four New Malware Families Targeting Sensitive Data

Golden Chickens, also known as Venom Spider, has once again come under the spotlight after cybersecurity researchers discovered four new malware families and updated modular implants linked to the group’s Malware-as-a-Service (MaaS) platform. The latest findings show that the group is actively improving its cyber tools to help criminals steal sensitive information and gain unauthorized … Continued

Hackers Abuse GitHub Actions to Attack cPanel and WHM Servers

A new cyber campaign has been uncovered in which attackers are abusing GitHub Actions runners and compromised GitHub repositories to launch attacks against internet-facing cPanel and WebHost Manager (WHM) servers. Instead of directly attacking victims from their own systems, the threat actors are using GitHub’s cloud infrastructure to perform scanning, exploitation, and data theft. Security … Continued

EU Fines Google $1 Billion for Search and Play Store Antitrust Violations

The European Union has fined Google €890 million (around $1 billion) after finding that the company violated the Digital Markets Act (DMA). According to the European Commission, Google used its strong position in online search and the Play Store in ways that gave its own services an unfair advantage over competitors. This is one of … Continued

Adobe Chrome Extension Flaw Exposed Private WhatsApp Chats to Malicious Websites

A serious security flaw was discovered in the Adobe Acrobat extension for Google Chrome that could allow malicious websites to access information displayed in WhatsApp Web. The issue did not affect WhatsApp’s end-to-end encryption directly, but instead abused the browser extension’s permissions. Security researchers from Guardio Labs named the attack HermeticReader and reported the problem … Continued

CISA Warns of Active Langflow AI Flaw That Lets Hackers Take Over Systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently fix a critical security vulnerability in Langflow after confirming that attackers are actively exploiting it in real-world attacks. The flaw, tracked as CVE-2026-0770, affects Langflow, a popular open-source platform used to build AI agents and AI-powered workflows. CISA has added the … Continued

Newsletter line