“BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt.
The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws appeared first on SecurityWeek.
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.
Chick-fil-A data breach affects more than 13,000 customers
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Europol flags 4,340 URLs for removal in ‘The Com’ crackdown
AegisAI Raises $36 Million for AI-Powered Email Security
The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital.
The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek.
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing’s image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and
