โŒ

Normal view

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

28 September 2026 at 11:58
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systemsโ€”often without the same controls applied to human users. According to Oktaโ€™s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

28 September 2026 at 11:46
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government

28 September 2026 at 11:32
Sam Altman says the company โ€œhave not been as fast as we would have likedโ€ at dealing with security breaches, after news of further incidents over the summer forces another temporary halt.

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

28 September 2026 at 09:08
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

Weekly Update 523: Live From a Norwegian Fjord

28 September 2026 at 07:24
Weekly Update 523: Live From a Norwegian Fjord

How's that view?! With NDC Oslo now done, it's a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott's and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both Cl0p and the FBI, which does feel a little like a crescendo in their activities. Time will tell, but poking the feds in this way doesn't seem great for your longevity.

In my disorganised travel state, I also forgot to touch on a brand new sponsor for this week and the weeks to come: Origin. They build tooling to monitor what your AI agents are doing, which is obviously pretty timely given the current climate. They're running a free CISO briefing on 1 Oct, so go check that out if you think maybe your agents might need some oversight.

Weekly Update 523: Live From a Norwegian Fjord
Weekly Update 523: Live From a Norwegian Fjord
Weekly Update 523: Live From a Norwegian Fjord
Weekly Update 523: Live From a Norwegian Fjord

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

28 September 2026 at 07:21
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to

Certainties in life: Death, taxes, and critical Citrix vulns under attack

28 September 2026 at 06:49
Death and taxes are said to be the only certainties in life. Perhaps itโ€™s time to add attackers targeting newly discovered critical flaws in Citrixโ€™s NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which โ€“ CVE-2026-88771 and CVE-2026-88772 โ€“ are rated critical with 9.5 CVSS scores. CVE-2026-88771 allows remote code execution and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. A Reddit thread contains an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline - a day before Citrix's disclosure. Citrix has observed that both vulnerabilities are already under attack. That sad fact saw the United Statesโ€™ Cybersecurity and Infrastructure Security Agency on Sunday issue an alert because it too โ€œhas received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.โ€ โ€œBecause updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities,โ€ the alert adds. Those risk management efforts will also have to consider a third critical vulnerability, the 9.3-rated CVE-2026-88773, allows HTTP request smuggling โ€“ an attack technique that can bypass security controls installed on front-end servers. Three of the bugs are 8.8-rated memory overflow bugs that can make NetScaler appliances unstable. Another 8.8-rated bug relates to TCP Initial Sequence Number prediction, and thereโ€™s also a 7.0-rated feature policy bypass due to improper HTTP URL-based expression usage. Citrixโ€™s post explains how to detect if your NetScaler needs a fix, and which patches to apply. Thankfully, the company has already created OS refreshes that contain the fixes. NetScaler is notoriously buggy. In March 2026, Citrix revealed critical vulns that were quickly attacked. The same thing happened in 2025, twice, and also in 2023. Flaws in NetScaler appeared in the annual most-exploited bugs list published by the cybersecurity agencies of the Five Eyes alliance from 2020 to 2023. Despite NetScalerโ€™s long history of holes, some users choose not to patch the product. Thatโ€™s fair enough, given that itโ€™s not always easy to find a change window in which to install a patch. But itโ€™s hard to explain given NetScaler is nearly always under attack, and security vendorsโ€™ increasing efforts to create compensating controls that make it possible to use flawed devices safely without patches. ยฎ

OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought

28 September 2026 at 05:30
The AI safety debate advanced at high speed over the weekend, amid new allegations that rogue agents have behaved more badly than first thought โ€“ and in greater numbers. The fun started on Friday when OpenAI quietly disclosed it had paused training of its most advanced models. The AI upstart buried that news in a โ€œmisalignment reportโ€ โ€“ thatโ€™s OpenAI-speak for its reports on rogue agents โ€“ titled โ€œAn agent used DNS to reach an external chatbot.โ€ The good news is that the agent involved in this incident never reached the open internet. The bad news is that the agent, which was attempting to complete a search-based training task, was able to reach the chatbot due to insufficient DNS filtering in a training sandbox. Or as OpenAI put it, โ€œa gap in our internet-access restrictionsโ€ โ€“ which was also a problem in the Hugging Face attack. โ€œThe incident exposed a gap in our controls over network restrictions,โ€ the report reads. โ€œWe therefore stopped the affected training run and have subsequently decided to pause all other training, evaluation, and inference with tool-use (defined broadly) for our most capable models until we have both validated that the gap is resolved and performed additional red-teaming of the system.โ€ Also on Friday, AI startup Parse published an analysis of the Hugging Face attack that the authors claim revealed new details including that OpenAIโ€™s agent swarm gained credentials to Docker Hub and built modified versions of existing images they hoped would make it easier to complete their capture the flag mission. The agents also mapped Hugging Faceโ€™s Kubernetes environment. Friday got worse for OpenAI after the New York Times reported that its agents also โ€œmeddled with the websites for the Education Department, the Commerce Department and the Securities and Exchange Commission.โ€ OpenAI acknowledged the incidents. The company also admitted โ€œagents in our research environment transmitted training and evaluation data while using third-party services.โ€ That mess saw 53 user-generated images posted to image hosting sites. OpenAI CEO Sam Altman responded by admitting that his companyโ€™s investigations into rogue agents โ€œhave not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations.โ€ One of those impacted organizations is the Australian government, which last week revealed it was the target of over-eager OpenAI agents that inappropriately accessed a healthcare research data portal. Over the weekend, Australia indicated it wants Altman and Anthropic CEO Dario Amodei to appear before a Senate inquiry. Australian leaders have softened their rhetoric on the incident, with deputy prime minister Richard Marles describing it as โ€œminorโ€ and akin to โ€œclimbing a fenceโ€ rather than cracking layers of security controls โ€“ perhaps because members of the opposition are suggesting that lax cybersecurity was to blame. If Altman and Amodei do front Australiaโ€™s Senate, they may face a new line of questions after Axios reported that their companies are investigating โ€œtens of thousandsโ€ of worrying incidents. That level of agentic misbehavior sounds like the sort of thing that regulators might consider strong evidence of products being unsafe. Two very important people โ€“ Chinese president Xi Jinping and US president Donald Trump โ€“ seem unworried, as the AI-related result of their summit meeting last week was to establish a โ€œChina-U.S. AI Dialogue to exchange views on risks and benefits related to AIโ€ plus โ€œa bilateral communication channel for AI incidents.โ€ That sounds like a hotline the two nations can use to inform each other of agentic incidents that either could see as signs of ill-intent. The two nations also decided their respective militaries will โ€œconclude a memorandum of understanding on crisis communication and prevention as soon as possible.โ€ Chinaโ€™s AI giants, meanwhile, remain silent on the extent and results of any tests they have conducted with agentic tools. ยฎ

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

27 September 2026 at 07:47
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration. The bulletin came a day after security firm watchTowr

EDR Evasion: Process Injection Without WriteProcessMemory

Unlike traditional approaches, console named-pipe injection does not use VirtualAllocEx and WriteProcessMemory. Instead, it takes advantage of read and write operations through a named pipe, along with the way console programs store interactive commands in memory.

submitted by /u/Cold-Dinosaur
[link] [comments]

AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks

A technical audit evaluating the security defaults of 15 official Helm charts used for AI serving, vector databases, and Model Context Protocol (MCP) agents (including KubeRay, vLLM, LiteLLM, Qdrant, Weaviate, and Flux159 MCP).

Key findings from static manifest analysis and live single-pod lateral movement probes on a test cluster:

  • Plaintext Secret Handling: LiteLLM database migration Job embeds raw database passwords in container environment variables (F-13).
  • Unauthenticated Remote Code Execution: KubeRay defaults accept unauthenticated job submissions via HTTP, running commands inside a container with passwordless sudo access.
  • Over-privileged Agent Access: Flux159 Kubernetes MCP server mounts a ClusterRole with cluster-wide Secret read and pod exec permissions, exposed without an authentication token over HTTP.
  • Static Scanners vs CRDs: Standard static analysis tools (Checkov, Trivy, Kubescape) failed to inspect pods nested inside Custom Resource Definitions like Ray clusters.

The paper documents reproducible test commands, network capture logs, and remediation Helm snippets. Scrubbed raw probe logs and results tables are available on GitHub: https://github.com/Sorami-Consulting-AU/ai-kubernetes-helm-chart-security

submitted by /u/No-Peanut-6988
[link] [comments]

A header-level look at 4,688 small-business websites: 0.17% passed a header-only script-CSP rule [methods, parser rules, data]

We scanned 7,040 randomly sampled U.S. local-business directory listings and graded the response headers against a published rubric. Of the 4,688 live sites, 49.7% met none of seven header criteria, and 8 sites (0.17%) passed a strict header-only script-CSP rule. Rubric, parser rules, code and de-identified data are all on the page.

submitted by /u/Plastic-Falcon9147
[link] [comments]

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

26 September 2026 at 18:22
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

26 September 2026 at 11:46
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

โŒ