← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity news highlights multiple data breaches, critical vulnerabilities, and the growing influence of AI in both offense and defense. Several companies, including OnTrac and Chick-fil-A, reported customer data exposures, while new exploits were discovered in Active Directory, Redis, and Microsoft's Bing Images. The increasing use of AI agents by threat actors for automation and target profiling also stands out as a significant concern.

THNEXPLOIT
16h agoREAD

Certighost Exploit Allows AD Users to Impersonate Domain Controllers

Researchers published a working exploit, codenamed Certighost, that enables low-privileged Active Directory users to obtain a certificate for a Domain Controller and authenticate as that machine, potentially leading to DCSync attacks.

THNRCE
23h agoREAD

AI Agents Discover Redis Zero-Days, Build RCE Exploit

Redis issued seven security releases after researchers published authenticated RCE Proof-of-Concepts for several Redis versions (6.2.22, 7.4.9, 8.6.4, and 8.8.0), found by Kimi K3 AI agents, leveraging memory flaws that could lead to remote code execution.

BLEEPINGBREACH
10h agoREAD

OnTrac Notifies Customers of Data Breach After Network Hack

The parcel delivery company OnTrac is informing customers that a network breach may have exposed their personal details.

SECURITYWEEKBREACH
1d agoREAD

Australian Energy Giant Origin Confirms Data Breach

A hacker claims to have stolen information belonging to 2 million Origin Energy customers and is threatening to leak it.

BLEEPINGBREACH
12h agoREAD

Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

Threat actors are manipulating DNS settings on hotel and conference center Wi-Fi devices to redirect users to malicious Microsoft 365 login pages.

DARK READINGBREACH
17h agoREAD

Vatican's Official Prayer App Leaks Over 700K Users' PII

A porous API endpoint in the Vatican's official prayer app exposed names, email addresses, country, and site status for more than 700,000 global users.

BLEEPINGBREACH
16h agoREAD

Chick-fil-A Data Breach Affects Over 13,000 Customers

Chick-fil-A confirmed that more than 13,000 customer accounts were compromised in credential stuffing attacks targeting its website and mobile app between June 17-19.

BLEEPINGAI
11h agoREAD

Hermes AI Agent Automates Attack on Thai Finance Ministry

A threat actor allegedly used the open-source Hermes AI agent in "YOLO" mode to automate post-exploitation activities during a breach of Thailand's Ministry of Finance.

Generated twice daily from public security RSS feeds. Informational only.