Posts of last 24 hours
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers […]
https://securityaffairs.com/195941/hacking/thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged.html
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hade
https://buaq.net/go-430714.html
Google 账号加入了可选的人脸识别登录。用户向 Google 提供自拍视频,随后就可通过人脸识别登录。在人脸验证过程中 Google 可能会要求用户以特定方式转动头部,此举旨在防止深度伪造之类的身份冒用,确保用户当前确实在摄像头前。Google 需要保存用户的自拍视频以将其用于未来的登录验证。搜索巨人表示会对视频进行加密,且仅用于登录不会用于其它用途。如果用户改变主意,可以从 Google 帐户中删除相关视频。
https://www.solidot.org/story?sid=84917
Google 账号加入了可选的人脸识别登录。用户向 Google 提供自拍视频,随后就可通过人脸识别登录。在人脸验证过程中 Google 可能会要求用户以特定方式转动头部,此举旨在防止深度
https://buaq.net/go-430709.html
Transform expert SOC analysis into an on-demand AI capability to empower all analysts and accelerate threat resolution.
https://www.sentinelone.com/blog/your-best-analyst-shouldnt-be-a-person-it-should-be-a-capability-everyone-can-summon/
For thirty years, we have measured security operations by the tools we buy. The next decad
https://buaq.net/go-430702.html
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
SectopRAT is at the center of a highly targeted malvertising campaign abusing Anthropic’s Claude platform to deliver a stealthy, HVNC‑enabled RAT that gives attackers deep, persistent access to victims’ passwords, credit cards, cookies and corporate files. The artifact masqueraded as a genuine Claude Desktop installer but redirected victims to claude.ai.download-app[.]us and then to downloading-api.it[.]com/html/claude/win, where […]
The post SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/sectoprat-campaign/
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization.
The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,
https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html