Drei Fragen und Antworten: Wie KI wirklich bei der Schwachstellensuche hilft (2026-07-24 12:53 UTC)
Kurz: Um KI erfolgreich in Code-Audits einzusetzen, ist die Wahl des Modells gar nicht so wichtig. Entscheidend ist der Workflow, damit man nicht in Funden versinkt.
OnTrac notifies customers of data breach after network hack (2026-07-24 19:55 UTC)
Kurz: OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. […]
Hermes AI agent used to automate attack on Thai Finance Ministry (2026-07-24 19:09 UTC)
Kurz: A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. […]
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts (2026-07-24 17:50 UTC)
Kurz: Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. […]
Kurz: The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineer…
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller (2026-07-24 14:15 UTC)
Kurz: Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Be…
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link (2026-07-24 11:53 UTC)
Kurz: Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agen…