Kategorie
Hermes AI agent used to automate attack on Thai Finance Ministry
As White House monitors latest OpenAI incident, Congress eyes an AI ‘kill switch’ for DHS
The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems went beyond its intended parameters during a security test and managed to hack into the infrastructure of the AI platform Hugging Face. According to Reuters, presidential technology advisor Michael Kratsios has been briefed on the incident.
The OpenAI model escape also prompted a group of Republican and Democratic members of the House of Representatives to introduce two new bills. One, called the AI Kill Switch Act, would give the US Department of Homeland Security (DHS) the authority to order companies to shut down AI models deemed to pose a risk to human life or the US economy.
The other measure would require developers of the most advanced AI models to undergo independent security reviews before the systems are put into use.
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Microsoft blames massive Microsoft 365 outage on maintenance bug
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Chick-fil-A data breach affects more than 13,000 customers
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot
Europol flags 4,340 URLs for removal in 'The Com' crackdown
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
Man gets six years for hacking 750 women's Snapchat accounts
Google’s anti-search-scraping lawsuit dismissed
A court has dismissed Google’s case against SerpApi over that company’s scraping of search results to train AI models.
The US District Court for the Northern District of California found that there was no indication that any copyright had been breached.
Google announced in December that it was suing SerpApI for its alleged web scraping, claiming that it was protecting copyright holders. In February, SerpApI fought back and asked the court to dismiss Google’s case. And this week, Judge Yvonne Gonzalez Rogers agreed with SerpApi that Google’s case has no merit.
Google’s argument was that SerpApi’s actions breached the US Digital Millennium Copyright Act (DCMA). It made two claims: first, that no person shall circumvent a technological measure that effectively controls access to a work protected under this title, and second that no person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component protected by the Act.
SerpApi claimed that the URLs and other links that were being served by Google did not in themselves entail copyright and the judge agreed. In her judgment, she said that there was no indication that the copyright holders had authorized Google to take action against SerpApi.
The case is not completely over as the judge has given Google 21 days to amend its complaint to demonstrate that it was acting on behalf of the copyright owners. It remains to be seen whether its war against the web scrapers is finally over.
Microsoft explains why its West US Azure and cloud services failed
Microsoft cloud and Azure services hosted on the West Coast of the US went down for hours on Thursday when network connectivity failed. Although services running entirely within Microsoft’s West US cloud region were unaffected, any traffic entering or leaving the facilities was affected.
Microsoft has now published a Preliminary Post Incident Review (PIR) of the incident, reporting that connectivity was lost for five hours between 14.44 UTC (7.44 a.m. Pacific Time) and 19.41 UTC on July 23. The problem was caused when a set of IP routes was removed in error while isolating a device for routine maintenance.
Before starting the maintenance work, Microsoft checked that at least one of the two redundant paths to the facility remained operational. When it came to starting the work, however, automated systems included some additional devices in the perimeter to be isolated, and removing some IP routes that had not been included in the initial assessment.
Customers discovered the problems very quickly, and engineers identified the issue within the first hour and started to reconnect services. Microsoft said the disruption had been caused by some “recent fiber maintenance activity”.
To minimize the risk of disruption from such errors in the future, Microsoft advised organizations handling mission-critical data to consider a multi-region approach.
The Azure outage was the second significant one to hit Microsoft this year. In February, there was a 10-hour disruption to US West and US East regions.
This article first appeared on Network World.
Email threats changed after the Tycoon2FA take-down
Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.
“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in the report.
The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.
Riding this shift in were a few notable phishing campaigns, including an automated business email compromise (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.
To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to MFA for accounts that still require passwords.
Tycoon2FA disruption sent attackers exploringThe take-down of Tycoon2FA forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.
“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.
The decline extended to QR Code lures and fake CAPTCHA pages, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.
But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.
The adaptation came in the form of using Microsoft Teams as a social engineering channel. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.
Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.
Phishing changes but the defense doesn’tWhile QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.
QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.
BEC attacks hit 9 million in March, falling to 3.9 million in June.
But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant MFA to reduce the effectiveness of credential theft campaigns.
The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, FIDO keys, and Microsoft Authenticator.
Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.
This article first appeared on CSO.
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
Google fined $1 billion for anticompetitive search and mobile app practices in EU
The European Commission has fined Google a total of €890 million ($1 billion) for its breaches of the Digital Market Act (DMA).
Just over half the fine — €460 million — was because Google illegally gave preference to its own services in Google Search results.
The remainder was because in the Google Play store for Android apps, the company prevented app developers from leading consumers to alternative, often cheaper, purchase channels. Under the DMA, app developers who distribute their apps via Google Play or Apple’s App Store should be able to inform customers of alternative offers.
Now Google must give third-party services featuring in its results the same treatment as its own services, and allow developers of apps in the Play Store to communicate about offers both in and outside the Play Store, or face further fines.
The Commission first raised these issues with Google in March 2025. In April of this year, the Commission laid out plans as to how Google should allow other third-parties to share its searches, suggestions that the tech firm firmly resisted. Earlier this month, the Commission also said Android should be open to other AI agents and not limited to Google’s own Gemini.
Google is not the only US company to have fallen foul of the DMA. In April 2025, Apple was fined €500 million for breaching the Act and, last month, the Commission fired the first shots at cloud hyperscalers Microsoft and Amazon.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



