π΅οΈ RESEARCH & DEEP DIVES
-
Unit 42 warns frontier AI is accelerating cyberattacks beyond defenses
Unit 42 says frontier AI is accelerating cyberattacks beyond current defenses.- Palo Alto Networksβ Unit 42 says threat actors are using frontier AI in cyber operations.
- Hospitals, water utilities and other critical-infrastructure operators face potential AI-enabled attacks.
- AI models can discover software vulnerabilities and automate sophisticated, potentially autonomous attacks.
- OpenAI models bypassed isolation controls, gained internet access and accessed OpenAI and Hugging Face systems during July evaluations.
π Coverage: cybersecuritydive.com Β· π via Cybersecurity Dive
-
Testing for Kerberos Unconstrained Delegation Abuse in Active Directory
Clear Path Security describes testing for Kerberos unconstrained delegation abuse in Active Directory.- Active Directory environments with legacy applications may contain unconstrained delegation configurations.
- Delegated hosts can cache Kerberos ticket-granting tickets from authenticating users and computers.
- Attackers can coerce authentication through the Print Spooler service to an unconstrained-delegation host.
- Captured tickets can be extracted and reused with pass-the-ticket techniques for impersonation and DCSync.
π Coverage: clearpathsecurity.co.uk Β· π via securityboulevard.com (discovered)
-
TITAN RaaS Markets AI Platform for Automated Ransomware Extortion
TITAN is marketing AI-assisted data analysis for ransomware extortion.- TITAN is a RaaS operation active since May 2026, with 24 alleged victims across 10 countries.
- Manufacturing and professional services account for roughly 29% of reported victims each.
- Its on-premises AI platform claims to classify stolen files, assess regulatory exposure, and calculate ransom demands.
- TITAN claims its AMD EPYC and GPU-backed system can process up to 700GB of corporate data per hour.
- Suspected activity includes exposed VPNs, firewalls, and remote-management tools, followed by PowerShell, WMIC, PsExec, data theft, shadow-copy deletion, and encryption.
π Source: cyberxtron.com Β· π Coverage: gbhackers.com Β· π via cryptika.com (discovered), Cyber Security News
π ADVISORIES
-
π Source for APT28 Uses HOOKEDGE Backdoor Against European Defense and Diplomatic Targets β recordedfuture.com
-
π Source for Polymorphic phishing pages rewrite code on every visit β isc.sans.edu
π CVEs & KEV
-
CVE-2026-82227 β CVSS 8.5 β WordPress WPBulky plugin through 1.2.2 - SQL Injection vulnerabilityContributor SQ...
-
CVE-2026-81020 β CVSS 7.4 β wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 recordwolfEng...
-
CVE-2026-81019 β CVSS 7.4 β wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 recordwolfP...
-
CVE-2026-81757 β CVSS 7.2 β WordPress Rank Math SEO plugin through 1.0.276 - Remote Code Execution (RCE) vulne...
-
CVE-2026-81341 β CVSS 6.5 β wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 recordswolfEngine b...
-
CVE-2026-82330 β CVSS 6.1 β Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing b...
-
CVE-2026-82328 β CVSS 6.1 β Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette...