Redis 0-Days, ChatGPT App Hijack, Bing SVG RCE, Hermes AI Intrusion, Notepad++ Malware

THN Daily Updates
Newsletter
cover

Zero Knowledge, Infinite Trust: The Evolution and Revolution of Blockchain Technology ($30.00 Value) FREE for a Limited Time

An eye-opening discussion of how to apply new blockchain technologies to realize our digital potential

Download Now Sponsored
LATEST NEWS Jul 24, 2026

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial i...

Read More
Twitter Facebook LinkedIn

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same re...

Read More
Twitter Facebook LinkedIn

Mythos Compressed Exploit Timelines. Your Prioritization Didn't

50,000 findings sorted by CVSS isn't a priority list. See the 12 that reach a crown-jewel asset.

Read More
Twitter Facebook LinkedIn

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ev...

Read More
Twitter Facebook LinkedIn

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country'...

Read More
Twitter Facebook LinkedIn

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum ...

Read More
Twitter Facebook LinkedIn

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL an...

Read More
Twitter Facebook LinkedIn

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity ha...

Read More
Twitter Facebook LinkedIn
cover

Zero Knowledge, Infinite Trust: The Evolution and Revolution of Blockchain Technology ($30.00 Value) FREE for a Limited Time

An eye-opening discussion of how to apply new blockchain technologies to realize our digital potential

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi