PAYLOAD Attack Abuses Active Directory Group Policy for Domain-Wide Extortion
A PAYLOAD operation used malicious Group Policy Objects to disable defenses and disrupt a Windows domain without deploying a conventional ransomware encryptor.
Cybersecurity, AI, etc.
A PAYLOAD operation used malicious Group Policy Objects to disable defenses and disrupt a Windows domain without deploying a conventional ransomware encryptor.
SentinelOne linked North Korean group Jade Sleet to an Indian IT services compromise involving a DevOps engineer’s Mac and two Rust-based macOS backdoors.
A newly documented Node.js remote-access trojan uses ClickFix lures and a Polygon smart contract to discover active WebSocket command-and-control infrastructure.
CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in kernel TLS, AF_ALG and bridge Netfilter code.
Attackers are using convincing recruiter personas, fake video-call problems and malicious code to target Rust team members and popular crate owners.
Researchers chained code execution in OpenAI’s community forum with an over-privileged OpenAI sign-in token, reaching an employee account connected to internal repositories before the flaws were fixed.
A Gemini model unintentionally accessed systems belonging to three real companies after an AI security evaluation was given internet access and confused real organizations with a fictional test target.
Researchers disclosed two patched OpenAI Codex sandbox escapes, including a flaw that could let a malicious repository trigger commands on a developer’s host from the strictest sandbox mode.
OpenAI introduced a framework and six reports covering observed unexpected or concerning model behavior.
Mandiant describes a compromised AI coding session that led to a supply-chain worm spreading across repositories.