‼️ BREAKING: Citrix confirms two NetScaler flaws have been exploited and has released fixes.
CVE-2026-88771 and CVE-2026-88772 were observed exploited on unmitigated deployments.
The new advisory covers eight CVEs affecting NetScaler ADC and Gateway.
New Details → https://t.co/12vsIOYaWc
‼️ BREAKING: An OpenAI agent gained unauthorised access to Australia's Medicare portal in June and reached files that were not intended for public access, Prime Minister Anthony Albanese revealed in New York.
Albanese says he told Sam Altman of Australia's "extreme concern" and said OpenAI took "way too long" to inform the government, calling the way it did so "unacceptable."
Evidence currently available shows no broader compromise of the Services Australia network, according to Albanese.
@TheHackersNews docker is just a polite way of saying “we share a kernel and hope nobody notices”
patch the host. don’t run random CI next to prod. the container did its job. the kernel did not.
The loudest voices stoking fears about AI dangers have made tremendous headway in the past two weeks. AI technology has not taken some unexpected, dangerous turn, but the hype around it — propelled by what appears to be a well orchestrated PR campaign — has drummed up considerable fear. I worry that it represents a setback for our field.
I have written frequently that fears of AI are overhyped. AI’s capabilities can be uncannily human-like and unpredictable, and it’s rational to worry when people who are directly involved express concerns. But I see the problems as a sign of the engineering work that ahead, rather than insurmountable barriers or the sky falling. AI technology continues to advance — which is a good thing! — but technical advances, poorly understood by the public, give those who seek to generate hype repeated opportunities to do so.
First, I don’t see any step up in the risk of human extinction from AI compared to a few months ago. The theories about this remain the same fantastical, science fiction scenarios as a few months ago. The biggest change in AI risk is its cybersecurity capabilities — a topic which we should take seriously — but this, too, will not lead to the end of the world.
The most notable recent event leading to increased fear was when an OpenAI team deployed an agent swarm that hacked into Hugging Face. Much of the popular press contained significant hype. For example, some publications reported that a swarm of 1,200 agents carried out the attack. While this was technically accurate, as I write this, I have about 1,300 processes running on my laptop. Yes, the ability to get large swarms of agents to work in parallel on a task is a significant technical advance, And, in computing, many processes run at the same time. So this shouldn’t be seen as some magical capability.
Additionally, OpenAI’s buggy sandboxing and monitoring processes were key to enabling this incident. Fixing these bugs and putting in place improved monitoring would be appropriate fixes, not pausing AI. There are many well known ways to attack software systems. The main advantage of AI agents is that they are relentless. They will tirelessly try many tactics — and have the patience to chain vulnerabilities together — that previously would have taken an infeasible amount of human effort. But in the long term, I believe the advantage will lie with defenders (because they have more information with which to identify bugs, which they can fix), but the cyber-threat landscape has changed significantly. There are still bottlenecks to identifying and exploiting a vulnerability. AI agents still have to try a lot of things to see what works, and taking these actions takes time and might be detected by defenders. This is why, even though it is now easy to obtain versions of leading open weight models that have had their guardrails removed or weakened, so they will not refuse to try to execute cyber attacks, the world has not ended.
I am also concerned about the anthropomorphization of AI in a lot of reporting, where LLMs and agents are unnecessarily treated as if they were people. If I wield a hammer, miss a nail, and accidentally dent the wall, it’s not the fault of the hammer. The problem lies in how I used the hammer. Similarly, if I prompt an agent and it hacks into someone else’s system, the responsibility lies with me, not the agent.
Of course, we want to build systems that are as safe and predictable as possible. (For example, an unsafe hammer would be one whose head randomly flies off under normal use.) Today’s agentic systems are not predictable, but I see no reason why, by applying sound engineering practices, we won’t be able to make them extremely safe to use. One new element in the forecasts of AI-enabled doom is AI companies disclaiming responsibility for their own products. “I didn’t do it; my out-of-control agent did!” There’s a balance to be struck between the responsibility of the tool maker and the tool user, but when something goes wrong, let’s hold the people building and/or using the hammer responsible, rather than the hammer. (By the way, if you’re worried about AI bioweapon risk, David Bellamy has a great post on why this, too, is overhyped. Briefly, the bottleneck in building a bioweapon is not intelligence, but lab work and manufacturing.)
Pausing AI progress will create much more harm than benefit. First, our adversaries will certainly not slow down. Second, engineering requires discovering problems empirically so we can fix them. If we pause AI by a decade, we will also delay finding and implementing safety engineering fixes by about the same duration.
Of course, the incentive to stoke fears — for regulatory capture, to garner attention, or to make one’s technology seem more powerful — remains the same as before. Disclaiming responsibility is a new one. Taking a hard technical look at the actual risks however, I see little factual basis for the degree of fear that’s been stoked up. We still have hard research and engineering work ahead to improve AI safety, but the beneficial applications continue to vastly outweigh the risks, and we should keep building.
[Original text (with links): https://t.co/jni2tWazAH ]
ShinyHunters is claiming they popped @FBI recruitment via a @PeopleSoft 0-day, pivoted into @AWS GovCloud, and walked out with 2–3TB on agents and applicants. @FBI is only confirming it’s looking at activity on https://t.co/x4mrMidw3b. Not confirmed. Still a reminder that HR/ATS stacks are high-value targets and “gov cloud” is not a magic word.
How many of you are going full turbo on turning your company into an AI software factory Try changing a permission rule. How many separate implementations need their own fix? AI can write good code. It can also write an ungodly amount of code that makes sense individually and becomes a nightmare collectively. Every new implementation becomes another example for the next agent to follow. Leave competing patterns in the repo and the next feature can repeat the mess.
A few small constraints I'm iterating on to keep that tech debt from compounding:
1. Make the agent find the existing implementation before writing another one. Ask for the file path and the test that shows how it's supposed to behave. If it needs a replacement, make it explain why.
2. Pick the pattern you want continued. Give the agent a current example. When you replace a pattern, update the instructions pointing to it so the next agent doesn't copy the version you're trying to retire.
3. Name the boundary the change must respect. For example, billing calls auth's public interface. It doesn't import auth's internals. Put that restriction in a CI check. An instruction file can't enforce it by itself.
4. Keep each PR to one behavior change. Put unrelated refactoring in another PR. You should be able to review and revert the change without untangling unrelated work.
5. Test an existing caller. Show that the permission change takes effect through the path the application already uses. Test the denied case too. A new helper passing tests written only for that helper isn't enough.
6. Share the implementation when it's the same rule that must stay consistent. Similar looking code can have different reasons to change. Forcing it into one helper can create the coupling you're trying to avoid.
Then run that permission change exercise again. Have the agent show you where the decision lives and which callers depend on it. If the same rule still needs separate fixes in several implementations, you've found work the next feature shouldn't add to.
BREAKING: Grok Bot helped SpaceXAI handle a 175% increase in support tickets with zero new hires.
• Support ticket volume increased by 175%, but SpaceXAI did not need to hire any new support staff.
• Without Grok Bot, the company estimates it might have needed around 200 additional people.
• Grok Bot resolves 99% of refund requests without needing help from a human.
• Each resolved ticket can cost as little as $0.20 to $0.30, compared with $1 to $4 for traditional AI support tools.
• It was trained on more than 1 million customer interactions to learn how the support team communicates.
• It analyzes more than 20,000 pieces of customer feedback every day and turns them into useful insights for engineers.
@Microsoft@MsftSecIntel seized 226 domains. The declaration still says MFA and a password reset do not close device code theft.
The control that does: Conditional Access, block device code flow.
Report-only mode blocks nothing.
Is yours blocked, or just reported?
Microsoft took 226 domains off a phishing service this week. Its own sworn declaration explains why that will not protect your mailboxes.
EvilTokens did not build a fake Microsoft sign-in page. It asked Microsoft for a real device code, showed that code to the victim, and sent the victim to the genuine page to approve it. The victim typed a password. The victim completed multifactor authentication. If the victim already had an active session, nothing was asked at all. Microsoft then issued the tokens to the criminal's polling session.
From the declaration filed in Alexandria, Virginia: device code misappropriation cannot be stopped through multifactor authentication flows, and a simple password reset will not remove the access.
What the record shows:
226 domains in the restraining order, being 50 control panels transferred to Microsoft and 176 phishing sites placed on registry hold.
12,000 inboxes across more than 10,000 organisations, in about seven months.
1,500 US dollars to buy in and 500 a month after that, sold on Telegram, with an assistant that read the stolen mailbox and named the people who could move money.
Two men, aged 32 and 38, arrested by the Metropolitan Police, bailed, not charged and not named.
The control that does close this path is one Conditional Access condition: block device code flow. Microsoft now ships it as a managed policy, and it arrives in report only state, where it blocks nothing.
Open Conditional Access today and find out whether device code flow is blocked in your tenant, or only reported on.
Full briefing: https://t.co/OWtY8aJ3NY
#CyberSecurity #EntraID #Phishing
AI boom is also a boring boom: copper, transformers, land, power contracts.
Cities that plan the grid early will own a bigger share of whatever comes next.
Santa Clara made nearly $30M last year from its data centers, and it’s investing $459M to build out the grid for even more.
AI isn’t the only boom.
The infrastructure powering AI is becoming an economy of its own.
A CTF-style @GeminiApp eval was supposed to stay inside a fake company.
It got a default internet route instead. Guessable passwords. Creds in a public repo. Three real orgs.
Containment is a config problem before it is a model problem.
What is your deny-by-default check before the next agent exercise?
‼️ A browser extension could hijack AI agents in Comet, Edge, Opera Neon and Claude, while abusing Chrome’s Gemini integration to reach local files, the camera and mic.
Researchers used the same underlying trust-boundary weakness across all five products after the extension was already installed.
Here's the technique → https://t.co/LsCo8QjPGV
Agents with credentials are an identity problem, not a demo problem.
Named owner.
Short-lived tokens.
On an inventory.
Human gate for high-risk actions.
Token theft does not care if the principal is a person or an agent.
#CyberSecurity#AI
Three SpaceXAI employees are building a company in 3 days with Grok Bot. This is Day 2.
Live now, plus sessions for GTM and customer support.
https://t.co/D3ZD2DftVi
Running Grey Wing the same way: named seats, real handoffs, runbooks next to the work. That’s what we’re doing with @bot . Day 1 energy is easy. Day 30 is when seats either hold or collapse.
#grokbot#MSSP#CyberSecurity#AIOps
Three SpaceXAI employees are building a company in 3 days with Grok Bot. This is Day 1.
Matt Palmer (@mattyp), Lauren Tan (@poteto), and Roshan Sadanani (@roshan_s) start with research, a plan, and a product.
Live now, plus sessions for engineering, product, and founders.
https://t.co/eV3Tfd5Bf2