ποΈ IAM for AI agents: A Practical Enterprise Framework ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identitycontrol architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The attacker who stole about 388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a thirdparty security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain highlevel internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malwareasaservice model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ β‘ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systemsoften without the same controls applied to human users. According to Oktas Global CISO Insights 2026 report, only 47 of CISOs are confident they can identify every AI agent in their environment. Even among those who feel.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an opensource artificial intelligence AI agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39line prompt directs it to execute tasks received through.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities KEV catalog, following reports of active exploitation. The vulnerabilities are listed below CVE202688771 CVSS score 9.5 An improper input validation vulnerability that could allow an unauthenticated attacker to.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π¨ Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway π¨
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
National Cyber Security Centre
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
π Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Bitget has restarted Bitcoin withdrawals after a 387.5m breach of its hot and warm wallets.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach
Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets
π NVIDIA Launches Open Platform to Secure Autonomous AI Agents π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
NVIDIA Launches Open Platform to Secure Autonomous AI Agents
NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents
π Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A quarter of victims of deepfake attacks have lost over 1m. CISOs worry that boardrooms dont understand the threat.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns
A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms donβt understand the threat
π MCP Is Creating Major Governance Gaps, Researchers Warn π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Ox Security found security shortcomings in analysis of over 15,000 MCP servers.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
MCP Is Creating Major Governance Gaps, Researchers Warn
Ox Security found security shortcomings in analysis of over 15,000 MCP servers
π Citrix Patches Critical Zero Days Under Active Exploitation π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Citrix has confirmed exploitation of two critical zeroday RCE bugs.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Citrix Patches Critical Zero Days Under Active Exploitation
Citrix has confirmed exploitation of two critical zero-day RCE bugs
π1
π UnderDefense Launches MAXI Service Desk, Delivering Direct Native Support for Enterprise Security Teams π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
New capability embeds SOC analyst communication directly into the UnderDefense platform, replacing slow ticket queues with contextaware, auditready support Jacksonville, FL, September 18, 2026. UnderDefense, a cybersecurity company delivering Agentic AI SOC and Compliance AI to enterprise clients across the US and EU, today announced the launch of MAXI Service Desk. The new native capability The post UnderDefense Launches MAXI Service Desk, Delivering Direct Native Support for Enterprise Security Teams appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
UnderDefense Launches MAXI Service Desk for Enterprise SOCs
UnderDefense introduces MAXI Service Desk, embedding native SOC analyst communication into its platform to deliver direct, context-aware enterprise support.
β€1
π¦
Attack Surface Management in 2026: Why Point-in-Time Scans Canβt Keep Up With Cloud Sprawl π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cloud infrastructure now changes by the hour, yet many security teams still map their external attack surface once a quarter or once a year. That mismatch creates blind spots that can last for months. A developer spins up a test environment on a Tuesday, an engineer opens a storage bucket for a partner on Wednesday, and a marketing team launches a campaign subdomain on Friday. If the next external assessment is scheduled for December, each of those assets sits exposed and unmonitored until then. For CISOs, security operations leads, and cloud security leads, the question is no longer whether the attack surface is growing. The question is whether visibility is keeping pace. In 2026, pointintime scanning is structurally unable to do that. Why Cloud Sprawl Breaks the Quarterly ...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
Attack Surface Management in 2026: Why Point-in-Time Scans Canβt Keep Up With Cloud Sprawl
Cloud assets change hourly, but most attack surface management run quarterly. See why continuous ASM with Cyble Odin closes the months-long exposure gaps.