Policy & LegalInfosecurity Magazine·3 days ago

NCSC Urges Stronger Controls for Agentic AI Systems

The UK's National Cyber Security Centre has issued guidance recommending sandboxing, oversight mechanisms, and strict access controls as essential safeguards for autonomous AI agents. These recommendations aim to mitigate security risks inherent in agentic AI systems that operate with limited human intervention.

OtherThe Hacker News·3 days ago

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Researchers at the University of Massachusetts Amherst have discovered a "Zombie Card" attack that allows expired Visa contactless cards to be used for in-store purchases by manipulating the expiration date read by POS terminals over NFC, without compromising the card's cryptographic protections. The attack requires only physical access to the card and demonstrates a vulnerability in how contactless payment systems validate card expiration data during transactions.

VulnerabilityCISA Advisories·3 days ago

Johnson Controls Simplex Incident Manager

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges. View CVE Details Affected Products Johnson Controls Simplex Incident Manager Vendor: Johnson Controls Inc. Product Version: Johnson Controls Simplex Incident Manager: <=V2.01 Product Status: known_affected Remediations Mitigation Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging. Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-28. https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Mitigation Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems. Relevant CWE: CWE-316 Cleartext Storage of Sensitive Information in Memory Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.8 MEDIUM CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L 4.0 5.8 MEDIUM CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N Acknowledgments Johnson Controls reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity. Revision History Initial Release Date: 2026-08-20 Date Revision Summary 2026-08-20 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28 Legal Notice and Terms of Use

VulnerabilityCISA Advisories·3 days ago

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-72529 (missing authentication for critical function) and CVE-2026-72530 (code injection), both showing evidence of active exploitation. Under BOD 26-04, federal agencies must prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices.

Data BreachMalwarebytes Labs·3 days ago

9 million images of people’s faces exposed by reverse lookup service

A researcher discovered an exposed database containing 9 million facial images belonging to ClarityCheck, a people finder service. The exposure represents a significant privacy breach affecting the sensitive biometric data stored by the reverse lookup platform.

Policy & LegalThe Hacker News·3 days ago

Why "Shady AI" is Security's Next Big Governance Problem

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee

MalwareThe Hacker News·3 days ago

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Researchers have disclosed a pair of denial-of-service attacks called "CDN Tsunami" that exploit HTTP/3 to HTTP/1.1 translation in major CDNs, achieving amplification factors of up to 350x against origin servers. The vulnerability stems from how content delivery networks convert client-facing HTTP/3 traffic into backend HTTP/1.1 requests, allowing attackers to magnify relatively modest bandwidth into devastating attacks on protected websites. The attacks were evaluated against multiple major CDN providers.

MalwareThe Hacker News·3 days ago

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud

OtherHelp Net Security·3 days ago

Corero brings cloud-based AI threat analysis to SmartWall ONE

Corero Network Security has integrated AI-Augmented Cloud-Assist into SmartWall ONE, adding cloud-based AI analysis and threat intelligence to its automated DDoS protection platform. The enhancement enables faster identification of emerging attack patterns and rapid generation of protective policies that can be deployed manually or automatically within seconds. This development reflects the industry's need for AI-driven defenses to match the sophistication of AI-powered attack campaigns.

OtherHelp Net Security·3 days ago

AWS limits AI agents’ data access, even when manipulated

AWS has introduced a method for maintaining user authorization context through AI agents, enabling infrastructure and downstream services to enforce access controls rather than depending solely on the agent itself. This approach addresses a critical security gap where agents without knowledge of the requesting user could potentially return unauthorized information, even when manipulated. Customers using Amazon Bedrock AgentCore can now build AI agents that safely access various data sources including DynamoDB tables, document repositories, and SaaS platforms while maintaining proper access restrictions.

VulnerabilityThe Hacker News·3 days ago

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have discovered a critical vulnerability chain in NASA/JPL's AIT-GUI operator console that enables unauthenticated attackers to send arbitrary commands to spacecraft and instruments. The flaw, rated 9.4 CVSS severity and tracked as GHSA-p9r8-2q67-fp86, affects the browser-based interface used with the open-source AMMOS Instrument Toolkit.

VulnerabilityInfosecurity Magazine·3 days ago

ICS Operators Warned of AI-Driven Attacks on Siemens PLCs

US government officials have alerted industrial control system operators to an emerging threat involving AI-generated exploitation scripts targeting exposed Siemens S7 Series PLCs. The advisory highlights how attackers are leveraging artificial intelligence to automate and accelerate attacks against critical infrastructure programmable logic controllers.

OtherThe Cyber Express·3 days ago

Guild Group’s Mohammad Arif on the Security Risks of Enterprise AI

Autonomous AI agents are now accessing sensitive enterprise data, writing code, and executing workflows once reserved for trusted employees, fundamentally shifting the attack surface and enterprise trust model beyond traditional cybersecurity controls. Mohammad Arif, Head of Information Security at Guild Group, warns that most organisations are treating AI security as a future problem despite widespread adoption already underway, and advocates for embedding AI governance into procurement, data protection, identity management, and incident response as a board-level priority. Over the next 12 months, enterprises should expect AI-assisted social engineering, sensitive data leakage into unapproved tools, insecure AI integrations with excessive permissions, and third-party AI supply-chain risks to materialise across their expanded attack surface.

MalwareHelp Net Security·3 days ago

Fake Gemini installer delivers Vidar infostealer via Google Colab lure

Attackers used a fake Google Gemini installer to deliver the Vidar infostealer onto a company network in the EMEA region, leveraging Google Colab—a legitimate cloud-based development platform—as part of the distribution chain. Darktrace researchers discovered the campaign, which exploited search results pointing to malicious files hosted on Google's own infrastructure to enhance credibility and evade detection.

MalwareThe Hacker News·3 days ago

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

Researchers have discovered ToxicPanda 2.0, an updated Android banking malware featuring 167 remote commands and expanded global targeting capabilities. The malware includes a PIN harvesting workflow designed to compromise over 140 banking and cryptocurrency applications, demonstrating significant functional enhancements in its attack infrastructure.

PhishingUnit 42·3 days ago

Identity Abuse Through Trusted Communication Channels

Attackers are exploiting trusted enterprise collaboration tools to conduct identity phishing and steal credentials from organizations. Unit 42 provides analysis of these attack techniques and outlines key defensive strategies to mitigate the threat.

Load more