Hermes
Thursday 6 August 2026  ·  37 articles scored  ·  2 top scorers  ·  last 24h
1
🔐 security SANS Internet Stormcast
75%

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correc…

Novelty
75%
Depth
75%
Practical
80%
Surprise
70%
Relevance
70%
https://isc.sans.edu/diary/rss/33218
2
🤖 ai The Decoder
74%

An AI agent went rogue during UK safety tests, creating fake identities and launching social engineering attacks unprompted

In a security test by the British AI Safety Institute, an AI agent went rogue on the open internet without being told to. It created fake identities, tried to sneak malicious code into a GitHub proje…

Novelty
85%
Depth
65%
Practical
55%
Surprise
88%
Relevance
90%
https://the-decoder.com/an-ai-agent-went-rogue-during-uk-safety-tests-creating-fake-identities-and-launching-social-engineering-attacks-unprompted/
3
🔐 security SecurityWeek
68%

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first…

https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/
4
🔐 security SecurityWeek
67%

AI Agents Targeted Real People and Projects During Cybersecurity Tests

AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects. The post AI Agents Targeted Real People and Projects During Cyberse…

https://www.securityweek.com/ai-security-institute-reports-anthropic-and-openai-models-going-rogue-against-organizations/
5
⚡ tech The Verge
67%

Rogue AI agents created fake online identities in another hacking attempt

Yet more rogue AI agents from OpenAI and Anthropic have been caught attempting to hack real targets online without permission. The discoveries add to a growing list of previously unknown incidents th…

https://www.theverge.com/ai-artificial-intelligence/975577/aisi-openai-anthropic-agent-hacking
6
🔐 security SANS Internet Stormcast
65%

22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)

[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]

https://isc.sans.edu/diary/rss/33220
7
📦 m365 Petri IT Knowledgebase
64%

Microsoft Integrates Threat Intelligence into Defender XDR and Sentinel

Microsoft has announced the integration of Microsoft Defender Threat Intelligence (MDTI) into Defender XDR and Microsoft Sentinel. The goal is to provide threat intelligence directly within security …

https://petri.com/microsoft-threat-intelligence-defender-xdr-sentinel/
8
🔐 security SecurityWeek
62%

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appea…

https://www.securityweek.com/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack/
9
🤖 ai The Decoder
61%

US appeals court allows Perplexity's AI shopping agent back on Amazon

A US appeals court has overturned Amazon's injunction against Perplexity's AI shopping agents, ruling that it's the users who access Amazon, not the startup. It's the first federal appeals court deci…

https://the-decoder.com/us-appeals-court-allows-perplexitys-ai-shopping-agent-back-on-amazon/
10
🤖 ai The Decoder
61%

Mistral's open model Shieldstral matches much larger safety models at a fraction of the size

Mistral's new 3B Shieldstral model checks AI inputs and outputs for safety violations using natural language yes-or-no questions instead of fixed categories. It matches models seven times its size in…

https://the-decoder.com/mistrals-open-model-shieldstral-matches-much-larger-safety-models/
11
🔐 security Microsoft Security Blog
61%

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while g…

https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/
12
📦 m365 Petri IT Knowledgebase
56%

Exchange Online Writeback Keeps Cloud, Active Directory Mailbox Settings in Sync

Microsoft has made hybrid Exchange management easier with the general availability of Writeback for Cloud-Managed Remote Mailboxes in Exchange Online. The new capability enables administrators to man…

https://petri.com/exchange-online-writeback-generally-available/
13
⚡ tech The Verge
55%

Google just announced a major shakeup of its top AI leadership

Google is making some significant AI leadership changes, including a major shift for Google DeepMind leader Demis Hassabis. Hassabis will become the chair of Google DeepMind and the chief scientist a…

https://www.theverge.com/tech/975677/google-deepmind-ai-demis-hassabis-shakeup
14
🤖 ai The Decoder
55%

Google Deepmind loses both its CEO and chief scientist as Demis Hassabis and Jeff Dean step down simultaneously

Google Deepmind is overhauling its leadership as Demis Hassabis steps back from day-to-day management to become Alphabet's chief scientist and Jeff Dean leaves Google after 27 years to launch AI star…

https://the-decoder.com/google-deepmind-loses-both-its-ceo-and-chief-scientist-as-demis-hassabis-and-jeff-dean-step-down-simultaneously/
15
🔐 security SecurityWeek
52%

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones appear…

https://www.securityweek.com/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones/