Hermes
Saturday 25 July 2026  ·  57 articles scored  ·  3 top scorers  ·  last 24h
1
📦 m365 Petri IT Knowledgebase
73%

Researchers Discover HOLLOWGRAPH Malware Abusing Microsoft 365, Graph API

Group-IB researchers have discovered HOLLOWGRAPH, a sophisticated malware linked with high confidence to the Cavern cyber-espionage framework. The malware abuses legitimate Microsoft 365 services to …

Novelty
75%
Depth
65%
Practical
70%
Surprise
70%
Relevance
90%
https://petri.com/hollowgraph-malware-microsoft-365-graph-api/
2
🔐 security SANS Internet Stormcast
72%

When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)

Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the m…

Novelty
80%
Depth
65%
Practical
60%
Surprise
80%
Relevance
85%
https://isc.sans.edu/diary/rss/33180
3
🔐 security Microsoft Security Blog
71%

Email threat landscape: Q2 2026 trends and insights

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat…

Novelty
70%
Depth
70%
Practical
75%
Surprise
50%
Relevance
90%
https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
4
🤖 ai The Decoder
70%

One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes

Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the v…

https://the-decoder.com/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/
5
🔐 security SecurityWeek
67%

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers …

https://www.securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/
6
🤖 ai The Decoder
67%

Anthropic claims its new Claude Opus 5 delivers near-Fable 5 performance at half the token price

Anthropic's new flagship model Claude Opus 5 posts top scores in coding and knowledge work at half of Fable 5's token rates. On ARC-AGI-3, a benchmark for novel problem-solving, Opus 5 hits 30.2 perc…

https://the-decoder.com/anthropic-claims-its-new-claude-opus-5-delivers-near-fable-5-performance-at-half-the-token-price/
7
🔐 security SecurityWeek
67%

Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday

Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feed…

https://www.securityweek.com/industry-reactions-to-openai-models-hacking-hugging-face-feedback-friday/
8
🔐 security SecurityWeek
66%

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability …

https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/
9
⚡ tech The Verge
66%

Anthropic releases Opus 5 with ‘close’ to Fable 5’s capabilities

Weeks after Anthropic's latest toe-to-toe with the US government, and days after an OpenAI security incident that dominated tech industry discussions, Anthropic on Thursday released its newest model,…

https://www.theverge.com/ai-artificial-intelligence/970105/claude-opus-5-announced-anthropic-ai-model-release
10
🤖 ai The Decoder
64%

Microsoft's open-weight AI push is so obviously an Azure play it hurts

Microsoft, along with Meta, Nvidia, and more than 20 other companies, is pushing for open-weight AI models in an open letter. The strategic logic is simple: the more models running on Azure, the less…

https://the-decoder.com/microsofts-open-weight-ai-push-is-so-obviously-an-azure-play-it-hurts/
11
🔐 security SecurityWeek
61%

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier A…

https://www.securityweek.com/nuclear-sabotage-malware-benchmark-trips-up-most-frontier-ai-models/
12
🤖 ai The Decoder
61%

Kimi K3 trails frontier US models by a wide margin on cyber exploits, and distillation may explain why

The British AI Security Institute and the U.S. Center for AI Standards and Innovation tested Moonshot AI's Kimi K3 on offensive cyber tasks. Kimi K3 scored 32 percent on ExploitBench, compared with 7…

https://the-decoder.com/kimi-k3-trails-frontier-us-models-by-a-wide-margin-on-cyber-exploits-and-distillation-may-explain-why/
13
📦 m365 Petri IT Knowledgebase
58%

Microsoft to Add TPM-Based Attestation to Secure Windows KMS Activation

As cyber threats continue to evolve, Microsoft is strengthening Windows activation security by extending protection beyond software and into the hardware layer. The new KMS Hardware-Secured feature u…

https://petri.com/microsoft-secure-windows-kms-tpm-attestation/
14
🔐 security Schneier on Security
58%

Why AI Needs a “Genie Coefficient”

This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what y…

https://www.schneier.com/blog/archives/2026/07/why-ai-needs-a-genie-coefficient.html
15
🤖 ai The Decoder
58%

Claude's voice mode now runs on Anthropic's most capable models across all platforms

Voice conversations now run on the more powerful Opus and Sonnet models with access to Gmail, Google Calendar, and Slack. Claude is currently the only AI assistant that can compose and send emails di…

https://the-decoder.com/claudes-voice-mode-now-runs-on-anthropics-most-capable-models-across-all-platforms/