TheHackersNews

  • What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.
  • The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
  • RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
  • A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing
  • AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel
  • Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
  • The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

netzpolitik.org/ Aktuell

netzpolitik.org

Wir thematisieren die wichtigen Fragestellungen rund um Internet, Gesellschaft und Politik und zeigen Wege auf, wie man sich auch selbst mit Hilfe des Netzes für digitale Freiheiten und Offenheit engagieren kann. Mit netzpolitik.org beschreiben wir, wie die Politik das Internet durch Regulierung verändert und wie das Netz Politik, Öffentlichkeiten und alles andere verändert.
  • Zum Tod von Bruno Kramm: Ein Spinner im allerbesten Sinne
    Bruno Kramm. – CC-BY-NC 2.0: Marquis
    Am vergangenen Freitag starb überraschend der Musiker und Netzaktivist Bruno Kramm. Er kämpfte für ein besseres Urheberrecht und hatte seine Finger bei vielen Protesten im Spiel, die er beflügelte und bereicherte. Ein Nachruf.
  • Malta versus Lilith Wittmann: Gerichtsurteil stärkt Meinungs- und Pressefreiheit
    Lilith Wittmann nach der öffentlichen Verhandlung beim Landgericht II Berlin – CC-BY-SA 4.0: Lilith Wittmann vorm Landgericht II Berlin Tegeler Weg: netzpolitik.org; Bearbeitung: netzpolitik.org
    Die IT-Sicherheitsexpertin Lilith Wittmann leitete Daten der maltesischen Glücksspielbehörde an Medien und Ermittlungsbehörden weiter, wonach diese mutmaßlich illegales Glücksspiel ermöglichte. Die Behörde ging daraufhin gerichtlich gegen Wittmann vor. Nun liegt ein Urteil vor, das die Meinungs- und Pressefreiheit stärkt.
  • Autistici / Inventati: Es ist immer noch viel zu still
    Die Terror-Sanktionen der USA gegen das Tech-Kollektiv sind eine besondere Form internationaler Zensur. (Symbolbild) – Gemeinfrei-ähnlich freigegeben durch unsplash.com: Mick Haupt
    Anne Roth hat vor 19 Jahren ein Blog bei NoBlogs.org gestartet. Jetzt hat die unkommerzielle Plattform dicht gemacht, weil die USA das dahinter stehende Tech-Kollektiv als Terrorismus eingestuft haben. Die USA greifen damit direkt und ohne jedes Verfahren die Meinungs- und Internetfreiheit in anderen Ländern an.

suche