View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical AgentForger Flaw Lets Phishing Links Deploy Rogue ChatGPT

๐Ÿšจ ACTIVE EXPLOITATION

  • Critical AgentForger Flaw Lets Phishing Links Deploy Rogue ChatGPT Workspace Agents A phishing link vulnerability allowed attackers to create autonomous malicious ChatGPT Workspace Agents.
    • Applies to OpenAI ChatGPT Workspace Agents integrated with Outlook, Gmail, Slack, Teams, and others
    • Vulnerability exploits URL parameters to auto-execute malicious agent creation on page load
    • Phishing link silently builds and publishes attacker-controlled agents with pre-authorized connectors
    • Agents bypass approval prompts by switching write-action settings to 'Never ask' for stealth
    • Malicious agents run recurring tasks polling attacker inbox, enabling data exfiltration and credential theft
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • PEAR Ransomware Group Breaches MCBS, Exposes Data of 1.2 Million Individuals The PEAR ransomware group stole 3 TB of data from MCBS, impacting 1.2 million people.
    • Targets medical business management company MCBS and its clients
    • Attackers accessed systems from September 22-26, 2025, stealing personal and medical info
    • Data stolen includes PII, PHI, financials, HR, business operations, and payment details
    • Seven healthcare organizations' data compromised, affecting 1,261,464 individuals
    • PEAR ransomware group claimed responsibility and published stolen data online
      ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ“‹ ADVISORIES

  • Eight High-Severity Vulnerabilities Found in NodeBB Versions Before 4.14.0 Multiple critical vulnerabilities were discovered in NodeBB forum software before version 4.14.0.
    • Applies to NodeBB forum platform versions prior to 4.14.0 affecting millions of users
    • Includes stored XSS flaws via federated profiles, admin panel logs, and template translation processing
    • Authorization bypasses allow private message access and admin page exposure via ActivityPub signature flaws
    • Attack vectors include malicious federation servers, crafted ActivityPub messages, and forged GET requests
    • Discovered through AI-assisted whitebox penetration testing by Aikido and responsibly patched in July 2026
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • PoCEvolve framework generates proof-of-concept exploits from security patches automatically Researchers developed PoCEvolve to generate proof-of-concept exploits directly from vulnerability-fixing commits.

    • Applies to software security patches lacking detailed vulnerability reports
    • Generates proof-of-concept exploits from public vulnerability-fixing commits
    • Uses vulnerability-aware prompt evolution to improve exploit generation success
    • Achieves 58.4% success rate, outperforming prior PoCGen and GPT-4o-mini baselines
    • Improves to 85.3% success with advanced Qwen3.7-Plus model
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR
  • New Self-Supervised Acoustic Attack Reconstructs Keystrokes from Keyboard Sounds Researchers developed an acoustic eavesdropping attack that reconstructs typed text from keystroke sounds.

    • Applies to physical and semi-public spaces and online meetings using keyboards
    • Reconstructs typed text from keystroke sounds without labeled data for the target device
    • Uses unsupervised acoustic clustering combined with Transformer-based language models and iterative self-training
    • Achieves over 99% accuracy with 100-150 keystrokes in close-proximity smartphone recordings
    • Effective across multiple laptops and scenarios including 3-meter distance, through-wall contact microphones, and noisy online calls
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check