๐จ ACTIVE EXPLOITATION
- Critical AgentForger Flaw Lets Phishing Links Deploy Rogue ChatGPT Workspace Agents
A phishing link vulnerability allowed attackers to create autonomous malicious ChatGPT Workspace Agents.
- Applies to OpenAI ChatGPT Workspace Agents integrated with Outlook, Gmail, Slack, Teams, and others
- Vulnerability exploits URL parameters to auto-execute malicious agent creation on page load
- Phishing link silently builds and publishes attacker-controlled agents with pre-authorized connectors
- Agents bypass approval prompts by switching write-action settings to 'Never ask' for stealth
- Malicious agents run recurring tasks polling attacker inbox, enabling data exfiltration and credential theft
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
- PEAR Ransomware Group Breaches MCBS, Exposes Data of 1.2 Million Individuals
The PEAR ransomware group stole 3 TB of data from MCBS, impacting 1.2 million people.
- Targets medical business management company MCBS and its clients
- Attackers accessed systems from September 22-26, 2025, stealing personal and medical info
- Data stolen includes PII, PHI, financials, HR, business operations, and payment details
- Seven healthcare organizations' data compromised, affecting 1,261,464 individuals
- PEAR ransomware group claimed responsibility and published stolen data online
๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
๐ ADVISORIES
- Eight High-Severity Vulnerabilities Found in NodeBB Versions Before 4.14.0
Multiple critical vulnerabilities were discovered in NodeBB forum software before version 4.14.0.
- Applies to NodeBB forum platform versions prior to 4.14.0 affecting millions of users
- Includes stored XSS flaws via federated profiles, admin panel logs, and template translation processing
- Authorization bypasses allow private message access and admin page exposure via ActivityPub signature flaws
- Attack vectors include malicious federation servers, crafted ActivityPub messages, and forged GET requests
- Discovered through AI-assisted whitebox penetration testing by Aikido and responsibly patched in July 2026
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ต๏ธ RESEARCH & DEEP DIVES
-
PoCEvolve framework generates proof-of-concept exploits from security patches automatically Researchers developed PoCEvolve to generate proof-of-concept exploits directly from vulnerability-fixing commits.
- Applies to software security patches lacking detailed vulnerability reports
- Generates proof-of-concept exploits from public vulnerability-fixing commits
- Uses vulnerability-aware prompt evolution to improve exploit generation success
- Achieves 58.4% success rate, outperforming prior PoCGen and GPT-4o-mini baselines
- Improves to 85.3% success with advanced Qwen3.7-Plus model
๐ Coverage: arxiv.org ยท ๐ Original: arxiv.org ยท ๐ via arXiv cs.CR
-
New Self-Supervised Acoustic Attack Reconstructs Keystrokes from Keyboard Sounds Researchers developed an acoustic eavesdropping attack that reconstructs typed text from keystroke sounds.
- Applies to physical and semi-public spaces and online meetings using keyboards
- Reconstructs typed text from keystroke sounds without labeled data for the target device
- Uses unsupervised acoustic clustering combined with Transformer-based language models and iterative self-training
- Achieves over 99% accuracy with 100-150 keystrokes in close-proximity smartphone recordings
- Effective across multiple laptops and scenarios including 3-meter distance, through-wall contact microphones, and noisy online calls
๐ Coverage: arxiv.org ยท ๐ Original: arxiv.org ยท ๐ via arXiv cs.CR