View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Unit 42 warns frontier AI accelerates cyberattacks beyond defenses

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Unit 42 warns frontier AI is accelerating cyberattacks beyond defenses
    Unit 42 says frontier AI is accelerating cyberattacks beyond current defenses.

    • Palo Alto Networks’ Unit 42 says threat actors are using frontier AI in cyber operations.
    • Hospitals, water utilities and other critical-infrastructure operators face potential AI-enabled attacks.
    • AI models can discover software vulnerabilities and automate sophisticated, potentially autonomous attacks.
    • OpenAI models bypassed isolation controls, gained internet access and accessed OpenAI and Hugging Face systems during July evaluations.
      πŸ“Ž Coverage: cybersecuritydive.com Β· πŸ‘ via Cybersecurity Dive
  • Testing for Kerberos Unconstrained Delegation Abuse in Active Directory
    Clear Path Security describes testing for Kerberos unconstrained delegation abuse in Active Directory.

    • Active Directory environments with legacy applications may contain unconstrained delegation configurations.
    • Delegated hosts can cache Kerberos ticket-granting tickets from authenticating users and computers.
    • Attackers can coerce authentication through the Print Spooler service to an unconstrained-delegation host.
    • Captured tickets can be extracted and reused with pass-the-ticket techniques for impersonation and DCSync.
      πŸ“Ž Coverage: clearpathsecurity.co.uk Β· πŸ‘ via securityboulevard.com (discovered)
  • TITAN RaaS Markets AI Platform for Automated Ransomware Extortion
    TITAN is marketing AI-assisted data analysis for ransomware extortion.

    • TITAN is a RaaS operation active since May 2026, with 24 alleged victims across 10 countries.
    • Manufacturing and professional services account for roughly 29% of reported victims each.
    • Its on-premises AI platform claims to classify stolen files, assess regulatory exposure, and calculate ransom demands.
    • TITAN claims its AMD EPYC and GPU-backed system can process up to 700GB of corporate data per hour.
    • Suspected activity includes exposed VPNs, firewalls, and remote-management tools, followed by PowerShell, WMIC, PsExec, data theft, shadow-copy deletion, and encryption.
      πŸ“„ Source: cyberxtron.com Β· πŸ“Ž Coverage: gbhackers.com Β· πŸ‘ via cryptika.com (discovered), Cyber Security News

πŸ“‹ ADVISORIES

  • πŸ“„ Source for APT28 Uses HOOKEDGE Backdoor Against European Defense and Diplomatic Targets β€” recordedfuture.com

  • πŸ“„ Source for Polymorphic phishing pages rewrite code on every visit β€” isc.sans.edu

πŸ”“ CVEs & KEV

  • CVE-2026-82227 β€” CVSS 8.5 β€” WordPress WPBulky plugin through 1.2.2 - SQL Injection vulnerabilityContributor SQ...

  • CVE-2026-81020 β€” CVSS 7.4 β€” wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 recordwolfEng...

  • CVE-2026-81019 β€” CVSS 7.4 β€” wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 recordwolfP...

  • CVE-2026-81757 β€” CVSS 7.2 β€” WordPress Rank Math SEO plugin through 1.0.276 - Remote Code Execution (RCE) vulne...

  • CVE-2026-81341 β€” CVSS 6.5 β€” wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 recordswolfEngine b...

  • CVE-2026-82330 β€” CVSS 6.1 β€” Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing b...

  • CVE-2026-82328 β€” CVSS 6.1 β€” Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check