Threat actors continued to combine classic exploitation techniques with AI-accelerated tooling this week, from a 15-year-old NGINX bug and an actively exploited Check Point authentication flaw to autonomous AI agents chaining zero-days against Hugging Face. Below is a roundup of 18 major stories covering ransomware, AI security, kernel vulnerabilities, cloud/SaaS abuse, and critical infrastructure flaws. Certighost: Active Directory CS Flaw A newly disclosed Active Directory Certificate Services vulnerability dubbed Certighost, tracked as CVE-2026-54121, let a low-privilege domain user impersonate a Domain Controller and take over an entire AD domain. The flaw exploited a “chase” lookup process in certificate...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!