Entity
Attackers
Attackers are malicious actors who exploit vulnerabilities in software and systems to compromise security, often by hijacking domains, obtaining fraudulent certificates, or locking organizations out of their own devices.
Why it’s in the news: They are in the news for rapidly exploiting a critical Atlassian vulnerability and hijacking country-code top-level domains to issue fake Google certificates.
Latest on Attackers
- Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
- Attackers Hijack Three ccTLDs to Obtain Google Certificates
- FBI: FortiBleed attackers can lock organizations out of their own firewalls
- FortiBleed Attackers Locking Victims Out of Fortinet Devices
- Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
- Attackers Hide AI Prompt Injections Inside Phishing Emails
- Attackers exploited tokens transmitted in metadata, weak virtual machine isolation, and expansive permissions to gain unauthorized access.
- Amazon Web Services (AWS) AgentCore was compromised after a prompt requested credentials, according to The Register.
- Barracuda discovered phishing emails containing AI prompt injection attacks targeting both human users and AI assistants.
- AI tools accelerating their use
- Attackers are increasingly weaponizing already-disclosed flaws
- The attackers exploited two zero-day vulnerabilities in the Zammad helpdesk software.
Connections
97 entities linked to Attackers across the news graph.
Under pressure from (55)
web applicationsAPIsAI-powered servicescustomer portalsopen-source AI systemsSoldiersciviliansAI gatewaysautonomous AI systemsArch User Repositoryreasoning-based guardrailscompromised gatewaysprivate repositoriesAIZammad helpdesk softwareDutch Institute for Vulnerability DisclosureSpaces platformtrojan malwareusers searching for ChatGPTethical safeguardsHugging FaceMETRenterprisesNVIDIA's tool
Also connected to (42)
Two characters open up a world of typosquatting opportunities in Chromium browsersAttackers Hijack Three ccTLDs to Obtain Google CertificatesSonicWall’s latest critical flaw indicates a security pattern, not another one-off bugAttackers hijacked top-level domains, minted fake security certs for Google and other orgs14 years after Nirbhaya gang rape horror, has India progressed on women’s safety?AI Made B2B Fraud Cheap and Trust ExpensiveCLOSEDQattack loopAWS AgentCoreThai authoritiesfraud detection systemsexpansive permissionsweak VM isolationtokens in metadatadisclosed flawsAI agentsAI toolsAI-assisted automationlarge language modelsAI-generated codeFrontier ModelsmachinesSECRoundcube Webmail Vulnerability