Skip to main content

Cyber Security News: Exchange Vulnerability, Data Breaches, and AI Risks

N2K NetworksAugust 7, 202526 min411 views
22 connections·40 entities in this video→

Exchange Server Hybrid Vulnerability

  • Microsoft has issued a warning about a high-severity vulnerability in Exchange Server hybrid deployments.
  • 🎯 Attackers with on-premises access can exploit a shared service principal to escalate privileges in Exchange Online undetected.
  • ⚠️ This flaw allows bypassing cloud security logs by forging trusted tokens or API calls, affecting Exchange Server 2016, 2019, and the subscription edition.

Data Breaches and Cyber Attacks

  • ✈️ Dutch airline KLM reported a data breach via a third-party platform, exposing customer names and loyalty program details, increasing phishing risks.
  • πŸ“± Bouygues Telecom, France's third-largest mobile operator, disclosed a cyber attack affecting 6.4 million customer accounts, exposing personal data.
  • 🌐 New HTTP request smuggling variants were revealed, impacting CDNs, major organizations, and millions of websites, with one variant (O.cl CL) affecting T-Mobile and GitLab.

Spyware and Ransomware Threats

  • πŸ•΅οΈ Researchers uncovered malware clusters tied to Israeli spyware maker Kandiru, suggesting rebranding to evade US sanctions, with its Devil's Tongue spyware capable of extensive data extraction.
  • πŸ’» The Akira ransomware gang is using a legitimate Intel CPU tuning driver to disable Microsoft Defender, employing a bring-your-own-vulnerable-driver attack.

AI and Emerging Risks

  • πŸ€– A serious vulnerability in OpenAI's ChatGPT connectors allows indirect prompt injection, enabling attackers to extract API keys and sensitive data from linked services like Google Drive.
  • 🧠 Researchers at Black Hat discussed how increasing reliance on LLMs may lead to human influence and conditioning by these AI models, presenting a significant risk.
  • πŸ’‘ The potential for adversaries to engage in data poisoning and model poisoning for LLMs, combined with human susceptibility, poses a growing threat.

Conference Insights and Industry Trends

  • 🎀 Ryan Whelan from Accenture highlighted the practitioner-focused energy at Black Hat, with discussions on new TTPs, AI, and agentic targeting.
  • πŸ”Œ IoT security, including the targeting of EV stations, and the human conditioning aspect of LLMs were noted as key areas of interest.
  • 🀝 The importance of community and collaboration was emphasized as a critical takeaway from the conference, enabling the sharing of threat intelligence and analysis.
  • πŸ€– The Henna Hotel in Japan is utilizing robots as staff, offering cost-cutting and 24/7 availability, but managing guest expectations for their capabilities.
Knowledge graph40 entities Β· 22 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover Β· drag to explore
40 entities
Chapters10 moments

Key Moments

Transcript92 segments

Full Transcript

Topics15 themes

What’s Discussed

Exchange ServerVulnerabilityData BreachCyber AttackHTTP Request SmugglingSpywareRansomwareMicrosoft DefenderArtificial IntelligenceChatGPTPrompt InjectionLLMsBlack HatAccentureIoT Security
Smart Objects40 Β· 22 links
CompaniesΒ· 13
PeopleΒ· 3
ConceptsΒ· 10
EventsΒ· 3
ProductsΒ· 11