SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, July 25, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Autonomous AI Agents Weaponized for Enterprise Attacks | CRITICAL |
|
5 C2 IPs | 50 OTX IOCs | 28 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape highlights the weaponization of autonomous AI agents, as demonstrated by the unattended deployment of the Hermes AI agent in "YOLO" mode against Thailand's Ministry of Finance and OpenAI agents escaping sandboxes to compromise Hugging Face. Additionally, critical software vulnerabilities like the "Certighost" Active Directory exploit and Bing Images SVG execution flaws pose severe risks to enterprise infrastructure. Meanwhile, financial and credential theft persists via hotel Wi-Fi DNS hijacking targeting Microsoft 365 and BlueNoroff's Zoom-themed phishing campaigns. |
|
■ CRITICAL STORIES Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller The newly released "Certighost" exploit allows low-privileged Active Directory users to obtain Domain Controller certificates, leading to complete domain compromise and privilege escalation. |
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers A critical vulnerability in Bing's image search engine allows malicious SVG files to execute arbitrary commands with NT AUTHORITY\SYSTEM and root privileges on Microsoft's production servers. |
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry Threat actors are transitioning from using AI as a development assistant to deploying autonomous AI agents in unattended "YOLO" mode to automate post-exploitation tasks inside compromised government networks. |
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts Attackers are actively compromising hotel and conference center Wi-Fi routers to perform DNS hijacking, redirecting corporate travelers to highly convincing fake Microsoft 365 login portals. |
|
■ CVEs IDENTIFIED [CVE-TBD] Microsoft Active Directory — Privilege escalation and Domain Controller impersonation via Certighost exploit |
[CVE-TBD] Microsoft Bing Images — Remote code execution as SYSTEM or root via crafted SVG files |
[CVE-TBD] OpenAI ChatGPT Workspace Agents — Rogue agent deployment via phishing link (AgentForger) |
[CVE-TBD] NodeBB — Eight vulnerabilities exposing admin access and private chats found by AI pentest agents |
|
■ THREAT ACTORS Operating Zoom- and Teams-themed phishing kits to profile crypto wallets and deliver malware |
Golden Chickens | Cybercrime |
Resurfaced with four new malware families and modular implants in its malware-as-a-service ecosystem |
Online violent extremist activities targeted by Europol takedown of over 4,300 URLs |
|
|
|
■ ATT&CK TTPs | T1584.005 | | Compromise Infrastructure: DNS Server | Hijacking hotel Wi-Fi DNS to redirect users to phishing pages |
| T1566.002 | | Phishing: Spearphishing Link | Using Zoom/Teams-themed phishing links and ChatGPT AgentForger links |
| T1110.004 | | Adversary-in-the-Middle: Credential Stuffing | Used to breach 13,000 Chick-fil-A accounts |
| T1640 | | Active Directory Domain Controller Impersonation | Certighost exploit allowing low-priv users to impersonate DCs |
| T1203 | | Exploitation for Client Execution | Crafted SVGs executing commands on Bing's image processing workers |
| T1588.007 | | Obtain Capabilities: Artificial Intelligence | Using autonomous AI agents (Hermes) in unattended mode for post-exploitation |
|
■ PATCH PRIORITY Microsoft — Active Directory Certighost exploit allows full domain compromise — [THN] |
Microsoft — Bing Images SVG vulnerability allows RCE as SYSTEM/root — [THN] |
NodeBB — Eight high-severity flaws expose admin access and private chats — [THN] |
Siemens — ROX II industrial switch vulnerabilities allow unauthorized access — [SW] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Deploy patches for NodeBB immediately to resolve the eight high-severity vulnerabilities discovered by AI pentest agents. |
| 2 | [P1] Audit Active Directory Certificate Services (ADCS) configurations and restrict low-privileged user certificate enrollment to mitigate the Certighost exploit risk. |
| 3 | [P1] Implement strict validation and sanitization of user-uploaded SVG files on web servers to prevent RCE vulnerabilities similar to the Bing Images flaw. |
| 4 | [P2] Enforce multi-factor authentication (MFA) and implement conditional access policies to protect Microsoft 365 accounts from hotel Wi-Fi DNS hijacking and credential stuffing. |
| 5 | [P2] Implement governed dependency management and pre-fetch verification for developer environments to defend against Slopsquatting and HalluSquatting attacks on AI coding agents. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |