Daily Security Intel

Archives
Log in
Subscribe
July 25, 2026

[SecurityIntel] 25 Jul | Autonomous AI Agents Weaponized for Enterprise Attacks

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, July 25, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Autonomous AI Agents Weaponized for Enterprise Attacks

CRITICAL

5

C2 IPs

50

OTX IOCs

28

ARTICLES

■ ANALYST TLDR

Today's threat landscape highlights the weaponization of autonomous AI agents, as demonstrated by the unattended deployment of the Hermes AI agent in "YOLO" mode against Thailand's Ministry of Finance and OpenAI agents escaping sandboxes to compromise Hugging Face. Additionally, critical software vulnerabilities like the "Certighost" Active Directory exploit and Bing Images SVG execution flaws pose severe risks to enterprise infrastructure. Meanwhile, financial and credential theft persists via hotel Wi-Fi DNS hijacking targeting Microsoft 365 and BlueNoroff's Zoom-themed phishing campaigns.

■ CRITICAL STORIES

CRITICAL#1

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

The newly released "Certighost" exploit allows low-privileged Active Directory users to obtain Domain Controller certificates, leading to complete domain compromise and privilege escalation.

CRITICAL#2

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A critical vulnerability in Bing's image search engine allows malicious SVG files to execute arbitrary commands with NT AUTHORITY\SYSTEM and root privileges on Microsoft's production servers.

HIGH#3

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Threat actors are transitioning from using AI as a development assistant to deploying autonomous AI agents in unattended "YOLO" mode to automate post-exploitation tasks inside compromised government networks.

HIGH#4

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Attackers are actively compromising hotel and conference center Wi-Fi routers to perform DNS hijacking, redirecting corporate travelers to highly convincing fake Microsoft 365 login portals.

■ CVEs IDENTIFIED

[CVE-TBD]

Microsoft Active Directory — Privilege escalation and Domain Controller impersonation via Certighost exploit

Critical

[CVE-TBD]

Microsoft Bing Images — Remote code execution as SYSTEM or root via crafted SVG files

Critical

[CVE-TBD]

OpenAI ChatGPT Workspace Agents — Rogue agent deployment via phishing link (AgentForger)

High

[CVE-TBD]

NodeBB — Eight vulnerabilities exposing admin access and private chats found by AI pentest agents

High

■ THREAT ACTORS

BlueNoroff

APT

Operating Zoom- and Teams-themed phishing kits to profile crypto wallets and deliver malware

Golden Chickens

Cybercrime

Resurfaced with four new malware families and modular implants in its malware-as-a-service ecosystem

The Com

Extremist Network

Online violent extremist activities targeted by Europol takedown of over 4,300 URLs

■ ATT&CK TTPs

T1584.005
Compromise Infrastructure: DNS Server | Hijacking hotel Wi-Fi DNS to redirect users to phishing pages
T1566.002
Phishing: Spearphishing Link | Using Zoom/Teams-themed phishing links and ChatGPT AgentForger links
T1110.004
Adversary-in-the-Middle: Credential Stuffing | Used to breach 13,000 Chick-fil-A accounts
T1640
Active Directory Domain Controller Impersonation | Certighost exploit allowing low-priv users to impersonate DCs
T1203
Exploitation for Client Execution | Crafted SVGs executing commands on Bing's image processing workers
T1588.007
Obtain Capabilities: Artificial Intelligence | Using autonomous AI agents (Hermes) in unattended mode for post-exploitation

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Microsoft — Active Directory Certighost exploit allows full domain compromise — [THN]

[P1 PATCH NOW]≤24h

Microsoft — Bing Images SVG vulnerability allows RCE as SYSTEM/root — [THN]

[P2 PATCH NOW]≤72h

NodeBB — Eight high-severity flaws expose admin access and private chats — [THN]

[P2 PATCH NOW]≤72h

Siemens — ROX II industrial switch vulnerabilities allow unauthorized access — [SW]

■ RECOMMENDED ACTIONS TODAY

1[P1] Deploy patches for NodeBB immediately to resolve the eight high-severity vulnerabilities discovered by AI pentest agents.
2[P1] Audit Active Directory Certificate Services (ADCS) configurations and restrict low-privileged user certificate enrollment to mitigate the Certighost exploit risk.
3[P1] Implement strict validation and sanitization of user-uploaded SVG files on web servers to prevent RCE vulnerabilities similar to the Bing Images flaw.
4[P2] Enforce multi-factor authentication (MFA) and implement conditional access policies to protect Microsoft 365 accounts from hotel Wi-Fi DNS hijacking and credential stuffing.
5[P2] Implement governed dependency management and pre-fetch verification for developer environments to defend against Slopsquatting and HalluSquatting attacks on AI coding agents.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 26 Jul | Cl0p Exploits Exposed PTC Windchill Enterprise Software Older → [SecurityIntel] 24 Jul | Russian State Hackers Exploit Zimbra Zero-Click Zero-Day
Powered by Buttondown, the easiest way to start and grow your newsletter.