433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS is a Microsoft Windows Server role that lets an organization run its own Public Key Infrastructure (PKI). It acts as a Certificate Authority (CA), issuing and managing digital certificates used for authentication, encryption, and signing across … More → The post PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) appeared first on Help Net Security.
http://news.poseidon-us.com/TTkJY9

ChatGPT joins the most impersonated brands in phishing attacks

Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, according to Check Point’s Q2 2026 Brand Phishing Report. Fake ChatGPT Plus billing email (Source: Check Point) Technology remains the top target, but… Brand phishing exploits trusted brands people recognise and … More → The post ChatGPT joins the most impersonated brands in phishing attacks appeared first on Help Net Security.
http://news.poseidon-us.com/TTkJXy

AWS gives DevOps teams an AI investigator for firewall incidents

AWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that investigates and troubleshoots application and infrastructure issues. It connects to monitoring tools, logs, code repositories, and deployment pipelines, analyses incidents, pinpoints likely root causes, and recommends fixes or preventive improvements. It works across AWS, multicloud, … More → The post AWS gives DevOps teams an AI investigator for firewall incidents appeared first on Help Net Security.
http://news.poseidon-us.com/TTk9hb

Marathon Petroleum’s CISO on OT security automation, supply chain risk

In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. She also covers cross-skilling the workforce and working … More → The post Marathon Petroleum’s CISO on OT security automation, supply chain risk appeared first on Help Net Security.
http://news.poseidon-us.com/TTk1g4

Nono: Open-source sandbox for AI agents

An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and … More → The post Nono: Open-source sandbox for AI agents appeared first on Help Net Security.
http://news.poseidon-us.com/TTk1fx

What the identity attack surface looks like when trust becomes the target

In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. He also covers how cloud and on-premises trust relationships give attackers a path between environments. Moses suggests number matching, FIDO2 keys, periodic reviews of third party application access, and watching … More → The post What the identity attack surface looks like when trust becomes the target appeared first on Help Net Security.
http://news.poseidon-us.com/TTk1fT