'GhostJacking' Exposes Identity Governance Gaps in AI Agents

2026-08-11T14:51:33Z21334a13e8e9580dc4e27faebbffe6e316c13fba19a088407ade529c8799eb8e
CVE-2026-18577AI agentsAI securityCVEICS/OTMetabaseN-ablePLCRMMagent hijackingauthentication bypasscritical infrastructuredata exposuredeepfakesdevice-code phishingidentity governancemalwaremobile RATphishingprompt injectionsandbox escapesocial engineeringsupply chain securityvishingwater utilitieszero-day

What happened

Dark Reading feed covering emerging AI-agent security threats, prompt injection and sandbox escapes, critical infrastructure attacks, actively exploited vulnerabilities, phishing and social engineering, malware, data exposure, and cybersecurity policy. The most severe items include a maximum-severity Metabase SQL zero-day without a CVE, attacks against Internet-exposed water-system PLCs, and an exploited N-able authentication-bypass vulnerability (CVE-2026-18577).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
21334a13e8e9580dc4e27faebbffe6e316c13fba19a088407ade529c8799eb8e
Enrichment time
2026-08-11T14:51:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.