'GhostJacking' Exposes Identity Governance Gaps in AI Agents
2026-08-11T02:51:33Z•9b7a34667fe65d2139455fea2779429be2e8e0fe87f89c721ba52c96bff9ae0e
CVE-2026-18577AI agentsAI securityICS/OTPLC securityRMMSBOMagent hijackingauthorization bypasscritical infrastructurecybercrimedata exposuredeepfakesdevice-code phishingidentity governancemobile malwarepatch managementphishingprompt injectionsandbox escapesocial engineeringsupply-chain securityvishingvulnerability exploitationwater utilitieszero-day
What happened
Dark Reading feed covering emerging cybersecurity threats and research, with a strong focus on AI-agent security, prompt injection, sandbox escapes, identity and authorization failures, critical-infrastructure attacks, social engineering, ransomware/RMM abuse, and newly disclosed vulnerabilities. Notable items include an apparently actively exploited N-able authentication-bypass vulnerability (CVE-2026-18577), a maximum-severity Metabase SQL zero-day without an assigned CVE, attacks against Internet-exposed water-system PLCs, and AI-agent/browser hijacking and sandbox-escape techniques.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 9b7a34667fe65d2139455fea2779429be2e8e0fe87f89c721ba52c96bff9ae0e
- Enrichment time
- 2026-08-11T02:51:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.