Security reporting and research highlighted how AI and automation are reshaping both attacker tradecraft and defender operations, while introducing new enterprise risk. ZDNET described research findings that agentic AI implementations from ServiceNow and Microsoft can be exploitable, warning that broadly permissioned agents could enable lateral movement and privilege escalation across systems of record if an attacker compromises an agent or chains between agents with different access levels; a least-privilege posture for agents was emphasized. Dark Reading separately reported that AI agents are increasingly augmenting—and in some cases supplanting—human penetration testing for “low-hanging” vulnerabilities, but that false positives and the need for human oversight remain material constraints as agentic testing matures.
Threat-intelligence coverage also underscored the industrialization of cybercrime and the ecosystems enabling it. CloudSEK detailed the evolution of the English-speaking cybercriminal milieu known as “The COM,” tracing its roots in OG-handle trading communities and forum migrations into a service-oriented underground linked to groups such as Lapsus$, ShinyHunters, Scattered Spider (UNC3944), and Silent Ransom Group, and associated activity spanning breaches, extortion, SIM swapping, ransomware, and crypto fraud. SC Media’s commentary similarly described a cyber underground where criminals can readily buy capabilities (credentials, tooling, automation), calling out techniques including carding and ClickFix social engineering that tricks users into running copied commands to install infostealers. Separately, Dark Reading reported allegations that the Chronus Group posted 2.3TB of purported Mexican government data affecting up to 36 million people, while Mexico’s ATDT disputed it as largely repackaged data from prior breaches and said no new sensitive accounts were identified and that impacted systems were primarily obsolete, third-party-administered state-level platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft issued guidance telling customers to disable Connected Agents before publishing agents that use unauthenticated tools or access sensitive knowledge sources. The company also noted that Entra Agent ID provides identity and governance controls but does not automatically generate alerts without additional monitoring.
Zenity Labs showed that malicious agents in Microsoft Copilot Studio could connect to legitimate higher-privilege agents through the 'Connected Agents' capability. Zenity and Microsoft characterized the issue as a risky design or feature pattern rather than a traditional software vulnerability.
AppOmni Labs publicly disclosed details of the severe ServiceNow 'BodySnatcher' issue, warning that agentic AI integrations can create exploitable privilege-escalation and lateral-movement paths. ServiceNow said it was unaware of any in-the-wild exploitation at the time of reporting.
ServiceNow says it fixed a severe vulnerability dubbed 'BodySnatcher' in October 2025. According to AppOmni Labs, the flaw could have allowed an unauthenticated attacker with only a target email address to impersonate an administrator, run an AI agent, bypass controls, and create full-privilege backdoor accounts.
CloudSEK says a coalition called 'Scattered Lapsus$ Hunters' emerged in mid-2025, combining social engineering, large-scale data exfiltration, and public extortion tactics. The report links the group to high-profile campaigns, including an alleged compromise affecting the Salesforce ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecloudsek.com
Open sourcezdnet.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.