This past week had one clear theme, artificial intelligence in the hands of attackers. Someone set an autonomous AI agent loose on Thailand's Ministry of Finance, researchers documented the first fully autonomous ransomware case, and a new trojan started using AI to profile victims by value. Because of that, defense is shifting from blocking known indicators to detecting behavior.
Alongside it, a varied mix of classic threats. A Russian group is reading other people's mail through a zero-click flaw in Zimbra, where simply viewing the message is enough. Clop returned with a mass campaign against exposed PTC Windchill and FlexPLM. The Certighost flaw hands a normal Active Directory account the keys to the entire domain. And on the road, attackers are changing DNS on hotel Wi-Fi to steal Microsoft 365 logins.