An entire ad agency in the palm of your hand.
Your next campaign needs a dozen fresh ad variations by Friday. Your agency quotes two weeks and a five-figure invoice. Your in-house designers are already buried under this quarter's requests.
Hightouch Ad Studio fixes that. It reads your brand guidelines, your best-performing creative, and your product catalog, then generates on-brand ads your team can ship the same afternoon. You review and approve every asset before it goes live, so quality holds.
Growth teams use it to build variations for every audience, test more of them, and stop rationing creative because production got expensive. The work that once needed a full agency retainer now runs inside your own workflow, at your pace and under your direction.
You direct the work while Ad Studio handles production, and your designers get their week back.
Active Exploitation
Critical ServiceNow code execution flaw now exploited in attacks
Technical Details And Exploitation
Attackers can trigger remote code execution without needing any login credentials or user interaction on exposed endpoints.
The vendor released security updates to address five related vulnerabilities in its July platform release.
Security teams note that applying individual hotfixes is not enough because multiple entry points exist across the same platform components.
Enterprise Risk And Mitigation
Attackers targeting these systems gain access to internal ticketing systems, departmental data flows, and integration tokens.
Organizations running self hosted or internet facing instances must apply the full platform upgrade immediately.
Defenders should also review system access logs for unauthorized API activity or unexpected administrative changes made after the patch release date.
Agentic Exploitation
Hermes AI agent used to automate attack on Thai Finance Ministry
Researchers at Hunt.io and independent analyst Bob Diachenko found exposed server files containing attack logs, stolen passwords, and custom hacking programs.
Autonomous Network Exploration
Attacking teams configured the Hermes agent to run in an unattended setting that bypasses approval checks for dangerous commands.
The AI tool automatically scanned internal networks, searched for computer weaknesses, and mapped out confidential database systems.
Logs showed the automated system gathering host information and reading system files across government computers without needing direct user clicks.
Custom Malware Delivery
In addition to using automated software, the attackers staged a previously unknown program named Hades to control infected systems.
Server records revealed custom scripts designed to access government data platforms using hardcoded credentials and web access tools.
This event shows how threat groups are handing off routine intrusion work to automated software systems that operate continuously without human control.
๐บ๏ธ Podcast
Creating Trust at Global Scale with Local AI
The Growing Internet Trust Crisis
Digital communication channels have been overrun by automated fraud, phishing, and scam campaigns, rendering traditional mediums like phone calls largely untrusted. As generative AI allows threat actors to synthesize voices and personalize messaging at scale, the internet faces a widespread denial-of-service on human trust. Cybercriminals exploit these tools to execute large-scale account takeovers and credential stuffing, forcing organizations to reconsider how they verify identities and secure communications.
On-Device AI for Privacy and Protection
To counter AI-generated threats without exposing sensitive corporate data to third-party clouds, modern security strategies are shifting toward local, on-device processing. Running small language models and security sensors directly on user endpoints allows for real-time analysis of messages, files, and remote management tools. This approach eliminates the privacy risks associated with exporting confidential emails to external cloud platforms while maintaining the speed needed to flag suspicious interactions.
Building Strong Network Effects in Defense
Creating lasting digital trust requires establishing defensive networks where individual endpoints protect each other through bidirectional verification. When protected devices interact, they establish a secure layer that verifies device integrity and flags malicious activity before it reaches the end user. Combining this local AI detection with a vigilant user mindsetโverifying identities through secondary channelsโprovides a resilient framework against evolving social engineering attacks.
Supply-Chain Extortion
Ransomware gangs go after EMEA healthcareโs supply chain
Security analyst Assaf Morag from research firm Flare discovered that extortion groups are targeting the entire medical supply chain to gain leverage.
Targeting Key Service Providers
Extortion groups are attacking telemedicine companies, diagnostic labs, pharmacies, and software providers that support larger health systems.
These support companies often maintain weaker network defenses while holding critical patient records and connected infrastructure links.
Attackers use these smaller vendors as stepping stones to reach larger, better-protected regional health networks.
Expanding Operational Damage
Fourteen active ransomware groups, including Qilin, LockBit, RansomHub, and DragonForce, were identified targeting European medical partners.
Intrusions at supply chain vendors create widespread disruptions, stopping patient record flows and forcing daily operational losses across connected hospitals.
European health systems face growing risks from these third-party breaches due to reliance on outdated software and connected medical devices.
Critical Exfiltration
Estรฉe Lauder discloses data breach via Oracle E-Business flaw
The company identified suspicious activity within its corporate systems involving an unpatched flaw in Oracle E-Business Suite software.
Exploitation Of Software Flaws
Attackers weaponized a critical code execution bug in the central business management platform to gain unauthorized entry.
The breach allowed unauthorized users to steal internal business data and company files before technical teams contained the incident.
Estรฉe Lauder confirmed taking impacted systems offline, notifying law enforcement, and hiring third-party cybersecurity experts to investigate the intrusion.
Operational Impact And Mitigation
The security team isolated affected networks to prevent further unauthorized access while keeping core business operations running.
Oracle previously released security patches to address the underlying software flaw across affected enterprise products.
This breach shows how unpatched enterprise software leaves major corporate networks exposed to data theft.
Malvertisting Vector
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Security firm eSentire identified these sponsored search results directing users to copycat websites that deliver remote control software.
Search Ad Exploitation
Attackers purchased top ad slots on Bing search result pages to trick people seeking official desktop downloads.
Clicking the sponsored link sends users to fake websites hosting a setup file that looks like a real application installer.
The setup file secretly installs SectopRAT malware alongside fake app files to keep users from noticing the background activity.
Trojan Payload Capabilities
The installed remote access software gives attackers full control over infected Windows machines without alerting safety tools.
Attackers can view active screens, control mouse movements, steal web browser passwords, and access crypto wallet files.
This campaign shows how cybercriminals manipulate paid search ad systems to spread remote control tools onto enterprise workstations.
Stay safe!








