Blackpoint Cyber has released an AI-powered security agent designed to automatically detect and neutralize identity-based cyberattacks. This agent focuses on threats targeting cloud-based productivity suites like Microsoft 365 and Google Workspace. By leveraging a combination of artificial intelligence and human oversight, the system aims to significantly reduce the time it takes to contain compromised accounts and prevent further damage.

Blackpoint Cyber has launched its AI SOC Agent, a new feature designed for autonomous response to identity-based threats. This capability, now generally available, aims to detect and contain attacks targeting Microsoft 365 and Google Workspace accounts with minimal human intervention. The system operates on an AI and human hybrid model, with the AI component acting on threats it identifies with high confidence.
The company states that the AI SOC Agent can contain credential-based attacks in an average of less than two minutes, with some instances taking as little as 21 seconds. This rapid response is presented as a crucial advantage given the increasing prevalence of identity-focused attacks. Microsoft has reported a 32% rise in such attacks during the first half of 2025, highlighting the growing threat landscape.
Blackpoint Cyber developed the AI SOC Agent by training it on data accumulated over years of its Security Operations Center (SOC) analyst decisions. This training also incorporated forensic evidence from hundreds of past security breaches and telemetry data from nearly one million user accounts. The company emphasizes that the AI has undergone rigorous validation to ensure it only takes autonomous action on threats deemed to be of high confidence.
The goal of this technology is to provide customers with the expertise of Blackpoint's frontline security team, delivered at machine speed. This allows for threat containment within seconds, according to the company.
Sean Furman, President of STF Consulting, commented that Blackpoint's SOC has served as a trusted extension of his team. He noted the critical importance of time in defending against contemporary cyber threats and expressed confidence that the combination of Blackpoint's AI and human analysts helps them stay ahead of the increasing volume of attacks.
Gagan Singh, CEO of Blackpoint Cyber, explained the company's philosophy regarding AI in cybersecurity. He stated that their SOC is integral to the effectiveness of their AI solutions, rather than being replaced by them. Singh anticipates that future adversaries will operate at unprecedented scales, potentially without direct human command, and that the same AI technologies used for defense are also being leveraged to create new attack methods.
Singh further elaborated that the AI SOC Agent's development was informed by Blackpoint's SOC team, which includes former operators from agencies such as the NSA, DIA, and CIA. He indicated that these individuals set the operational boundaries for the AI, ensuring that while the AI can act more rapidly, human judgment remains the ultimate arbiter for securing outcomes.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed