The EU AI Act is the first comprehensive regulation for AI systems, and it’s right around the corner.
With the clock running down, we took a deeper look at what these requirements mean for your agents at the Article level, and how LangSmith LangChain directly address them.
⚠️ New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hacker's Server
Source: cybersecuritynews.com/agentj…
New “Agentjacking” attack that hijacks AI coding agents and silently executes attacker-controlled code on developer machines using nothing more than a single injected Sentry error.
The technique turns trusted AI assistants like Claude Code and Cursor into an execution layer for malicious commands, without phishing, malware delivery, or any breach of the victim’s infrastructure.
In this attack, the entry point is Sentry’s public Data Source Name (DSN). This write-only credential is routinely embedded in frontend JavaScript and indexed across the web.
#cybersecuritynews
Remove the Unlock Teams Premium Button from Microsoft Teams!
An Unlock Teams Premium button appears in Microsoft Teams for users, and many keep asking what it is.
Some even click it and start a Trial.
That's something most organizations want to avoid.
Here's what you should do:
Prevent users from accidentally starting Teams Premium trials and reduce confusion about features that are not licensed in your organization.
This helps maintain a consistent user experience and keeps license management under control.
Learn more:
alitajran.com/remove-unlock-…#Microsoft365#Teams#Microsoft
🔥 An AI worm used a local open-weight LLM to find targets, choose attack paths, and copy itself.
> No human help.
> No OpenAI or #Anthropic API.
> No API key to shut off.
In 7 days, it replicated to 62% of a 33-host test network.
It also used fresh CVE advisories to find new attack paths.
Read full story: thehackernews.com/2026/06/re…
🚨 Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers
Source: cybersecuritynews.com/window…
A researcher known as Nightmare Eclipse has publicly released a new proof-of-concept (PoC) exploit named RoguePlanet, targeting a previously undisclosed race condition vulnerability in Microsoft Windows Defender.
When successfully executed, the exploit spawns a command shell running under SYSTEM-level privileges, granting an attacker the highest possible access on a compromised Windows machine.
The release, posted to GitHub, arrives on Patch Tuesday, June 10, 2026, adding urgency to an already escalating series of Defender-targeting disclosures.
#cybersecuritynews
Atos Group's adoption of Microsoft 365 E7 brings AI, identity, security, compliance and agent governance together in a unified platform — creating a secure foundation to scale agentic AI across its workforce and client ecosystem. msft.it/6017vg1mP
ServiceNow customers are being notified after unauthorized access hit multiple tenants.
The messy part?
A Scripted REST endpoint reportedly shipped with authentication disabled.
No token.
No valid session.
No real user account.
Just requests landing as “Guest” in logs.
The IOC: 51.159.98.241
Security teams should be checking /api/now/related_list_edit transaction logs immediately.
Microsoft’s AI Observability Starter Kit for Foundry agents looks like a solid direction towards making agent behavior easier to trace, evaluate, and trust. techcommunity.microsoft.com/…
Threat actors are increasingly exploiting the hype around AI as social engineering lure in phishing, malvertising, and search-driven attacks. By impersonating trusted tools and services, they capitalize on user curiosity and urgency to improve success rates. msft.it/6019v5k6N
Despite using hooks tied to new technologies, these campaigns combine familiar techniques like multi-stage redirects, abuse of legitimate infrastructure, and interaction-based evasion to enable credential theft, financial fraud, or malware infection.
Read the latest Microsoft Defender Research blog to get an analysis of some of these campaigns and guidance for detecting, mitigating, and responding to these threats.
🚨 Microsoft’s June 2026 Patch Tuesday fixes 200 flaws, including 3 publicly disclosed zero-days affecting Windows privilege escalation, HTTP.sys, and BitLocker.
⚫️33 flaws are rated Critical, including 28 RCE bugs.
⚫️Microsoft patched the new “HTTP/2 Bomb” DoS attack targeting HTTP.sys.
⚫️The BitLocker bypass dubbed YellowKey that allowed access to encrypted drives was also patched.
Read our full report: bleepingcomputer.com/news/mi…
By default, block all unverified agents from Entra-managed resources with Conditional Access policies — then exclude verified agents to grant least-privilege access. See how. youtu.be/Wz16P678QiY Take control of every AI agent, managed or not, running in your environment using Agent 365 and Microsoft Entra. Surface agents across AWS Bedrock, Google Vertex, Databricks, and Salesforce in one registry, assign Entra Agent IDs via CLI or SDK, and enforce least-privilege access through Conditional Access policies and Agent Blueprints, all without rebuilding your existing identity infrastructure. #Agent365Entra#agent365#microsoftsecurity#microsoft365#aigovernance#agenticai
🚨 Microsoft is bringing some #GitHub repos back online. Others are still down.
The Miasma worm hit 73 of its open-source projects and planted an info stealer. Now it's warning affected customers.
See what happened 👇 thehackernews.com/2026/06/mi…