access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors F5 Security Incident Advisory…
-
ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents’ Data
ShinyHunters hacks the FBI Jobs portal and claims sensitive data on nearly all FBI agents and job applicants before the site is taken offline for security work. First seen on hackread.com Jump to article: hackread.com/shinyhunters-hacks-fbi-jobs-portal-fbi-agents-data/ also interesting: Who Owns Threat and Exposure Management in Your Organization? D&O liability protection rising for security leaders, unless you’re…
-
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators, separate from another administration-proposed pilot program. First seen on cyberscoop.com Jump to article: cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot/ also interesting: The Imperative of Tunnel-Free Trusted Cloud Edge Architectures The New Edge: Tunnel-Free, AI and Quantum-Ready Cyber…
-
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service also interesting: Tycoon 2FA Attacking Microsoft 365 AND Google Users To Bypass MFA Phishing-as-a-Service Rockstar 2FA continues to be prevalent How are…
-
Check Point Fixes a New Actively Exploited Critical Security Flaw
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to…
-
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release. First seen on therecord.media Jump to article: therecord.media/canadian-regulator-opens-probe-of-idscan-following-data-breach also interesting: HHS Strengthens Privacy of Reproductive Health Care Data E.U. Commission Fined for Transferring User Data to Meta…
-
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release. First seen on therecord.media Jump to article: therecord.media/canadian-regulator-opens-probe-of-idscan-following-data-breach also interesting: US Federal Data Privacy Law Introduced by Legislators Big tech reps call for U.S. data privacy law…
-
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/ also interesting: Microsoft hijacks keyboard shortcut to bring Copilot to your attention Copilot AI Bug Could Leak Sensitive Data via Email Prompts Article 5 and the EU AI Act’s Absolute Red Lines FireTail Blog A…
-
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.” First seen on thehackernews.com…
-
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.” First seen on thehackernews.com…
-
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for…
-
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server…
-
Angreifer machen mehr Tempo: Wie KI den Cyberdruck auf KMU erhöht
KI schafft neue Angriffsflächen und verstärkt zugleich bekannte Cyberbedrohungen. Für kleine IT-Teams wird es damit schwieriger, Risiken früh zu erkennen und mit begrenzten Ressourcen richtig zu reagieren. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/business-security/angreifer-machen-mehr-tempo-wie-ki-den-cyberdruck-auf-kmu-erhoht/ also interesting: Searchlight Cyber Buys Intangic to Help Quantify Cyber Risk Healthcare’s blind spot: What happens after our data is…
-
Angreifer machen mehr Tempo: Wie KI den Cyberdruck auf KMU erhöht
KI schafft neue Angriffsflächen und verstärkt zugleich bekannte Cyberbedrohungen. Für kleine IT-Teams wird es damit schwieriger, Risiken früh zu erkennen und mit begrenzten Ressourcen richtig zu reagieren. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/business-security/angreifer-machen-mehr-tempo-wie-ki-den-cyberdruck-auf-kmu-erhoht/ also interesting: Searchlight Cyber Buys Intangic to Help Quantify Cyber Risk Healthcare’s blind spot: What happens after our data is…
-
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/ also interesting: The most notorious and damaging ransomware of all time TDL 008 – Defending the Frontline:…
-
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
The theft of agents’ personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/ also interesting: 6 rising malware trends every security pro should know Cybersecurity Snapshot: Top Advice for Detecting and Preventing AI Attacks, and…
-
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. First seen on cyberscoop.com Jump to article: cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/ also interesting: OAuth Identity Attack”Š”, “ŠAre your Extensions Affected? Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week…
-
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used…
-
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication…
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The…
-
Shai-Hulud Attack Nips Cyber-Firm CrowdSec’s GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data also interesting: Cybersecurity Snapshot: CISA Analyzes Malware Used in SharePoint Attacks, as U.K. Boosts Cyber Assessment Framework Cybersecurity Snapshot: CISA Analyzes Malware Used in…
-
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/ also interesting: Cybersecurity Snapshot: AI Will Take Center Stage in Cyber in 2026, Google Says, as MITRE Revamps ATTCK…
-
Dubai Unveils Open-Source Deepfake Detection AI
Cybersecurity Regulator Says Saraab AI Model Can Spot Deepfakes With 91% Accuracy. The Dubai Electronic Security Center, the Middle Eastern emirate’s cybersecurity regulator, has built an AI model called Saraab that detects deepfake videos, and plans to open source it by the end of the year so it can be improved by researchers, AI companies…
-
New Optiv CRO: AI Is Disrupting Security In A ‘Compressed Timeframe’
The unprecedented pace of the AI revolution is creating massive opportunities for cybersecurity powerhouse Optiv to become even more essential to customers”, particularly when it comes to helping customers to navigate security challenges that are changing more rapidly than in the past, according to new Optiv CRO Sean Forkan. First seen on crn.com Jump to…
-
ShinyHunters Hacked Cl0p. Now What About Cl0p’s Victims?
ShinyHunters defaced Cl0p’s Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims also interesting: 5 things to know about ransomware threats in 2025 The dirty dozen: 12 worst ransomware groups active today Qantas among nearly 40…
-
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/rogue-incidents-debate-ai-safety-gets-real also interesting: Unlocking Data Control Across Regions: Oracle and Thales Enhance CipherTrust Cloud Key Management for OCI Vault EKMS…
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit, the identity and access management (IAM) company for AI agents, today announced support for Cross App Access (XAA), an open protocol introduced by Okta that lets a user’s existing enterprise identity authorize access to downstream applications without a separate consent step for each connection. Launching this…
-
Check Point warns of Management Server zero-day exploited in attacks
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/ also interesting: Ransomware Hackers Exploiting Cleo Software Zero-Day Researchers expose a surge in hacker interest in SAP systems Cybersecurity Snapshot: AI Will Take Center Stage in Cyber…
-
UK government defends ‘fundamentally flawed’ eVisa system
Tags: governmentThe government has rejected a suggestion from the Commons Home Affairs Committee that the electronic visa system should move to a more stable, token-based process, rather than the current error-prone system that relies on real-time database checks First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650798/UK-government-defends-fundamentally-flawed-eVisa-system also interesting: Hacked Crimean servers reveal information about abducted children,…
-
Data dive: Mapping UK police forces’ hyperscale dependence
Computer Weekly used public DNS records to map which outside companies Britain’s 48 police forces connect to and found a service that has quietly standardised on one US hyperscaler First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650799/Data-dive-Mapping-UK-police-forces-hyperscale-dependence also interesting: 9 VPN alternatives for securing remote network access What is a CISO? The top IT security…
-
Operational Technology Scope Expands as Security Matures
Resilience Focus Driven by Major Attacks, Geopolitical Tensions, Fresh Regulations. While technology-driven thinking once dominated operation technology security planning, a more mature and business-driven discussion focused on resilience and cautious AI adoption is fast becoming the norm, finds Honeywell Technologies’ 2026 Operational Technology Cybersecurity Benchmark Report. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/operational-technology-scope-expands-as-security-matures-a-32890 also…
-
Looking Back Over 14 Years of Identity Theft Scams
Retiring ITRC CEO Eva Velasquez on Identity Crime, Victim Recovery, the Work Ahead. After 14 years leading the Identity Theft Resource Center, Eva Velasquez will retire as CEO in January 2027. She reflects on the organization’s growing reach, identity crime trends and why victim support is crucial in the evolving threat landscape. First seen on…
-
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
RatHat Android malware uses generative AI to navigate infected devices, steal banking credentials, intercept OTP codes and reinstall itself after removal again. First seen on hackread.com Jump to article: hackread.com/rathat-android-malware-ai-banking-credentials/ also interesting: Cybersecurity Snapshot: Global Agencies Target Criminal “Bulletproof” Hosts, as CSA Unveils Agentic AI Risk Framework Keenadu: Android malware that comes preinstalled and can’t…
-
MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
MovieReaper malware spreads through compromised Odyssey torrents, infecting hundreds of victims while using Solana to locate command-and-control infrastructure. First seen on hackread.com Jump to article: hackread.com/moviereaper-malware-odyssey-torrents-infect-users/ also interesting: The high cost of misconfigured DevOps: Global cryptojacking hits enterprises Clément Domingo: “We are not using AI correctly to defend ourselves” Defending digital identity from computer-using agents…
-
Eco-Verband bringt Internet-Security-Days erstmals auf die it-sa
Der Eco Verband der Internetwirtschaft e. V. bringt die Internet-Security-Days am 28. Oktober 2026 erstmals auf die it-sa Expo&Congress in Nürnberg. Mit NIS2, dem Cyber-Resilience-Act und weiteren europäischen Vorgaben geht die Cybersicherheitsregulierung zunehmend von der Gesetzgebung in die praktische Umsetzung über. Im Mittelpunkt des Kongresstags stehen daher Fragen, die für Unternehmen angesichts neuer europäischer […]…
-
Datenschutz mit VPN for AIAgenten
Bitdefender hat seinen neuen Stand-Alone-Dienst für den Endverbraucher, Bitdefender <>, als öffentlich verfügbare Beta-Version vorgestellt. Dies soll den Datenschutz beim Einsatz von KI-Agenten, die sich für ihre menschlichen Auftraggeber im Netz bewegen, recherchieren und agieren, sichern. Jede Aufgabe für einen Agenten erhält eine eigene, private und vorübergehende Verbindung in das Internet. KI-Agenten […] First seen…
-
Stolen passwords are exposing America’s water providers to hackers
Researchers say another looming threat hangs over some of America’s most important critical infrastructure. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/ also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks Cybersecurity Snapshot: CISA’s Best Cyber Advice on Securing Cloud, OT, Apps and…
-
Impacket for Pentester: tstool
Overview Terminal Services, better known today as Remote Desktop Services, governs every interactive and remote session on a Windows host. impacket-tstool lets an operator query First seen on hackingarticles.in Jump to article: www.hackingarticles.in/impacket-for-pentester-tstool/ also interesting: ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access What is Security Posture Management and Why is it Important?…
-
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud. First seen on therecord.media Jump to article: therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens also interesting: Detecting cloud ransomware in Azure…
-
Insurance sector begins to offer clarity on AI-related cyber claims
The emergence of agentic AI and frontier models has led to widespread uncertainty for policyholders. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/insurance-sector-begins-to-offer-clarity-on-ai-related-cyber-claims/831028/ also interesting: AI Cyberattacks Rise but Businesses Still Lack Insurance 12 most innovative launches at RSA 2025 Rogues gallery: 15 worst ransomware groups active today 12 cyber industry trends revealed at RSAC…
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html also interesting: Qantas among nearly 40 companies facing ransom demand from hacker group Hackers leak Qantas data containing 5 million customer records after ransom deadline passes Five…
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html also interesting: Qantas among nearly 40 companies facing ransom demand from hacker group Hackers leak Qantas data containing 5 million customer records after ransom deadline passes Five…
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html also interesting: Qantas among nearly 40 companies facing ransom demand from hacker group Hackers leak Qantas data containing 5 million customer records after ransom deadline passes Five…
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html also interesting: Qantas among nearly 40 companies facing ransom demand from hacker group Hackers leak Qantas data containing 5 million customer records after ransom deadline passes Five…
-
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/ also interesting: Microsoft Sues Hacking Group Exploiting Azure AI for Harmful Content Creation Cobalt Strike Exploitation by Hackers Drops, Report…
-
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/ also interesting: 7 biggest cybersecurity stories of 2024 Phishing click rates tripled in 2024 despite user training AI gives superpowers to BEC attackers Top 10…
-
Citing China, President Trump doubles down on hands-off approach to AI regulation
Following a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations. First seen on cyberscoop.com Jump to article: cyberscoop.com/trump-hands-off-ai-regulation-china-race/ also interesting: Privacy Roundup: Week 3 of Year 2025 Open-Weight Chinese AI Models Drive Privacy Innovation in LLMs The Imperative of Tunnel-Free Trusted…
-
Google AI models broke out of sandbox, hacked three companies
The incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/google-ai-gemini-autonomous-hacks/830884/ also interesting: ChatGPT Search is now smarter as OpenAI takes on Google Search What’s Powering Enterprise AI in 2025: ThreatLabz Report Sneak Peek OpenAI Warns AI-Enabled Cyberattacks Will Surge, Calls for…
-
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
The use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/retail-ai-agents-visibility-data-breaches-netskope/831002/ also interesting: xAI API Key Leak Exposes Proprietary Language Models on GitHub âš¡ Weekly Recap: iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and…

