Tag: breach
-
Autonomous AI Agent Exploits Zero-Day to Breach Hugging Face Infrastructure
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a zero-day vulnerability. Documented by HiddenLayer’s Research Team on July 31, the agent was undergoing an internal cyber capability evaluation on ExploitGym, a benchmark designed to test an AI’s ability to discover and…
-
CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of sensitive personnel and recruitment data from the automaker’s assessment systems. According to CyberWatch, first flagged on its data-leak portal, the target is described as a >>Korean automotive manufacturer (Turkish operations)<< with the…
-
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
-
AI-Enabled Data Breaches Cost Organizations $6 Million on Average
IBM found AI-enabled breaches cost organizations $6 million on average, exposing gaps in vulnerability management, access controls, and AI governance. The post IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-ibm-ai-enabled-data-breach-costs/
-
What the Hugging Face breach reveals about defense in the age of agentic AI
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased…
-
South Korea fines telco giant KT $39 million for customer data breach
South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-39-million-for-customer-data-breach/
-
Breach Roundup: OpenAI Models on a Hacking Tear
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production. This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department and Angola teleco breached, SonicWall credential stuffing, Telegram founder charged in Russia, hidden prompt turns Microsoft Copilot into an AI worm. First seen on govinfosecurity.com…
-
Semiconductor chip titan Analog Devices reports data breach
In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation. First seen on therecord.media Jump to article: therecord.media/analog-devices-semiconductor-company-data-breach
-
Rogue OpenAI Agent Hit More Than One Target, New Disclosures Show
OpenAI disclosed that the rogue AI agent behind the Hugging Face breach also accessed four additional public services during the same cybersecurity incident. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/openai-rogue-ai-agent-accessed-four-additional-services/
-
Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates
Coca-Cola has confirmed data was stolen in the ransomware attack on Fairlife after the Anubis gang published allegedly stolen files, escalating the incident. The post Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-coca-cola-confirms-data-theft-fairlife-ransomware/
-
Medical Billing Vendor Hack Affects 1.3M Patients
Extortion Gang PEAR Claims Theft of 3.3TB of MCBS LLC’s Client and Patient Data. A Georgia-based medical billing firm is notifying nearly 1.3 million patients of seven healthcare practices of a 2025 hack, ranking the incident among the largest health data breaches reported so far this year. Extortion gang PEAR claimed it stole 3.3 terabytes…
-
Your Money Was Never the Target. Your Identity Was
Identity Theft, Not Transaction Systems, Now Drives the Biggest Banking Fraud Risks Bank of Baroda’s recent breach shows why core systems unaffected is no longer enough. While transactions remained secure, leaked KYC data can fuel mule accounts, synthetic identity fraud and account takeovers, making customer identity – not banking infrastructure – the real target. First…
-
ShinyHunters Claims Ernst Young (EY) Data Breach, Threatens July 31 Leak
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data. First seen on hackread.com Jump to article: hackread.com/shinyhunters-ernst-young-ey-data-breach-threat-leak/
-
Printers remain a security weakness
Quocirca research reveals a surge in print-related data breaches, costing organisations £1m per incident on average. This presents an opportunity for the channel to step in and tighten up security First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366646170/Printers-remain-a-security-weakness
-
Hugging Face breach reignites open-weights debate, raises liability questions
The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/hugging-face-breach-ciso-playbook-open-weight-llms/
-
AI Agents, Trust Abuse, and Breaches Define Cybersecurity News this Week of July 2026
Weekly summary of Cybersecurity Insider newsletters for July 2026 First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-agents-trust-abuse-and-breaches-define-cybersecurity-news-this-week-of-july-2026/
-
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for…
-
Tanaka Dominates Data Leak Landscape With 25 Leak Posts
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble. First seen…
-
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/coca-cola-subsidiary-fairlife-data/
-
Origin Energy Data Breach Affects 900,000 Current and Former Customers
The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia’s largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/origin-energy-data-breach-900000-customers/
-
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/
-
ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data
ShinyHunters has claimed responsibility for the data breach at Ernst & Young (EY) and is threatening to publish allegedly stolen client tax information unless the professional services firm engages in negotiations before July 31, 2026. The extortion group posted about EY on its dark web leak site, describing the deadline as a “final warning” and…
-
The next MSSP breach may start with a “low” severity alert
First seen on scworld.com Jump to article: www.scworld.com/perspective/the-next-mssp-breach-may-start-with-a-low-severity-alert
-
OnTrac parcel delivery company reports customer data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/ontrac-parcel-delivery-company-reports-customer-data-breach
-
Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected
Reuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Hugging Face breach operated undetected for over a week before OpenAI realized what had happened, long after the FBI had been alerted and Hugging Face…
-
Bank of Baroda Breach Tests Disclosure Readiness
Email Compromise Exposes Sensitive Data, Raising DPDP Act Compliance Questions. A Bank of Baroda employee email compromise exposed customer and internal data allegedly leaked by the Triple X ransomware group. The incident shows how India’s new DPDP Act breach notification rules test banks’ readiness to disclose cyber incidents quickly and transparently. First seen on govinfosecurity.com…
-
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-crypto-wallet-app-stealing-18m-in-bitcoin/
-
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
-
Origin Energy Data Breach Exposes Customer and Partial Card Details
Origin Energy confirms hackers stole customer and partial payment-card data, but the number affected and the method of access remain unknown. The post Origin Energy Data Breach Exposes Customer and Partial Card Details appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-origin-energy-customer-data-breach/
-
DentaQuest disclosed a data breach that impacted +23 million individuals
DentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have exposed customers’ personal information and dental health data. DentaQuest, part…

