Tag: breach
-
OpenAI Models Escaped Sandbox, Breached Hugging Face
Tags: ai, attack, breach, credentials, cybersecurity, exploit, infrastructure, openai, risk, zero-dayReduced Guardrails Enabled Advanced Models to Pursue Unrestricted Attack Paths. OpenAI said advanced frontier models escaped a constrained testing environment, exploited multiple zero-days and stolen credentials and breached Hugging Face infrastructure while attempting to obtain answers for an internal ExploitGym evaluation, highlighting the growing cybersecurity risks posed by autonomous AI agents. First seen on govinfosecurity.com…
-
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/
-
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide. First seen on therecord.media Jump to article: therecord.media/spain-fines-23andme-3-million-cyber-failings-data-breach
-
AI music generator Suno breach affects 55M users, per Have I Been Pwned
A hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/
-
Closing the Identity Gaps in Critical Infrastructure Security
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/closing-the-identity-gaps-in-critical-infrastructure-security/
-
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
-
Paidwork breach exposes sensitive data of 23 million users
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
-
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026. Paidwork Data…
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
-
Cosmetics giant Estée Lauder victim of mass Oracle breach
Employee data at US-based cosmetics firm Estée Lauder was compromised through a vulnerability in Oracle’s software, likely orchestrated by the Cl0p ransomware gang. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645849/Cosmetics-giant-Estee-Lauder-victim-of-mass-Oracle-breach
-
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/
-
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
-
The 12 Best Identity Threat Detection Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs and MSPs, Microsoft Defender for Identity is effectively the bundled default inside E5 estates, Sophos…
-
Hackers steal customer data from major hospital software vendor
The breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/craneware-health-care-data-breach/825643/
-
Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/
-
Paidwork breach exposes sensitive data of 23 million user
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so…
-
Italy fines WINDTRE Euro1.7 million over security flaws behind two data breaches
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE Euro1.7 million over >>serious data security shortcomings<< … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/italy-windtre-1-7-million-fine/
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/
-
20th July Threat Intelligence Report
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/20th-july-threat-intelligence-report/
-
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/
-
Hugging Face breached by autonomous AI agent
Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hugging-face-breached-by-autonomous-ai-agent/
-
Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB. The malware, dubbed HOLLOWGRAPH, was detailed…

