Tag: breach
-
Most WordPress pros still lack a breach recovery plan
Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/wordpress-security-survey-recovery-plan/
-
Breach Roundup: China Calls for Stronger AI Oversight
Also, Spain’s First AI Agent-Linked Data Breach, NightmareStresser Domains Seized. This week: a call for stronger AI oversight in China, an AI agent-linked breach in Spain, Cisco active exploits, Check Point patched flaws. NightmareStresser seized – again! South Korea data breach fines, AI made BEC attacks worse. An Android Trojan, an exploited Pixel flaw and…
-
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links.Helpfeel said…
-
Hackers claim breach of Russian election systems days before parliamentary vote
An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament. First seen on therecord.media Jump to article: therecord.media/russia-election-hackers-breach
-
CISO’s Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production.TL;DRExploitation is now the front door.…
-
Spain reports first data breach involving autonomous AI agent
Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/spain-ai-agent-data-breach/
-
Spain reports first data breach involving autonomous AI agent
Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/spain-ai-agent-data-breach/
-
NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
AI Agent Carries Out Multi-Stage Data Theft Attack
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-agent-carries-out-multistage/
-
NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
Credentials Are Still the Shortest Path In
How Brutus grew into an engine that finds your identities, tests them everywhere they’re accepted, and remembers what it confirms. An attacker rarely needs a novel exploit when a valid username and password pair is sitting in a breach dump,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/credentials-are-still-the-shortest-path-in/
-
Spain’s data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/
-
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/
-
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/
-
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/
-
Threat Intelligence Alone Won’t Close the Exploitation Gap
Tags: advisory, ai, breach, credentials, data-breach, exploit, intelligence, marketplace, threat, vulnerabilityA leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most…
-
CISOs to Watch in Atlanta: From City Hall to the Credit Bureau
Atlanta has more reason than most cities to take security leadership seriously. The 2018 ransomware attack on city systems and the 2017 Equifax breach both happened here, and both organisations appear on this list under new security leadership. The other… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-atlanta-from-city-hall-to-the-credit-bureau/
-
Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and…
-
Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and…
-
Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and…
-
Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and…
-
Microsoft Teams IT Support Calling? Not So Fast, Hackers are Exploiting Trust in Spring Ring
Hackers are impersonating IT support staff in Microsoft Teams calls, using vishing, remote-access tools and trusted collaboration workflows to breach organizations. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsoft-teams-it-support-calling-not-so-fast-hackers-are-exploiting-trust-in-spring-ring/
-
The modern attack chain: Rethinking Google Workspace security in the age of AI
Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/material-google-workspace-attack-chains/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/
-
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs
The Hugging Face Wake-Up Call: What an Autonomous AI Attack Means for CISOs andrew.gertz@t“¦ Wed, 09/16/2026 – 01:04 Data Breach Data Security Encryption Key Management Identity & Access Management Camille Charaudeau – Global Vice President, Strategy & Innovation More About… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-hugging-face-wake-up-call-what-an-autonomous-ai-attack-means-for-cisos/

