Tag: Internet
-
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-the-openai-models-that-hacked-hugging-face-were-active-on-the-internet-for-days/
-
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion. The advisory, first issued in April 2026 and revised on July 22, 2026, is cosigned…
-
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering and product design data. This chaining enables unauthenticated remote code execution, allowing attackers to deploy…
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
-
CISA Again Sounds Warning Over Exposed PLCs
Internet-Exposed Programmable Logic Controllers ‘An Easy Target’. Thousands of vulnerable industrial devices, accessible from the public internet, are being targeted by Iran-linked hackers, U.S. authorities said this week. The warning was an update to an advisory CISA originally published in April. The revision is because a broader range of device brands are under attack. First…
-
Cloudflare CEO: How AI Commerce Is Upending the Web Economy
Matthew Prince: AI Assistants Are Replacing Traditional Search and Commerce Models. Cloudflare’s CEO said AI assistants are replacing traditional search and advertising-driven internet models, arguing that AI firms and search engines must adopt more efficient, event-driven crawling to reduce infrastructure costs while preparing for an AI-first internet powered by autonomous agents. First seen on govinfosecurity.com…
-
Censys Finds AI/LLM Tool Exposures Up More Than 60%
Censys found Internet-exposed AI/LLM tools increased more than 60% in nine months, expanding organizations’ attack surfaces. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/censys-finds-ai-llm-tool-exposures-up-more-than-60/
-
CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure
CISA and partner agencies are directing U.S. critical infrastructure operators to immediately remove Rockwell and other programmable logic controllers (PLCs) from direct internet exposure and to hunt for Iranian-affiliated APT activity in OT environments aggressively. In a joint advisory first issued on April 7, 2026 and updated on July 22, 2026, the FBI, CISA, NSA,…
-
US seizes over 1,000 domains used for illegal World Cup 2026 streams
Tags: InternetThe US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/world-cup-2026-illegal-stream-domains-seized/
-
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims
The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimize individuals who have already fallen prey to scams. Released on July 20, 2026, the alert highlights…
-
Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers
Tags: credentials, crime, cyber, cybercrime, germany, infrastructure, Internet, office, phishing, serviceAuthorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted…
-
OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers
OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers…
-
Cyberattack disrupts internet service for 23 Maine towns
First seen on scworld.com Jump to article: www.scworld.com/brief/cyberattack-disrupts-internet-service-for-23-maine-towns
-
OpenAI Models Escaped Containment and Hacked Hugging Face
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
OpenAI Models Escaped Containment and Hacked HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public…
-
Altersverifikation im Internet: CISPA-Forscher warnt vor pauschalen Lösungen
Tags: InternetFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/altersverifikation-internet-cispa-warnung-pauschal-loesungen
-
Fake FBI agents target people who already got scammed
Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/fbi-ic3-impersonation-scam-warning/
-
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and…
-
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Tags: advisory, cctv, cybersecurity, intelligence, Internet, military, russia, service, spy, ukraineAt least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and military…
-
Digitale Zertifikate für die Gebäudeautomation
Moderne Gebäude sind hochkomplex egal ob Büroflächen, Krankenhäuser, Flughäfen oder beispielsweise Rechenzentren. Zutrittskontrolle, Heizung, Belüftung, Brandmeldesysteme, Sicherheitskameras und vieles mehr: alles ist heute vernetzt und kann im Zweifel remote überwacht oder gewartet werden. BxC Security, ein Cybersicherheitsunternehmen für den Bereich Operational Technology (OT) und Industrial Internet of Things (IIoT), erklärt, warum vernetzte Gebäudetechnik zum… First…
-
Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw
Millions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to control devices remotely, access onboard cameras, retrieve home maps, and potentially steal stored Wi-Fi credentials. An independent researcher disclosed this issue following a 90-day reporting period, and it arises from overly permissive AWS…
-
Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw
Millions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to control devices remotely, access onboard cameras, retrieve home maps, and potentially steal stored Wi-Fi credentials. An independent researcher disclosed this issue following a 90-day reporting period, and it arises from overly permissive AWS…
-
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel. First seen on therecord.media Jump to article: therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands
-
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel. First seen on therecord.media Jump to article: therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands
-
EU-Bericht zum Kinderschutz im Internet: Bitkom fordert risikobasierten Ansatz als Leitprinzip zu erhalten
Tags: InternetFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/eu-bericht-kinderschutz-internet-bitkom-forderung-risikobasiert-ansatz
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate
VEXAIoT, an autonomous multi-agent framework designed to discover and exploit vulnerabilities in the Internet of Things (IoT) within controlled test environments. In 200 attack trials against the intentionally vulnerable IoTGoat platform, the system completed 189 attacks, achieving an overall success rate of 94.5% (rounded to 95%). New VEXAIoT AI Agents Attack Workflow VEXAIoT, short for…
-
Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access
A large-scale exploitation campaign is actively weaponising known vulnerabilities across multiple content management systems, with WordPress plugins forming the primary attack surface. Cyber actors are scanning the internet for vulnerable sites and chaining unauthenticated file upload, remote code execution (RCE), server-side request forgery (SSRF) and deserialization vulnerabilities to deploy webshells that grant persistent remote access.…
-
Internet-Intelligence und Attack-Surface-Management als Basis für Exposure-Management
Die Angriffsfläche von Unternehmen wächst kontinuierlich. Cloud-Dienste, SaaS-Anwendungen, IoT-Sensoren, hybride Infrastrukturen und Remote-Work sorgen dafür, dass immer mehr Systeme direkt über das Internet erreichbar sind. Eine umfassende Transparenz mit Exposure-Management wird damit zu einer zentralen Voraussetzung für wirksame Cybersecurity. Externe Angriffspunkte bilden den Ausgangspunkt vieler erfolgreicher Angriffe. Fehlkonfigurationen, Schatten-IT, unbeabsichtigter Remote-Access und im Internet sichtbare…

