Tag: security-incident
-
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
From the massive DOGE data breach and the compromise of critical infrastructure to the hack of federal surveillance systems, here are the most damaging security incidents and data breaches of 2026 so far. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/15/the-worst-hacks-and-breaches-of-2026-so-far/
-
SaaS API Security Incidents: What 2026 Breach Data Shows
Key TakeawaysAn analysis of 60 disclosed API breaches in 2025 found broken authentication caused 52 percent of incidents, with unsafe consumption of third party APIs accounting for another 27 percent.SaaS companies accounted for 8 percent of breaches in that same… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/saas-api-security-incidents-what-2026-breach-data-shows/
-
Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC
The Liquid Network security incident has taken an unusual turn after the unidentified actors behind the theft of nearly 4,000 BTC offered to return “most” of the funds, but only after the vulnerability that enabled the exploit is fixed across the network. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/liquid-network-security-incident/
-
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.”Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,”…
-
METR discloses 2 security incidents, including $600,000 model credit theft
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-model-testing-org-discloses-two-security-incidents-including-600000-credit-theft
-
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA’s…
-
Vektorisierung und Abliteration als KI-Risiken
Die Zahl der Kompromittierungsversuche auf öffentlich zugängliche KI-Modelle und eigenentwickelte LLMs nimmt zu. Laut den Ergebnissen des aktuellen Cost of a Data-Breach-Reports von IBM stieg die Zahl der KI-gestützten Angriffe im Vergleich zum Vorjahr um 56 Prozent. Die finanziellen Folgen waren nicht unerheblich. KI-gestützte Angriffe verursachten pro Sicherheitsvorfall durchschnittlich 1 Million US-Dollar an Kosten, da Angreifer…
-
OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities
OpenAI has temporarily slowed the development of its latest frontier AI models after initial testing suggested that its upcoming Astra system may meet the company’s >>Critical<< cybersecurity capability threshold. This decision follows a recent security incident involving OpenAI and Hugging Face. It reflects growing concerns that advanced models could significantly increase the risks of cyber…
-
AI Security Incident Case: Encrypted Reasoning Blocks of Proprietary LLMs Can Be Stolen via Cross-Model Replay
Overview On August 10, 2026, MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and other institutions jointly published the paper Stealing Reasoning Traces from Proprietary LLM APIs. The research reveals a common architectural flaw in the reasoning model APIs of three major AI providers, Anthropic, OpenAI, and Google, which allows……
-
Cyberresilienz als Gesamtpaket – Arctic Wolf bündelt Security, Incident Response und Garantie
First seen on security-insider.de Jump to article: www.security-insider.de/arctic-wolf-buendelt-security-incident-response-und-garantie-a-8ec480487f8e846d27c4c58b916e3274/
-
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
-
Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials
Tags: attack, cloud, credentials, cyber, endpoint, exploit, flaw, security-incident, sql, update, vulnerability, zero-dayMetabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited this previously unknown flaw to target Metabase Cloud before the vulnerable endpoints were blocked and a patch was developed. Customers using Metabase…
-
AI Sandbox Failures Expose Need for Continuous Monitoring
Recent AI Incidents Show Sandbox Security Cannot Be Assumed. The fallout from the Hugging Face security incident continues with more artificial intelligence labs revealing that their models and agents either accessed the internet or escaped isolated test environments to hack into other companies. Frontier model labs can’t take sandbox containment as a given. First seen…
-
Top 10 Breaches of the Week
Security Boulevard’s weekly after-action roundup looks at the breaches and security incidents that mattered most over the past two weeks. This edition spans large healthcare exposures, attacks on government and financial infrastructure, a fast-moving software supply-chain compromise, and incidents where the final scope is still being established. #1: Unlimited Technology Systems: 3.8 million healthcare records..…
-
Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident
The Updoc data breach has raised fresh concerns about cybersecurity in Australia’s healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/updoc-data-breach/
-
Open Secure AI Alliance Proposes AI Agent Security Rules
SAFE framework seeks incident sharing after AI agent security breaches. The Open Secure AI Alliance has proposed a cybersecurity information-sharing framework for AI agents following recent security incidents involving OpenAI and Anthropic models. The SAFE guidelines would require members to report AI security incidents, share threat intelligence and preserve evidence to help reduce systemic risks…
-
OpenAI Says Its AI Hacked Another Company on Its Own
OpenAI disclosed an unusual AI security incident involving a frontier model evaluation and Hugging Face, but the episode cuts through the hype: was this true autonomous intent, an agent following bad scope boundaries, or a warning about giving AI systems real tools and permissions? Tom, Scott, and Kevin discuss why anthropomorphizing AI makes the story……
-
AI Security Incident Response Framework – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-security-incident-response-framework-kovrr/
-
Eine Million offengelegte Datensätze: Was der Merkur-Datenleak über API-Sicherheit verrät
Bild: magnific.com/rajibcpcs1986 Ein massiver Sicherheitsvorfall bei Plattformen der bekannten Glücksspiel-Marke zeigt erneut die kritischen Schwachstellen moderner API-Architekturen auf. Über eine Million Datensätze darunter hochsensible KYC-Dokumente, Finanztransaktionen und Spielverhaltensprofile waren über ungesicherte Schnittstellen frei im Netz abrufbar. Der Fall illustriert eindringlich, warum API-Sicherheit längst zur Chefsache werden muss und welche Lehren IT-Verantwortliche daraus… First seen…
-
KI greift eigenständig an Unternehmen müssen ihre Cyberabwehr neu denken
Die aktuelle Berichterstattung ruft erschreckende Zukunftsszenarien wach: Zum ersten Mal wurde ein selbstständiger Hackerangriff durch eine künstliche Intelligenz bekannt. Der KI-Anbieter OpenAI meldet einen neuartigen Sicherheitsvorfall, hervorgerufen von einer unternehmenseigenen KI-Technologie. Dan Schiappa, President Technology and Services bei Arctic Wolf, erklärt, was die Evolution eigenständig angreifender KI für die Cyberbedrohungslandschaft bedeutet. ‘KI ist zunehmend in…
-
Sicherheit: Politik, Industrie und Behörden reagieren auf autonomen OpenAI-Hack
Nach dem Sicherheitsvorfall bei OpenAI mehren sich Stellungnahmen aus Politik, Wirtschaft und Aufsichtsbehörden mit Warnungen und Sorgen. First seen on golem.de Jump to article: www.golem.de/news/sicherheit-politik-industrie-und-behoerden-reagieren-auf-autonomen-openai-hack-2607-211179.html
-
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week.The AI company said the models were operating with “reduced cyber refusals for evaluation purposes” that might otherwise limit their ability…
-
Craneware confirms customer and employee data exposed in security incident
First seen on scworld.com Jump to article: www.scworld.com/brief/craneware-confirms-customer-and-employee-data-exposed-in-security-incident
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using…
-
Accenture Confirms Security Incident After Hacker Claims Data Haul
Accenture acknowledged that it suffered a data breach, but said it has remediated it with no impact on operations or service delivery. First seen on crn.com Jump to article: www.crn.com/news/security/2026/accenture-confirms-security-incident-after-hacker-claims-data-haul
-
Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle >>888<< posted on the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/

