Tag: security-incident
-
Eine Million offengelegte Datensätze: Was der Merkur-Datenleak über API-Sicherheit verrät
Bild: magnific.com/rajibcpcs1986 Ein massiver Sicherheitsvorfall bei Plattformen der bekannten Glücksspiel-Marke zeigt erneut die kritischen Schwachstellen moderner API-Architekturen auf. Über eine Million Datensätze darunter hochsensible KYC-Dokumente, Finanztransaktionen und Spielverhaltensprofile waren über ungesicherte Schnittstellen frei im Netz abrufbar. Der Fall illustriert eindringlich, warum API-Sicherheit längst zur Chefsache werden muss und welche Lehren IT-Verantwortliche daraus… First seen…
-
KI greift eigenständig an Unternehmen müssen ihre Cyberabwehr neu denken
Die aktuelle Berichterstattung ruft erschreckende Zukunftsszenarien wach: Zum ersten Mal wurde ein selbstständiger Hackerangriff durch eine künstliche Intelligenz bekannt. Der KI-Anbieter OpenAI meldet einen neuartigen Sicherheitsvorfall, hervorgerufen von einer unternehmenseigenen KI-Technologie. Dan Schiappa, President Technology and Services bei Arctic Wolf, erklärt, was die Evolution eigenständig angreifender KI für die Cyberbedrohungslandschaft bedeutet. ‘KI ist zunehmend in…
-
Sicherheit: Politik, Industrie und Behörden reagieren auf autonomen OpenAI-Hack
Nach dem Sicherheitsvorfall bei OpenAI mehren sich Stellungnahmen aus Politik, Wirtschaft und Aufsichtsbehörden mit Warnungen und Sorgen. First seen on golem.de Jump to article: www.golem.de/news/sicherheit-politik-industrie-und-behoerden-reagieren-auf-autonomen-openai-hack-2607-211179.html
-
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week.The AI company said the models were operating with “reduced cyber refusals for evaluation purposes” that might otherwise limit their ability…
-
Craneware confirms customer and employee data exposed in security incident
First seen on scworld.com Jump to article: www.scworld.com/brief/craneware-confirms-customer-and-employee-data-exposed-in-security-incident
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using…
-
Accenture Confirms Security Incident After Hacker Claims Data Haul
Accenture acknowledged that it suffered a data breach, but said it has remediated it with no impact on operations or service delivery. First seen on crn.com Jump to article: www.crn.com/news/security/2026/accenture-confirms-security-incident-after-hacker-claims-data-haul
-
Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle >>888<< posted on the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/
-
How to prioritize AI agent security by business impact
Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/prioritize-ai-agent-security-business-impact/
-
Wo sich wertvolle Metriken für das Security-Operations-Center finden lassen
Wie effizient ein Security-Operations-Center (SOC) arbeitet, ist durchaus messbar. Leider lassen sich Unternehmen oft von nichtssagenden Metriken blenden. Ontinue, Experte für Managed-Extended-Detection and Response (MXDR), erklärt anhand von drei Personas, wie Unternehmen maßgeschneiderte KPIs definieren. Schließt ein Security-Operations-Center täglich hunderte Tickets von Security-Incidents, ist das erst einmal beeindruckend. Diese Zahl kann allerdings trügen, denn in…
-
Von der Planung bis zum Betrieb IT-Systeme richtig aufbauen und verwalten
Die IT-Infrastruktur eines Unternehmens ist wie das Fundament eines Gebäudes: Solange alles funktioniert, denkt kaum jemand darüber nach. Wenn aber etwas schiefgeht ein Server ausfällt, Daten verloren gehen oder ein Sicherheitsvorfall eintritt zeigt sich schlagartig, wie gut oder schlecht das Fundament gelegt wurde. Viele Unternehmen, gerade im Mittelstand, entwickeln ihre IT-Infrastruktur historisch gewachsen: […] First…
-
Top Agentic SOC Vendors Defining Autonomous Security Operations
More than 100 vendors now position themselves as AI SOC platforms, but the category didn’t even exist 18 months ago. The Cloud Security Alliance found that AI-enhanced SOCs investigated cloud security incidents 4561% faster than manual teams, explaining the boom in interest. The vendors truly defining the AI SOC space are the ones The post…
-
London Hydro customer data potentially compromised in security incident
First seen on scworld.com Jump to article: www.scworld.com/brief/london-hydro-customer-data-potentially-compromised-in-security-incident
-
Klue Breach Exposes Salesforce Data at Cybersecurity Firms
A security incident at Klue exposed Salesforce data across multiple cybersecurity firms. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/klue-breach-exposes-salesforce-data-at-cybersecurity-firms/
-
Klue OAuth breach victim list grows as Icarus hackers claim attack
Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
-
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026.To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert published…
-
Azul schließt Sicherheitslücke im Java-Stack, die autonome KI-Angreifer ausnutzen können
Autonome KI-Exploit-Tools unterscheiden nicht zwischen regulierten und unregulierten Zielen. Doch die Konsequenzen eines Sicherheitsvorfalls in regulierten Umgebungen sind gravierend First seen on infopoint-security.de Jump to article: www.infopoint-security.de/azul-schliesst-sicherheitsluecke-im-java-stack-die-autonome-ki-angreifer-ausnutzen-koennen/a45545/
-
FIFA schrammt knapp an schwerem IT-Sicherheitsvorfall vorbei
…wäre da nicht die Hartnäckigkeit eines ethischen Hackers in Japan gewesen. Die FIFA hat sich mit einer schwerwiegenden Sicherheitslücke, über die Bobdahacker gestern berichtete, beinahe ein Eigentor geschossen. Der japanische Hacker fand heraus, dass sich jedermann einfach mit einem Ausweis auf der offiziellen FIFA-Agentenplattform registrieren konnte. Durch eine fehlerhafte clientseitige Rollenprüfung im Backend konnte… First…
-
Ozempic Maker Novo Nordisk Confirms Security Incident After $25M Hacker Demand
Hackers claim they stole 1.3TB of Novo Nordisk data, including clinical trial and AI model information, after issuing a $25 million demand. The post Ozempic Maker Novo Nordisk Confirms Security Incident After $25M Hacker Demand appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-novo-nordisk-1-3tb-theft-25m-demand-emea/
-
Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)
Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/16/cisco-sd-wan-cve-2026-20262-exploited/
-
Maine Shuts Down Breach Reporting Portal Following Fake VRChat and Discord Submissions
The Office of the Maine Attorney General has temporarily taken its public data breach reporting portal offline following the discovery of fraudulent submissions falsely claiming security incidents at VRChat and Discord. The incident, disclosed in an official statement on June 12, 2026, highlights growing concerns over the integrity and potential abuse of publicly accessible breach…
-
Japanese energy firm loses drive with data of 10.9 million clients
Kyushu Electric Power Co., Inc. has disclosed a physical security incident that affects private data of more than 10 million customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/
-
Mehr als die Hälfte der europäischen Unternehmen hat im vergangenen Jahr einen Sicherheitsvorfall durch nicht-menschliche Identitäten erlebt
Keeper Security weist heute auf eine erhebliche Lücke in der Governance hin: Unternehmen weiten den Einsatz von KI-gesteuerten und nicht-menschlichen Identitäten aus, ohne über die erforderlichen Kontrollmechanismen zu verfügen, um deren Sicherheit zu gewährleisten. Erkenntnisse aus einer Umfrage unter Cybersicherheitsexperten auf der Infosecurity Europe 2026 in London zeigen, dass KI-Agenten und nicht-menschliche Identitäten mittlerweile fest…
-
Mackay Sugar Security Incident Forces Mill Shutdowns and Halts Harvesting Operations
Australia’s second-largest sugar producer, Mackay Sugar, is investigating a cyberattack that has disrupted parts of its operations and temporarily halted sugarcane harvesting in Queensland’s Mackay region. The Mackay Sugar security incident has led to the suspension of milling activities at two of the company’s facilities while cybersecurity specialists and authorities work to determine the nature and impact…
-
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of its open-source projects being compromised to inject an information stealer into the code.”Our priority is to protect customers and the broader ecosystem,” a Microsoft spokesperson told The Hacker News via email. “We…
-
Hacked, leaked, and held for ransom: the worst breaches of 2026 so far
From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/07/the-worst-hacks-and-breaches-of-2026-so-far/
-
Cloud Security Alliance Report Highlights Growing Patch Gap Risks
AI is accelerating exploitation timelines while known vulnerabilities remain a leading cause of security incidents, according to a CSA report. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cloud-security-alliance-report-highlights-growing-patch-gap-risks/

