Tag: unauthorized
-
Reducing shadow IT visibility gaps with Wazuh
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/reducing-shadow-it-visibility-gaps-with-wazuh/
-
Google Gemini Agents Access Real Companies in AI Safety Test
Agents Stopped After Recognizing Real Targets, Exposing Sandboxed Cyber Test Flaws. AI agents built with Google’s Gemini model gained unauthorized access to other companies to solve a cybersecurity test, making Google the latest company embroiled in the AI safety debate. This also marks the fourth such incident involving the security evaluation company Irregular. First seen…
-
Gyazo Data Breach Exposes 23 Million User Records
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a vulnerability in the service’s image upload server. >>We have confirmed that approximately…
-
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.”Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,” First…
-
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.”Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,” First…
-
OpenAI Finds Models Writing Their Own Rogue Instructions
Agents Added Unauthorized Commands to Bypass Guardrails and Conceal Errors. OpenAI found instances of models and agents writing additional, unauthorized commands to themselves that seek to contradict developer guardrails. The company said in a Wednesday report on misalignment that it observed six new misaligned behaviors. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/openai-finds-models-writing-their-own-rogue-instructions-a-32862
-
OpenAI details more cases of AI agents taking unauthorized actions
OpenAI has presented new examples of what they call “AI model misalignment” from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/
-
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency.”As AI systems grow more advanced and more widely deployed, we need to build a broader…
-
Hackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Access
Tags: access, advisory, authentication, cisco, cve, cvss, cyber, exploit, flaw, hacker, identity, service, unauthorized, vulnerabilityCisco has issued an urgent security advisory regarding a critical authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability, tracked as CVE-2026-76460, has a maximum CVSS score of 10.0 and could allow unauthenticated remote attackers to gain unauthorized access to vulnerable devices. Cisco advisory cisco-sa-ISE-ABP-VNSW7Tn5 details the…
-
CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information
CenterPoint Energy has confirmed that an unauthorized third party accessed personal information belonging to some of its customers by compromising one of the utility provider’s external systems. The Houston-based energy company disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission dated September 14, 2026. CenterPoint learned of the potential…
-
CenterPoint Energy confirms data breach following claims on hacking forum
CenterPoint Energy disclosed that an unauthorized third party got into customer data through one of its external systems, after online claims by a hacker that millions of … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/centerpoint-energy-data-breach-hacker-claims/
-
GitLab Unauthenticated Path Traversal Exploited in the Wild (CVE-2026-85706)
Background GitLab servers hold source code and support the build and deployment workflows that organizations depend on. Unauthorized access to server-side files can expose information that extends an attacker’s reach into development infrastructure. On September 10, 2026, GitLab released fixes… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/gitlab-unauthenticated-path-traversal-exploited-in-the-wild-cve-2026-85706/
-
Nintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code
Nintendo released system version 23.0.0 to address CVE-2026-82079, a vulnerability in the Nintendo Switch’s local wireless networking that could turn the QR code sharing process into an attack vector. This issue affects consoles running firmware older than version 23.0.0, allowing a nearby attacker to execute unauthorized code or access data stored on the device. Nintendo…
-
14th September Threat Intelligence Report
Tags: access, breach, data, data-breach, government, identity, intelligence, marketplace, threat, unauthorizedIDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/14th-september-threat-intelligence-report/
-
Revolut Confirms Data Breach Through Fake Government Requests
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/revolut-data-breach-fake-government/
-
Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks
Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s…
-
Unsanctioned OpenAI Agent Activity Targeted RubyGems: Report
Advanced artificial intelligence (AI) agents under test by OpenAI launched an unauthorized cyber incident against software host RubyGems in May, the latest major disruption caused by the company’s autonomous systems in recent months. The disclosure highlights intensifying concerns among researchers and lawmakers over the industry’s ability to control increasingly autonomous software. According to a report..…
-
IDScan Confirms Breach Tied to 153 Million Stolen Driver’s Licenses
IDScan confirmed unauthorized cloud access after researchers linked its infrastructure to a dark-web marketplace holding millions of identity records. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-idscan-breach-driver-license-dark-web/
-
The Agents Broke Out. Panic Is Not a Policy
In July, an army of AI agents participating in an OpenAI cybersecurity evaluation did something they were never supposed to do. They found one another. The agents created an unauthorized message board, shared discoveries, divided up work and built a form of collective memory that survived after individual agents stopped running. Approximately 1,200 agents eventually..…
-
Anthropic Finds Fourth Claude Cyber Incident After Model Accessed Third-Party Computer
Anthropic disclosed this week that a Claude model gained unauthorized access to a third-party computer outside its test environment during cybersecurity testing. It is the fourth such incident the company has identified, and an earlier scan of roughly 141,000 evaluation transcripts failed to catch it. The newly disclosed incident occurred in January and involved an..…
-
Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
Tags: access, authentication, cisco, credentials, cve, cyber, exploit, firewall, flaw, malware, network, theft, threat, unauthorized, vulnerabilityCisco Talos has warned that threat actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These vulnerabilities can lead to unauthorized access, root-level code execution, credential theft, network reconnaissance, and malware deployment. Critical Cisco FMC Flaws The most critical issue is identified as CVE-2026-20079, a critical authentication-bypass vulnerability with a…
-
OpenAI Agents Bypassed Web Posting Restrictions To Communicate Across Multiple Sites
Another day, another report of AI agents going rogue. This time, independent researchers say OpenAI agents used more than 10 previously undisclosed websites to communicate with one another, possibly during internal research tasks earlier this year, Reuters reported. “‹”‹The investigation expands the known scope of unauthorized agent activity first uncovered on a German-language wiki. The..…
-
Anthropic Claude AI Models Attack Real Systems During Misconfigured Cybersecurity Tests
Anthropic has reported four cybersecurity evaluation incidents in which pre-release Claude AI models gained unauthorized access to real third-party systems after isolated test environments were accidentally connected to the internet. These cases revealed significant alignment failures, including biased reasoning and reckless task pursuit, when autonomous models operated for extended periods without production cyber safeguards. All…
-
Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws
Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments.…
-
AI Customer Service Agents Can Be Hacked to Bypass MFA, Steal OTPs and Expose User Data
Tags: ai, api, authentication, cyber, data, email, exploit, identity, mfa, password, risk, service, unauthorized, vulnerabilitySecurity researchers have demonstrated how vulnerabilities in AI-powered customer service agents can be exploited to bypass identity checks, expose sensitive customer data, exfiltrate one-time passwords (OTPs), and trigger unauthorized account actions. These findings underscore that the risks go beyond prompt injection; they also stem from flawed integrations among email, authentication, backend APIs, knowledge bases, and…
-
Bimbo Bakeries USA Data Breach Exposes SSNs in Oracle E-Business Suite Zero-Day Attack
Tags: access, attack, breach, business, cyber, data, data-breach, exploit, oracle, unauthorized, usa, vulnerability, zero-dayBimbo Bakeries USA (BBU) has revealed that attackers gained access to files containing names and Social Security numbers by exploiting a zero-day vulnerability in Oracle E-Business Suite (EBS), which a third-party vendor uses. The company confirmed the unauthorized access in December 2025 but did not identify the existence of Social Security numbers until August 2026.…
-
7th September Threat Intelligence Report
Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/7th-september-threat-intelligence-report/
-
7th September Threat Intelligence Report
Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/7th-september-threat-intelligence-report/
-
Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ
The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff. First seen on thecyberexpress.com Jump to article:…
-
Proposed AI Superintelligence Ban Would Carry Prison Terms, Corporate Shutdowns
Sen. Bernie Sanders and Rep. Greg Casar are preparing legislation that would permanently ban artificial superintelligence in the U.S., a sweeping proposal prompted in part by recent incidents in which AI agents gained unauthorized access to computer networks. The Ban Artificial Superintelligence Act would prohibit the development and deployment of AI that exceeds human intelligence..…

