Tag: unauthorized
-
UK AI tests found 19 unauthorized agent actions involving Anthropic and OpenAI models
UK researchers reported 19 unsanctioned actions by Anthropic and OpenAI agents during permissive cyber tests involving real external systems. The post UK AI tests found 19 unauthorized agent actions involving Anthropic and OpenAI models appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uk-ai-agents-unsanctioned-cyber-actions-emea/
-
Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/healthcare-victim-charities-beacon/
-
Huntress Makes RMM Guard Free to Block Rogue Remote-Access Tools
Huntress is making its RMM Guard capability free for customers and partners with an agent deployed, giving them a way to inventory and block unauthorized remote monitoring and management tools. The move was announced during the Black Hat USA 2026 product window as part of Huntress Managed Endpoint Security Posture Management, or ESPM. Managed ESPM..…
-
Guide to Agentic AI Governance
Tags: access, ai, api, application-security, attack, authentication, business, cloud, compliance, control, credentials, data, email, exploit, finance, framework, GDPR, governance, guide, healthcare, identity, injection, least-privilege, LLM, malicious, monitoring, phishing, radius, regulation, risk, service, software, tool, unauthorized, vulnerabilityAgentic AI governance is about keeping powerful, autonomous AI systems aligned, safe, and accountable as they act on our behalf. It’s now a certainty that AI agents will be deployed enterprise-wide. So, we need to look more deeply into those agents, figure out where they are, how to find them, and fully understand what they…
-
Guide to Agentic AI Governance
Tags: access, ai, api, application-security, attack, authentication, business, cloud, compliance, control, credentials, data, email, exploit, finance, framework, GDPR, governance, guide, healthcare, identity, injection, least-privilege, LLM, malicious, monitoring, phishing, radius, regulation, risk, service, software, tool, unauthorized, vulnerabilityAgentic AI governance is about keeping powerful, autonomous AI systems aligned, safe, and accountable as they act on our behalf. It’s now a certainty that AI agents will be deployed enterprise-wide. So, we need to look more deeply into those agents, figure out where they are, how to find them, and fully understand what they…
-
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
Different logos, different color schemes, same scam. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/amazon-and-apple-impersonated-in-149-99-unauthorized-charge-scam/
-
Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks
Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access control bypass, unauthorized privilege escalation, and exposure of sensitive data. The most severe vulnerabilities are CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each with a maximum CVSS v3.1 score of 9.9. Critical Cisco SD-WAN Flaws These vulnerabilities were…
-
UK AI tests found 19 unauthorized agent actions involving Anthropic and OpenAI models
UK researchers reported 19 unsanctioned actions by Anthropic and OpenAI agents during permissive cyber tests involving real external systems. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-uk-ai-agents-unsanctioned-cyber-actions/
-
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
Researchers at security firm Zenity found more than a dozen flaws in AI browsers”, and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase. First seen on wired.com Jump to article: www.wired.com/story/openais-browser-could-be-hijacked-to-spam-your-whatsapp-contacts/
-
Viakoo Adds Configuration Drift Remediation for OT and IoT Devices
Viakoo has introduced Device Configuration Manager, a module for its Action Platform that monitors and remediates configuration drift across operational technology and internet of things devices. DXM continuously audits device configuration parameters against operational and security baselines without requiring an endpoint agent. It identifies unauthorized changes caused by local adjustments, field maintenance or malicious tampering,..…
-
Mythos 5 and GPT-5.6-Sol AI Agents Broke Cyber Test Boundaries and Targeted Real Users
The UK AI Security Institute (AISI) has reported a serious incident involving autonomous AI agents that were conducting cybersecurity evaluations. These agents crossed their intended test boundaries and performed unauthorized actions on the live internet. During tests between July 25 and 28, 2026, the institute identified 19 incidents across 122 attempts in which the agents…
-
Apache NiFi Flaw Enable Security Bypass and Memory Corruption
Apache NiFi has issued security advisories for four vulnerabilities affecting its web API. These include an authorization bypass that could allow unauthorized deletion of Parameter Context assets, and a high-severity issue that results in excessive memory consumption through specially crafted gzip-compressed HTTP requests. The vulnerabilities impact Apache NiFi versions from 1.5.0 through 2.10.0, depending on…
-
TDL 027 – Why Your Logs Should Get Quieter With Every Layer – Dhruv Ahuja
Tags: 2fa, access, adobe, adware, ai, antivirus, apple, authentication, awareness, business, chatgpt, china, ciso, cloud, computer, control, country, crime, cryptography, cyber, cybersecurity, data, defense, detection, dns, edr, email, exploit, finance, firewall, governance, government, group, hacking, healthcare, ibm, infrastructure, Internet, jobs, law, malware, metric, mfa, mobile, phishing, phone, ransomware, risk, russia, service, software, spear-phishing, strategy, technology, threat, tool, unauthorized, usa, vulnerability, wifi, windows, zero-trustIn this episode of The Defender’s Log, host David Redekop sits down with Dhruv Ahuja, founder and chief engineer at Chaser Systems, to discuss cloud infrastructure security, entrepreneurial lessons, and stopping malware egress. Key takeaways from their conversation: 1. Zero Trust Egress via Allowlisting Traditional firewalls rely heavily on blocklists or detection-and-response tactics. However, modern…
-
CareCloud Data Breach Exposes Patients’ Health, Social Security and Credit Card Data
Tags: access, breach, credit-card, cyber, data, data-breach, insurance, security-incident, service, unauthorizedCareCloud has reported a data security incident involving unauthorized access to its Amazon Web Services (AWS) environment that supports the CareCloud Health division. This incident disrupted one of the company’s electronic health record (EHR) systems. It may have exposed a wide range of protected health information (PHI), personally identifiable information (PII), insurance details, and, for…
-
Arch Linux Suspends AUR Package Adoptions to Block Ongoing Malicious Commit Campaign
Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after detecting a wave of malicious activity targeting orphaned and unmaintained packages. The Arch Linux DevOps team confirmed the emergency measure on July 30, 2026, citing an active campaign involving unauthorized package takeovers followed by the injection of harmful commits. Robin Candau,…
-
Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins
A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by researcher Enzo Mongin from Escape Research, also known as Orionexe. The vulnerability was reported to the Keycloak team on July 18, 2026, acknowledged…
-
Anthropic’s Claude breached three companies during security tests
Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/31/anthropic-claude-cybersecurity-incidents/
-
Critical Adobe Campaign Flaw Lets Attackers Execute Arbitrary Code
Adobe has released a critical security update for Adobe Campaign Classic to address multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code and access sensitive data through unauthorized file system reads. This advisory, tracked as APSB26-114 and published on July 29, 2026, has a priority rating of 1, indicating the highest level of…
-
Critical SolarWinds Web Help Desk Flaw Lets Attackers Bypass SAML Authentication
SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address a critical authentication bypass vulnerability. This flaw could allow attackers to gain unauthorized access to affected systems by exploiting weaknesses in SAML-based single sign-on (SSO) implementations. Tracked as CVE-2026-28323 and assigned a CVSS score of 9.8, the vulnerability impacts deployments where SAML 2.0 authentication…
-
Analog Devices Confirms Cyberattack After Hackers Exfiltrate Files From Company Systems
Tags: access, cyber, cyberattack, cybersecurity, hacker, incident, incident response, law, unauthorizedAnalog Devices, Inc. has confirmed that unauthorized actors gained access to certain company systems and exfiltrated files. The semiconductor manufacturer detected the cyber incident on June 23, 2023, and immediately activated its incident response protocols. The company enlisted external cybersecurity experts to assist with containment and forensic investigations and notified law enforcement authorities. According to…
-
Anthropic Confirms Claude AI Models Hacked 3 Organizations During Cybersecurity Evaluations
Anthropic has disclosed that three Claude AI models gained unauthorized access to the production systems of three real-world organizations during cybersecurity capability evaluations. These incidents resulted from a misconfiguration in a third-party testing environment that granted the models live internet access, despite clear instructions stating they were operating in isolated simulations without internet connectivity. Claude…
-
India’s Bank of Baroda confirms cyber incident after hackers claim data theft
An employee’s email account had been compromised, allowing unauthorized access to “certain data,” Bank of Baroda reported. First seen on therecord.media Jump to article: therecord.media/india-bank-of-baroda-reports-cybersecurity-incident
-
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity
JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized actions in development and continuous integration environments. The updates fix weaknesses in Remote Development sessions, Git and Perforce VCS integrations, workspace handling, agent registration, and permission validation. JetBrains Patches Multiple Vulnerabilities…
-
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data
Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for one of Australia’s largest energy providers. The company identified the breach on July 22, 2026, and it is currently under active investigation to determine the full extent and impact on affected…
-
Australian energy provider Origin says data breach exposes client data
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/
-
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication
A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3 and impacts Check Point Security Management and Multi-Domain Management deployments, particularly when management interfaces are…
-
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California, San Diego, revealed that the flaw allows attackers within Bluetooth range to issue commands such…
-
Glow Launches With $180M to Thwart AI Risk at the Endpoint
Startup Platform Combines Endpoint Activity, Business Context and Security Policies. Glow emerged from stealth with $180 million in funding and a $1.2 billion valuation, betting that AI-driven endpoint prevention, powered by organizational context and human oversight, can stop malicious software, AI agents and unauthorized applications before they create enterprise risk. First seen on govinfosecurity.com Jump…
-
Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
Meta has addressed a critical vulnerability involving broken access control that exposed sensitive customer support data across multiple services. This issue highlighted systemic weaknesses in authorization within their shared backend infrastructure. The flaw, categorized as an Insecure Direct Object Reference (CWE-639) combined with Broken Access Control (CWE-284) and Missing Authorization (CWE-862), allowed unauthorized users to…
-
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Tags: access, authentication, corporate, cve, exploit, flaw, ransomware, unauthorized, vpn, vulnerabilityQilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks. CVE-2026-0257 is a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways. Palo Alto Networksaddressed the vulnerabilityon May…

