Tag: unauthorized
-
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Tags: cve, data, exploit, flaw, microsoft, office, rce, remote-code-execution, unauthorized, update, vulnerabilityA third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network.…
-
Craneware Cyberattack Exposes Employee and US Healthcare Customer Data
Craneware plc, a UK-based provider of healthcare financial performance software, has disclosed that it experienced a cyberattack in which an unauthorized party accessed and extracted data from a portion of its systems. The company revealed that the incident involved employee information and records related to certain customers and partners, including organizations in the US healthcare…
-
US Hospital Finance Software Provider Craneware Reports Data Theft
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/craneware-reports-data-theft/
-
Abbott Confirms Cyberattack After Unauthorized Access to Cancer Diagnostics Systems
Abbott has disclosed a cybersecurity incident involving unauthorized access to a limited number of internal systems used by its Cancer Diagnostics business. Upon discovering the activity, the company acted swiftly by launching an investigation, engaging external cybersecurity experts, and coordinating with law enforcement agencies. Abbott Confirms Cyberattack According to Abbott’s statement released on July 16,…
-
Shadow AI Is Rewriting Cyber Disclosure Risk
Bank Filing Shows Why Unauthorized Tools Belong in Cyber Response Plans. A bank’s SEC filing over unauthorized AI use shows how shadow AI can turn an employee shortcut into a material cyber event. Even if federal disclosure rules ease, companies still face state laws, sector requirements, escalating litigation risk and costs. First seen on govinfosecurity.com…
-
Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
Craneware, which is headquartered in Edinburgh and listed on London’s AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators. First seen on therecord.media Jump to article: therecord.media/software-provider-for-us-hospitals-customer-data-breach
-
Craneware Confirms Data Breach, Employee Records Among Exposed Data
Craneware plc has disclosed a Craneware data breach after detecting unauthorized access to a portion of its data environment. The company confirmed on 20 July 2026 that it is investigating the incident with the support of external cybersecurity and forensic experts. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/craneware-data-breach/
-
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.The company said it detected and responded to the incident targeting its production infrastructure earlier last week.”We identified unauthorized access to a limited set of internal datasets and to…
-
Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens
Tags: access, ai, breach, credentials, cyber, data, infrastructure, security-incident, service, unauthorizedHugging Face has disclosed a security incident involving unauthorized access to certain parts of its production infrastructure, affecting a limited set of internal datasets and several service credentials. The AI platform made this disclosure on July 16, 2026, noting that it is still investigating whether any partner or customer data was compromised. The company stated…
-
EY Data Breach Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
Tags: access, breach, cyber, data, data-breach, finance, hacker, office, security-incident, service, unauthorizedErnst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform used by its tax practice, exfiltrating documents containing client personal and financial information. The Big Four firm filed formal breach notifications with the California Attorney General’s office on July 15, 2026,…
-
Abbott probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/
-
Abbott Laboratories probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/
-
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, fortinet, infrastructure, injection, kev, unauthorized, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Fortinet FortiSandbox to its Known Exploited Vulnerabilities (KEV) catalog. These flaws are actively being exploited in the wild to execute unauthorized commands on affected systems. The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089, involve OS command injection weaknesses (CWE-78) and impact FortiSandbox…
-
New Framework Redefines AI Penetration Testing Around Prompt Injection and Behavioral Objective Violations
Tags: access, ai, cyber, data, framework, infrastructure, injection, penetration-testing, service, theft, unauthorizedA newly proposed framework argues that AI penetration testing must move beyond conventional infrastructure compromise and assess whether an adversary can make an AI-enabled system act against its intended operational purpose. Traditional penetration testing typically measures compromise through outcomes such as unauthorized access, privilege escalation, data theft, service disruption, or persistence. Those outcomes remain critical…
-
OpenAI Unveils GPT-Red AI Model That Automatically Finds Prompt Injection Vulnerabilities
OpenAI has introduced GPT-Red, an automated safety red-teaming model trained to identify and exploit prompt injection weaknesses in AI agents. Prompt injection occurs when malicious instructions hidden in webpages, emails, local files, code repositories, or tool outputs manipulate an AI system into ignoring its intended task, potentially causing data theft, unauthorized actions, or policy bypasses.…
-
Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions
Tel Aviv, Israel, 14th July 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/tego-ai-finds-claude-tag-slack-integration-can-trigger-unauthorized-enterprise-actions/
-
Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended
Japan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings. Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving malware infection in the early morning hours of Saturday, July 11. The company immediately shut down systems…
-
NHS staff warned of jail time for unauthorized patient data access
First seen on scworld.com Jump to article: www.scworld.com/brief/nhs-staff-warned-of-jail-time-for-unauthorized-patient-data-access
-
Critical BeyondTrust Authentication Flaws Expose Remote Support Appliances to Attacks
Tags: access, advisory, attack, authentication, cvss, cyber, data, flaw, risk, service, unauthorized, vulnerabilityBeyondTrust has disclosed multiple critical and high-severity vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) appliances. These flaws expose organizations to risks such as authentication bypass, denial-of-service attacks, and unauthorized data access. Tracked under advisory BT26-03, these vulnerabilities have a maximum CVSS v4 score of 9.2 and were identified through the company’s…
-
6th July Threat Intelligence Report
River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/6th-july-threat-intelligence-report-2/
-
NO FAKES Act advances: What CISOs need to know
As the NO FAKES Act moves to the Senate, the country is closer to real protections against unauthorized AI replica use — a move that also has enterprise implications. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366645063/NO-FAKES-Act-advances-What-CISOs-need-to-know
-
JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Vulnerabilities
JetBrains has released patches for several critical vulnerabilities in JetBrains Hub that could allow for full authentication bypass, account takeover, and unauthorized privilege escalation across integrated JetBrains services. Administrators are urged to update their Hub instances immediately. Critical Hub Vulnerabilities JetBrains’ latest fixed-issues bulletin highlights three new critical vulnerabilities affecting Hub, the central identity and…
-
Medtronic notifies customers impacted by ShinyHunters data breach
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/
-
Medtronic notifies customers impacted by ShinyHunters data breach
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/
-
The Shadow AI Problem Starts in the C-Suite
Executives Are More Likely to Use Unapproved AI Tools Than Their Teams. Shadow AI may look like a rank-and-file problem, but new data suggests the biggest users of unauthorized tools are senior leaders and C-suite executives. The findings point to a governance challenge rooted in speed, surveillance fears and uneven AI training. First seen on…
-
Prohibiting AI Use Increases Enterprise Data Risk
Fortra’s Tony Kelly on Securing AI Adoption With Governance, Data Protection. Organizations that block generative AI use often create greater security risks by driving employees toward unauthorized tools, said Tony Kelly, regional sales director at Fortra. He outlines why governed AI adoption and modern data protection provide a safer path than outright bans. First seen…
-
Microsoft WinRE Vulnerability Allows Hackers to Bypass UEFI/BIOS Password Enforcement
A newly disclosed vulnerability in the Microsoft Windows Recovery Environment (WinRE) could allow attackers to bypass UEFI and BIOS password protections, exposing systems to unauthorized access even when firmware-level security controls are active. This issue, tracked under CERT/CC VU#226679 and associated with CVE-2026-45585, affects Windows 10 and Windows 11 systems that use WinRE for recovery…
-
Hackers Use Microsoft Teams-Themed Lures to Deploy Legitimate Remote Access Software
An active phishing campaign that impersonates Microsoft Teams to trick victims into downloading a legitimately signed remote access tool (RAT) preconfigured for unauthorized access. Attackers deliver Teams-themed lures notifications about meeting transcripts, missed recordings, or “download transcript” prompts linking to convincing landing pages that mimic collaboration and productivity services. The offered downloads are pitched as…
-
Phishing attack on healthcare firm Xsolis impacts 1.4 million people
Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/
-
LastPass Customer Data Exposed in Klue Supply Chain Attack Using Stolen OAuth Tokens
Tags: access, attack, authentication, breach, cyber, data, data-breach, risk, saas, security-incident, supply-chain, unauthorizedA security incident involving the third-party platform Klue has resulted in unauthorized access to limited customer data in LastPass. The breach occurred after attackers compromised OAuth tokens associated with enterprise integrations. This incident, disclosed by LastPass, underscores the ongoing risks related to SaaS integrations and token-based authentication in today’s enterprise environments. LastPass Customer Data Exposed…

