A massive supply chain attack on LiteLLM open-source AI gateway has exposed the authentication secrets of over 2,500 organizations and more than 434,000 CI/CD pipelines.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A cyber attack hit the northern California city of Suisun, forcing authorities to declare a state of emergency and shut down public services for at least a week.
In what is being called the first cyber attack of its type, autonomous AI agents were used to map a score of Taiwan government systems and crack 85 accounts. While there has been no formal attribution as of yet, evidence points strongly to an overseas origin and likely to hackers based in China.
Legal AI solutions provider LexisNexis shut down Diligence, Newsdesk, and Metabase API data services following a cyber attack on a managed third-party vendor.
A data breach at global logistics company Ceva has exposed the personal information of its partners’ customers and disrupted operations at various warehouses, resulting in delays.
A number of attendees of the most recent DEF CON are accused of jamming a Delta flight's Wi-Fi network during their flight home and attempting to get other passengers to connect to a rogue hotspot they controlled.
Attackers now have access to the same AI-powered tools that defenders use to discover weaknesses, and they can use them just as quickly. Fully autonomous cyberattacks are now an inevitable evolution.
A U.K. police database hack has exposed the personal information of over 100,000 law enforcement officers, criminal justice professionals, officials, and government partners.
After multiple stories of OpenAI and Anthropic AI models going rogue and independently opting to breach live targets on the internet, Meta has joined in with claims that at least one AI model made its way to the internet and exploited a security vulnerability in a target.
Testing of frontier AI agents by the UK’s AI Security Institute (AISI) found that "autonomous, unsanctioned action" took place on the open internet in about 1 out of 12 runs, with the agents cited as attempting to socially engineer humans into taking action and in at least one case attempting to hack an open-source project using a variety of different approaches.










