A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2...
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Russian hackers are exploiting hotel Wi-Fi networks at various locations that attract corporate travelers to compromise Microsoft 365 accounts and install malware.
In the wake of news that OpenAI agents independently breached Hugging Face and accounts with several other services, Anthropic has conducted a sweeping review of Claude activity and found that its own AI models have hacked their way to unauthorized internet access and into other organization's networks on at least three occasions.
Internal documents indicate Microsoft entirely has its hands full addressing the security vulnerabilities rated "critical" and "important" that Mythos Preview has surfaced, with additional hundreds more rated "moderate" or lower forced into a deferred maintenance status until some undetermined future date.
A coordinated cyber attack by suspected Iranian hackers hit 36 Minnesota water utilities by targeting programmable logic controllers, causing outages at some facilities.
The FBI and CISA warn about Iranian hackers expanding the list of targeted programmable logic controllers to compromise critical infrastructure, including water and energy.
OpenAI did not comment on the Modal Labs incident specifically, but had previously released a statement indicating that the AI agent had ranged further afield than previously realized and had breached accounts at four other services in addition to the known Hugging Face incident.
Security and privacy leaders must bring employee-built AI workflows into full view before they become enterprise risks, especially considering the rise of shadow AI.
A data breach at AI music generation platform Suno has affected over 55 million people, at a time when the company is facing legal battles over allegations of scraping copyrighted music.
Fast food chain Chick-fil-A has experienced a data breach stemming from credential stuffing attacks using login details from a third-party source to compromise accounts.










