The Oasis researchers document a vulnerability chain that can be initiated from any website the AI agent (or its user) visits, without users needing to interact in any way or being at all aware that they are being compromised. The attack targets the OpenClaw "gateway" that essentially acts as the AI agent's nerve center.
A third-party data breach at the online DIY platform ManoMano has affected nearly 38 million customers after attackers breached its subcontractor’s Zendesk instance.
Reddit has been assessed £14.47 million in fines by the UK Information Commissioner's Office (ICO) due to failures to adequately age-gate children under 13, which in turn led to impermissible collection and use of their personal data as well as potential exposure to mature content. The penalty is one of the largest it has issued thus far, and the largest for a children's privacy offense.
A sophisticated vishing attack by the suspected ShinyHunters cybercrime gang has leaked business contact information from the New York-based ad tech company Optimizely.
Discord's controversial new age verification requirements will be delayed until at least the latter half of 2026, after the sudden announcement of mandatory collection of user ID scans and facial biometrics drew a major backlash from platform users.
A software security flaw in PayPal’s loan app leaked customer data for 6 months, forcing the payment giant to issue refunds after unauthorized transactions occurred in some affected accounts.
A long-term Chinese cyber espionage operation that has been active since at least 2017 and has a count of at least 53 victims has been substantially disrupted, according to the Google Threat Intelligence Group (GTIG) and Mandiant.
A security breach at France’s national bank registry has compromised the personal information of 1.2 million people, after a threat actor downloaded a database containing the information of all bank accounts in the country.
An INTERPOL-led law enforcement operation across 16 African countries has nabbed 651 suspects linked to online scams targeting victims across the continent and worldwide.
Microsoft has downplayed the issue in official communications, stating that the summaries of the confidential emails were not exposed to anyone that did not already have access to the messages in question. There is always some concern about exactly where information goes once AI tools have ingested it, however.










