The AI agent incident is described as "unprecedented" as the model went to "extreme lengths" to achieve a security testing goal, independently opting to find a path to internet access and break into Hugging Face to obtain secret solution information.
Cosmetics giant Estée Lauder is notifying customers of a ten-month-old data breach stemming from Oracle EBS that leaked the personal information of its employees.
Fast food chain Chick-fil-A has experienced a data breach stemming from credential stuffing attacks using login details from a third-party source to compromise accounts.
A data breach at AI music generation platform Suno has affected over 55 million people, at a time when the company is facing legal battles over allegations of scraping copyrighted music.
OpenAI did not comment on the Modal Labs incident specifically, but had previously released a statement indicating that the AI agent had ranged further afield than previously realized and had breached accounts at four other services in addition to the known Hugging Face incident.
The FBI and CISA warn about Iranian hackers expanding the list of targeted programmable logic controllers to compromise critical infrastructure, including water and energy.
A coordinated cyber attack by suspected Iranian hackers hit 36 Minnesota water utilities by targeting programmable logic controllers, causing outages at some facilities.
Internal documents indicate Microsoft entirely has its hands full addressing the security vulnerabilities rated "critical" and "important" that Mythos Preview has surfaced, with additional hundreds more rated "moderate" or lower forced into a deferred maintenance status until some undetermined future date.
In the wake of news that OpenAI agents independently breached Hugging Face and accounts with several other services, Anthropic has conducted a sweeping review of Claude activity and found that its own AI models have hacked their way to unauthorized internet access and into other organization's networks on at least three occasions.
Russian hackers are exploiting hotel Wi-Fi networks at various locations that attract corporate travelers to compromise Microsoft 365 accounts and install malware.










