A security flaw enabled hackers to take over Instagram accounts by tricking Meta AI support chatbot into adding an attacker-controlled email address and triggering a password reset.
On June 2, Anthropic confirmed that it will be adding 150 new organizations across some 15 countries to the "Project Glasswing" access to Mythos AI Preview and that ENISA will be among these.
United States Central Command has disclosed that commercially available location data was used to track deployed U.S. military personnel across various theatres of operation.
The world’s largest cruise operator, Carnival Cruise, has confirmed a data breach that affected nearly 6 million people, with the ShinyHunters hacking group claiming responsibility.
A massive supply chain attack dubbed Megalodon has infected over 5,500 GitHub repositories with credential-stealing malware, creating backdoors and automated workflows.
Iranian hackers linked to Iran’s Ministry of Intelligence and Security were responsible for the Los Angeles transit system breach that disrupted online services.
The back-and-forth over public disclosure policy does have substantial "gray area" and nuance. As Microsoft points out, the zero-day vulnerabilities that Chaotic Eclipse provided a "road map" to threat actors and some were almost immediately put to use in real-world attacks. On the other side of the coin, security researchers have long complained of unresponsive and heavy-handed communications from Microsoft.
The European Central Bank (ECB) has concluded a weeks-long inspection of Euro banks with a warning: preparedness for the AI security risk is not adequate, and more spending on cybersecurity will be required to get up to speed.
American convenience store chain 7-Eleven has confirmed a data breach claimed by the notorious ransomware gang ShinyHunters, which leaked personal data and corporate information.
On May 19 GitHub confirmed the security breach across its social media channels, verifying that there was unauthorized access to internal repositories and stating that it was monitoring the situation for further activity. It also said that it had no evidence that information stored in customer repositories or internal information about customers was compromised.










