AI Agent Introduced A Flaw in Snowflake’s Code—Then Another AI Agent Exploited It post, augustus 18, 2026augustus 24, 2026 An artificial intelligence-generated security fix introduced a vulnerability into one of Snowflake’s public GitHub repositories, before a separate autonomous AI security agent found the defect, exploited it and extracted credentials providing access to parts of the company’s internal Jira environment. The incident did not result from an uncontrolled attack or… Continue Reading
Hacker Claims To Have Stolen 3.6 Million Records From McDonald’s, Vodafone and Other Corporate Azure Tenants post, augustus 18, 2026augustus 24, 2026 A threat actor using the name “TheHatman” is attempting to sell approximately 3.64 million records allegedly collected from the Microsoft Azure and Entra environments of nine major international organisations. The advertised information is linked to McDonald’s, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware Technologies and… Continue Reading
Linux Botnet Turns Devices Including Routers Into Persistent Attacker Infrastructure post, augustus 17, 2026augustus 24, 2026 A newly identified Linux botnet is exploiting years-old security vulnerabilities to compromise routers, firewalls, IP cameras and other internet-facing systems, transforming them into a distributed infrastructure for cyberattacks, credential theft and covert traffic relaying. The malware, named Evooo1Bot, is based partly on the leaked source code of the notorious Mirai… Continue Reading
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees post, augustus 11, 2026augustus 17, 2026 Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers… Continue Reading
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities post, augustus 6, 2026augustus 17, 2026 Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were… Continue Reading
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself post, augustus 5, 2026augustus 17, 2026 An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch… Continue Reading
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests post, augustus 4, 2026augustus 17, 2026 OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. These incidents are unrelated to the previously disclosed Hugging Face breach, in which OpenAI… Continue Reading
AI-systeem Claude van Anthropic hackte onbedoeld drie bedrijven post, juli 31, 2026 Het bekende AI-systeem Claude van het Amerikaanse bedrijf Anthropic heeft ingebroken bij drie bedrijven, nadat het onbedoeld toegang had gekregen tot het internet. Dat heeft Anthropic bekendgemaakt, een week nadat iets soortgelijks was gemeld door concurrent OpenAI. Volgens Anthropic hebben de hacks ergens sinds april plaatsgevonden, tijdens zogeheten ‘capture-the-flag’-oefeningen. Daarbij kreeg Claude… Continue Reading
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs post, juli 30, 2026juli 31, 2026 CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat… Continue Reading
OpenAI hackt ander AI-bedrijf, maar van ‘op hol geslagen AI’ is geen sprake post, juli 23, 2026juli 31, 2026 OpenAI heeft per ongeluk een ander AI-bedrijf gehackt. Dat gebeurde tijdens een test waarmee OpenAI wilde kijken hoe goed zijn AI-programma’s presteren op het gebied van cybersecurity. Nadat OpenAI zijn AI-programma’s veel vrijheid had gegeven om de test te voltooien, gebeurde iets wat niet de bedoeling was: ze verlieten de… Continue Reading