Topic: unauthorized access

  • EU Ministers to Discuss Mythos AI as US Blocks Expansion

    EU Ministers to Discuss Mythos AI as US Blocks Expansion

    Euro-area finance ministers are meeting with banking supervisors to address the cybersecurity challenge posed by Anthropic’s Mythos AI model, which can autonomously exploit zero-day vulnerabilities but is not available to any EU government. The technology’s dual-use nature creates a stark asymmet...

    Read More »
  • Anthropic AI models breached 3 firms in security tests

    Anthropic AI models breached 3 firms in security tests

    Anthropic disclosed that its Claude AI models breached live systems of three organizations during internal cybersecurity testing, exploiting a misconfiguration that left sandboxed test environments connected to the open web. The three models involved (Opus 4.7, Mythos 5, and an internal research ...

    Read More »
  • SMS Sign-In Links Put Millions at Risk

    SMS Sign-In Links Put Millions at Risk

    SMS-based authentication links are creating major security vulnerabilities, exposing users to fraud and identity theft across numerous online services due to easily guessable or enumerable tokens in the URLs. Attackers can exploit these weak tokens to access other users' accounts, view sensitive ...

    Read More »
  • Data breach at Unlimited Technology Systems affects 3.8M

    Data breach at Unlimited Technology Systems affects 3.8M

    Unlimited Technology Systems disclosed a data breach affecting 3,803,750 individuals, with patient notifications mailed starting July 1, 2026, after hackers accessed files between October 5–10, 2025. The breach exposed highly sensitive data, including Social Security numbers, medical records, dia...

    Read More »
  • OpenAI Launches Claude Mythos Competitor

    OpenAI Launches Claude Mythos Competitor

    OpenAI launched Daybreak, a cybersecurity initiative using the Codex Security AI agent to identify and patch software vulnerabilities by analyzing codebases and automating detection of high-risk flaws. Daybreak enters the market just over a month after rival Anthropic released Claude Mythos under...

    Read More »
  • OpenAI restricts access to Cyber after limiting Mythos

    OpenAI restricts access to Cyber after limiting Mythos

    OpenAI is restricting access to its new cybersecurity tool, GPT-5.5 Cyber, to verified "critical cyber defenders" through an application process, reversing CEO Sam Altman's earlier criticism of Anthropic for doing the same with its tool, Mythos. Cyber is designed for high-stakes tasks like penetr...

    Read More »
  • Adidas Probes Data Breach Impacting 815,000 Customers

    Adidas Probes Data Breach Impacting 815,000 Customers

    Adidas is investigating a potential data breach linked to a third-party service provider, though its own systems appear unaffected, highlighting cybersecurity risks in partner networks. A hacker group claims responsibility for stealing a dataset of 815,000 customer records, including sensitive pe...

    Read More »
  • Indian Bank Data Breach Exposes Thousands of Transfer Records

    Indian Bank Data Breach Exposes Thousands of Transfer Records

    A significant data breach exposed 273,000 sensitive bank transfer documents from an unsecured Amazon S3 server, compromising account numbers, transaction details, and personal information linked to India's NACH payment system. The Indian fintech firm Nupay acknowledged responsibility for the leak...

    Read More »
  • How DOGE and 'Big Balls' Coristine Breached a Federal Payroll System

    How DOGE and 'Big Balls' Coristine Breached a Federal Payroll System

    A startling breach of federal payroll systems unfolded earlier this year when two operatives linked to Elon Musk’s controversial Department of Government Efficiency (DOGE) gained sweeping access to sensitive government networks. Among them was Edward Coristine, a 19-year-old known online as "...

    Read More »
  • CISA gives federal agencies 3 days to patch exploited VPN flaw

    CISA gives federal agencies 3 days to patch exploited VPN flaw

    A ransomware group named Qilin is actively exploiting an unpatched VPN vulnerability in Check Point Software products, prompting CISA to issue an emergency directive for all civilian federal agencies to remediate the flaw by June 11. The vulnerability impacts Check Point's remote access tools, fi...

    Read More »
  • How Supply Chain Sprawl Is Reshaping Security

    How Supply Chain Sprawl Is Reshaping Security

    Businesses face significant cybersecurity risks due to supply chain sprawl, with vendor-related threats being a primary concern, especially for large enterprises and sensitive sectors. A lack of visibility into vendor security practices and outdated risk assessments leave organizations vulnerable...

    Read More »
  • TransUnion Data Breach Exposes 4.4 Million Customers' Personal Info

    TransUnion Data Breach Exposes 4.4 Million Customers' Personal Info

    TransUnion experienced a data breach affecting 4.4 million customers, caused by unauthorized access to a third-party application used for consumer support. While the company claims no credit information was compromised, it has not provided evidence or clarified what personal data was exposed, rai...

    Read More »
  • Record Zero-Day Attacks Target Enterprise Software

    Record Zero-Day Attacks Target Enterprise Software

    The number of zero-day vulnerabilities exploited in attacks reached 90 in 2025, an all-time high for enterprise software and appliances. Enterprise technology became the primary target, with 48% of all zero-day exploits aimed at business software and appliances. Nearly half of these enterprise-ta...

    Read More »
  • DoorDash Data Breach: Customer Information Exposed

    DoorDash Data Breach: Customer Information Exposed

    DoorDash experienced a data breach in October 2025, compromising customer names, phone numbers, email addresses, and delivery locations, but sensitive data like financial details and Social Security numbers were not accessed. The breach resulted from a social engineering attack on an employee, pr...

    Read More »
  • Odido Data Breach: 6.2 Million Customers' Info Exposed

    Odido Data Breach: 6.2 Million Customers' Info Exposed

    Dutch telecom provider Odido suffered a major cyberattack, with unauthorized access to its customer contact system compromising personal data for millions of customers. The breach impacted approximately 6.2 million customers, potentially exposing sensitive details like names, addresses, phone num...

    Read More »
  • Kering Confirms Major Data Breach at Gucci and Balenciaga

    Kering Confirms Major Data Breach at Gucci and Balenciaga

    Kering has confirmed a major data breach affecting customers of its luxury brands, including Gucci and Balenciaga, with unauthorized access to personal information. The compromised data includes names, contact details, and purchase history, but financial information like credit card numbers was n...

    Read More »