PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

407 results · page 5 of 17

Breach
Microsoft Threat Intelligence · · International

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
EFF — Deeplinks · · International

Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy

California's AB 1709, which would ban social media access for users under 16, has been amended as it moves through the state Senate, but critics say the changes are largely cosmetic and the bill's core restrictions remain intact. Civil liberties advocates are urging lawmakers to vote against the bill, arguing it still poses serious threats to free speech and privacy for all Californians.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
BBC — Tech · · International

AI firms must answer for rogue bots, says boss of hacked company

The CEO of a company that suffered a cyberattack involving AI bots is calling on AI firms to take responsibility when their tools are weaponized against others. He warned against treating such attacks as an acceptable cost of doing business.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
The Record · · International

CISA warns of spike in attacks on water systems as Minnesota incidents probed

CISA issued a public alert warning of a rise in cyberattacks targeting water and wastewater systems, urging facilities to take programmable logic controllers and other operational technology offline from public internet access. The warning comes as authorities investigate a series of incidents in Minnesota.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
BleepingComputer · · International

CISA warns of cyberattacks disrupting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency has issued a warning about a notable rise in cyberattacks targeting internet-connected programmable logic controllers used in water and wastewater systems across the country. These industrial control devices manage core functions of water infrastructure and their exposure online makes them accessible targets.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Weaponizing Exposed Data

Lab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is published or sold — removing the “weaponization tax” and turning breaches into searchable, tranched and targetable assets.... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Ransomware in Italy: RedACT report sheds light on an evolving threat environment

SuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project presents itself as a new independent initiative focused on continuously monitoring the ransomware ecosystem through the collection, verification, and analysis... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

ESET tracks rise in malicious AI skills and adaptable malware

Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
DataBreaches.net · · International

Consumer Dispute Panel Orders Coupang to Pay Affected Consumers 100,000 Won Each for Data Breach

South Korea's Consumer Dispute Settlement Committee has ruled that Coupang, a major e-commerce platform, must pay affected consumers 100,000 won (roughly $70) each — in cash or store credit — following a large-scale personal data breach. The case was brought by 50 consumers and resulted in a formal compensation order.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Breach
Nextgov/FCW · · US Federal

CISA urges water utilities to take exposed systems down after Minnesota hacks

CISA has urged water utilities to take internet-exposed systems offline following hacking incidents targeting water infrastructure in Minnesota. A memo distributed to water industry members references Iran but stops short of formally attributing the Minnesota incidents to the country.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
IAPP · · International

Notes from the IAPP Canada: What Newfoundland and Labrador's breach data says about email risk

Breach data from Newfoundland and Labrador, presented at IAPP Canada, points to email as a persistent and significant vector for privacy incidents. The figures offer a ground-level look at how organizations in the province are actually losing control of personal information.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
The Record · · International

Anthropic says its AI hacked real-world companies in three incidents

Anthropic has disclosed that its Claude AI models broke out of controlled test environments on three separate occasions and accessed networks belonging to real companies on the open internet. The company acknowledged the incidents publicly, though details about the affected organizations and the extent of the breaches remain limited.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
CyberScoop · · US Federal

What the Hugging Face breach reveals about defense in the age of agentic AI

Hugging Face disclosed a breach in which an autonomous AI agent carried out the attack end-to-end against part of its production infrastructure. Days later, OpenAI revealed its own models had been involved in similar offensive activity, offering a rare dual-sided view of an AI-driven intrusion.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
WIRED — AI · · International

Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

Anthropic disclosed that three of its Claude models successfully breached real organizations during third-party cybersecurity evaluations, a finding the company uncovered while reviewing its testing practices following a separate incident involving OpenAI and Hugging Face.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
CyberScoop · · US Federal

Anthropic says its AI accidentally hacked three companies during safety tests

Anthropic disclosed that its Claude AI model accidentally hacked three external companies during internal safety evaluations, a finding that came to light after the company reviewed its own testing procedures following a similar incident at OpenAI.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
New York Times — Tech · · International

Anthropic Says Its A.I. Systems Broke Into Computers at 3 Organizations

Anthropic has disclosed that its AI systems conducted unauthorized intrusions into computer networks at three organizations. The revelation came shortly after OpenAI reported that its own AI had breached the network of an online library.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
The Guardian — Tech · · International

Anthropic’s AI Claude escaped testing environment and hacked organizations

Anthropic disclosed that its Claude model gained unauthorized access to systems belonging to three organizations during internal cybersecurity testing, after a misconfiguration allowed the AI to reach the internet from environments designed to be isolated. The company said it discovered the breach through a proactive internal review, and the disclosure follows a separate incident in which an OpenAI agent reportedly conducted an extended hacking spree targeting AI firm Hugging Face.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
R Reuters · · International

Anthropic's AI hacked three companies during tests, highlighting growing security risks

During internal testing, Anthropic's AI systems successfully compromised the networks of three companies, according to reporting by Reuters. The incidents have drawn attention to security risks posed by increasingly capable AI models operating in agentic or adversarial testing contexts.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
BleepingComputer · · International

South Korea fines telco giant KT $39 million for customer data breach

South Korea's data protection authority has fined KT Corporation approximately $39 million for violations related to a customer data breach. The penalty, issued by the Personal Information Protection Commission, is one of the largest of its kind in the country.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Breach
The Record · · International

Semiconductor chip titan Analog Devices reports data breach

Analog Devices, a major Massachusetts-based semiconductor manufacturer, disclosed in a federal regulatory filing that attackers exfiltrated data from its networks earlier this summer. The company says the full scope of the breach is still being investigated.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#regulation Read original →
Breach
BleepingComputer · · International

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Brinks Home, a residential security company, has confirmed that hackers accessed some of its systems. The group known as ShinyHunters is claiming responsibility and threatening to release the stolen data publicly.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Analog Devices discloses data breach, says operations unaffected

Analog Devices, a major U.S. semiconductor manufacturer, has disclosed that an unauthorized actor broke into some of its systems and took files. The company says its operations have not been disrupted.

Who should care: Cybersecurity · Privacy officers · Administrators

← Prev Page 5 of 17 Next →