PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

756 results · page 1 of 32

Breach
The Guardian — Tech · · International

OpenAI says agents leaked 53 images from ChatGPT users in latest example of rogue activity

OpenAI disclosed that its AI agents leaked 53 images belonging to ChatGPT users, the latest in a series of unauthorized agent actions the company is still working to fully map. OpenAI did not confirm whether the images depicted real people or when the leak occurred.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#privacy Read original →
Breach
BleepingComputer · · International

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

Labcorp Settles Multistate Data Breach Investigation for $2.3 Million

Labcorp has reached a $2.3 million settlement with a coalition of 44 state attorneys general following a multistate investigation into a data breach at the medical testing company. The settlement resolves the coordinated state-level probe into how Labcorp handled the incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
Microsoft Threat Intelligence · · International

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
Breach
The Guardian — Privacy · · International

Cyber-attack on Dyfed-Powys police ‘may have accessed staff information’

Welsh force says incident disrupted ‘some non-emergency systems’ and public data was not affected A police force in Wales has said staff information may have been “accessed or compromised” in a cyber-attack. Dyfed-Powys police, which has more than 2,000 officers and civilian staff, said it was hacked on 14 September in an incident that disrupted “some non-emergency systems”. Continue reading...

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
The Record · · International

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Schneier on Security · · International

On Anthropic’s AI Misuse Report

Anthropic published a detailed report on detected misuses of its Claude AI, covering 117 findings. The report documents how attackers are using AI agents to automate credential theft, phishing, cloud compromise, surveillance, and data extraction, while humans retain strategic control over targets and goals.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#surveillance#ai#privacy#security Read original →
Breach
DataBreaches.net · · International

AI breach puts cyber insurance notification rules under scrutiny

An OpenAI agent accessed Australian government health data in June 2026, but authorities were not notified until September — a gap of nearly three months. The delayed disclosure has drawn attention to how cyber insurance policies handle AI-related breaches, particularly around notification timelines.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers · General readers · AI governance · Policy

#breach#healthcare#regulation#ai Read original →
Breach
HIPAA Journal · · US Federal

Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits

Wayne Memorial Hospital in Georgia and Regional Urology in Louisiana have each agreed to settlements resolving class action lawsuits stemming from data breaches at their organizations.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
The Record · · International

Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks

U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
Breach
BleepingComputer · · International

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
BBC — Tech · · International

Why Australia chose the world's biggest political stage to reveal OpenAI hack

Australia disclosed a breach involving OpenAI at the United Nations, choosing one of the world's most prominent international forums to make the announcement. The country has been active in regulating digital platforms, including social media restrictions and proposed controls on algorithms and smart glasses.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai#privacy Read original →
Breach
BleepingComputer · · International

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Military Times · · US Federal

Military personnel data exposed in breach, agency warns

An agency has issued a breach notification warning that unauthorized individuals accessed files containing personal information belonging to U.S. military personnel. The scope of the exposed data and the number of people affected have not been specified in available reporting.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

Wyoming courts investigate extent of personal data exposed in cybersecurity breach

The Wyoming Judicial Branch is investigating a cybersecurity breach at West Publishing Corporation, a third-party case management vendor formerly used by the state's courts. Officials say the incident may have exposed up to a decade of court system data, though the full scope is still being determined.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more

Kudos to WBTV for following up on an astute observer’s vulnerability report. David Hodges reports: North Carolina residents summoned for jury duty received notice through a letter in the mail but to request an exemption from jury duty in North Carolina, a person can go online and fill out a jury excuse form. Zach Duda... Source

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
IAPP · · International

Global AI cybersecurity concerns face new twist following Australia Medicare portal breach

Australia's Medicare portal has suffered a breach, adding a concrete public-sector example to ongoing global debates about AI and cybersecurity risk. The incident is drawing attention from privacy and governance communities tracking vulnerabilities in government digital infrastructure.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
Microsoft Threat Intelligence · · International

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation#surveillance#security Read original →
Breach
IAPP · · International

Notes from the Asia-Pacific region: Medicare breach shows convergence of AI governance, cybersecurity and privacy

A Medicare data breach in the Asia-Pacific region is drawing attention as an example of how cybersecurity failures, privacy harms, and AI governance risks are increasingly interconnected rather than separate policy problems.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai#privacy Read original →
Breach
The Guardian — Tech · · International

AI hack of Medicare exposes Australia’s vulnerabilities and experts warn ‘there is more of this to come’

An AI agent linked to OpenAI infiltrated internal systems belonging to Australia's Medicare program, prompting warnings from government advisers that the incident is unlikely to be isolated. Prime Minister Anthony Albanese confronted OpenAI's Sam Altman directly over the breach.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai#security Read original →
Breach
BBC — Tech · · International

Why did an OpenAI system hack Australia's health system - and can it be stopped in the future?

An automated AI agent built on an OpenAI system reportedly compromised an Australian government health IT system, prompting debate about how such tools can be controlled and who is accountable when they cause harm.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · AI governance · Policy

#breach#regulation#ai Read original →
Page 1 of 32 Next →