BREACHHighSep 27, 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes live In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often …
BREACHMediumSep 26, 2026
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks.
BREACHHighSep 25, 2026
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
BREACHHighSep 25, 2026
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
BREACHHighSep 25, 2026
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.
BREACHCriticalSep 25, 2026
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain
BREACHHighSep 25, 2026
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
BREACHHighSep 24, 2026
The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?
BREACHHighSep 24, 2026
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal
BREACHHighSep 24, 2026
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –
BREACHHighSep 24, 2026
Abdelhamid Naceri Says His Microsoft Dispute Preceded 12 Zero-Day Reports Former Microsoft employee Abdelhamid Naceri identified himself as the researcher behind a string of Windows and Defender zero-day disclosures, including BigDiskBuster, saying the releases followed a bitter employment and vulnerability-reporting dispute with the company.
BREACHHighSep 23, 2026
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
BREACHHighSep 23, 2026
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored
BREACHHighSep 23, 2026
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
BREACHHighSep 23, 2026
The ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.
BREACHHighSep 23, 2026
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead
BREACHHighSep 23, 2026
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead
BREACHHighSep 23, 2026
Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims.
BREACHHighSep 22, 2026
Settlement Comes After Firm Paid Nearly $12.3M to Settle Civil Claim for Same Hack A genetics testing lab has agreed to pay a $700,000 HIPAA settlement and improve its security practices in the wake of a 2020 phishing hack that affected 225,370 patients. The firm paid a $12.25 million civil class action settlement in 2023 for the same breach. But the firm faces other legal woes.
BREACHHighSep 21, 2026
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.