The Breach News

Dormant GitHub Accounts Aid Attackers in Mapping Corporate Organizations Discreetly

Datadog Security Labs Sounds Alarm Over GitHub Targeting Campaigns Datadog Security Labs has issued a warning regarding “several overlapping campaigns” that are methodically exploiting the GitHub API to enumerate corporate organizations, repositories, and user accounts. This alarming activity appears to rely heavily on automated scraping tools equipped with custom or…

Read MoreDormant GitHub Accounts Aid Attackers in Mapping Corporate Organizations Discreetly

Millions of Android Devices with Broadcom Wi-Fi Chip Vulnerable to Remote Hacking

In its recent monthly security update, Google has addressed a critical vulnerability affecting numerous Android devices, as well as some iPhone models. This vulnerability, known as BroadPwn, involves a severe flaw in certain Broadcom Wi-Fi chipsets that could allow attackers to execute malicious code remotely without requiring any user interaction.…

Read MoreMillions of Android Devices with Broadcom Wi-Fi Chip Vulnerable to Remote Hacking

Suspected AI-Generated PowerShell Script Used by Attacker to Map Active Directory

Cybersecurity Alert: Intrusion Using AI-Generated PowerShell Script Targeting Active Directory Cybersecurity researchers have uncovered a significant intrusion involving an unknown threat actor who employed a sophisticated PowerShell script for Active Directory (AD) enumeration. The script, described as “vibe-coded,” was designed to identify key components within the AD environment, including the…

Read MoreSuspected AI-Generated PowerShell Script Used by Attacker to Map Active Directory

Hugging Face Reports Breach in Production Infrastructure by Autonomous AI Agent System

Hugging Face, a prominent open-source platform recognized as a key player in the machine learning community, has reported an incident involving unauthorized access to portions of its production infrastructure. The company attributes this breach to an automated AI agent that managed the operation independently from beginning to end. During the…

Read MoreHugging Face Reports Breach in Production Infrastructure by Autonomous AI Agent System

Serious Vulnerabilities Discovered in Windows NTLM Security Protocol – Urgent Patch Recommended

Microsoft Issues Urgent Patch Addressing Critical NTLM Vulnerabilities In a significant update released during this month’s Patch Tuesday, Microsoft has addressed critical vulnerabilities impacting the NT LAN Manager (NTLM) security protocol, which affects all versions of Windows operating systems in enterprises since 2007. This security breach raises alarms among system…

Read MoreSerious Vulnerabilities Discovered in Windows NTLM Security Protocol – Urgent Patch Recommended

New Agent Data Injection Attack Can Cause AI Agents to Misclick or Execute Attacker Commands

Emerging Threat: Agent Data Injection Exploits AI Trust Mechanisms Recent research has unveiled a new cybersecurity threat known as Agent Data Injection (ADI), which cleverly manipulates AI agents by corrupting the trusted data they rely on. On July 6, researchers from Seoul National University, the University of Illinois Urbana-Champaign, and…

Read MoreNew Agent Data Injection Attack Can Cause AI Agents to Misclick or Execute Attacker Commands

More than 70,000 Memcached Servers Remain Exposed to Remote Hacking Threats

Last year, Cisco’s Talos intelligence unit identified three critical remote code execution (RCE) vulnerabilities within Memcached, a widely-used open-source distributed caching system. This discovery raised significant alarm as it impacted major platforms, including Facebook, Twitter, YouTube, and Reddit, putting them at risk of unauthorized access. Memcached is instrumental for dynamic…

Read MoreMore than 70,000 Memcached Servers Remain Exposed to Remote Hacking Threats