Colombian energy giant Ecopetrol says thousands of user accounts hit in cyberattack

The Ecopetrol attackers demanded a ransom payment but did not deploy an encryptor.

Four teams just broke AI agents four ways in ten days. The flaw is the same one.
Four teams just broke AI agents four ways in ten days. The flaw is the same one.

We spent two years asking whether AI would lie to us. The more useful question this summer is what happens once we hand it the keys. Give a model your Gmail, your calendar, a memory and the power to act, and its mistakes stop being embarrassing. They s…

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity.

The ‘synthetic insider’: how AI deepfakes turned the fake employee into a corporate threat
The ‘synthetic insider’: how AI deepfakes turned the fake employee into a corporate threat

The most dangerous person in your company might not work there at all. AI deepfakes are getting cheaper and better. Hackers now use them to pose as trusted staff, a threat the industry calls the “synthetic insider.” The tactic sits at the sharp end of …

Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up

Qilin and The Gentlemen are going at it, at the expense of SMBs facing more attacks than ever.

Ernst & Young reveals data breach following hack on support system

Someone pulled sensitive customer data from EY’s servers, but the data is yet to surface anywhere.

Kenya investigates hack of Ruto’s official website after bitcoin ransom demand
Kenya investigates hack of Ruto’s official website after bitcoin ransom demand

Kenyan authorities are investigating a cyberattack that defaced President William Ruto’s official website over the weekend, replacing the homepage with a ransom message and a cryptocurrency wallet address. The government pulled president.go.ke offline …

An AI agent hacked Hugging Face. Another AI caught it.
An AI agent hacked Hugging Face. Another AI caught it.

The machines are now hacking each other. Hugging Face, the world’s largest hub for open AI models, says an autonomous AI agent broke into its production infrastructure. Its own AI defences spotted the intrusion and picked it apart. The company disclose…

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets

A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.

New X phishing scam copies real login alerts down to the pixel to hijack accounts
New X phishing scam copies real login alerts down to the pixel to hijack accounts

Scammers are sending phishing emails that are near-exact replicas of X’s legitimate login notifications, warning recipients of a login “from a new device” in a location they have never been. The emails include X’s logo, correct formatting, proper gramm…