The Ecopetrol attackers demanded a ransom payment but did not deploy an encryptor.
Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity.

The most dangerous person in your company might not work there at all. AI deepfakes are getting cheaper and better. Hackers now use them to pose as trusted staff, a threat the industry calls the “synthetic insider.” The tactic sits at the sharp end of …
Qilin and The Gentlemen are going at it, at the expense of SMBs facing more attacks than ever.
Someone pulled sensitive customer data from EY’s servers, but the data is yet to surface anywhere.

Kenyan authorities are investigating a cyberattack that defaced President William Ruto’s official website over the weekend, replacing the homepage with a ransom message and a cryptocurrency wallet address. The government pulled president.go.ke offline …

The machines are now hacking each other. Hugging Face, the world’s largest hub for open AI models, says an autonomous AI agent broke into its production infrastructure. Its own AI defences spotted the intrusion and picked it apart. The company disclose…
A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.

Scammers are sending phishing emails that are near-exact replicas of X’s legitimate login notifications, warning recipients of a login “from a new device” in a location they have never been. The emails include X’s logo, correct formatting, proper gramm…