The Dutch Institute for Vulnerability Disclosure (DIVD), a volunteer security research nonprofit, disclosed it was breached after seven incident-free years, with the intrusion executed autonomously by what it called an agentic AI system. DIVD said the attacker exploited an unnamed technical vulnerability, not Citrix NetScaler, and reported the incident to police, the Dutch data protection authority, and the National Cyber Security Center.
bleepingcomputer.com
· 2026-09-29
Security firm Strix ran an unauthenticated scan against Baseten's public infrastructure and within 25 minutes uncovered a live GitHub personal access token with admin rights to Baseten's core product repo, GitOps repo, and Homebrew tap. The token, tied to a container image built in March 2023, had gone unnoticed for over three years and still granted read/write access to private customer repositories when discovered in July 2026. Baseten's security team confirmed the issue as critical and rotated the token within a day of disclosure.
strix.ai
· 2026-09-15