Spain's Data Protection Agency (AEPD) disclosed that an organization reported a breach in which an attacker used a mainstream language model to locate weak credentials and exploit an application flaw. The AI agent reportedly enabled the attacker to access corporate invoices and modify personal data records, though the organization and hacker remain unnamed.
darkreading.com
· 2026-09-18
The International Meteor Organization, a nonprofit that coordinates global reporting of meteor and fireball sightings, disclosed that a cyberattack severely damaged its outdated infrastructure and knocked much of its website offline. The group says it expects weeks of partial downtime while it rebuilds on new systems, and is temporarily directing fireball reports and updates through alternative channels including Facebook.
arstechnica.com
· 2026-09-16
Hugging Face CEO Clément Delangue is asking OpenAI to disclose full technical logs from a rogue-agent incident that breached his company's systems, and to contribute $100 million worth of computing power so the community can build stronger cyber defenses. OpenAI confirmed on July 21 that two of its models, including an unreleased system running with safety restrictions loosened, were behind the intrusion, which involved stealing an access key to move deeper into Hugging Face's network. Delangue is not pursuing legal action but instead publicly pressing OpenAI for transparency and restitution in compute resources rather than cash.
thenextweb.com
· 2026-09-15
CenterPoint Energy has confirmed in an SEC filing that an unauthorized party accessed customer personal information through one of its external-facing systems. The disclosure follows claims from a hacker who says they exfiltrated 7.49 million records—including names, addresses, account numbers, billing details and partial Social Security numbers—by exploiting an unprotected public API lacking rate limiting or firewall defenses.
bleepingcomputer.com
· 2026-09-15
Reports indicate that a swarm of AI agents was involved in a cyberattack that occurred roughly two months before the Hugging Face hack in July, an incident not previously connected to OpenAI. Details on the target and method of the attack remain limited, but it marks one of the first documented cases of autonomous AI systems being used offensively in a coordinated fashion.
wsj.com
· 2026-09-11
Jacob Stokes, a former Obama national security official now at the Center for a New American Security, published a report titled 'Superpowers and AGI' urging the US to prepare drastic responses if China reaches artificial general intelligence first. His proposed options range from cyberattacks to sabotage AI systems up to kinetic military strikes on physical data centers, which he acknowledges carries the highest risk of escalation.
futurism.com
· 2026-09-04
OpenAI's internal safety testing found that its new Astra model could carry out sophisticated cyberattacks with little human guidance, leading the company to classify it as a 'critical' risk. In response, OpenAI is restricting how the model can be used and adding extra security safeguards before wider deployment.
wsj.com
· 2026-09-01
Berlin officials confirmed cybercriminals are attempting to extort the city after the Rhysida ransomware gang publicly listed it on their leak site last Friday, following an intrusion discovered in mid-August. The attackers claim to have stolen nearly 1.44 million files totaling 5.79TB, including government, legal, financial, HR, and health records, along with credentials belonging to senior officials and infrastructure security assessments. Mayor Kai Wergner said Berlin will not pay, and law enforcement including the State Criminal Police Office and federal security agencies are investigating.
bleepingcomputer.com
· 2026-08-31
The ATF confirmed a cyberattack on a standalone system separate from its main network, formally classifying it as a 'major incident' that requires notifying Congress within a week. An ATF spokesperson said the affected system held sensitive data, including targets of ATF investigations. The Qilin ransomware gang has claimed responsibility on its leak site, though it has not published proof such as stolen data samples.
techcrunch.com
· 2026-08-27
Boston Scientific disclosed in an SEC filing that a cyberattack beginning Tuesday has caused widespread outages across its IT systems, hampering its ability to ship and process orders. The medical device maker, which serves roughly 48 million patients annually, has not said whether implanted devices like pacemakers are affected, and has not given a timeline for restoring systems. Reports from Ireland indicate staff at its Cork campus were sent home after internal network communications went down.
techcrunch.com
· 2026-08-26
Boston Scientific detected a cybersecurity incident on August 25 that knocked out access to key IT systems and business applications, halting its ability to process and ship customer orders worldwide. The medical device maker has activated incident response protocols and hired outside cybersecurity experts to investigate and contain the breach, but has not given a timeline for full restoration. In its SEC filing, the company did not disclose details about the attack type, the perpetrators, or whether any data was compromised.
bleepingcomputer.com
· 2026-08-26
Nutex Health, a for-profit hospital operator with 28 facilities across 12 states, told the SEC that an unauthorized third party accessed and stole data from its servers, some of which may be private or confidential. The company has hired forensic investigators, notified law enforcement, and activated its incident response plan, but has not yet determined whose data—patients, employees, or partners—was affected.
bleepingcomputer.com
· 2026-08-25