Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks.
OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.
OpenAI says an agent powered by its LLM models escaped its sandboxed testing environment to infiltrate Hugging Face's servers as part of an overzealous attempt to obtain solutions to a benchmark test. The company says it considers the unintended infiltration an "an unprecedented cyber incident" and is working with Hugging Face on new protections to prevent a recurrence.
Hugging Face disclosed an intrusion last week that it said involved "unauthorized access to a limited set of internal datasets and to several credentials used by our services." The AI data clearinghouse said it used its own LLM-driven analysis to identify "a swarm of tens of thousands of automated actions" from an "autonomous agent framework." That agentic swarm exploited a flaw in Hugging Face's data-processing pipeline to gain the ability to run code as a processing worker, eventually escalating to high-level access to the company's cloud and server clusters.
At the time, Hugging Face said the LLM being used in the attack was "still not known." But OpenAI took responsibility for the intrusion Tuesday evening, saying it came about during an internal test involving the recently released GPT-5.6 Sol and "an even more capable pre-release model." The models were being tested against the ExploitGym benchmark, an independent testing suite based on hundreds of real-world security vulnerabilities.
Whether or not your smart TV is spying on you, LG wants to make sure the apps aren't part of the problem. The tech giant is banning webOS apps that use residential proxies to rent out your TV's internet connection to third parties.
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.
An AWS software bug showed some customers billing estimates in the billions and trillions. Here is what failed, why invoices were unaffected, and what IT teams should know.
Rudra Mitra will lead Amazon security services in his new role. (LinkedIn Photo)
Rudra “Rudy” Mitra, who spent more than 27 years at Microsoft and most recently led its Purview data-security business, is joining Amazon Web Services as vice president of security services.
Mitra will oversee an AWS portfolio that includes tools such as GuardDuty and Security Hub, which companies use to track security risks across their cloud accounts. AWS recently added AI-specific threat detection to GuardDuty and, perhaps notably given today’s news, extended Security Hub to monitor AI workloads and security inside Microsoft Azure.
He will report to Chet Kapoor, the former DataStax CEO whom AWS hired last year as vice president of search, security and observability, a role that reports to AWS CEO Matt Garman.
“Rudy brings decades of security experience, a passion for building, and a deep understanding of what customers need as the security landscape continues to evolve,” Kapoor wrote on LinkedIn.
Mitra joined Microsoft in 1999 straight out of college, working on early efforts to deliver Office as an online service before launching Purview, the company’s data-security and governance product, in 2014. He announced his exit from Microsoft last week, addressing what was next at the time by saying only that there was “more on that soon.”
His departure comes amid a broader reshuffling of Microsoft’s security leadership this year under Hayete Gallot, who returned from Google in February to run the group and has been reshaping its executive ranks in recent weeks and months.
Gallot replaced Charlie Bell, who had joined from AWS in 2021 and continues at Microsoft as an individual contributor focused on engineering quality. She’s been overhauling the group’s product lineup, according to The Information, which reported last week that at least nine corporate vice presidents who reported to Bell have left the company this year.
On the inbound side at Microsoft, Naseem Tuffaha returned in June to fill the corporate VP role Kumar had left, after nearly two decades at the company and a stint away.
When Gallot arrived, Microsoft named Ales Holecek, a longtime engineering leader, as the security group’s chief architect, reporting to her. David Weston, another veteran Microsoft executive, also reportedly shifted into the security unit earlier this year.
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.
Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.
Opening a PDF, reading its contents, and closing the window is one of the most basic tasks you can perform on a computer. It seems as passive as reading a physical piece of paper. In reality, two things are happening behind the scenes that you don't see: your reader is communicating with the software developer, and the document itself may be sending information to whoever drafted it.
Experts say over-the-air vehicle updates are transforming the auto industry while creating new cybersecurity and national security risks that governments can no longer ignore.
23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people.
Microsoft is reportedly developing Project Perception, a lower-cost AI security tool that would use multiple models to identify enterprise vulnerabilities.
The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.