โŒ

Normal view

There are new articles available, click to refresh the page.
Yesterday โ€” 22 July 2026Main stream

FedRAMP and Identity Security: Why federal organizations are consolidating identity security platforms

Identity security consolidation helps federal agencies reduce risk, cut costs and strengthen Zero Trust by unifying governance, access and AI controls.

ยฉ Getty Images/Orhan Turan

Digital Identity and Cybersecurity Technology Concept

New Data Shows Suno Breach Affected 55M Accounts

22 July 2026 at 11:53

New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.

The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic.

How OpenAIโ€™s human mistake led to the AI-powered hack on Hugging Face

22 July 2026 at 15:11
OpenAI made a mistake setting up what it called a โ€œhighly isolatedโ€ testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.

New Data Shows Suno Breach Affected 55M Accounts

22 July 2026 at 11:53

New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.

The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic.

OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face

22 July 2026 at 12:47

OpenAI says an agent powered by its LLM models escaped its sandboxed testing environment to infiltrate Hugging Face's servers as part of an overzealous attempt to obtain solutions to a benchmark test. The company says it considers the unintended infiltration an "an unprecedented cyber incident" and is working with Hugging Face on new protections to prevent a recurrence.

Hugging Face disclosed an intrusion last week that it said involved "unauthorized access to a limited set of internal datasets and to several credentials used by our services." The AI data clearinghouse said it used its own LLM-driven analysis to identify "a swarm of tens of thousands of automated actions" from an "autonomous agent framework." That agentic swarm exploited a flaw in Hugging Face's data-processing pipeline to gain the ability to run code as a processing worker, eventually escalating to high-level access to the company's cloud and server clusters.

At the time, Hugging Face said the LLM being used in the attack was "still not known." But OpenAI took responsibility for the intrusion Tuesday evening, saying it came about during an internal test involving the recently released GPT-5.6 Sol and "an even more capable pre-release model." The models were being tested against the ExploitGym benchmark, an independent testing suite based on hundreds of real-world security vulnerabilities.

Read full article

Comments

ยฉ Getty Images

Linux kernel team publishes 432 CVEs in two days

22 July 2026 at 12:58
If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didnโ€™t take long for seasoned sysadmins to start expressing concerns. Jan Schaumann, chief information security architect at Akamai Technologies, took to the OSS-SEC mailing list Tuesday to express concerns over the sheer volume of Linux kernel CVEs published in recent days. Aside from noting that the CVE system isnโ€™t the best way to track security changes, Schaumann also wondered in his post whether there was any good way to deal with so many kernel security issues. โ€œThis onslaught really shows it's not feasible to attempt to prioritize individual kernel changes,โ€ Schaumann said. โ€œYou might attempt to process this large set of changes by pointing an LLM at the intake and asking it to prioritize them,โ€ he suggested, โ€œbut if it spits out a dozen today and another 25 the next, you haven't won much.โ€ Schaumann also suggested waiting to see which ones emerge as serious issues and focusing on those in the weeks to come, or updating oneโ€™s entire fleet of Linux machines on a weekly basis. โ€œI sure would like to be able to do [that], but reality keeps getting in my way,โ€ Schaumann said. โ€œI'm not sure what to do here going forward.โ€ In an email to The Register, Schaumann said that individually reviewing vulnerabilities for patching was already difficult enough before things rose to this level, and that automation may be the only option - but it's not a great one. "Automated, regular, and frequent updates that pull in all changes within a given time window of tolerance seem to me the only reasonable approach, but that is very difficult for many large organizations," Schaumann explained. Those orgs often rely on lengthy QA processes, slow and staged development cycles, and may even have contractual requirements for long-term support that make an automated approach an impossible one. The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldnโ€™t be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become โ€œalmost entirely unmanageableโ€ due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." On that note, it's worth understanding what a Linux kernel CVE actually means - many of the vulnerabilities included in the Sunday-to-Monday batch are small in scope, but they're vulnerabilities nonetheless. As senior Linux maintainer Greg Kroah-Hartman noted in a February blog post, the Linux kernel CVE team follows the CVE Program's definition of a vulnerability: a weakness in a product that can negatively affect a system's confidentiality, integrity, or availability. โ€œAt the level that the Linux kernel runs, almost any type of bug that can affect a running system can be classified as a vulnerability,โ€ Kroah-Hartman noted. The kernel team looks at every bugfix that is added to stable kernel releases, he added, and if it fixes an issue that meets that CVE criteria, a CVE is assigned. AI-assisted bug hunting has increased the volume of reports reaching Linux kernel maintainers. We reached out to the Linux kernel team, but didnโ€™t hear back. Kroah-Hartman did tell The Register earlier this year that AI bug reports had become worthwhile in recent months, and he predicted they're likely to keep adding to his workload. Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isnโ€™t one thatโ€™s readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Hope youโ€™ve got the coffee machine filled up: The onslaught is unlikely to ease if other recent patch cycles are any indication. ยฎ

Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits

22 July 2026 at 09:00
EXCLUSIVE A Windows information-stealer targeting more than 300 applications comes equipped with a novel surveillance tool: an AI profiler that ranks infected victims so crooks know who to target first. Varonis Threat Labs spotted the new stealer and remote access trojan (RAT), called Dolphin X, for sale on a cybercrime forum, and shared their research exclusively with The Register. The ad for the malware claims it can target upwards of 300 applications and has the ability to bypass browser passwords and steal enterprise credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps secrets. Dolphin X also promises users a super-sneaky surveillance feature called the AI Profiler. It scores infected users by app usage, browsing history, and installed software, and sends the cybercriminals a daily summary that ranks victimsโ€™ based on the likely payoff from an attack. โ€œThere's two things that stand out,โ€ Daniel Kelley, a senior threat researcher with Varonis, told The Register. โ€œThe first thing is the AI profiler. That's something I've never seen before. And then itโ€™s also the breadth of applications that it steals - and itโ€™s not even just applications. Itโ€™s everything, you name it: it will steal files, or credentials, cryptocurrencies. Itโ€™s probably one of the biggest stealers Iโ€™ve ever seen, and covers the biggest attack surface.โ€ A malware vendor using the alias โ€œKontraktnikโ€ posted Dolphin X for sale, promising: โ€œYou can use it as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, as a loader.โ€ The crimeware currently only runs under Windows, but โ€œwe are working on Debian,โ€ Kontraktnik claimed, adding that the malware also only supports English and Russian. Kelley suspects the developer is Russian-speaking, and told us that the stealer includes an option not to infect any users in the Commonwealth of Independent States (CIS) countries, a common choice among Russian-based ransomware and cybercrime gangs. Kelley and his team obtained and analyzed the malware builder, operator panel and its network traffic, but didn't examine a malware sample. Varonis therefore canโ€™t guarantee that all of the developerโ€™s claims are true. However, โ€œwhen we looked at the builder, it had everything to suggest the features were legitimate,โ€ he said. โ€œWe couldnโ€™t test out the malware itself, but I would say it probably lives up to most of its expectations.โ€ Feedback left on the forum where the malware is sold supports that analysis. As of Tuesday, the sales thread has passed 3,000 views, weโ€™re told, with Kontraktnik closing at least two confirmed deals. Both of these included positive feedback from the buyers. Three-tier subscription model Beyond the 300 + apps it targets, Dolphin X's operator panel lists 329 features across 10 categories. Buyers can subscribe to one of three tiers, each unlocking new features, or buy a lifetime subscription. The minimalist suscription costs about $80 per month, which buys rewriting and altering capabilities across Windows Portable Executable (PE) timestamp, Rich headers, and section padding, along with capabilities allowing the malware to exploit the brittle YARA rules to bypass detection and hash-based blocklists. The middle tier advertises shuffling the import table, which would change the binary's import hash between builds. The top level sub (about $230 per month) claims to rewrite the codeโ€™s control flow, substitute instructions, and re-encrypt embedded strings with a new random key each time, thus making stable byte sequences harder to identify. Lifetime subscription cost about $1,140 for basic access, $2,280 for mid-tier malware, or $3,420 for perpetual pro-level Pwnage. โ€œIt really lowers the barrier to entry,โ€ Kelley said, adding that in the not-so-distant past, cybercriminals needed a certain level of technical expertise to develop and use different types of malware. โ€œNow it's set up in a way where it's almost like SaaS. Anyone can purchase it. Anyone can take it out of the package and use it.โ€ All of this suggests two takeaways for defenders, according to the security sleuths. First, keep long-lived credentials off disk if possible. โ€œInfostealers are designed to grab everything in one pass, so anything stored locally should be treated as potentially exposed,โ€ the report warns. Second: focus threat detection on behavior - not file signatures - because this and other malwares include capabilities to bypass signature-based detection. โ€œFor example, explorer.exe running under a non-default desktop is a strong indicator of an HVNC session, regardless of how the malware binary is packed or what hash it uses,โ€ the authors wrote. Varonisโ€™ threat hunters previously uncovered other AI-powered malware, including an all-in-one phishing kit called Bluekit, and an email attack tool called SpamGPT. โ€œItโ€™s a huge trend,โ€ Kelley said. โ€œCybercriminals are finding a lot of unique ways to integrate AI, and then they're using it to make their lives a lot easier, which is problematic.โ€ ยฎ

โŒ
โŒ