700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
284 articles found
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways...
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in repor...
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record.
In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house....
OpenAI has issued a warning that AI-enabled cyberattacks could become significantly more widespread and sophisticated within months. The organization urges i...
OpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophis...
SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader. The post CISO Conversations: Chr...
AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways, RAGFlow retrieval platforms, and Kestr...
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media ...
FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S.
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and crypt...
Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure.
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium....
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector...
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches D...
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S.
The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids any...
Too often today the hiring funnel becomes the attack surface – here’s how to catch insider threats before they escalate.
Dutch data protection authorities have fined Uber nearly $1 billion, saying the ride-hailing company used automated software to suspend driver accounts, some...
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisemen...