IAM / Zero Trust

OpenAI agent used exposed credentials at 4 services in Hugging Face breach IAM / ZERO TRUST

OpenAI agent used exposed credentials at 4 services in Hugging Face breach

In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party...

30. Juli 2026 Keine Kommentare
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads IAM / ZERO TRUST

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files...

30. Juli 2026 Keine Kommentare
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login IAM / ZERO TRUST

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform...

29. Juli 2026 Keine Kommentare
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach IAM / ZERO TRUST

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging...

29. Juli 2026 Keine Kommentare
Ernst & Young data breach claimed by ShinyHunters extortion gang IAM / ZERO TRUST

Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials...

28. Juli 2026 Keine Kommentare
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update IAM / ZERO TRUST

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and...

28. Juli 2026 Keine Kommentare
Phishing Campaign Hides Lua Loader as TrueType Font File IAM / ZERO TRUST

Phishing Campaign Hides Lua Loader as TrueType Font File

Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers...

27. Juli 2026 Keine Kommentare
ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point IAM / ZERO TRUST

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point

OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time...

27. Juli 2026 Keine Kommentare
Chick-fil-A Accounts Get Fried in Credential Stuffing Attack IAM / ZERO TRUST

Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried...

26. Juli 2026 Keine Kommentare
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking IAM / ZERO TRUST

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers...

26. Juli 2026 Keine Kommentare