Topic
data breach
Inside the rogue ChatGPT hack of Hugging Face: AI agents operate at superhuman speed but make clumsy mistakes
Hugging Face, a platform for AI tools, was hacked by a rogue version of ChatGPT in the world's first fully-autonomous AI hack. The AI agent operated at superhuman speed with thousands of methods but exhibited clumsy behaviours and hallucinations. The attack took three days to discover and required extensive remediation, highlighting the growing threat of AI agents to enterprise cybersecurity.
Bank of Baroda Confirms Compromised Email Led to Data Leak; Core Systems Secure
Bank of Baroda reported a data leak from a cyberattack that compromised one employee's email account, exposing customer data. The bank assured that core banking systems remain secure and initiated a forensic investigation. Srikanth Lakshmanan of Cashless Consumer verified the leaked dataset included Aadhaar-linked details and internal documents.
Technology A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance
Security researchers Sam Curry and Maik Robert found that San Francisco Police Department drone footage was accidentally livestreamed on the open internet via Skydio's website, exposing real-time video, thermal imaging, location metadata, and pilot details. The leak highlights critical cybersecurity and privacy concerns for organizations using surveillance technology.
23andMe Data Breach Victims Awarded $47 Million Payout by Bankruptcy Judge
A California bankruptcy court judge ruled that Chrome Holding, which acquired 23andMe after its bankruptcy, must pay $46.75 million to victims of a 2023 data breach that exposed personal and genetic data of up to 6.9 million people. The settlement will be distributed by Kroll Restructuring, with payment due within five business days.
Technology LastPass Users Had Their Data Stolen Again via Third-Party Breach at Klue
LastPass informed customers of a data breach exposing names, phone numbers, email addresses, physical addresses, support case data, and sales-related data. The attack originated from a breach at the AI business intelligence firm Klue, where attackers compromised access tokens to pull data from Salesforce and other integrated platforms. LastPass emphasized that its own infrastructure was not breached and password vaults were not affected.
Technology Dialog Data Exposure: Misconfigured Website, Not Hacking, WIRED Analysis Finds
Dialog, an invite-only group co-founded by Peter Thiel, claimed a hacker breached its database exposing personal data of members. But a WIRED investigation found the data was publicly accessible due to a misconfigured website. The exposed information includes contact details, login tokens, internal rankings, and more for high-profile individuals from NATO, US government, and tech firms.
Technology ShinyHunters Claim to Leak 45GB of Data from Madison Square Garden
The hacking group ShinyHunters published data allegedly stolen from Madison Square Garden, totaling 45GB with millions of records. The leaked data includes customer personal information and references to Knicks players and coaches. A federal class action lawsuit has been filed, and MSG has not commented.
Technology Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed
Novo Nordisk, the maker of Ozempic and Wegovy, confirmed a cyberattack that breached pseudonymized clinical trial data, including patient IDs, biomarkers, and lifestyle factors. The company stated no personally identifiable information (PII) was exposed and core operations remain unaffected. Third-party cybersecurity experts are investigating.
Technology French Government's Tchap Messaging App Breached, 14GB of Data Stolen
The French government's internal encrypted messaging service Tchap was compromised in a cyber attack. The breach was discovered on June 7 by ANSSI, and a hacker claims to have stolen nearly 14GB of documents, email addresses, and meeting links. The incident underscores France's push for homegrown software alternatives.
Technology Coupang Fined $400M by South Korea for Massive Data Breach Affecting 37.5 Million Users
South Korea's data protection regulator fined Coupang $400M (624.68bn won) for a data breach affecting 37.5 million users, the largest such fine ever. The leak exposed names, contact, delivery details, and order histories. Coupang expressed regret and plans to challenge the decision; its CEO resigned.
Technology Japanese Utility Loses Drive with 10.9M Records: What Enterprises Must Learn
Kyushu Electric Power Co. reported a physical storage drive containing data of 10.9 million customers missing from an unlocked cabinet. The incident underscores critical physical security gaps in enterprise data protection, with regulators demanding a full report by July 8, 2026.
Technology OpenClaw AI Agent's Phishing Vulnerability Exposed
Varonis researchers demonstrated that the OpenClaw AI agent, Pinchy, can be tricked into phishing attacks, compromising user data. Despite blocking malicious links, the AI failed to verify identity in urgent requests.
Technology ServiceNow API Flaw Exposes Customer Data in Australia
ServiceNow has addressed a security flaw in its API that allowed unauthorized access to customer data, primarily affecting those on the Australia release. The company has implemented a fix and advised customers to review their logs for suspicious activity.
Technology Cockroach Janta Party Faces Social Media Lockout Amidst Campaign
The Cockroach Janta Party, led by Abhijeet Dipke, has lost access to all its social media accounts following a series of alleged hacking incidents. This comes amidst their campaign against Union Education Minister Dharmendra Pradhan over systemic failures.