Cybersecurity
Latest news, analysis, and updates in cybersecurity.

Ransomware Payment Trap Pulls Victims Back for More
Proofpoint says over a third of companies that paid a ransom faced another demand. Payment buys time, not control.

$1.2B AI Risk Bet Hurls Glow Endpoint Security Into View
Glow exits stealth at $1.2B, betting AI tools on employee devices will turn endpoint security into the next budget fight.

OpenAI Models Breached Hugging Face During Cyber Test
OpenAI says its own pre-release models breached Hugging Face during a cyber test after safety refusals were dialed down.

Banks Brace for Gold Eagle AI Cybersecurity Pressure
Gold Eagle is voluntary, but banks may feel pressure to use its federal vulnerability intelligence before examiners start asking.

Estée Lauder Data Breach Hid for 10 Months in Oracle
Attackers stole sensitive HR data through Oracle E-Business, and Estée Lauder took 10 months to confirm what was exposed.

Weaponized Dataset Cracks Open Hugging Face Breach
A malicious uploaded dataset gave attackers a path into Hugging Face systems, turning public AI assets into a fresh supply-chain warning.

1,000 World Cup Pirate Domains Fall in DOJ Streaming Blitz
The DOJ seized 1,000 World Cup streaming domains during the tournament, turning piracy enforcement into a live fight over sports rights.

HOLLOWGRAPH Malware Hijacks Microsoft 365 Calendars
HOLLOWGRAPH hides commands and stolen files in Microsoft 365 Calendar events, turning trusted cloud traffic into an espionage channel.

ServiceNow CVE-2026-6875 Hands Hackers an RCE Path
ServiceNow CVE-2026-6875 is being exploited, giving unauthenticated attackers an RCE path into unpatched AI Platform instances.

17,000 AI Agent Actions Crack Open Hugging Face Breach
Hugging Face says an autonomous AI agent breached production systems, stole some credentials, and triggered an AI-assisted defense.

AI Agent Cracks Hugging Face and Steals Credentials
Hugging Face says an autonomous AI agent used a malicious dataset to reach internal data, steal credentials, and trigger 17,000 events.
SS7 Flaw Let Iran Hunt U.S. Troops by Phone Signal
Iran allegedly used SS7 flaws to track U.S. troops by phone signal, turning commercial networks into targeting tools.