A large Azure data theft campaign is surfacing on the dark web. A hacker is offering employee lists taken from big companies around the world. The seller, operating under the alias “TheHatman,” claims to have pulled these records directly from victim organizations’ Azure and Entra tenants using compromised credentials, and the …
Read More »LiteLLM supply chain attack reveals 153GB of stolen credentials online
153GB record surface online stolen during the LiteLLM supply chain attack linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock said the archive has 433,909 files, and linked 118,829 CI runner dumps to 2,488 company domains. “We are leveraging this data for a global ethical …
Read More »Greatness PhaaS Evades Email Security and MFA to Take Over Microsoft 365 Accounts
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers. Instead of just getting a password, it can take a real sign-in token that allows an attacker to access cloud services as the victim. …
Read More »“CyberStrike” AI-Driven Security Platform for Automated Testing
A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn any subscription of Claude, GPT, or LLM into an independent red-team operator. CyberStrike is not just a chatbot. It works as a tool that runs in a terminal. It helps …
Read More »Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day
CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw impacts Fortinet FortiOS, the system found in FortiGate firewalls and other Fortinet security tools. It is seen as a risk of sensitive data being shown to someone not allowed, linked …
Read More »Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves
OpenAI’s CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading to fast growth that might be hard to manage. Altman said the “singularity” is a big event that can bring great benefits to society, seeming to dismiss worries from critics about …
Read More »Shinyhunters claimed and set deadline to publish E&Y data
ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their dark web site. It says they will release all stolen data by July 31, 2026, unless EY talks to them before the mentioned date. EY shared details about the incident …
Read More »Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security
Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber threats. They are getting involved in the debate about the safety of free AI models. The Open Secure AI Alliance has members like Microsoft, IBM, Palantir, CrowdStrike, Cisco, Dell, and …
Read More »Google Search Results Reportedly Show Claude AI Shared Chats
Claude’s share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared private talks. A Reddit post this weekend showed that many Claude AI chats could be found on Google. People searching for site:claude.ai/share could see talks about legal advice, engineering projects, …
Read More »Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher
A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like the very secure GPT-5.6 Sol, Claude Opus 5, and Fable. In a public post on X, Pliny the Liberator described the technique as effective “on ALL models” and across every …
Read More »
InfoSecBulletin Cybersecurity for mankind