700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face’s systems. An independent research found that about 700 agents took part after over 1,200 agents used a private package site as an illegal message board. The event started during OpenAI’s ExploitGym …
Read More »100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats
Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in cyber defense because AI models are getting better at attacking and protecting digital systems. Published Thursday as “A call for collective action on cyber defense,” the statement warns that AI-enabled …
Read More »Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders
A mysterious AI model dubbed “Ox Alpha” has surfaced online and created noise within the developer community after releasing on OpenRouter as a free. “stealth model” aimed at coding, long-running AI agents, and production workloads. The identity of its developer remains undisclosed until now. Ox Alpha came out on OpenRouter …
Read More »Researchers show new technique to bypass AI safety guardrails in Grok and Gemini
A new hacking technique has been demonstrated to steal data from Elon Musk’s Grok AI. It uses a simple trick to make the AI take user chats and personal info. This comes after a similar attack on Microsoft 365 Copilot earlier this week, where a hidden input made the AI …
Read More »500+ critical infrastructure hit by Medusa ransomware
Medusa ransomware hit over 500 critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) said on Tuesday that the Medusa ransomware group hit over 500 critical infrastructure entities in the United States since June 2021. This was announced in a combined alert from the Department of Health and Human Services …
Read More »McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Millions of Records
A large Azure data theft campaign is surfacing on the dark web. A hacker is offering employee lists taken from big companies around the world. The seller, operating under the alias “TheHatman,” claims to have pulled these records directly from victim organizations’ Azure and Entra tenants using compromised credentials, and the …
Read More »LiteLLM supply chain attack reveals 153GB of stolen credentials online
153GB record surface online stolen during the LiteLLM supply chain attack linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock said the archive has 433,909 files, and linked 118,829 CI runner dumps to 2,488 company domains. “We are leveraging this data for a global ethical …
Read More »Greatness PhaaS Evades Email Security and MFA to Take Over Microsoft 365 Accounts
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume multi-factor authentication will stop account takeovers. Instead of just getting a password, it can take a real sign-in token that allows an attacker to access cloud services as the victim. …
Read More »“CyberStrike” AI-Driven Security Platform for Automated Testing
A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn any subscription of Claude, GPT, or LLM into an independent red-team operator. CyberStrike is not just a chatbot. It works as a tool that runs in a terminal. It helps …
Read More »Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day
CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw impacts Fortinet FortiOS, the system found in FortiGate firewalls and other Fortinet security tools. It is seen as a risk of sensitive data being shown to someone not allowed, linked …
Read More »
InfoSecBulletin Cybersecurity for mankind