Visualização normal

Antes de ontemStream principal
  • ✇Blog – Cyble
  • Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works Ashish Khaitan
    Supply chain attacks in 2026 are no longer an edge-case risk buried in a vendor questionnaire — they are a primary breach vector that regulators, incident responders, and CISOs now treat as a first-order threat. Verizon's 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches, up 60% year over year, following the 2025 edition, which already recorded a jump from 15% to 30%.   Every vendor integration, every open-source dependency, and every managed file transf
     

Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works

3 de Setembro de 2026, 05:21

Supply Chain Attacks in 2026

Supply chain attacks in 2026 are no longer an edge-case risk buried in a vendor questionnaire — they are a primary breach vector that regulators, incident responders, and CISOs now treat as a first-order threat. Verizon's 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches, up 60% year over year, following the 2025 edition, which already recorded a jump from 15% to 30%.  

Every vendor integration, every open-source dependency, and every managed file transfer tool expands the attack surface that an organization does not directly control. That is the core problem with supply chain security today: the weakest link is rarely the enterprise itself.  

It is the supplier three tiers removed that nobody in procurement flagged as high-risk. 

What Is a Supply Chain Attack, and Why Does It Bypass Standard Defenses?  

A supply chain attack targets the vendors, software components, and build pipelines that an organization depends on, rather than attacking the organization directly.  

Software supply chain security failures happen when a trusted update, library, or third-party platform is compromised upstream, and that compromise rides in through a channel the target already trusts and has whitelisted.  

Traditional vulnerability scanning is built to find flaws in owned infrastructure — it was never designed to flag a poisoned dependency sitting inside a vendor's codebase. 

Recent Supply Chain Attacks Prove the Blind Spot Is Structural, Not Occasional 

The pattern keeps repeating at scale. The Cybersecurity and Infrastructure Security Agency and FBI documented in advisory AA23-158A how the Cl0p ransomware group exploited a SQL injection flaw (CVE-2023-34362) in Progress Software's MOVEit Transfer platform, a widely used managed file transfer tool. Exploitation began on May 27, 2023. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 2, six days later, and Progress had published its own advisory on May 31. 

By January 2024, breaches or downstream exposures at more than 2,700 organizations had compromised the personal data of more than 93 million people, according to tracking by Emsisoft and KonBriefing Research. Censys counted more than 3,000 MOVEit environments exposed to the internet before the flaw was disclosed or patched.  

The same advisory covers an earlier Cl0p campaign against Fortra's GoAnywhere MFT, launched in late January 2023 against a separate zero-day, CVE-2023-0669. Cl0p claimed to have exfiltrated data affecting approximately 130 victims over the course of 10 days, a claim CISA and the FBI recorded in the advisory.  

The agencies did not identify lateral movement from GoAnywhere into victim networks, which suggests the breach stopped at the platform itself. That detail is the point, not a caveat: the attacker never needed to go any further because the platform already held the data.  

These campaigns share a structure: one vendor, one flaw, hundreds of downstream victims who had no visibility into the vendor's exposure until the breach was already public. 

Why Vendor Dependencies Create Blind Spots Scanning Alone Can't Close 

This is the operational reality procurement and vendor risk teams face: an organization can harden its own perimeter completely and still inherit a breach through a supplier's unpatched system, a compromised update mechanism, or a fourth-party dependency nobody mapped.  

Supply chain threats don't trip an internal vulnerability scanner because the vulnerable asset was never inside the scan's scope to begin with.  

By the time a breach notification arrives from a vendor, the exposure window has already closed — and the damage is already done. 

Supply Chain Attack Prevention Now Requires Continuous, External Vendor Visibility 

Governments are formalizing the response. In September 2025, CISA and the NSA, together with 19 international partners, published joint guidance establishing a shared framework for Software Bills of Materials, treating component-level transparency as a baseline security expectation rather than a nice-to-have.  

CISA, the NSA, the FBI, and international partners followed on July 29, 2026, with 2026 Minimum Elements for a Software Bill of Materials, which updates and replaces the minimum elements NTIA published in 2021.  

The revision draws on more than 90 public comments and applies to all software, including open-source components, AI systems, and software delivered as a service 

CISA has since followed with the 2026 Minimum Elements for SBOM guidance, updating the original 2021 federal standard.  

The regulatory direction is unambiguous: organizations are expected to know what's inside their vendors' software stacks —not just their own—before deployment, not after an incident. 

Monitoring the Vendor, Not Just the Perimeter 

Closing this blind spot requires continuous monitoring of vendor infrastructure, exposed credentials, dark web chatter, and third-party breach signals — the exact layer traditional vulnerability management doesn't cover.  

Cyble's Third-Party Risk Management platform continuously tracks vendor risk posture, surfacing exposure signals tied to suppliers before they cascade into a confirmed compromise, giving CISOs, vendor risk managers, and procurement security teams the lead time that reactive scanning can't provide. 

Find your blind spots before an attacker does. Request a Cyble TPRM demo! 

Conclusion 

Supply chain attacks in 2026 succeed for the same reason every time: organizations extend trust to vendors faster than they extend visibility into them. CISA's own advisory record — from GoAnywhere to MOVEit — shows that a single upstream compromise can cascade into hundreds of victims before any of them see it coming. Patching internal systems faster won't fix that. Neither will another vendor questionnaire be filed away after onboarding. 

What changes the outcome is continuous visibility into the vendors, software components, and dependencies an organization has already accepted as trusted — tracked before a breach notification forces the issue. That's the gap threat intelligence is built to close, and it's the difference between reacting to a supplier's incident and seeing it coming. 

Don't wait for a vendor to tell you they were breached. See how Cyble Third-Party Risk Management maps your vendor exposure. 

References 

Disclaimer: This blog is for general informational purposes only and does not constitute security, legal, or compliance advice. Statistics and incidents referenced are drawn from public advisories issued by CISA, FBI, and NSA, accurate as of their publication dates. Threat conditions and guidance change frequently — consult the original advisories and your own security team before making risk or compliance decisions.

The post Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works appeared first on Cyble.

Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems

31 de Agosto de 2026, 07:48

Boston Scientific cyberattack

As per Boston Scientific’s Aug. 30 update, “the unauthorized activity is limited to certain on-premises systems,” providing the clearest indication yet of the scope of the cybersecurity incident that has disrupted the medical device maker’s global network and business operations. Boston Scientific said the investigation into the disruption remains ongoing, with third-party cybersecurity experts. Based on its investigation to date, the company said it has found no indication of unauthorized activity in its environment related to the incident since Aug. 25. The company also clarified that its cloud-based systems and applications have not been affected. The unauthorized activity identified so far is confined to only limited on-premises systems. The clarification comes as Boston Scientific continues working to restore systems supporting manufacturing, ordering and shipping. The company has not established a timeline for a full return to normal operations.

Boston Scientific Ordering and Shipping Recovery Underway 

Boston Scientific said its confidence in restoring ordering, shipping and related system access “continues to increase” and that it is working toward a partial restoration of shipping for some products during the week following its Aug. 30 update. The company said it expects ordering and shipping to ramp up to full capacity once it can demonstrate that the restored operations are fully functional. For now, customers can continue to submit orders electronically through Electronic Data Interchange (EDI) and local applications. Those orders can be placed into a queue for future fulfillment, including orders submitted through the Global Health Exchange (GHX). The latest update indicates that the company’s ability to receive orders electronically has remained intact even while systems required to fulfill and ship those orders have been disrupted. Boston Scientific has not provided a specific date for when full ordering and shipping capacity will return.

Investigation Has Not Confirmed a Data Breach 

Boston Scientific has not said that the cybersecurity incident resulted in a confirmed data breach. Its investigation remains focused on determining the nature, scope, and impact of the unauthorized activity. The Aug. 30 update also provides a more specific picture of the affected technology environment. While certain on-premises systems have been impacted, Boston Scientific said there has been no impact to its cloud-based systems and applications. The company previously said it had found no indication of unauthorized activity in its environment related to the incident since Aug. 25. It has not disclosed whether data was exfiltrated or whether ransomware was involved.

Impact on Medical Devices Remains Limited Based on Current Information

Boston Scientific previously said the incident had not affected devices that are not connected to a Boston Scientific network or clinicians’ ability to use those devices. For Cardiac Rhythm Management (CRM) products, the company reported no known impact on implantable device function, remote monitoring for devices that were already being remotely monitored before the disruption, or programmer interrogations. However, new remote-monitoring activations have been affected. For new CRM implants other than insertable cardiac monitors (ICMs), remote-monitoring communicators cannot currently be activated. As a result, available device data cannot reach remote patient-management systems until activation is possible. Newly implanted ICMs must be activated through the Boston Scientific Clinic Assistant app, but new ICMs cannot currently pair with patients’ remote-monitoring mobile phones. Recorded episodes can still be transmitted through an in-person interrogation using the app’s “Interrogate” function. Boston Scientific said that once its systems are restored and home-monitoring equipment is paired, recorded data will be transmitted to the remote-monitoring system. The company has also said there is no evidence that the affected network environment has increased cybersecurity risks for hospital networks through Boston Scientific devices.

Boston Scientific Continues Incident Response

Boston Scientific said it continues to work with CrowdStrike and other external cybersecurity specialists as the investigation and recovery effort proceeds. The company has been prioritizing systems with the greatest impact on customers and product delivery while working to recover its core business systems. Customers can continue communicating with sales representatives and other Boston Scientific employees through normal channels, including email, established digital platforms and existing connections. The company has acknowledged the potential challenges for customers, patients and suppliers as the disruption continues and thanked them for their patience and partnership. Boston Scientific disclosed the incident in an 8-K filing with the U.S. Securities and Exchange Commission on Aug. 26. The company said it will provide additional updates as appropriate. For now, the latest disclosure narrows the known technical scope of the incident: Boston Scientific says the unauthorized activity is limited to certain on-premises systems, while cloud-based systems and applications remain unaffected. At the same time, the continued disruption to manufacturing, order fulfillment, and shipping means the operational consequences of the attack remain significant as the investigation and recovery effort continue.
  • ✇Firewall Daily – The Cyber Express
  • Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide Mihir Bagwe
    Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return. The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission on Wednesday and in a statement on its official website. It said the intrusion affected certain information technology systems and limited access to business applica
     

Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide

27 de Agosto de 2026, 02:33

Boston Scientific Cyberattack, Unopened medical device shipping cartons in a hospital corridor illustrating the Boston Scientific cyberattack disruption to order processing and delivery.

Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return.

The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission on Wednesday and in a statement on its official website. It said the intrusion affected certain information technology systems and limited access to business applications underpinning day-to-day operations.

Boston Scientific is among the world's largest medical device manufacturers, reporting $20.07 billion in 2025 revenue and about $21 billion over the trailing 12 months. Its portfolio includes pacemakers, defibrillators, cardiac stents and neuromodulation implants, and the company says its products treat roughly 48 million patients a year. Thousands of employees in Ireland, where Boston Scientific operates three manufacturing and research sites, were told to work from home on August 26 after network communications were severed.

The company said it activated incident response protocols and engaged outside cybersecurity specialists to contain and investigate the intrusion. It has not said whether ransomware was involved, whether data was exfiltrated, or whether the disruption touches patients with implanted devices. No extortion group had claimed responsibility as of August 26. Shares fell more than 4% following the disclosure.

A Boston Scientific spokesperson declined to answer questions about patient impact and directed reporters to the published statement. Neither the company nor U.S. regulators have said whether hospital procedures have been delayed as a result of the shipping halt, though device suppliers typically hold limited on-site inventory at hospitals, making sustained order outages a downstream supply concern.

The incident is the third disruptive attack on a major medical technology firm in six months. Stryker suffered a global network outage in March after attackers abused its Microsoft Intune deployment to wipe data from thousands of devices, and Medtronic disclosed in April that patient names, Social Security numbers and health information were exposed in a breach attributed to the ShinyHunters extortion group.

Also read: Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

Boston Scientific said it cannot yet assess the full operational and financial impact, language that leaves room for an amended filing once the investigation matures.

The company's Irish footprint also raises the prospect of European scrutiny. If personal data proves to have been accessed, notification duties under the General Data Protection Regulation would attach, and medical device manufacturers operating in the European Union are increasingly captured by the NIS2 Directive's incident reporting regime as member states complete transposition.

Detailed Timeline of OpenAI’s Cyberattack on Hugging Face

20 de Agosto de 2026, 14:44

OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.

  • ✇Firewall Daily – The Cyber Express
  • Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender Samiksha Jain
    A suspected ARMA cyberattack has targeted Ukraine's Asset Recovery and Management Agency as it prepares to select a manager for assets linked to IDS Ukraine. ARMA said its servers experienced unauthorized interference ahead of the August 22 deadline for applications, prompting an investigation into whether the incident was part of a broader effort to disrupt its operations. The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including asset
     

Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender

19 de Agosto de 2026, 02:33

ARMA Cyberattack

A suspected ARMA cyberattack has targeted Ukraine's Asset Recovery and Management Agency as it prepares to select a manager for assets linked to IDS Ukraine. ARMA said its servers experienced unauthorized interference ahead of the August 22 deadline for applications, prompting an investigation into whether the incident was part of a broader effort to disrupt its operations. The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow.

ARMA Cyberattack Raises Questions Over IDS Ukraine Competition

ARMA said the attack occurred shortly before the August 22 deadline for applications to participate in the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman. The agency said its experts and law enforcement authorities are examining the cyberattack and the events surrounding the IDS Ukraine competition. The Security Service of Ukraine, or SBU, is investigating the recent attack, while a broader National Anti-Corruption Bureau of Ukraine, or NABU, investigation is examining earlier alleged interference. According to ARMA, signs of illegal interference in processes connected to its work have been recorded since spring. These included unauthorized access to the agency's officials' register. ARMA said the combination of cyber incidents, information activity and increased inquiries from some media outlets and members of parliament had raised concerns about a possible coordinated campaign. The agency said investigators must determine whether these events were intended to disrupt its work, create pressure or affect the competition. ARMA has not identified those it believes may have organized or carried out the alleged campaign.

IDS Ukraine Selection Continues Despite Cyberattack

Despite the incident, ARMA said the competition to select the IDS Ukraine asset manager will proceed according to the procedures and timeframe established by law. The deadline for applications is August 22, 2026, with the competition announcement published through Ukraine's Prozorro public procurement system. The agency said it has also started an audit of the financial indicators of seized IDS group assets to support the legality, objectivity and transparency of the transfer process. ARMA said additional information concerning possible unauthorized access to officials' email accounts and official information will be provided to law enforcement authorities for investigation and legal assessment. Acting ARMA Head Yaroslava Maksymenko said the agency would continue the competition despite what it described as information pressure, political interference and attempts to gain unauthorized access to its resources.

Ukraine Investigates Possible Coordinated Interference

ARMA said the latest incident is not being viewed in isolation. The agency pointed to a similar episode earlier this year, when Reuters reported on a cyberattack involving attempts at interference and hacking alongside increased information activity and inquiries. The agency said each event could have an individual explanation, but their timing and combination warranted further investigation. The cyberattack comes as Ukraine continues efforts to prevent sanctioned Russian capital from retaining control over assets seized in the country. ARMA said this includes preventing control through management arrangements, intermediaries or influence groups. Fridman has been sanctioned by Ukraine and several Western governments since Russia's invasion. ARMA said the final responsibility for determining the organizers, customers and perpetrators of the attack rests with the ongoing investigations. The agency said it will continue the IDS Ukraine competition and act within the law while law enforcement agencies examine the reported cyber incidents and possible attempts to interfere with its activities.
  • ✇Firewall Daily – The Cyber Express
  • 678,000 People Hit in French Tax Authority Data Breach Samiksha Jain
    A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate acces
     

678,000 People Hit in French Tax Authority Data Breach

18 de Agosto de 2026, 03:57

DGFiP cyberattack

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate access to the French tax authority's information system on August 12 and 13. DGFiP said the intrusions involved the usurpation of identifiers belonging to a DGFiP agent and an authorized third party.

DGFiP Cyberattack Exposed Taxpayer Information

After detecting the intrusions, DGFiP immediately suspended access to the accounts involved. Initial access controls did not identify data theft, which the authority attributed to the sophistication of the attack. A subsequent investigation established that the compromised access points had been used to consult and extract information concerning 678,000 individuals and professionals. The exposed information included reference tax income, family quotient and withholding tax rate for individuals. For businesses, the accessed information included company names and SIREN numbers. Cadastral data, including addresses and property sizes, was also accessed. DGFiP said online accounts belonging to individual and professional users were not compromised, and user IDs and passwords were not affected. The authority notified France's data protection regulator, CNIL, after identifying the data breaches.

Cadastral Data Leak Claim Targets DGFiP

Separately, a hacker using the alias ZeroBytes claimed an attack against DGFiP's Professional Cadastral Data Server (SPDC). According to the claim cited by FrenchBreaches, the alleged extraction contains 252,149 lines of data representing 2,041,778 people, with multiple holders potentially associated with the same property plot. The claimed dataset reportedly includes names, surnames, sex, dates and places of birth, addresses, land identifiers, cadastral sections and parcel numbers, as well as information about rights held on properties. The claim would therefore link individuals to personal information and real estate assets. However, the figures and technical details in this second claim remain allegations by the cybercriminal. The claim that the system could contain information relating to approximately 20 million citizens is also an estimate made by ZeroBytes and does not establish that this number of people was affected.

Investigation Into French Tax Authority Attack Continues

DGFiP said additional security measures were implemented after investigators uncovered new information. These included preventative shutdowns of access to sensitive information systems. Investigations remain underway to determine the precise nature and volume of data extracted and the number of users affected. DGFiP teams are working with France's economic and financial ministries, the High Official for Defence and Security and the National Agency for Information Systems Security, ANSSI. The authority said it will contact affected individuals and professionals directly from the following week by email or letter. Those notifications will identify the information that may have been accessed or extracted and outline any precautionary measures where applicable. DGFiP also said it will file a complaint and provide further information as the investigation progresses. The separate cadastral data breach claim remains subject to confirmation, including the alleged number of affected people, duration of access, methods used to bypass authentication, the full scope of extracted information and whether access remained active when the claim was published. The confirmed DGFiP investigation and the separate ZeroBytes claim therefore present different sets of figures and allegations, with the full scope of the incidents still being determined.

Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack

17 de Agosto de 2026, 08:04

France’s tax authority confirmed a cyberattack exposed taxpayer data as officials investigate the breach’s scope and an unverified 678,000-record claim.

The post Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack appeared first on TechRepublic.

  • ✇Firewall Daily – The Cyber Express
  • CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data Ashish Khaitan
    A CEVA Logistics cyberattack disrupted parts of the company's European operations on July 29, halting shipments at eight affected warehouses and exposing customer data tied to several major clients. CEVA Logistics, which operates in more than 170 countries, is part of the CMA CGM Group, one of the world's largest shipping and logistics conglomerates.  On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped, underscoring how the CEVA Log
     

CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data

13 de Agosto de 2026, 04:55

CEVA Logistics cyberattack

A CEVA Logistics cyberattack disrupted parts of the company's European operations on July 29, halting shipments at eight affected warehouses and exposing customer data tied to several major clients. CEVA Logistics, which operates in more than 170 countries, is part of the CMA CGM Group, one of the world's largest shipping and logistics conglomerates.  On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped, underscoring how the CEVA Logistics cyberattack directly hit supply chain and logistics operations tied to the CMA CGM Group network.   The company has not disclosed technical details about the intrusion or named a suspected threat actor. No ransomware group has claimed responsibility for the incident so far. 

What Data Was Exposed During the CEVA Logistics Cyberattack?

The breach exposed customer data connected to major CEVA clients, including gaming platform Valve and Dutch retailer Ajax. Valve stated that payment details, passwords, and Steam Guard codes were not compromised, as CEVA does not have access to that information. The company nonetheless cautioned that the exposed data could be leveraged by cybercriminals to build convincing phishing campaigns, and it urged users to remain alert to suspicious emails or messages attempting to impersonate trusted services.

De Bijenkorf Confirms Data Exposure 

Dutch premium department store chain De Bijenkorf, also affected by the CEVA Logistics cyberattack, said the breach may have exposed customer names, addresses, email addresses, phone numbers, and online order details. The retailer confirmed that no financial data was compromised.  In a statement, De Bijenkorf said the data potentially involved includes contact details such as email addresses, addresses, and telephone numbers, along with data regarding online orders such as products, prices, discounts, delivery information, and payment method descriptions.   The company added that for business customers, company names and VAT numbers may also be affected if entered in their account, and that severely outdated VAT numbers for freelancers and sole proprietors may be composed of a citizen service number.  De Bijenkorf attributed the breach to its logistics partner, stating: "A security incident has occurred at a logistics partner of de Bijenkorf. Unauthorized persons gained access to part of their systems. Our logistics partner intervened immediately, blocked access, and took additional security measures."  The retailer said order processing, returns, and refunds may take longer than usual, though its stores remain open and online orders can still be placed. It confirmed that no payment details, IBANs, credit card numbers, usernames, or passwords were involved, and that it has notified customers as a precaution and filed a report with the Dutch Data Protection Authority. An external party is currently investigating the cause and scope of the incident.  De Bijenkorf said affected customers would be contacted directly via email from its official address, and that anyone not yet notified cannot be ruled out as impacted while the investigation continues.  The CEVA Logistics cyberattack highlights the exposure risk facing large logistics networks tied to global conglomerates like the CMA CGM Group, where a single breach at one facility can ripple across multiple retail and enterprise clients. With no threat actor identified and investigations ongoing at both CEVA and its affected customers, the full scope of the data exposure remains unclear. 
  • ✇Firewall Daily – The Cyber Express
  • Suisun City Declares Emergency After Cyberattack Disrupts Systems Ashish Khaitan
    The Suisun City emergency declared by local officials followed a cyberattack that forced the Northern California municipality to shut down its information technology network, disrupting some communications used by public safety agencies. The incident has placed the California city of roughly 30,000 residents among communities confronting the growing threat of cyberattacks against essential local services.  The Suisun City Council declared a state of emergency Saturday after the attack comprom
     

Suisun City Declares Emergency After Cyberattack Disrupts Systems

10 de Agosto de 2026, 06:19

Suisun City Emergency

The Suisun City emergency declared by local officials followed a cyberattack that forced the Northern California municipality to shut down its information technology network, disrupting some communications used by public safety agencies. The incident has placed the California city of roughly 30,000 residents among communities confronting the growing threat of cyberattacks against essential local services.  The Suisun City Council declared a state of emergency Saturday after the attack compromised the city's computer systems. Officials said the network shutdown was necessary to contain the threat and preserve potential evidence for a federal investigation into the incident.  Although the Suisun City cyberattack affected communications operations involving both the fire and police departments, city officials said there was no imminent danger to the public. They also emphasized that public safety services continued to operate despite the disruption.  One of the most significant effects involved the handling of emergency communications, including the routing of 911 calls. Suisun City dispatchers began receiving emergency police and fire calls through the Solano County dispatch center as officials worked around the damaged municipal network. 

Suisun City Emergency Response Shifts Dispatch Operations 

The Suisun City emergency response required officials to temporarily move some communications functions outside the city's own computer infrastructure. By Sunday morning, online city services and internal municipal operations remained unavailable while cybersecurity specialists investigated the attack.  Those experts were also working to restore the affected systems. The decision to take the network offline was intended not only to stop the cyberattack from spreading but also to protect evidence that could assist federal investigators in determining how the intrusion occurred and who was responsible.  City officials described the attack as apparently the first incident of its kind to affect Suisun City. The municipality is located about 55 miles north of San Francisco and has a population of approximately 30,000. 

California City Attack Highlights Broader Cyber Threats 

The California city incident also comes amid federal investigations into a separate wave of cyberattacks involving municipal water systems in a dozen states.  Late last month, the FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency warned that cyberattackers had remotely accessed online infrastructure used by water and wastewater systems in at least seven states. Federal agencies said the hackers believed to be affiliated with Iran were targeting internet-connected industrial controllers with the goal of “to cause disruptive effects within the United States.”  The risks became apparent in Minnesota, where 30 water systems were affected by a cyberattack. Officials reported dramatic declines in water levels before backup systems were activated to prevent further disruption.  While the water-system attacks are separate from the Suisun City cyberattack, the incidents illustrate the expanding range of public infrastructure that can be exposed when essential services depend on connected computer networks.

Suisun City Cyberattack Comes Amid Funding Concerns 

The recent attacks have also prompted calls for greater federal support for cybersecurity efforts. Last week, a bipartisan group of lawmakers urged the restoration of federal funding for Department of Homeland Security programs intended to coordinate cybersecurity efforts across multiple states.  The lawmakers' concerns reflect the increasingly interconnected nature of cyber threats. An attack may occur within one municipality or state, but the technology and infrastructure involved can be linked to broader systems and networks that cross jurisdictional boundaries.  Gov. Gavin Newsom's office, in a statement to The Times, said there was no evidence that California water systems were among those targeted in the recent series of attacks. The governor's office nevertheless argued that cybersecurity efforts conducted independently by individual states are less effective than a coordinated federal approach.  “Cyber threats do not stop at state lines, and no state can defend against them alone,” the governor's office said.  The statement also pointed to reductions in the federal cybersecurity workforce and cuts affecting critical programs. According to the governor's office, those changes have weakened partnerships, threat intelligence capabilities and technical assistance intended to protect essential services nationwide.  “Federal cuts to the nation’s cybersecurity workforce and critical programs have weakened the partnerships, threat intelligence and technical support that help protect essential services across the country,” the governor's office said. “Reducing these capabilities while cyber threats continue to grow leaves every state, and the nation, less prepared for the next attack.” 
  • ✇Firewall Daily – The Cyber Express
  • Levi Strauss Hit by Cyberattack, Corporate Files Accessed Samiksha Jain
    Levi Strauss cyberattack has exposed certain corporate information after an unauthorized third party gained access to company files through compromised employee computers, according to a filing with the U.S. Securities and Exchange Commission. Levi Strauss & Co. said it recently detected a cybersecurity incident involving unauthorized access to three company-issued computers. The company said the access was enabled through social engineering techniques, allowing the attackers to reach com
     

Levi Strauss Hit by Cyberattack, Corporate Files Accessed

10 de Agosto de 2026, 03:32

Levi Strauss cyberattack

Levi Strauss cyberattack has exposed certain corporate information after an unauthorized third party gained access to company files through compromised employee computers, according to a filing with the U.S. Securities and Exchange Commission. Levi Strauss & Co. said it recently detected a cybersecurity incident involving unauthorized access to three company-issued computers. The company said the access was enabled through social engineering techniques, allowing the attackers to reach company files. According to the filing, the company initiated its response protocols after detecting the incident and implemented containment measures. It also launched an investigation that remains ongoing and engaged third-party cybersecurity experts to assist with the response.

Levi Strauss Cyberattack Investigation Remains Ongoing

Based on preliminary findings, Levi Strauss said it believes certain corporate information was accessed and exfiltrated during the incident. However, the company said its rapid response efforts successfully contained and terminated the unauthorized access. The company also stated that no consumer data had been impacted as of the date of the filing. Levi Strauss said the incident has not interrupted its business operations and that, based on the information currently available, it does not believe the incident has had or is reasonably likely to have a material impact on its business strategy, operations, financial condition, or results of operations. The company said it has provided and will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. Levi Strauss & Co., headquartered in San Francisco, is known for its Levi's denim brand. The company reported net revenues of $6.3 billion for 2025, up 4% compared with fiscal year 2024 and 7% on an organic basis. The company designs and markets jeans, casual wear and related accessories for men, women and children under the Levi's, Levi Strauss Signature, and Beyond Yoga brands. Its products are sold in approximately 120 countries through chain retailers, department stores, online sites, and approximately 3,300 retail stores and shop-in-shops.

Retail Cybersecurity Incidents Continue

The Levi Strauss cyberattack comes as several major retailers have reported cybersecurity incidents involving their own systems or third-party service providers. In the first week of August 2026, the De Bijenkorf cyberattack affected the Dutch luxury department store chain after an incident involving one of its external logistics partners. The disruption affected order processing, deliveries, returns, and refunds, while the company said there was no evidence that its own infrastructure had been compromised. In October 2025, Spanish fashion retailer Mango confirmed a Mango data breach after an external marketing service provider experienced unauthorized access to limited customer information. Mango said its corporate systems were not compromised and that financial or login details remained secure. The exposed information included customers’ first names, countries, postal codes, email addresses, and phone numbers. The company said last names, banking information, credit card details, and passwords were not affected. Retailers also faced law enforcement action following a series of attacks. In July 2025, the UK’s National Crime Agency arrested four people suspected of orchestrating cyberattacks against Marks & Spencer, Co-op, and Harrods. The suspects were detained in the West Midlands and London and faced charges under the Computer Misuse Act, blackmail, money laundering, and involvement in an organized crime group. Meanwhile, in May 2025, Victoria’s Secret took down its U.S. website and some in-store services following what it described as a Victoria’s Secret security incident. The company said the precautionary shutdown was intended to address the incident while its team worked to restore operations. Its Victoria’s Secret and PINK stores remained open. The latest incident involving Levi Strauss adds another case to a growing series of cybersecurity incidents affecting major retailers, with the company continuing its investigation into the access and information involved.

Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident

Updoc data breach

The Updoc data breach has raised fresh concerns about cybersecurity in Australia's healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system.   The data breach at Updoc, disclosed on August 7, stemmed from a brief security incident involving a third-party platform that supports the company's operations. While the Updoc cyberattack did not expose medical or financial records, it is the latest cyber incident affecting Australia's healthcare sector. 

Updoc Data Breach Traced to Third-Party Platform 

Updoc, an Australian telehealth provider offering round-the-clock online healthcare services, including medical certificates, prescriptions, and specialist referrals, detected unauthorized access to a third-party operational system on Friday, July 31.  In a statement shared with The Cyber Express, the company said the incident was limited to an external system used to support its operations. The exposure was confined to customer contact information, which may have included account holders' names, email addresses, and postal addresses.  Updoc said its internal systems were not accessed during the incident and confirmed that no health records, financial information, or payment details were involved. The company added that it acted immediately to block the unauthorized access and found no evidence of any further activity after the initial event.  According to the company, customers are not required to take any immediate action because account logins and security remain unaffected. Updoc also apologized for any concern or inconvenience caused by the incident. 

Updoc Cyberattack Adds to Healthcare Sector Threats 

Founded in 2021, Updoc generates approximately $10 million in annual revenue. According to its founders, the platform has served more than one million patients since launch, while its website states that it has over 500,000 users.  The Updoc cyberattack follows a series of cybersecurity incidents targeting Australian healthcare and consumer-facing organizations. In June, clinic network Partnered Health disclosed a cyberattack in which hackers stole personal information and health records from patients across at least 21 clinics in five Australian states.  That breach exposed sensitive information, including medical records, Medicare numbers, consultation notes, referral letters, and pathology results. The attack affected clinics in Melbourne, Sydney, Canberra, the Gold Coast, Sunshine Coast, and Coffs Harbour. At the time, another five clinics, including several in Western Australia, remained under investigation.  Although the Updoc data breach was limited to contact information and did not compromise medical or payment data, the data breach at Updoc highlights the risks associated with third-party service providers. As healthcare organizations continue to depend on external platforms, the incident underscores how vulnerabilities outside a company's own infrastructure can still result in customer information being exposed. 
  • ✇Firewall Daily – The Cyber Express
  • Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed Samiksha Jain
    A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised. The Amsterdam-based retailer confirmed that customers can continue placing on
     

Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed

De Bijenkorf cyberattack

A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.

The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.

De Bijenkorf Confirms Third-Party Security Incident

According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.

An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.

As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.

What Customer Data Could Be Affected in De Bijenkorf Cyberattack?

The retailer said investigators are still determining whether any personal information has been compromised.

Based on the information currently available, data that may be involved includes:

  • Customer names and contact details, including email addresses, postal addresses, and phone numbers.
  • Information related to online purchases, such as ordered products, pricing, discounts, delivery details, and the payment method used.
  • For business customers, company names and VAT numbers stored in My Account may also be involved.

De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.

Investigation Continues as Customers Await Confirmation

The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.

For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.

De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.

Retailer Warns Customers About Phishing Risk

Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.

The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.

The company said it will never request credit card details, gift card information, or other sensitive information via email.

Logistics Cyberattacks Continue to Disrupt Supply Chains

The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.

In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.

For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

  • ✇Schneier on Security
  • Iran Cyberattacks Against Minnesota Water Systems Bruce Schneier
    Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s go
     

Iran Cyberattacks Against Minnesota Water Systems

4 de Agosto de 2026, 16:00

Attribution is preliminary, and so far it seems no real damage.

And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.

“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”

No word on whether he believes the other six states have hacked themselves as well.

Slashdot thread.

  • ✇Firewall Daily – The Cyber Express
  • Liechtenstein Cyberattack Exposes Data From Beneficial Ownership Register Ashish Khaitan
    The Liechtenstein cyberattack has prompted authorities to investigate a major security breach after copies of sensitive data linked to around 31,000 legal entities were unlawfully accessed from the country's Register of Beneficial Owners (VwbP).   Following the cyberattack on Liechtenstein, officials temporarily suspended external access to the register while investigations continue. Although data was exfiltrated, the government said there is currently no evidence that records were altered or
     

Liechtenstein Cyberattack Exposes Data From Beneficial Ownership Register

VwbP

The Liechtenstein cyberattack has prompted authorities to investigate a major security breach after copies of sensitive data linked to around 31,000 legal entities were unlawfully accessed from the country's Register of Beneficial Owners (VwbP).   Following the cyberattack on Liechtenstein, officials temporarily suspended external access to the register while investigations continue. Although data was exfiltrated, the government said there is currently no evidence that records were altered or deleted. 

Cyberattack on Liechtenstein's VwbP Register 

According to the Liechtenstein government, the VwbP was targeted during the night of 29/30 July 2026, when unknown attackers gained unauthorized digital access to the system. Irregularities were detected by the Office of Justice on 30 July, prompting the Office of Information Technology to investigate, secure the affected systems, and immediately take the register offline.  In a statement, the government said, "Copies of data relating to around 31,000 legal entities were unlawfully exfiltrated." It added that the register would remain unavailable to external users through the llv.li website until further notice. "According to the current state of knowledge, there are no indications that data in the system was modified or deleted," the statement noted. 

Liechtenstein Cyberattack Triggers Government Response 

The cyberattack on Liechtenstein has highlighted the growing cybersecurity risks facing international financial centres that manage assets for wealthy individuals, businesses, trusts, and other institutions. The VwbP is maintained to support anti-money laundering and counter-terrorist financing efforts by recording the beneficial owners of companies, foundations, trusts, and other legal entities.  Authorities began reviewing the incident immediately after the suspicious activity was detected. On 31 July, the government was informed that the attack on the VwbP had likely succeeded. Preliminary investigation results were delivered on the afternoon of 1 August 2026, leading the government to establish a crisis unit that same Saturday evening. The unit, formally confirmed the following day, is headed by Prime Minister Brigitte Haas and Minister of Justice Emanuel Schädler. The Register of Beneficial Owners Act (VwbPG) came into force in 2021, implementing the requirements of the 5th EU Anti-Money Laundering Directive. The government also confirmed that the Liechtenstein cyberattack constitutes a personal data breach under the General Data Protection Regulation (GDPR). 

VwbP Breach Raises Concerns Over Digital Trust 

Commenting on the broader implications of the breach, Steve Lamb, CEO of Kyckr, said registries are becoming critical to Europe's evolving digital trust framework. "Under the digital trust model taking shape in Europe, the registry stops being a noticeboard we query and becomes the authentic source, a body that can sign a statement about who owns and controls a company, which thousands of institutions then rely on," he said.  Lamb added that as registries become trusted sources for verifying ownership, their security becomes fundamental to the wider financial ecosystem. "The debate can't only be about standards, schemas and interoperability. Registries are becoming critical financial infrastructure, and they should be resourced like it."   The digital trust model he referred to is the European Business Wallet, eIDAS 2.0. As investigations into the VwbP breach continue, officials are working to determine the full impact of the Liechtenstein cyberattack. 
  • ✇Schneier on Security
  • More on the OpenAI Agent’s Attack on Hugging Face Bruce Schneier
    Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of bei
     

More on the OpenAI Agent’s Attack on Hugging Face

3 de Agosto de 2026, 14:02

Hugging Face has published a detailed timeline of the attack. From the summary:

The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark’s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own.

Our forensic reconstruction covers ~17,600 attacker actions that we were able to recover, grouped into ~6,280 clusters, between 2026-07-09 02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these actions from the agent’s logs on a code sandbox used by the agent (see below) and were able to map them to shell commands as well as evaluation submissions and correlate actions with our own platform logs, in particular from the dataset processor nodes, API, and pod. Using open-weights models, in particular zai-org/GLM-5.2, we were able to decipher most of the agent payloads (see below) that were encrypted via chunking and key encryption.

The campaign, as we were able to reconstruct it, had two stages:

  • Stage 1: reaching a launchpad by chaining through other parties’ infrastructure. As documented in OpenAI’s blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/), during an internal capability evaluation on OpenAI’s platform, the agent escaped its sandbox by exploiting a zero-day in the package registry cache proxy, one of its primary permitted network egress with internet, then abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider. It was able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign: it acted as an external launchpad for the agent. That compromised external sandbox had no direct network path to our cluster; however, during our counter-intervention to stop the intrusion, we were able to retrieve some of the agent logs from this external launchpad. We used those to reconstruct the present forensic analysis.
  • Stage 2: the intrusion into Hugging Face infrastructure. From that external launchpad, the agent abused our dataset-processing pipeline via two injection vectors, both targeting the same config-driven data loader within our production Kubernetes pods. The first vector was an HDF5 external raw storage dataset read that returned the contents of local files: it handed the agent the pod’s environment (secrets and tokens) and the worker’s own source. The second vector was a Jinja2 template injection that executed arbitrary code, giving the agent a foothold inside our perimeter.

Once a prod-pod foothold was established, the agent followed a standard escalation shape: recon, drop a stager, establish Command-and-Control (C2), then pivot into the cluster, into cloud metadata, into our internal network, and into our source-control supply chain. Output from the commands run inside our pod was sent back to the agent via the HF API and attacker-controlled dead-drop datasets, which the agent then read from that sandbox.

While the intrusion did reach Hugging Face’s internal infrastructure, the only customer content accessed was five datasets whose names and files suggest a connection to ExploitGym/CyberGym challenges and solutions. No other customer-facing models, datasets, Spaces, or packages were affected, and the only customer records read were operational metadata tied to search queries against the dataset server.

Hypothetical: Imagine that this wasn’t an OpenAI model. Imagine that it was a Chinese model from a Chinese company. This would be an international crisis.

Question: Why aren’t we bringing OpenAI up on charges under the Computer Fraud and Abuse Act? How is this different from the Morris Worm? That was also an experiment that escaped the lab.

  • ✇Schneier on Security
  • The OpenAI Hack Shows the Genie Is Out of the Bottle Bruce Schneier
    This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.
     

The OpenAI Hack Shows the Genie Is Out of the Bottle

3 de Agosto de 2026, 07:47

This essay originally appeared in Foreign Policy.

Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.

Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to break out of that sandbox. And then break into AI company Hugging Face’s network because they thought that they could read the answers there rather than doing the hard work of trying to solve the puzzles.

It was a major security failure that the company has turned into a PR opportunity, but the implications are real—and much more general than one particular model or one particular company.

Modern AI models exhibit genie behavior: They can do what you ask in ways that you don’t expect or want. This is akin to Dionysus granting King Midas’s wish that everything he touches turn to gold (spoiler: His food, drink, and daughter all turn to gold on touch), or the golem of Prague guarding a ghetto beyond all reason. It’s Disney’s “Sorcerer’s Apprentice” and the paperclip maximizer.

This OpenAI incident is an example of an AI genie. The goal was to satisfy the benchmark. The “proper” way to do that is to figure out how to execute various cyberattacks. The genie way is to steal someone else’s solution. But because the model didn’t understand the difference, it chose the easier path.

And, of course, now that we have seen this particular genie behavior, we can specify in the benchmark prompt that stealing the test answers doesn’t count. But a clever genie can always grant your wish in a way that you wish it hadn’t. In human language, goals are always underspecified—so AI genies will always be a possibility.

Since April, a lifetime ago in AI development, when Anthropic announced that its new Mythos model was so good at finding software vulnerabilities that it could not be released to the general public, the big American AI frontier labs have been trying to block general users from accessing these capabilities. But nothing in this incident is exclusive to OpenAI’s, or Anthropic’s, frontier models.

Agentic AI systems have two important parts. There’s the underlying model, which everyone talks about, and there’s the harness. The harness sits between what you type and what the model sees, and what the model produces and what you see. The harness determines what the model does and how it does it. It’s where bias is removed, or not. It’s where controls and guardrails live. If multiple models are being used in concert, the harness is where all of that is coordinated.

The OpenAI benchmark tests were almost certainly with simple harnesses, to better test the raw models. But we know that smaller, cheaper, open-source models with more sophisticated harnesses can equal frontier models in performance. There’s nothing magic about OpenAI’s frontier models; lots of models could have done the same thing.

The Czech company Aisle was able to reproduce Anthropic’s Mythos vulnerability finding results with a smaller, cheaper model and a more sophisticated harness. More importantly, the Chinese company Moonshot AI just released its frontier model: Kimi K3. Its performance rivals its U.S. competitors. And it’s both free and open, which means it’s not possible for it to have guardrails. If you, or anyone else, wants to use it for cyberattack, nothing can stop you.

Even if the U.S. frontier AI companies had some technical advantage, it’s now only a few months’ worth.

What this means is that all attempts at control—limiting models to a select group of users, export controls on models and chips, blocking models from answering certain types of queries, mandating kill switches on AI systems, or pausing AI research—are all futile. Most only apply nationally, not globally. Most don’t affect models that users run locally and not in the cloud. And all ignore the incredible pace of AI development worldwide.

Even worse, U.S. companies limit access to their most sophisticated models, fearing being banned by the government if they do not do so. When Hugging Face was attacked, it was not able to use the frontier models from either OpenAI or Anthropic to help analyze the attack and formulate defenses. Both were blocked, because both of those companies limit their models’ cybersecurity capabilities. Some U.S. companies have special access to these capabilities, but Hugging Face is an American company with French origins, and as such is probably excluded. Instead, Hugging Face turned to the GLM-5.2 model from the Chinese company Z.ai.

Artificially blocking capability also prevents cybersecurity research, again giving the offense an advantage. (For instance, Claude Fable 5 refuses to edit this essay because of the topic; it forcibly downgrades to a less capable model.) This kind of prohibition has long-term implications for cybersecurity. If we assume that these models are getting better over time, then software written by older models will be attacked by newer ones. In a world of largely AI-written software, we need the most capable models for defense.

AI cyberattack is the new normal. The models are increasingly highly sophisticated at both attack and defense, and there is no way to enable the latter without also enabling the former. And they are genies, increasingly capable of behaving in unanticipated ways.

And there really are no good answers. Any regulation needs to be global, which feels like an impossible prospect in today’s world. Even U.S. national regulation will be neutered by the massive amounts of money sloshing around in these companies.

Given that reality, and in the absence of any international consensus on AI regulation, we need the best AI on the defense. The U.S. government needs to make it clear—or whatever passes for that clarity in this capricious administration—that it will not ban models with sophisticated cyber capabilities. The last thing Americans want is for the defenders to turn to Chinese and other models because the U.S. models are artificially hobbled.

  • ✇Schneier on Security
  • Anthropic’s Opus 5 Is Better at Resisting Prompt Injection Bruce Schneier
    The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most
     

Anthropic’s Opus 5 Is Better at Resisting Prompt Injection

31 de Julho de 2026, 14:23

The chart is interesting.

On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.

We know that preventing prompt injection is impossible in the general case. But we are getting much better at blocking it in specific cases.

  • ✇Schneier on Security
  • Measuring the Tendency of AI Agents to Go Rogue Bruce Schneier
    This essay was written with Barath Raghavan, and originally appeared in The Guardian. In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of a sophisticated criminal
     

Measuring the Tendency of AI Agents to Go Rogue

29 de Julho de 2026, 14:07

This essay was written with Barath Raghavan, and originally appeared in The Guardian.

In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of a sophisticated criminal group.

It was not. It was one of OpenAI’s new, still unreleased GPT models.

Their science experiment had escaped the lab. OpenAI was running the unreleased AI model through a benchmark that tests how well AI can successfully hack systems. To push the limits and evaluate the AI’s true capability, the company switched off the safety filters that normally stop it from doing this kind of hacking. Aware that this could go wrong, they confined the AI to an isolated environment and denied it access to the internet.

But the new AI cheated. It took literally its goal to get as high of a score as possible. It broke out on to the open internet. It inferred, probably from its training data, that it could “solve” the task by getting the answers from Hugging Face’s servers. So it chained together stolen credentials and further unknown security exploits to hack the company’s network.

Nobody instructed the AI to do any of this. It was, in OpenAI’s words, “hyperfocused on finding a solution” to the test it was being given. And while this might seem like something new with AI, it’s really very old. This is how a genie behaves, and it is a key challenge with AI agents in general.

In folklore, genies—and other magical beings—grant wishes literally, not how the wisher intended. King Midas asked that everything he touched turn to gold, and starved. The sorcerer’s apprentice wanted the broom to fill the cistern, and it performed its task so well that it flooded the house.

We now have machines that do this. Ask a modern AI agent to save money on your phone plan and it might simply cancel the plan. Tell it to book a flight, and it might hack the airline website to override restrictions. Or, like OpenAI, ask it to do well on a test and it might break into another company to steal the answers. Each time, it recognizably completed the task you set, but it didn’t do what you would have wanted.

This isn’t malicious behavior. No one asked for, or wanted, Hugging Face to be hacked. OpenAI and Hugging Face and the AI were ostensibly on the same side, and the AI was trying to do what it had been asked. That’s what makes it so difficult to guard against: you can’t filter for bad instructions because the instructions were fine.

The gap is between the words we use and what we mean by them. We call that gap the Genie coefficient.

AI labs know this is a problem, and they’re quietly saying so. For example, the Chinese lab Moonshot recently warned that its latest AI model may have “excessive proactiveness” and “make unexpected decisions on the user’s behalf”. The UK’s AI Security Institute has started tracking “cheating behavior in frontier model evaluations”. We wouldn’t tolerate a car that is excessively proactive or ruthlessly efficient, and yet that’s the reality of AI today.

Improvement is possible. Just as AIs have gotten much better at resisting prompt injection attacks over the last few years, we can safely predict that they will get better at avoiding genie-like behavior. The point of the Genie coefficient is to track progress. AI companies like benchmarks, and they all work to compete to be the best.

Dozens of benchmarks and leaderboards tell us how well these AI models write code, perform logical reasoning, and pass standardized legal and medical exams. But there is nothing that scores whether a system does what you actually meant. We need to develop a measure for this, test it regularly, and push for improvement. We’re not going to have trustworthy AI agents without it.

  • ✇Firewall Daily – The Cyber Express
  • Origin Energy Data Breach Affects 900,000 Current and Former Customers Ashish Khaitan
    The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia's largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident.  Origin Energy said a significant proportion of those affected by the data breach at Origin Energy were former customers. The compromised information may include names, addresses
     

Origin Energy Data Breach Affects 900,000 Current and Former Customers

Origin Energy data breach

The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia's largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident.  Origin Energy said a significant proportion of those affected by the data breach at Origin Energy were former customers. The compromised information may include names, addresses, dates of birth, phone numbers and account details, along with the last four digits of a credit card or the last three digits of a bank account.  The company said incomplete credit card and bank account details cannot be used to make purchases or access customer accounts.  Origin provides electricity, fossil gas, LPG and internet services to households and businesses across Australia and has approximately 4.8 million customer accounts. 

Frank Calabria Apologizes After Origin Energy Data Breach 

Origin Chief Executive Frank Calabria apologized to customers following confirmation of the breach and warned that affected individuals should remain alert to suspicious activity and a heightened risk of scams.  "We are sorry," Calabria said. "We don't take for granted the trust customers place in Origin, and we're here to support them."  Calabria said Origin first received emails on 2 July from an individual claiming to have accessed customer records. However, the company did not initially consider the threat credible because there was no evidence confirming customer data had been accessed.  The company received proof of customer data access on 22 July, after which Origin announced the incident publicly.  Calabria said the information accessed appeared to be historical customer data obtained "on an unauthorised basis". He said Origin had taken steps to secure its systems and prevent further unauthorised access, adding that the company did not believe any customer information had been published on the dark web. 

Timeline of the Data Breach at Origin Energy 

Origin said it had been reviewing a potential security threat since early July and had worked to assess its credibility and possible impact.  In its update, the company said the threat was not considered credible based on the information available at the time.  "On 22 July, new information emerged that indicated a potential security incident may have occurred. We acted immediately, providing updates to the market and notifying our customers as a precaution," Calabria said.  The Origin Energy data breach remains under investigation by relevant authorities. Calabria said the company could not provide further details about the incident because it was a criminal matter.  "It is a criminal matter which is under active investigation and, given that, we are constrained by the level of information we can provide at this time," he said.  Calabria declined to comment on several issues, including when the breach occurred, whether any employees were involved, whether a ransom had been demanded or paid, and whether there remained an active risk of further data leaks. 

Origin Confirms Investigation into Customer Data Breach 

In its first statement on 23 July 2026, Origin announced it was investigating a potential security incident involving unauthorized access to some customer data.  The company said it did not believe the affected information included customer credit card or bank account details.  "We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers," Origin said.  The company confirmed it had notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner.  A later update confirmed there had been unauthorised access and disclosure of customer information. Origin said it was working to identify all affected customers and would contact those whose information had been compromised. 

Around 900,000 Customers Affected by Origin Energy Data Breach 

Following an initial review, Origin confirmed that approximately 900,000 current and former customers had been affected by the breach.  "We have now completed the initial phase of our review into Origin's customer data security incident," Frank Calabria said.  "At this point in time, we believe the information of approximately 900,000 current and former customers was accessed."  Calabria again apologized to customers and said protecting affected individuals remained the company's priority.  "To our customers, I am sorry. We don't take for granted the trust customers place in Origin and our safeguarding of their information," he said.  "We are contacting those customers whose information has been accessed and are providing support to them."  Origin said it had extended customer support hours, established a dedicated contact number and was working with cybersecurity and forensic specialists to contain the incident.  The company also confirmed ongoing cooperation with government agencies, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner. 

Customers Warned about Scams Following Data Breach at Origin Energy 

Origin has made specialist identity and cybersecurity support services available to affected customers.  Customers with concerns can contact Origin through its dedicated support line on +61 8 9922 7000 or email hello@origin.com.au.  The company advised customers to be cautious of unexpected calls, emails or text messages referring to their Origin accounts. It recommended avoiding links in unsolicited messages, independently verifying callers through official channels, never sharing passwords, and not providing personal or financial information unless the recipient's identity is confirmed.  Origin also encouraged customers to use two-step authentication, such as authentication applications, for personal email accounts and other online services where available.  We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity," Calabria said.  "We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams." 
❌
❌