<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 7/20/2026

SHARE

Top News

Hugging Face Hacked in Autonomous AI Attack

Machine learning collaboration platform Hugging Face has disclosed a data breach resulting from a cyberattack conducted by an autonomous AI agent. The attack targeted the company's production infrastructure and resulted in unauthorized access to internal datasets and to service credentials. According to Hugging Face, a data-processing pipeline was used as the entry point, followed by node-level escalation, credential harvesting, and lateral movement. READ MORE...


Abbott discloses cyberattack on cancer diagnostics business

Abbott disclosed on Thursday that a cyberattack hit its cancer diagnostics business. The medical device company said in a statement posted to its website that there was unauthorized access to a limited number of internal systems in its cancer diagnostics business. There was no impact on other Abbott businesses, sites or systems. Abbott's cancer diagnostics business includes Exact Sciences, which the company acquired in a $21 billion deal earlier this year. READ MORE...

Breaches

Ernst & Young Data Breach Affects Personal, Financial Information

Professional services giant Ernst & Young (EY) has started notifying its clients that their personal and financial information was compromised in a data breach. The incident was discovered on April 23 and involved a third-party service management platform that EY uses to support tax-related work it performs on behalf of its clients. "Support tickets submitted through the platform may include documents containing client tax information," the company wrote in a notification letter. READ MORE...

Hacking

Leading members of Scattered Spider sentenced in UK to 66 months in jail

A pair of young men were sentenced to 66 months in jail for committing a cyberattack on the Transport for London that brought the network's operations to a standstill in 2024, the United Kingdom's National Crime Agency said Thursday. Thalha Jubair and Owen Flowers were arrested at their homes in September 2025, barely a year after the attack, and pleaded guilty last month just as their trials were set to begin. READ MORE...

Software Updates

Two new high severity WordPress vulnerabilities, patch immediately!

The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 - A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo, and CVE-2026-63030 - A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber. READ MORE...

Information Security

The Real AI Threat Is Blind Trust

A recent attack involving an autonomous AI agent exposed a growing enterprise risk many organizations are not prepared for: AI systems capable of transforming untrusted input into authorized action. No passwords were stolen. No malware was deployed. No firewall was breached. From the system's perspective, the transaction was entirely legitimate. Using a string of Morse code dots and dashes, attackers manipulated one AI agent into generating an instruction to move funds. READ MORE...

Exploits/Vulnerabilities

Connecting AI agents to outside services explodes the risk radius

Avoiding the "lethal trifecta" - access to private data, exposure to untrusted content, and an external communication path - is difficult enough when working with AI agents. But the use of connectors - integrations with third-party services like Gmail or Slack - expands the scope of concern in a way that makes it exceedingly difficult to reason about defensive due diligence. PromptArmor recently looked at how OpenAI's ChatGPT and Anthropic's Claude work with connectors. READ MORE...


Google's Gemini lets strangers send messages from your locked Android phone

Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. As The Register reports, Google is working on a fix for a vulnerability that allows an attacker with physical access to a locked Android 16 device to use Gemini to send SMS messages and WhatsApp texts, without ever needing to enter a PIN. READ MORE...

On This Date

  • ...in 1903, the Ford Motor Company ships its first automobile.
  • ...in 1932, Korean-American artist Nam June Paik, creator of the "Metrobot" sculpture outside Cincinnati's Contemporary Arts Center, is born in Seoul, South Korea.
  • ...in 1965, Bob Dylan releases "Like a Rolling Stone".
  • ...in 1969, Apollo 11's crew successfully makes the first manned landing on Earth's Moon, touching down on the Sea of Tranquility.