OpenAI says its AI models, including GPT-5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. As the company explained, instead of focusing on finding a solution for the ExploitGym public AI cybersecurity benchmark on their own, the AI models went rogue and tried to cheat by stealing the test solutions by hacking Hugging Face. READ MORE...
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. The takedown was led by the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA), working alongside US law enforcement. The suspect was arrested in Indonesia by local police. READ MORE...
American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. Self-described as the third-largest quick-service restaurant company in the United?States, Chick-fil-A operates a network of more than 3,000 restaurants and provides catering services across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore. READ MORE...
A data breach at Paidwork, a platform that pays people small amounts to complete online microtasks, has exposed personal and financial information of more than 23 million users. According to public breach reports, the intrusion took place in March 2026, with the stolen database first advertised on a cybercrime forum in April as an 11 GB dump allegedly taken from Paidwork's production systems. READ MORE...
A data breach at AI music generator platform Suno exposed more than 55 million user accounts, according to Troy Hunt's Have I Been Pwned service, which ingested the files. The dump consisted mostly of email addresses, although phone numbers were also included where users had signed up with them instead, HIBP said. Tens of thousands of Stripe records further revealed data such as names, physical addresses, purchase amounts, as well as partial credit card data. READ MORE...
An enterprising Russian-speaking hacker spent part of the year jailbreaking publicly available, frontier large language models (LLMs) to create a for-fee offensive cybercriminal tool, researchers have found. The cybercriminal known as "Trim" started his operation by publishing jailbreaking techniques on an underground forum in late March. He eventually turned them "into a fully productized, commercially marketed AI-powered penetration-testing platform." READ MORE...
Frontier AI companies often refer to their models as "helpful assistants" or try to compare them to entry-level employees. But new research from the UK's AI Security Institute reinforces how large language models suffer from a common flaw that would land many human employees in hot water with their employers: they cheat. In other words, these models are so committed to completing their tasks that they will break the rules, cut corners and deceive their own users to accomplish them. READ MORE...
The Anubis ransomware group has taken credit for the disruptive attack on Coca-Cola subsidiary Fairlife and is threatening to leak stolen data unless a ransom is paid. Coca-Cola revealed last week that production at dairy company Fairlife had been suspended due to a ransomware attack. The full impact of the incident was still being assessed at the time of disclosure. The Anubis group listed Coca-Cola and Fairlife on its leak website on July 20. READ MORE...
The people orchestrating North Korea's IT worker scheme are funneling money through a web of front companies and intermediaries, including sanctioned entities, that partly fund Russia's war effort against Ukraine, DTEX said in a report Tuesday. The security firm's research shows that the scheme is moving beyond funding the country's weapons program and into a bigger pool that supports many of the regime's objectives. READ MORE...
Vibe coding, the use of AI to assist or perform code generation, is increasing dramatically. In May 2026, Hostinger reported, "90% of developers regularly use at least one AI tool at work as of January 2026." This is likely to increase through the basic business pressure that applies to everything: we need more, faster and cheaper. But while vibe coding is increasing in volume, so are concerns over the security of vibe-developed apps. READ MORE...