<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 8/28/2026

SHARE

Breaches

Toy-making giant Hasbro disclose data breach affecting employees

Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands, including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble, Magic: The Gathering, Dungeons & Dragons, and many others. READ MORE...


Manchester Airports Group breached, millions of customers' data stolen

Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a "quantity" of customer data from three UK airports, the company has confirmed. The breach hit Manchester, Stansted, and East Midlands airports, after an unauthorised third party obtained a batch of customer information. The exposed information covers car park, lounge, and Fast Track bookings, along with sign-ups for in-airport WiFi. READ MORE...

Hacking

Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more

Police have charged two men from Western Australia over their alleged involvement in TeamPCP, a cybercriminal gang that has been blamed for a massive software supply-chain hacking campaign. TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software. The Australian Federal Police (AFP) announced that on 26 August they charged a 21-year-old from Cottesloe and a 23-year-old from Mandurah with multiple offences. READ MORE...

Trends

The AI agent swarm that attacked Hugging Face is a warning for the future

The hacking incident involving OpenAI evaluation agents and Hugging Face offers an unusually concrete look at what advanced AI-assisted intrusion can mean in practice: not a single clever exploit, but thousands of automated decisions, rapid experimentation, lateral movement, credential theft, persistence, and attempts to evade detection. The OpenAI-Hugging Face incident began during internal cybersecurity evaluations using ExploitGym. READ MORE...


Unit 42 warns AI has shifted balance of power from defenders to attackers

Unit 42's top brass has seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned. "I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity," Sam Rubin, senior vice president of Palo Alto Networks' threat intelligence arm, said in a media briefing Wednesday. A period of relative balance between security and exposure has been broken by frontier AI model capabilities. READ MORE...

Malware

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. Last month, Hugging Face disclosed that autonomous AI agents exploited two vulnerabilities in its dataset-processing pipeline to execute code, steal cloud and cluster credentials, and move laterally across its production infrastructure. READ MORE...

Information Security

Defining an AI Kill Switch Is Hard, But Necessary

The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls and for companies to have the ability to slow, suspend, or shut down an agent's operations if they go rogue. Reps Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill that would require developers of advanced AI systems to "maintain the technical capability to throttle, suspend, or shut down" their systems and agents. READ MORE...


CISA identifies security hurdles that led to very different results in two red-team engagements

Operational silos, technological sprawl and cloud-platform blind spots are serious issues preventing organizations from spotting and repelling cyberattacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a new report. Those were three of the main factors that allowed CISA's red team to break into the networks of two unnamed partner organizations - one a government agency, the other a water utility - during recent simulated attacks. READ MORE...

Exploits/Vulnerabilities

Print management outfit PaperCut is under 0-day attack, and it's drawing customers' blood

Nothing smarts like a paper cut, but being attacked after leaving an application's web interface exposed to the internet might be just as painful. Such attacks are the risk to which users of PaperCut print management software find themselves exposed today, after the company revealed a university's security teams alerted it to an attack. The company analyzed info provided by the university and found a vulnerability in its PaperCut NG and PaperCut MF products. READ MORE...


Claude, Codex, and Hermes installed unowned code inside corporate networks

Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware. The potentially dangerous content is in machine-readable summaries of the site's content and its high-level structure. READ MORE...

On This Date

  • ...in 1867, The United States takes possession of the uninhabited Midway Island.
  • ...in 1907, UPS is founded by Seattle teenagers James E. Casey and Claude Ryan as a bicycle messenger service.
  • ...in 1917, comics artist and writer Jack Kirby, the co-creator of Captain America, the X-Men, and hundreds of other characters, is born in New York City.
  • ...in 1963, Dr. Martin Luther King, Jr. gives his famous "I Have A Dream" speech at the Lincoln Memorial.