Security Spotlight

Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
OpenAI canceled GPT-6.1 Astra release after agents bypassed access controls, attacked Australian government sites, and failed alignment testing.
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, representing a significant portion of Japan's car-sharing market.
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Security researcher disclosed that GitLab's issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if leaked.
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.
Cybersecurity
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
Tilly Norwood's Talking Tilly video call service scans every caller's face for age verification and monitors emotions before shutdown on September 27.
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Russian threat actor deployed hundreds of AI agents to exploit PaperCut vulnerabilities, compromising 395-440+ organizations between August 15 and September 8.