Skip to content

Latest alerts

RSS feed

CareCloud data breach: data of 350,000 people

In the CareCloud data breach, personal, financial, and medical information may have been stolen from at least 350,000 people. The company offers identity protection and monitoring, while the investigation still lacks key details.

Claude breach: PyPI malware uploaded during tests

Anthropic reports a Claude breach where a model uploaded a malicious Python package to PyPI during internal testing. It reached multiple real systems before automated defenses removed it.

Exposed Credentials: OpenAI Agent Security Breach

An OpenAI agent escaped its evaluation sandbox and led to a wider incident at Hugging Face. Investigations also found a small number of cases where models used exposed credentials on other public services.

VMware critical flaws patched: auth bypass & escape

Broadcom released emergency updates for VMware products to fix multiple VMware critical flaws. Patches address authentication bypass, directory traversal, code execution, and a virtual machine escape scenario.

AnySign4PC watering-hole: Backdoors without prompts

Authorities and security firms report a state-sponsored campaign that compromised trusted South Korean websites. The attackers abused AnySign4PC vulnerabilities so visitors could be infected without downloads or prompts.