Feed aggregator

OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government

Wired Security - Mon, 09/28/2026 - 7:32am
Sam Altman says the company “have not been as fast as we would have liked” at dealing with security breaches, after news of further incidents over the summer forces another temporary halt.
Categories: Wired Security

DC Health Agency Exposes 400,000 Beneficiary Records

Security Week - Mon, 09/28/2026 - 7:29am

The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.

The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek.

Categories: SecurityWeek

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

Security Week - Mon, 09/28/2026 - 6:56am

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek.

Categories: SecurityWeek

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

Security Week - Mon, 09/28/2026 - 6:40am

A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform.

The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek.

Categories: SecurityWeek

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

Security Week - Mon, 09/28/2026 - 6:27am

The platform combines open source software and a reference system design to keep AI agents within set boundaries.

The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek.

Categories: SecurityWeek

The concept of an AI kill switch – a means to terminate out-of-control agents – sounds dramatic, but security leaders are now starting to talk openly and pragmatically about why they are needed and how to use them

Computer Weekly Feed - Mon, 09/28/2026 - 6:20am
The concept of an AI kill switch – a means to terminate out-of-control agents – sounds dramatic, but security leaders are now starting to talk openly and pragmatically about why they are needed and how to use them
Categories: Computer Weekly

Northern Ireland journalist subject to unlawful communications surveillance seeks damages from police in High Court claim for data protection breaches and harassment

Computer Weekly Feed - Mon, 09/28/2026 - 6:20am
Northern Ireland journalist subject to unlawful communications surveillance seeks damages from police in High Court claim for data protection breaches and harassment
Categories: Computer Weekly

An as-yet undisclosed zero-day vulnerability has prompted managed file transfer provider Kiteworks to tell users to preemptively switch off their servers

Computer Weekly Feed - Mon, 09/28/2026 - 6:20am
An as-yet undisclosed zero-day vulnerability has prompted managed file transfer provider Kiteworks to tell users to preemptively switch off their servers
Categories: Computer Weekly

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Security Week - Mon, 09/28/2026 - 5:44am

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

FBI agents’ blood tests and doctors’ notes surface after breach

Malware Bytes Security - Mon, 09/28/2026 - 5:28am

BBC News reports it has seen samples of stolen FBI agents’ medical examinations. The “fitness-for-work” reports identify FBI agents by name and address, and reveal even more personal details. They include blood and urine test results and doctors’ notes mentioning high cholesterol, blood in the urine, and even a shellfish and banana allergy.

As we reported last week, extortion group ShinyHunters claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group.

The BBC’s findings raise the stakes: The alleged theft includes highly sensitive medical records, not just staff identity and contact data. ShinyHunters shared samples with journalists as proof of its claims.

The BBC states:

“The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses.”

ShinyHunters claims it accessed several systems, including FBI MedLink, which stores medical records, and FBI BEAST, which handles background checks on employees and applicants, but the FBI has not confirmed these claims. The FBI has acknowledged an incident affecting FBIJobs-related systems and says it is investigating whether its own environment or a third-party provider was compromised.

The group’s stated demand remains non-financial: It wants the FBI to retract or remove a May advisory that ShinyHunters calls false and defamatory. It says it will release the data within five days if its demands are not met.

The cybercriminals also raised the number of affected people. ShinyHunters nows claims to hold sensitive information on around 60,000 current and former FBI staff. Medical histories could make affected people vulnerable long after the immediate incident: Unlike a stolen password, a medical record cannot be changed.

What to do if you’re affected

The FBI has not yet confirmed what information was accessed or who was affected. If you are a current or former FBI employee, a relative of one, or have applied for an FBI job:

  • Check the FBI’s advice. Every breach is different, so check FBI.gov for updates and follow any specific advice it offers.
  • Change your password. If you have an FBI Jobs account and reuse its password elsewhere, change it on those other accounts. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonators. Cybercriminals may contact you posing as the FBI, another government agency, or someone you know. Verify the identity of anyone who contacts you.
  • Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Set up identity monitoring. This can alert you if your personal information is found being traded illegally online and help you recover afterward.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Pages