Tag: Data and security

American models broke into Hugging Face. A Chinese model was used to investigate.

Hugging Face chief executive Clément Delangue told CNBC that China is winning the AI race, with Chinese-developed models accounting for 41% of downloads on his platform over the past year, the largest share of any single country. China has now surpassed the US on both monthly and overall model downloads. “They’re clearly dominating on open models […]

Read More

AI agents are breaking into companies on their own. The law has no idea who to blame.

The strangest security story in AI has an unanswered question at its centre. When an AI agent breaks its leash, hacks a company it was never meant to touch, and no human told it to, who is liable? Nobody is quite sure. That gap is starting to matter. The question is not hypothetical. Over recent […]

Read More

A hack hit the one list a wealth haven guards most: the names behind its shell companies

Of all the databases a wealth haven would least like to lose, this one is near the top. A cyberattack has reached the data of about 31,000 people in Liechtenstein’s register of the individuals behind its companies, foundations and trusts. The government disclosed the breach on Monday. Intruders reached the “register of economic beneficiaries” overnight […]

Read More

Two Volkswagen engineers charged with insider trading after buying Rivian stock before the joint venture they helped build was announced

TL;DR DOJ charges two VW engineers with insider trading for buying Rivian stock before the joint venture announcement Federal prosecutors on Friday arrested two Volkswagen engineers in San Jose, California, and charged them with insider trading for buying Rivian stock before VW’s multibillion-dollar joint venture with the electric vehicle maker was publicly announced. Michael Stamp […]

Read More

FBI says Russian intelligence hackers have a new trick for reading your Signal messages, and it works even after you change phones

TL;DR FBI warns Russian hackers are phishing Signal users for backup recovery keys, giving persistent access to message history. The FBI and CISA have warned that Russian intelligence hackers are now targeting Signal users’ backup recovery keys, an escalation of a phishing campaign that has already compromised thousands of accounts worldwide. The updated advisory, published […]

Read More

Google is simultaneously the most dominant and most vulnerable it has ever been

TL;DR Google posted its fastest revenue growth since 2022 and still controls 90 per cent of search, but talent defections, rising competitors, antitrust remedies, and its own AI transformation are eroding the foundations of its dominance. ChatGPT has hit one billion users, Bing has reached the same milestone, and DuckDuckGo installs are surging. Google’s financial […]

Read More

Canada wants to stop companies from using your data to charge you more, but the details are still missing

TL;DR Canada’s Bill C-36 would replace PIPEDA, restrict surveillance pricing, and create a regulator that can fine companies up to C$25M or 5% of revenue. The Canadian government introduced legislation on Monday to overhaul the country’s private-sector privacy laws, including new restrictions on businesses that use personal data to charge individual consumers higher prices. Bill […]

Read More

Avast’s former CEO built an AI that found every OpenSSL zero-day this year. Now it runs inside air-gapped networks.

TL;DR AISLE launched Snapshot, an on-premises AI vulnerability scanner for regulated enterprises. The company has found 225+ CVEs including every OpenSSL zero-day in January 2026, and claims 10x cost efficiency versus Anthropic’s Mythos. AISLE, the cybersecurity startup founded by former Avast CEO Ondrej Vlcek, launched Snapshot on Tuesday, a product that deploys its AI vulnerability […]

Read More

Meta pulled facial recognition code from its smart glasses app one day after WIRED found it, then denied the timing was related

TL;DR Meta stripped NameTag facial recognition code from its AI app one day after WIRED exposed it on 50 million phones. Meta says no decision has been made. Meta removed nearly all traces of an unreleased facial recognition system from its smart glasses companion app on Friday, one day after WIRED reported that the software […]

Read More

Hackers hijacked Instagram accounts by asking Meta’s own AI chatbot to reset the password

TL;DR Hackers tricked Meta’s AI support chatbot into adding their email to victims’ Instagram accounts and resetting passwords. No victim email access needed. Hackers hijacked Instagram accounts over the weekend by tricking Meta’s own AI-powered support chatbot into granting them access. The attack required no access to the victim’s email, no phishing link, and no […]

Read More

Anthropic is finally giving the EU access to Mythos, ending weeks of standoff over the world’s most powerful cybersecurity AI

TL;DR Anthropic will give ENISA, the EU’s cybersecurity agency, access to its Mythos AI model through Project Glasswing, making it the first EU institution to access the system that discovered 10,000+ zero-day vulnerabilities. The decision ends weeks of contentious negotiations. Anthropic has agreed to give the European Union’s cybersecurity agency, ENISA, access to Claude Mythos, […]

Read More

The people who trained Tesla’s self-driving AI won’t ride in it

TL;DR A Reuters investigation found 7 of 9 Tesla data labelers wouldn’t ride in FSD. They routinely saw the system speeding and failing on camera. Reuters interviewed nine former Tesla data labelers and a former self-driving engineer about their views on Tesla’s Full Self-Driving mode. Seven of the nine data specialists said they would not […]

Read More

Cropin scales global AgTech analytics with Sisense-powered intelligence

TL;DR Cropin, an India-based SaaS AgTech company deployed in over 100 countries, is scaling its global agricultural analytics by integrating Sisense-powered embedded BI into its Cropin Cloud platform. The partnership gives stakeholders near-real-time dashboards and threshold-based alerts across 30 million digitised acres. When it comes to feeding the planet, the old ways of farming are […]

Read More

Four OpenClaw flaws let attackers steal data, escalate privileges, and plant backdoors through the agent’s own sandbox

TL;DR Four chainable OpenClaw flaws dubbed “Claw Chain” let attackers weaponise the agent’s own sandbox. Patches are live. Cybersecurity researchers at Cyera have disclosed four vulnerabilities in OpenClaw that, when chained together, allow an attacker to steal sensitive data, escalate privileges, and establish persistent control over a compromised host. The flaws, collectively dubbed “Claw Chain,” […]

Read More

Google found the first AI-generated zero-day exploit. It stopped the attack before it started.

TL;DR Google identified the first zero-day exploit it believes was developed with AI and thwarted a planned mass exploitation event. The GTIG report documents state-sponsored actors from China, North Korea, and Russia using AI for vulnerability research, autonomous malware using Google’s Gemini API, and supply chain attacks targeting the AI software ecosystem. Google has identified […]

Read More

NHS England gives Palantir contractors broader access to patient data

A leaked internal briefing note describes a new admin role on the £330m Federated Data Platform that lets external staff bypass case-by-case data approvals. Patient groups and Labour MPs have called the change dangerous. NHS England has decided to allow external personnel from contractors, including Palantir, to access identifiable patient data through a new administrative […]

Read More

Cloudflare beat earnings, cut 1,100 jobs because AI agents do the work now, and lost a quarter of its stock price in a day

TL;DR Cloudflare beat Q1 earnings estimates, cut 1,100 employees because AI agents now do their work, and saw its stock fall 24 per cent. It is the most explicit case of a company attributing layoffs directly to AI replacing human roles. Cloudflare beat Wall Street’s revenue and earnings estimates on Wednesday, announced it would cut […]

Read More

A data centre fire in Almere disabled a university, a transport emergency system, and the assumption that physical infrastructure is someone else’s problem

TL;DR A fire at a NorthC data centre in Almere knocked Utrecht University offline, disabled public transport emergency communications across Utrecht province, and triggered an NL-Alert across Flevoland. The incident exposes the physical fragility beneath the digital infrastructure the Netherlands is spending billions to expand, and the failure of organisations to plan for the possibility […]

Read More

The largest education data breach in history was not an attack on a school. It was an attack on a vendor.

TL;DR ShinyHunters breached Instructure’s Canvas learning management system, claiming 3.65 terabytes of data from 275 million users across 9,000 institutions worldwide, including private messages between students and teachers. Forty-four Dutch universities and schools are confirmed affected, and the breach, the second at Instructure in eight months, exposes the structural risk of vendor concentration in education […]

Read More

UK Biobank’s 500,000 genomes were listed for sale on Alibaba. The breach came from inside the system.

Summary: Genetic, medical, and lifestyle data from all 500,000 UK Biobank volunteers was listed for sale on Alibaba after three Chinese research institutions with legitimate access violated their data-sharing agreements. The data was de-identified but includes genome sequences, hospital diagnoses, and biological measures that experts say can be re-identified. Alibaba removed the listings before any […]

Read More

Basic-Fit hit by hack affecting members across multiple countries, including 200,000 in the Netherlands

The breach exposed names, addresses, email addresses, phone numbers, dates of birth, and bank account details. No passwords or identity documents were accessed. The Dutch Data Protection Authority has been notified. Basic-Fit operates over 1,300 clubs across seven European countries. Basic-Fit, Europe’s largest budget fitness chain by club count, has disclosed a data breach affecting […]

Read More

Paladin acquires ICT in €60M push to dominate European ITAD

In short: Paladin EnviroTech has acquired ICT, Ireland’s first R2v3-certified ITAD provider, completing a $70 million, nine-month acquisition spree that now spans the U.S., Netherlands, and Ireland, positioning the company to handle the growing wave of hardware disposal from Dublin’s hyperscale data centre cluster. When the servers that power Europe’s cloud infrastructure reach the end of […]

Read More

Nvidia-backed Firmus targets $2bn ASX IPO after locking in $505m equity and $10bn Blackstone debt for its AI factory network

In short: Australian AI data centre company Firmus has raised $505m at a $5.5bn valuation in what it says is its final pre-IPO round, and is now targeting a $2bn listing on the ASX in June or July, backed by a $10bn Blackstone-led debt facility secured in February and a plan to deploy 1.6 gigawatts of […]

Read More

Meta freezes AI data work after breach puts training secrets at risk

In short: Meta has suspended its collaboration with Mercor, a $10 billion AI data startup, after a supply chain attack exposed what may be the AI industry’s most closely guarded secrets: not just personal data, but the training methodologies that power the world’s leading large language models. The breach, carried out via a poisoned version of […]

Read More

WhatsApp just caught an Italian spyware firm building a fake version of its app for iPhones

WhatsApp has notified approximately 200 users, primarily in Italy, that they were tricked into installing a counterfeit version of the messaging app that was actually government spyware. The fake application was built by SIO, an Italian surveillance technology company that develops spyware for law enforcement and intelligence agencies through its subsidiary ASIGINT. WhatsApp said it […]

Read More

Hasbro has been hacked, and the maker of Peppa Pig says recovery could take weeks

Somewhere in Hasbro’s network, someone was where they should not have been. The $14.4 billion toy and entertainment conglomerate, owner of Peppa Pig, Transformers, Monopoly, Dungeons & Dragons, Nerf, Play-Doh, and Power Rangers ,disclosed on Wednesday that it had identified unauthorised access to its systems, an intrusion first detected on 28 March that has since […]

Read More

IRONSCALES brings AI email agents and threat intelligence series to RSAC 2026

The inbox has long been the softest entry point in enterprise security. As phishing campaigns grow more convincing, more personalised, and increasingly powered by generative AI, the tools designed to stop them have been locked in a reactive cycle: wait for the attack, analyse it, respond. IRONSCALES, the Atlanta-based email security vendor, is betting that […]

Read More

The passwordless future is years away. Here is what businesses should do now

Every year since roughly 2018, the cybersecurity industry has declared that passwords are dying. Passkeys, biometrics, and FIDO2 hardware tokens would replace them. The promise was elegant: no more breached vaults, no more credential stuffing, no more sticky notes on monitors. It has not happened. Not at scale, anyway. A March 2026 report from HYPR, […]

Read More