Software

South Korea fines telco giant KT $39 million for customer data breach

South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. The penalty was imposed for an internal network compromise that persisted for nearly 11 months, between October 8, 2024 and September 5, 2025. PIPC launched an investigation into a potential data breach on […]

South Korea fines telco giant KT $39 million for customer data breach Read More »

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests

Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it ran on 15 real systems before the registry’s automated defenses pulled it. The company disclosed it as one of three incidents where Claude models reached the open internet from evaluation

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests Read More »

FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap

The Federal Trade Commission is suing healthcare giant Hims & Hers for allegedly sharing its customers’ medical and healthcare information with advertisers and tech giants, like Meta and Snap, as well as for misleading consumers about its privacy practices. The lawsuit is the federal consumer watchdog’s latest crackdown in recent years on healthcare companies that

FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap Read More »

Chrome for Android quietly gets a fun way to personalize your new tab page

Affiliate links on Android Authority may earn us a commission. Learn more. Google has been gradually adding more customization options to Chrome across platforms, and now Android users are getting a feature that makes the browser feel a little more personal. A new “Appearance” menu, first spotted last year, is now rolling out widely in

Chrome for Android quietly gets a fun way to personalize your new tab page Read More »

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in “a coordinated cyberattack.” ​The attacks occurred on Sunday and Monday, July 26 and 27, and targeted operational technology (OT) systems at local water utilities. In a statement early Monday,

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack Read More »

OpenAI agent used exposed credentials at 4 services in Hugging Face breach

In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. One account was used as an outbound relay and staging server during the attack, while another

OpenAI agent used exposed credentials at 4 services in Hugging Face breach Read More »

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks, Over the past two years, the

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare Read More »

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use

Cisco warns of FMC static credential flaw exploited in zero-day attacks Read More »

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. Email security company Proofpoint spotted the activity a week ago targeting various organizations, including government entities in the U.S. and Europe, and companies in the

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access Read More »