Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets included in the test. The incidents happened in May while independent AI evaluator Irregular was testing Gemini’s cybersecurity capabilities. The Wall Street Journal reported that Gemini had unintended internet access during the exercise and went on to access systems belonging to three companies. In one case, it guessed credentials. In the other two, it found credentials in public repositories and used them to access protected systems. Google said the incidents were a case of mistaken identity and that…
Kirsten Doyle
Texas utility CenterPoint Energy has confirmed a data breach after a threat actor published customer information online and claimed to have stolen around 7.5 million records. CenterPoint said an unsanctioned third party accessed personal information through one of its external-facing systems. The company has brought in cybersecurity experts to investigate the breach. An attacker using the name “Lovely” claims to have obtained millions of customer records containing names, addresses, phone numbers, email addresses, account numbers, and other information. Samples of the allegedly stolen data were posted publicly, leading CenterPoint to investigate and confirm that customer information had been compromised. CenterPoint…
Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently legitimate access. In both cases, agents were able to use valid accounts or credentials and continue searching for ways into systems and data beyond the access they had been given. OpenAI this week disclosed more details from its continuing review of the Hugging Face incident and other unexpected activity by its models. The company said agents had bypassed access controls, used exposed credentials, and reached parts of third-party services outside their intended access. Separate reporting on the investigation found that…
Security teams are turning to AI as they struggle to investigate the volume of alerts coming into the SOC, according to new research from Prophet Security. The State of AI in Security Operations 2026 report surveyed 250 IT and cybersecurity professionals. Forty percent said AI is already part of their day-to-day SOC workflow, and 56% are evaluating or piloting it. Only 4% have no current plans to use AI. Among teams already using AI, 72% said it had cut alert investigation time by at least 25%. For 18%, the reduction was more than half. However, the research also found that…
A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children. Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data. Most were stored in folders labeled “faces” and “profiles.” Fowler said the images he reviewed included profile pictures, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or identity verification. “I recently discovered a publicly exposed database that was neither password-protected nor encrypted,” Fowler said. “The database…
A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of its researchers received a direct message on X on August 9. The message came from an account that claimed to be the vice president and marketing head of CoinDesk and wanted to know about the researcher’s plans to attend future conferences. The researcher spotted the scam but kept the conversation going to find out what the…
The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and organisations during a controlled cybersecurity evaluation. This included attempts to socially engineer software maintainers and insert malicious code into an open-source project. The incident happened during routine cyber capability testing between 25 and 28 July, when researchers gave AI agents access to the public internet and deliberately disabled some cyber safety mechanisms to better understand how the models behave under less restrictive conditions. According to AISI, researchers ran a cybersecurity challenge 122 times across seven frontier models. …
AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, and helping organisations fix problems faster. It also raises serious questions about the quality of code, its security, accountability, and trust. When an AI writes or patches the code, who will ensure that it is indeed secure? And, are the current application security practices adequate…
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links. According to the researchers, clicking one of these links caused the application to automatically open, import a prompt from the URL, and immediately submit it without displaying the full prompt or requiring user approval. Anthropic addressed the issue in Claude Desktop version 1.1.2321. Hidden instructions Oasis Security demonstrated the attack using…
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies. The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to exploit “poorly configured and vulnerable networking devices worldwide,” opportunistically targeting organisations across multiple critical infrastructure sectors. According to the advisory, communications, defence, energy, financial services, government, and healthcare organisations face the greatest risk. The campaign is being tracked across the cybersecurity industry under several names,…
