Security Point Break
Online/Digital
Cybersecurity news and analysis with clarity, candor, and human intelligence. Source
Actions
Media Outlet details
| Scope | Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesAnthropic’s Claude Breach: Containment Failure or PR Play?
Three of Anthropic’s most advanced Claude models breached the real-world systems of three outside organizations during internal cybersecurity testing, the company disclosed Thursday. It was the second frontier AI lab in nine days to reveal that its models compromised production infrastructure while being evaluated for safety.
NVIDIA’s Answer to the Hugging Face Breach: Open Secure AI Alliance
Following OpenAI’s breach of Hugging Face, the debate over AI security has often centered on whether open or closed models are inherently safer. NVIDIA’s launch of the Open Secure AI Alliance suggests the industry is finally asking a more important question. How do we actually secure AI systems as they become embedded in enterprise environments?
Russia vs. Telegram: What’s Behind the Durov Terrorism Charge
Russia’s FSB has charged Telegram founder Pavel Durov with aiding terrorism and issued an international arrest warrant, placing him on a wanted list. Durov, who lives in Dubai, has not been detained. The FSB’s statement, announced Wednesday, July 29, accuses Telegram’s administration of failing to remove channels, chats and bots hosted on the platform’s servers. It alleges Telegram is being used by Ukrainian intelligence services and extremist organizations to coordinate attacks inside Russia.
Cyberattack Hits 30+ Minnesota Water Systems
More than 30 Minnesota water systems were targeted in a coordinated cyberattack Sunday and Monday, disrupting automated controls and briefly knocking one city’s water treatment plant offline. Minnesota IT Services said the attacks targeted technology used by community water systems July 26 and 27. Four communities — Braham, Plymouth, South St. Paul and Maple Plain — have publicly disclosed incidents. Drinking water remained safe, and officials have issued no boil-water advisories.
LogoKit Builds Phishing Pages Around Each Victim
LogoKit, a phishing kit that generates fake login pages, is using victims’ email addresses to build customized corporate login pages in real time, according to new research from Barracuda. The attack starts with a phishing link containing the victim’s email address. Code on the fake page reads the email domain to identify the victim’s employer, then pulls in the organization’s logo and a screenshot of its legitimate website.
OpenAI’s Rogue Test Agent Hacked a Second Company, Modal Labs Confirms
An autonomous OpenAI agent that broke containment during an internal security test this month didn’t stop at Hugging Face. Modal Labs, a New York cloud platform for AI workloads, confirmed Tuesday that the same agent compromised one of its customers during the same campaign. The disclosure shows the incident reached further than either company first let on.
Facebook Rolls Out Real-Person Verification Badge
Meta began rolling out Facebook Verified last week, a free badge intended to confirm that a real person, rather than an AI-generated or fake account, is behind a Facebook profile, according to Meta’s newsroom post. The verification process requires users to record a short video selfie, which Meta checks against existing profile photos to confirm a match. The company says the process typically takes a few minutes and carries no subscription fee.
Nvidia, CrowdStrike, 30+ Firms Launch Open Secure AI Alliance
Nvidia and more than 30 technology, cybersecurity and enterprise software companies launched the Open Secure AI Alliance on Monday, a coalition built around sharing open-source AI models and security tooling among defenders. The stated mission is to “promote responsible use of and trust in AI”, according Nvidia.
ChatGPT Agents Could Allow CSRF Attack Chaos: Here’s How
A flaw in the way ChatGPT handled Workspace Agents could have allowed for serious cross-site request forgery attacks. According to researcher Mike Takahashi of Zenity Labs, a flaw dubbed AgentForger could allow for the creation of ChatGPT agents that are able to harvest account credentials and spy on users across multiple accounts with persistence. Zenity demonstrated the attack scenario in a post Thursday showing the forged agent’s post-exploitation reach.
Google’s Fix for Account Recovery Will Cost You Your Face
Google’s answer to the nagging problem of account recovery is allowing you to record a short selfie video and use it as a fallback sign-in method. It’s the virtual equivalent of a spare hidden key for when a passkey or trusted device isn’t nearby. On Thursday it rolled out what it calls selfie video. Setup takes a few minutes. Look at the camera, follow a handful of guided head movements – chin up, look at the ceiling, back to center.