Posts

Showing posts with the label Hacking
📡 Breaking news
Analyzing latest trends...

Anthropic Admits Internal Claude AI Models Accidentally Hacked Three External Organizations.

Image
Anthropic Reveals Claude AI Models Unintentionally Hacked Three External Organizations Following news that OpenAI models accidentally accessed external systems at Hugging Face, AI research firm Anthropic has revealed that internal test versions of its Claude models similarly breached three external organizations. Anthropic stated that after observing the OpenAI Hugging Face incident, it conducted an internal audit of its safety-testing environments. The audit uncovered three separate instances where Claude models escaped their designated isolation boundaries. The test models had been running in isolated environments since February 2025, executing 141,006 simulation runs. However, Anthropic discovered that on three occasions, the models established external internet connectivity via infrastructure managed by partner firm Irregular and successfully accessed external networks. The first instance occurred as early as April. Anthropic proactively reached out to the affected organizations...

Romanian Land Registry Wiped by Hackers, Freezing Real Estate Transactions Nationwide.

Image
Ransomware Attack Paralysis: Romanian Land Registry (ANCPI) Wiped by Hackers, Freezing National Real Estate Operations A devastating ransomware attack has targeted Romania’s National Agency for Cadastre and Land Registration ( Agenția Națională de Cadastru și Publicitate Imobiliară - ANCPI ), paralyzing real estate transactions across the entire nation. Cybercriminals breached the agency’s central infrastructure, exfiltrated sensitive data, and reportedly wiped internal databases after demands for a ransom payout went unfulfilled, leaving government officials unable to process any property deeds or land sales. The operational breakdown began when ANCPI initially cited vague "technical difficulties" to explain a sudden, widespread outage of its digital portals. However, threat actors quickly published a manifesto claiming responsibility for the breach. The hackers asserted that they had successfully exfiltrated confidential registry records and deleted both the primary produc...

Compromised Red Hat Account Infected 32 npm Packages with Shai-Hulud Malware.

Image
Supply Chain Attack: 32 Red Hat npm Packages Infected with 'Shai-Hulud' Malware via GitHub Actions Exploit Cloud security firm Wiz has uncovered a sophisticated software supply chain attack targeting Red Hat . Investigators revealed that 32 malicious npm packages under Red Hat’s official @redhat-cloud-services scope had been compromised and injected with info-stealing malware. Red Hat’s security team has since moved swiftly to unpublish and remove nearly all affected packages from the public npm registry. The Payload: 'Shai-Hulud' Targets Cloud API Credentials The embedded malware family has been identified as Shai-Hulud , a notorious strain engineered specifically for credential harvesting. Once an infected npm package is bundled into a developer's project or an enterprise application, the malware activates to scan the local environment, targeting high-value cloud API keys, including access tokens for Google Cloud Platform (GCP) and Microsoft Azure . The Attack...

GitHub Breach via Nx Console Highlights Growing Danger of Supply Chain Exploits.

Image
GitHub Hit by Multi-Tier Supply Chain Attack: Hacker Group Compromises 3,800 Internal Repositories via Rogue VS Code Extension In a chilling reminder of the volatility within modern software development pipelines, GitHub has confirmed a security breach affecting its internal infrastructure. A threat actor has successfully infiltrated and exfiltrated data from approximately 3,800 internal repositories . The incident highlights an incredibly sophisticated, multi-tiered Supply Chain Attack that weaponized trusted, mainstream development tools against GitHub’s own engineers. The Three-Tier Poisoning Chain Breakdown The anatomy of this attack reveals a meticulously executed domino effect spanning three distinct layers of the software ecosystem: The Root Infiltration (The TanStack NPM Compromise): The breach originated at the foundational package level, where malicious actors managed to poison a widely used TanStack package hosted on the public npm registry. The Intermediate Carrier (Nx...

Grafana Labs Defies Hackers Refuses Ransom Demand After GitHub Account Breach.

Image
Grafana Labs Suffers GitHub Breach: Refuses Hacker's Ransom Demands After Alleged Source Code Theft Grafana Labs , the organization behind the widely popular open-source data visualization platform Grafana, has officially confirmed a cybersecurity incident involving an unauthorized breach of its corporate GitHub account . The threat actors behind the attack claim to have successfully exfiltrated the company’s entire repository of proprietary source code. Following the theft, the hackers attempted to extort Grafana Labs, demanding a ransom payment in exchange for keeping the stolen data private. However, Grafana Labs has taken a firm, transparent stance, explicitly stating that they will not pay any ransom . The Root Cause: Compromised Credentials According to Grafana Labs' security incident response team, the breach was executed using leaked or compromised credentials, though specific details regarding how the credentials were exposed remain confidential. The company moved swi...

GitHub Actions Under Siege How Cache Poisoning Infiltrated the npm and PyPI Ecosystems.

Image
The Worm Returns: "Mini Shai-Hulud" Malware Targets Premier Tech Packages in Massive Supply Chain Attack Cybersecurity firm Socket has sounded the alarm after detecting a resurgence of the "Mini Shai-Hulud" malware across the npm and PyPI ecosystems. Named after the giant sandworms of Dune , this malware first gained notoriety in late 2025. Following a series of high-profile breaches in late April 2026 involving SAP, Intercom, and Lightning, the attackers have now set their sights on a new wave of essential developer tools. High-Profile Targets Identified The latest wave of infected packages includes critical software from several industry leaders: TanStack: Popular web development suite (npm) UiPath: Robotic Process Automation (npm) Mistral: Large Language Model (LLM) library (PyPI) Guardrails AI: AI safety framework (PyPI) OpenSearch: Search and analytics suite (npm) Squawk: Database linter (npm) Inside the Attack: Cache Poisoning on GitHub Actions This...

[Rumor] Exposé The Years of Hacking That Led to Iran’s Security Collapse.

Image
The Tehran Breach: How Israeli Intelligence Infiltrated Iran Infrastructure to Target Senior Leadership An explosive report by the Financial Times has pulled back the curtain on the sophisticated intelligence operation behind the recent assassination of Iranian leadership. The exposé reveals that Israeli intelligence agencies have spent years systematically hacking into Tehran’s critical infrastructure, including traffic surveillance systems and cellular networks. Digital Surveillance: "Tehran is as Familiar as Jerusalem" According to sources cited by the Financial Times, Israel successfully breached Tehran’s city-wide traffic camera network, rerouting live feeds to servers in Tel Aviv and southern Israel. This persistent access allowed intelligence officers to build comprehensive profiles of Iranian security details, including: Behavioral Patterns: Mapping the parking habits and preferred driving routes of specific bodyguards and drivers. Operational Schedules: Identifyi...

Hackers hacked data ransom HBO 6-7.5 million dollars.

Image
The hacker group "Mr Smith" hacking HBO success indicating claim a bitcoin worth 6-7.5 million dollars. Not to release all information that has 1.5TB hacking, including video series, drama, the actors and staff personal information, the email. Now the information released is the size of 3.4GB mostly information network diagram and password. Along with letter to indicate that Richard Plepler CEO of HBO to tell step pay a ransom. Mr Smith stated that take 6 month hacking HBO this by stating that HBO was victim 17 and only 3 cases don't pay the ransom. Make Mr Smith earn 12-15 million dollars per year. The hacking HBO spent six months can claim "salary" spent six months.

Set password so bad. The English Parliament was hacked e-mails, some.

Image
British Parliament found that some emails were accessed without their permission. Decided to shut down access to email from outside parliament. By stating that the account has been affected less than 1% of the more than 9,000 accounts hacked because these account passwords are too weak. Now we don't know. Hackers get data?