#cyberattack — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberattack, aggregated by home.social.
-
CSF_03: today’s Cybersecurity Friday post: the effective security of small business websites has likely gotten worse due to LLMs and “AI agents” (with or without safeguards) and what actions you may want to consider.
This article documents an instance of this problem:
* https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
Small business websites tend to be sloppily written (no pun intended though that may also be true) and are likely riddled with numerous very fundamental security holes. There are many possible explanations (economics) from poor initial construction, perhaps using the latest new trendy framework rather than established hardened libraries, to lack of maintenance after initial setup. They have obvious holes like lack of server-side form validation (people being able to change values in forms using browser dev tools), and less obvious like buggy APIs allowing more access than they should.
In the past, many of these holes didn’t really matter because those sites were “not worth attacking” for the incentive models of human-based cyber-attackers or collectives thereof.
However, now that there are LLMs that have likely been trained on any number of common security holes in websites (and how to exploit them), when an “AI agent” is given a task, it may very well use any “tool” at its disposal, including website vulnerabilities to accomplish its goals, as illustrated by the example in the Australia ABC news article above.
Since such chatbots are now essentially "hack websites as a service", I expect we will see LOTS more of this happening, likely unintentionally, or sometimes with mild intention like “can you get me higher on the waitlist”.
Ultimately I think both the human giving instructions to (prompting) such chatbots and the creators of such chatbots should be held responsible for any such intrusions and any damage they cause, even if/when unintended.
There are a few things you can do about this emerging phenomenon:
1. If you use such “agents”, be very careful about what you ask it/them to do, avoiding asking for anything that’s morally gray or questionable at all, even something as “minor” as cutting the line in an online waitlist.
2. If you run a small business site, you have your work cut out for you. Pay a professional web developer to audit the security of your website, document what they find, and patch holes / repair it accordingly.
3. If you have accounts on small business sites you rarely or ever use, consider exporting any data (receipts, transactions), replacing your profile details (name, addresses, photos) with noise, and then deleting your account. If you need to use the site again, use a different email address (as recommended in https://tantek.com/2025/122/b1/more-steps-indieweb-cybersecurity) to create a new account.
That last tip is also helpful for reducing your own personal “attack surface”. By pruning your online accounts, you both reduce the number potential data breaches that you’re in, and reduce the places and ways that attackers can cause you trouble (or that you have to double-check if you’re ever the target of a cyber-attack)
Previously: https://tantek.com/2025/122/b1/more-steps-indieweb-cybersecurity
#CyberSecurity #Friday #cyber #security #cyberAttack #cyberAttacker #chatBot #chatBots #LLM #LLMs #AI #agent #agents #AIagent #AIagents
#Blaugust #Blaugust2026 -
CSF_03: today’s Cybersecurity Friday post: the effective security of small business websites has likely gotten worse due to LLMs and “AI agents” (with or without safeguards) and what actions you may want to consider.
This article documents an instance of this problem:
* https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
Small business websites tend to be sloppily written (no pun intended though that may also be true) and are likely riddled with numerous very fundamental security holes. There are many possible explanations (economics) from poor initial construction, perhaps using the latest new trendy framework rather than established hardened libraries, to lack of maintenance after initial setup. They have obvious holes like lack of server-side form validation (people being able to change values in forms using browser dev tools), and less obvious like buggy APIs allowing more access than they should.
In the past, many of these holes didn’t really matter because those sites were “not worth attacking” for the incentive models of human-based cyber-attackers or collectives thereof.
However, now that there are LLMs that have likely been trained on any number of common security holes in websites (and how to exploit them), when an “AI agent” is given a task, it may very well use any “tool” at its disposal, including website vulnerabilities to accomplish its goals, as illustrated by the example in the Australia ABC news article above.
Since such chatbots are now essentially "hack websites as a service", I expect we will see LOTS more of this happening, likely unintentionally, or sometimes with mild intention like “can you get me higher on the waitlist”.
Ultimately I think both the human giving instructions to (prompting) such chatbots and the creators of such chatbots should be held responsible for any such intrusions and any damage they cause, even if/when unintended.
There are a few things you can do about this emerging phenomenon:
1. If you use such “agents”, be very careful about what you ask it/them to do, avoiding asking for anything that’s morally gray or questionable at all, even something as “minor” as cutting the line in an online waitlist.
2. If you run a small business site, you have your work cut out for you. Pay a professional web developer to audit the security of your website, document what they find, and patch holes / repair it accordingly.
3. If you have accounts on small business sites you rarely or ever use, consider exporting any data (receipts, transactions), replacing your profile details (name, addresses, photos) with noise, and then deleting your account. If you need to use the site again, use a different email address (as recommended in https://tantek.com/2025/122/b1/more-steps-indieweb-cybersecurity) to create a new account.
That last tip is also helpful for reducing your own personal “attack surface”. By pruning your online accounts, you both reduce the number potential data breaches that you’re in, and reduce the places and ways that attackers can cause you trouble (or that you have to double-check if you’re ever the target of a cyber-attack)
Previously: https://tantek.com/2025/122/b1/more-steps-indieweb-cybersecurity
#CyberSecurity #Friday #cyber #security #cyberAttack #cyberAttacker #chatBot #chatBots #LLM #LLMs #AI #agent #agents #AIagent #AIagents
#Blaugust #Blaugust2026 -
📢⚠️ Researchers found that AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, and stole over 2,500 personnel records in a four-day attack.
Listen/Read: https://hackread.com/ai-agents-compromise-taiwan-government-accounts/
-
📢⚠️ Researchers found that AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, and stole over 2,500 personnel records in a four-day attack.
Listen/Read: https://hackread.com/ai-agents-compromise-taiwan-government-accounts/
-
Suspected #China-linked hackers used #AI to run the first-ever end-to-end autonomous #cyberattack on #Taiwan's government
-
Suspected #China-linked hackers used #AI to run the first-ever end-to-end autonomous #cyberattack on #Taiwan's government
-
Dane osobowe prawie 19 milionów osób, w tym informacje medyczne, zostały naruszone w wyniku poważnego cyberataku na firmę świadczącą usługi dla tysięcy placówek medycznych w Polsce. https://linuxiarze.pl/wyciekly-dane-19-mln-polakow/ #cybersecurity #cyberattack #polska #zdrowie
-
Dane osobowe prawie 19 milionów osób, w tym informacje medyczne, zostały naruszone w wyniku poważnego cyberataku na firmę świadczącą usługi dla tysięcy placówek medycznych w Polsce. https://linuxiarze.pl/wyciekly-dane-19-mln-polakow/ #cybersecurity #cyberattack #polska #zdrowie
-
🔶 DATA BREACH ALERT
RingCentral - 1.6M accounts exposed
Compromised data:
Email Addresses, Names, Phone Numbers, Physical AddressesCheck if you're affected and what to do:
https://www.yazoul.net/breaches/breach/ringcentral-breach-1-6m-emails-names-phone-numbers-2026by Yazoul AI
-
AI agents ran a near-autonomous four-day attack on Taiwan's government, researchers say
Our best stories, delivered daily. Follow us.
https://1ban.news/ai-agents-autonomous-cyberattack-taiwan-2026/
-
27 potencjalnych ofiar w cztery dni. INTERPOL tropi e-pimping. Mroczna strona platform subskrypcyjnych. INTERPOL i sektor technologiczny uderzają w cyfrowy wyzysk. Cyberprzestępczość nie ogranicza się już do ataków ransomware, kradzieży danych czy oszustw finansowych. Zorganizowane grupy przestępcze coraz częściej... https://linuxiarze.pl/27-potencjalnych-ofiar-w-cztery-dni-interpol-tropi-e-pimping/ #cybersecurity #interpol #cyberattack
-
27 potencjalnych ofiar w cztery dni. INTERPOL tropi e-pimping. Mroczna strona platform subskrypcyjnych. INTERPOL i sektor technologiczny uderzają w cyfrowy wyzysk. Cyberprzestępczość nie ogranicza się już do ataków ransomware, kradzieży danych czy oszustw finansowych. Zorganizowane grupy przestępcze coraz częściej... https://linuxiarze.pl/27-potencjalnych-ofiar-w-cztery-dni-interpol-tropi-e-pimping/ #cybersecurity #interpol #cyberattack
-
Biały Dom uruchomił platformę do analizy cyberbezpieczeństwa „Gold Eagle”, która ma udostępniać i naprawiać luki w oprogramowaniu wykryte przez sztuczną inteligencję. https://linuxiarze.pl/bialy-dom-uruchomil-platforme-gold-eagle/ #sztucznainteligencja #cybersecurity #usa #cyberattack
-
Biały Dom uruchomił platformę do analizy cyberbezpieczeństwa „Gold Eagle”, która ma udostępniać i naprawiać luki w oprogramowaniu wykryte przez sztuczną inteligencję. https://linuxiarze.pl/bialy-dom-uruchomil-platforme-gold-eagle/ #sztucznainteligencja #cybersecurity #usa #cyberattack
-
DATE: August 12, 2026 at 06:24PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#Ransomware Attack Disables #Canadian Hospital's Doors, #HVAC: Experts: Incident Underscores OT Risks in #Healthcare Environments https://t.co/8uzCYjaZSb #HSCWinnipeg #SharedHealth #cyberattack
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: August 12, 2026 at 06:24PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#Ransomware Attack Disables #Canadian Hospital's Doors, #HVAC: Experts: Incident Underscores OT Risks in #Healthcare Environments https://t.co/8uzCYjaZSb #HSCWinnipeg #SharedHealth #cyberattack
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
This was posted yesterday, if you missed it.
CloudSek: 2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026 https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines @cloudsek
More:
Security Week: https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/ @SecurityWeek #infosec #supplychain #cyberattack
-
This was posted yesterday, if you missed it.
CloudSek: 2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026 https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines @cloudsek
More:
Security Week: https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/ @SecurityWeek #infosec #supplychain #cyberattack
-
📰 AI-Powered Cyberattacks Hit Major US Corporations in 2026
A surge of AI-powered cyberattacks has hit major US companies in 2026, including Nike, Coca-Cola & Wynn Resorts. Attackers are enhancing ransomware & phishing, causing massive data breaches & operational shutdowns. #AI #CyberAttack #Ransomware
-
📰 AI-Powered Cyberattacks Hit Major US Corporations in 2026
A surge of AI-powered cyberattacks has hit major US companies in 2026, including Nike, Coca-Cola & Wynn Resorts. Attackers are enhancing ransomware & phishing, causing massive data breaches & operational shutdowns. #AI #CyberAttack #Ransomware
-
📰 Polish Power Plant Breached via Private Cellular APN Network
A novel attack on a Polish power plant used a private cellular APN to pivot into the OT network. Attackers, linked to Russia's FSB, used default PLC credentials to shut down a steam turbine. #ICS #OT #CyberAttack #CriticalInfrastructure #Poland
-
New.
Sophos: ClickFix campaign abuses Deno runtime for infostealer delivery https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery @SophosXOps #infosec #cyberattack #threatresearch #ClickFix
-
New.
Sophos: ClickFix campaign abuses Deno runtime for infostealer delivery https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery @SophosXOps #infosec #cyberattack #threatresearch #ClickFix
-
New.
Kaspersky: Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/ @Kaspersky #infosec #threatresearch #Windows #cyberattack
-
New.
Kaspersky: Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/ @Kaspersky #infosec #threatresearch #Windows #cyberattack
-
"The attack has affected 911 call routing, police and fire dispatch, records and City services."
The city posted an update yesterday: https://www.suisun.com/Community/20260807Cybersecurity-Incident-Updates
Infosecurity-Magazine: Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks https://www.infosecurity-magazine.com/news/suisan-cyber-incident-government/ #cyberattack #infosec
-
"The attack has affected 911 call routing, police and fire dispatch, records and City services."
The city posted an update yesterday: https://www.suisun.com/Community/20260807Cybersecurity-Incident-Updates
Infosecurity-Magazine: Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks https://www.infosecurity-magazine.com/news/suisan-cyber-incident-government/ #cyberattack #infosec
-
#SuisunCity Council declares state of emergency after #cyberattack
https://www.nbcbayarea.com/news/local/suisun-city-state-of-emergency-cyberattack/4125654/
#California #cybersecurity #911 #infrastructure #safety #Suisun
-
#SuisunCity Council declares state of emergency after #cyberattack
https://www.nbcbayarea.com/news/local/suisun-city-state-of-emergency-cyberattack/4125654/
#California #cybersecurity #911 #infrastructure #safety #Suisun
-
Iran wykorzystał luki w zabezpieczeniach sieci komórkowych, aby zlokalizować wojsko USA na Bliskim Wschodzie. Rząd Iranu wykorzystał System Sygnalizacji 7, w skrócie SS7, zestaw protokołów dla sieci 2G i 3G, który od dawna stanowi podstawę połączeń między sieciami komórkowymi... https://linuxiarze.pl/iran-wykorzystal-luki-w-zabezpieczeniach-sieci-komorkowych-aby-zlokalizowac-wojsko-usa-na-bliskim-wschodzie/ #cybersecurity #cyberattack #smartphone #android #ios #usa #iran
-
Iran wykorzystał luki w zabezpieczeniach sieci komórkowych, aby zlokalizować wojsko USA na Bliskim Wschodzie. Rząd Iranu wykorzystał System Sygnalizacji 7, w skrócie SS7, zestaw protokołów dla sieci 2G i 3G, który od dawna stanowi podstawę połączeń między sieciami komórkowymi... https://linuxiarze.pl/iran-wykorzystal-luki-w-zabezpieczeniach-sieci-komorkowych-aby-zlokalizowac-wojsko-usa-na-bliskim-wschodzie/ #cybersecurity #cyberattack #smartphone #android #ios #usa #iran
-
Suisun City in Solano County shuts down city government after #cyberattack. https://www.kqed.org/news/12094482/suisun-city-declares-state-of-emergency-after-cyberattack
-
Suisun City in Solano County shuts down city government after #cyberattack. https://www.kqed.org/news/12094482/suisun-city-declares-state-of-emergency-after-cyberattack
-
Suisun City in Solano County shuts down city government after #cyberattack. https://www.kqed.org/news/12094482/suisun-city-declares-state-of-emergency-after-cyberattack
-
Suisun City in Solano County shuts down city government after #cyberattack. https://www.kqed.org/news/12094482/suisun-city-declares-state-of-emergency-after-cyberattack
-
#gPWN: #Wiretapping #Fiber #ISP Deployments From the Comfort of Your Home
source: gpwn.io
GPON is the fiber-to-home protocol that carries traffic for hundreds of millions of subscribers worldwide (and climbing). It operates on a threat model that makes several assumptions that break in the real world.
We'll chat about how it's possible to become a modern day fiber optic voyeur with hardware that costs about $100 and watch your neighbor's DNS, SIP calls and most-
-excitingly, GTP-tunneled 4G/5G traffic from the cellular towers that you share a fiber line with.
#hack #hacking #cybersecurity #cyberattack #surveillance #privacy #internet #fail #threat #traffic #FiberOpticCable #fiberoptics #fiberoptic #problem #security #news #mobile #Wiretap #5g #4g
gPWN -
📰 Suisun City, CA Declares Emergency After Cyberattack on 911
Suisun City, CA declares a state of emergency after a cyberattack disabled its IT network, impacting 911 routing and public safety dispatch. Federal investigation underway. #Cyberattack #SuisunCity #911 #EmergencyServices
-
🔶 DATA BREACH ALERT
Alcon - 218K accounts exposed
Compromised data:
Email Addresses, Names, Phone Numbers, Physical AddressesCheck if you're affected and what to do:
https://www.yazoul.net/breaches/breach/alcon-breach-218k-contacts-exposed-in-extortion-2026by Yazoul AI
-
🔎 Curso de OSINT - Open Source Intelligence 2026 📅 Miércoles 12, Viernes 14, Miércoles 19 y Viernes 21 de Agosto 🕖 De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌐 Información: https://www.reydes.com/archivos/cursos/Curso_OSINT_Open_Source_Intelligence.pdf #osint #infosec #threatintel #socmint #cybersecurity #geoint #cyberattack #databreach -
To quote the great Cap'n Mal: it's a real burden being right all the time.
#Iran #iranwar #cyberattack #infrastructure #infrastructureattacks #ifyourenotreadygetready #nooneiscomingtosaveus
https://www.cbsnews.com/news/more-states-water-systems-cyberattacks-iran-backed-hackers/
-
To quote the great Cap'n Mal: it's a real burden being right all the time.
#Iran #iranwar #cyberattack #infrastructure #infrastructureattacks #ifyourenotreadygetready #nooneiscomingtosaveus
https://www.cbsnews.com/news/more-states-water-systems-cyberattacks-iran-backed-hackers/
-
#LeviStrauss & Co. says hackers stole corporate data in #cyberattack
-
#NorthCarolina Ports confirms #cyberattack disrupting operations
#cybersecurity #PortAuthority #NCPA #Wilmington #MoreheadCity #Charlotte
-
Nowe złośliwe oprogramowanie dla systemu Android może potajemnie opróżnić Twoje konta bankowe.Naukowcy odkryli nowe złośliwe oprogramowanie, które uzyskuje głęboki dostęp do telefonu i uzyskuje... https://linuxiarze.pl/nowe-zlosliwe-oprogramowanie-dla-systemu-android-moze-potajemnie-oproznic-twoje-konta-bankowe/ #cybersecurity #cyberattack #spartphone #android
-
Nie zatrzymasz zagrożenia, którego nie widać. Dlaczego integracja IT i OT staje się nowym wyzwaniem dla cyberbezpieczeństwa? Cyfrowa transformacja przedsiębiorstw coraz częściej wykracza poza biura i centra danych. Do firmowych sieci podłączane są linie produkcyjne... https://linuxiarze.pl/nie-zatrzymasz-zagrozenia-ktorego-nie-widac/ #cybersecurity #cyberattack #sztucznainteligencja