home.social

#hackincidents — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hackincidents, aggregated by home.social.

fetched live
  1. TechSpot: Microsoft is killing off SMS login codes, citing AI-powered hacking. “Sending codes to users via SMS has long been discredited as the least secure multi-factor authentication method, and Microsoft will soon discontinue support for this practice altogether. Citing the rising danger of hackers armed with AI tools, the company has now provided a timeline for phasing out SMS codes.”

    https://rbfirehose.com/2026/08/15/techspot-microsoft-is-killing-off-sms-login-codes-citing-ai-powered-hacking/
  2. Ars Technica: Terabytes of credentials leaked in massive supply-chain attack. “Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities […]

    https://rbfirehose.com/2026/08/14/ars-technica-terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
  3. TechSpot: FBI warns hackers are breaking into social media accounts to steal and sell users’ nude photos. “The FBI has issued a warning for anyone who likes to take explicit photos (i.e., nudes) of themselves. Hackers are targeting both adult and underage users by compromising their social media and personal accounts to steal these images and sell them on criminal marketplaces – and they […]

    https://rbfirehose.com/2026/08/14/techspot-fbi-warns-hackers-are-breaking-into-social-media-accounts-to-steal-and-sell-users-nude-photos/
  4. The Register: ‘Near-autonomous’ AI agents attack Taiwan’s nuclear safety agency. “Suspected Chinese cyber operatives used publicly available AI tools to compromise Taiwanese government systems before expanding the attack to its nuclear safety agency, supply-chain vendors, and at least seven energy companies in what security researchers called a ‘near-autonomous attack.'”

    https://rbfirehose.com/2026/08/13/the-register-near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/
  5. ABC News (Australia): AI assistant hacks gym website in first known Australian autonomous cyber attack. “Andrew asked his personal assistant to book him a spot in one of his gym’s coveted morning classes. … His AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software. Then it went further, […]

    https://rbfirehose.com/2026/08/10/ac-news-ai-assistant-hacks-gym-website-in-first-known-australian-autonomous-cyber-attack/
  6. The Register: Intrusion at US healthcare software provider puts 3.8M people’s data at risk. “A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year.”

    https://rbfirehose.com/2026/08/09/the-register-intrusion-at-us-healthcare-software-provider-puts-3-8m-peoples-data-at-risk/
  7. The Register: AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project. “The UK’s AI Security Institute has observed AI models performing what it calls ‘unsanctioned action’ 19 times during security tests. The Institute (AISI) revealed the incidents in a Tuesday post and technical report that details tests it conducted to see if AI models can […]

    https://rbfirehose.com/2026/08/06/the-register-ai-researchers-let-models-off-the-leash-then-watched-as-they-tried-to-add-malware-to-a-foss-project/
  8. Reuters: Liechtenstein says hackers access information on 31,000 legal entities. “Hackers have illegally accessed and ​copied data from Liechtenstein’s register of beneficial owners, ‌compromising information relating to about 31,000 companies, foundations and trusts, the principality’s government said late on Sunday.”

    https://rbfirehose.com/2026/08/04/reuters-liechtenstein-says-hackers-access-information-on-31000-legal-entities/
  9. Associated Press: FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems. “Michigan on Saturday joined Minnesota in reporting cyberattacks on nine of the state’s water systems but an official said all systems were operating ‘safely.’ Earlier this week, authorities said cyberattacks targeted over 30 water systems in Minnesota. The source of the attacks is […]

    https://rbfirehose.com/2026/08/03/associated-press-fbi-investigates-as-michigan-joins-minnesota-in-reporting-cyberattacks-on-its-water-systems/
  10. Associated Press: Anthropic says its AI models hacked 3 organizations during testing. “Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company.”

    https://rbfirehose.com/2026/08/02/associated-press-anthropic-says-its-ai-models-hacked-3-organizations-during-testing/
  11. New York Times: Bluesky Says Kremlin Is Hacking Its Platform to Spread Propaganda. This link goes to a gift article. “The campaign, which the researchers at Clemson linked to the Social Design Agency, a company in Moscow, shows how Russia continues to seek new ways to erode public support for Ukraine, which Russian forces invaded in 2022. Bluesky has grown more prominent as a rival platform to […]

    https://rbfirehose.com/2026/08/02/new-york-times-bluesky-says-kremlin-is-hacking-its-platform-to-spread-propaganda/
  12. Reuters: Minnesota IT officials disclose ‘coordinated cyberattack’ at more than 30 local water systems. “The attacks are similar ⁠to a wave of cyber intrusions against U.S. water infrastructure that officials have in the past attributed to ​Iranian-affiliated hackers, raising concerns about the vulnerability of local utilities that serve millions of people.”

    https://rbfirehose.com/2026/07/31/reuters-minnesota-it-officials-disclose-coordinated-cyberattack-at-more-than-30-local-water-systems/
  13. BBC: Ariana Grande sues hackers who leaked music and videos. “Pop star Ariana Grande has filed a lawsuit against two unidentified hackers who, she claims, leaked unreleased music and studio footage after gaining access to her collaborators’ computers.”

    https://rbfirehose.com/2026/07/29/bbc-ariana-grande-sues-hackers-who-leaked-music-and-videos/
  14. Reuters: Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week. “The OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn’t notice until well after the threat was contained and the FBI was alerted, according ​to people familiar with the investigation.”

    https://rbfirehose.com/2026/07/25/reuters-its-ai-agent-spent-days-hacking-a-company-but-sources-say-openai-did-not-notice-for-a-week/
  15. Reuters: Illinois man sentenced for hacking Snapchat accounts to steal nude photos. “Kyle Svara, 27, was sentenced by U.S. District Judge Brian Murphy in Boston to 76 months in prison after pleading guilty to charges arising out of an earlier prosecution of a ​former Northeastern University track-and-field coach who paid him to hack the accounts of ​student athletes and other women.”

    https://rbfirehose.com/2026/07/24/reuters-illinois-man-sentenced-for-hacking-snapchat-accounts-to-steal-nude-photos/
  16. Associated Press: OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company. “ChatGPT maker OpenAI said Tuesday that its artificial intelligence system hacked into another AI company on its own in what the company called an ‘unprecedented cyber incident.'”

    https://rbfirehose.com/2026/07/22/associated-press-openai-says-its-ai-technology-acted-on-its-own-in-an-unprecedented-hack-of-another-company/
  17. Korea Herald: Personal data of nearly all S. Korean diplomats may have been exposed in cyberattack. “The personal information of nearly all South Korean diplomats may have been exposed after hackers gained access to an online training system used by Foreign Ministry personnel and remained inside it for about 10 months, officials said Tuesday.”

    https://rbfirehose.com/2026/07/21/korea-herald-personal-data-of-nearly-all-s-korean-diplomats-may-have-been-exposed-in-cyberattack/
  18. TechCrunch: Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk. “Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.”

    https://rbfirehose.com/2026/07/21/techcrunch-hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/
  19. Hugging Face: Security incident disclosure — July 2026. “Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own.”

    https://rbfirehose.com/2026/07/19/hugging-face-security-incident-disclosure-july-2026/
  20. Engadget: A hacker accessed Suno source code that reportedly details how the company scraped millions of songs . “Suno — an app that vomits out soulless audio in the form of AI-generated ‘music’ — has been hacked. According to 404 Media, the hacker accessed data related to Suno’s training practices, as well as details on its customers.”

    https://rbfirehose.com/2026/07/16/engadget-a-hacker-accessed-suno-source-code-that-reportedly-details-how-the-company-scraped-millions-of-songs/
  21. The Register: EU and UK officially blame Russian spies for cyberattack on Poland’s power grid. “The UK and EU are demanding urgent action from critical infrastructure organizations after formally attributing the December 2025 cyberattack on Poland’s power grid to Russia’s Federal Security Service.”

    https://rbfirehose.com/2026/07/15/the-register-eu-and-uk-officially-blame-russian-spies-for-cyberattack-on-polands-power-grid/
  22. Engadget: Xbox gamer wins lawsuit against Microsoft to restore account and digital library. “A sole Xbox gamer has seemingly won an important judgement against Microsoft, which requires the tech giant to restore the user’s suspended Xbox account and accompanying video game library. In a post on Reddit, Ordo_Liberal said that a Brazilian court has ordered Microsoft to reverse its decision to […]

    https://rbfirehose.com/2026/07/15/engadget-xbox-gamer-wins-lawsuit-against-microsoft-to-restore-account-and-digital-library/
  23. The Register: Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert. “Data on more than 2.3 million people associated with Moody Bible Institute (MBI) has been exposed online after the Christian college was targeted by ShinyHunters. The attack was first disclosed by MBI in June, and the extortion crew later leaked the stolen data. Have I Been Pwned has since […]

    https://rbfirehose.com/2026/07/09/the-register-moody-bible-institute-breach-leaves-2-3m-accounts-needing-salvation-says-cyber-expert/
  24. Ars Technica: US offers $10 million for info on group behind Signal and WhatsApp hacking spree. “Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees.”

    https://rbfirehose.com/2026/06/30/ars-technica-us-offers-10-million-for-info-on-group-behind-signal-and-whatsapp-hacking-spree/
  25. Gizmodo: Hackers Steal Funds From Polymarket Users, Potentially Millions. “A third-party vendor has been compromised, and some Polymarket users have lost money to hackers, according to a tweet from the betting site. The company has not confirmed how much was lost, though independent monitors on X suggest it could be around $3 million.”

    https://rbfirehose.com/2026/06/28/gizmodo-hackers-steal-funds-from-polymarket-users-potentially-millions/
  26. Ars Technica: One-two punch delivered in global operation disrupts cybercrime “assembly line”. “International authorities and a raft of private technology companies say they have disrupted a cybercrime ‘assembly line’ that allowed crooks to collect millions of login credentials and steal more than $47 million in ransom payments and by other fraudulent means.”

    https://rbfirehose.com/2026/06/27/ars-technica-one-two-punch-delivered-in-global-operation-disrupts-cybercrime-assembly-line/
  27. BBC: How 100 hospitals switched to pen and paper to defeat a national cyber-attack. “Medical staff had to switch to pen and paper, improvising workarounds to protect patients while IT teams scrambled and the national cyber response centre tried to find out how the hackers had got in – and how they could stop them.”

    https://rbfirehose.com/2026/06/25/bbc-how-100-hospitals-switched-to-pen-and-paper-to-defeat-a-national-cyber-attack/
  28. Bleeping Computer: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.. “A newly discovered data leak dubbed ‘FortiBleed’ has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.”

    https://rbfirehose.com/2026/06/17/bleeping-computer-fortibleed-leak-exposes-fortinet-vpn-credentials-for-73000-devices/
  29. KOMO: Iran-linked hackers claim breach of CA water systems in Bakersfield, Visalia, Chico. “A reported cyber breach involving several California water systems has raised concerns about the security of critical infrastructure, though the water provider says there are no signs service has been disrupted. The breach happened last Thursday and involved systems connected to Bakersfield, Visalia and […]

    https://rbfirehose.com/2026/06/16/komo-iran-linked-hackers-claim-breach-of-ca-water-systems-in-bakersfield-visalia-chico/
  30. Politico: Hawkish GOP lawmaker Don Bacon says he was hacked by Russia. “Rep. Don Bacon (R-Neb.), a frequent critic of Russian leader Vladimir Putin and Moscow’s war in Ukraine, says his Signal messaging account was recently hacked by Russians.”

    https://rbfirehose.com/2026/06/13/politico-hawkish-gop-lawmaker-don-bacon-says-he-was-hacked-by-russia/