Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. Continue reading Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

OpenAI Models Escaped Test Environment and Breached Hugging Face

OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers. Continue reading OpenAI Models Escaped Test Environment and Breached Hugging Face

Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure

An AI-led cyberattack breached limited Hugging Face datasets and service credentials, while public models, Spaces and published packages showed no signs of tampering. Continue reading Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure