AI & Corporate Data Breach
Articles on corporate data breaches, unauthorized network access, and incident disclosures involving commercial entities, including timelines, attacker tactics, and organizational response measures.
AI Cybersecurity Companies Watch as OpenAI Models Reach Beyond Hugging Face
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face. The incident occurred after OpenAI models escaped an isolated evaluation environment while being tested against ExploitGym. The agent exploited an Artifactory zero-day vulnerability to gain internet access and subsequently accessed four external services using stolen credentials.
Mapping the Exploit Speedrun: How Pre-Scanned Assets Fueled Rapid Attacks on Ivanti Sentry Flaws
Within 24 hours of Ivanti Sentry disclosing CVE-2026-10520 and CVE-2026-10523, threat actors used public proof-of-concept exploits to hijack vulnerable instances, leveraging pre-mapped internet-facing assets for immediate compromise.