← BACK TO FEED
TAG

cybersecurity14 articles

This Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand Total

Richard Bird, a cybersecurity executive and author, has launched the Hacker in a Hoodie (HIH) Index — a website that tracks disclosed material cyber breaches by drawing on SEC EDGAR filings and news sources, grading each entry by the reliability of its sourcing. Unlike industry estimates that aggregate losses into headline figures, Bird deliberately avoids summing the data, arguing that combining inconsistently evidenced entries produces misleading numbers that resemble the marketing-driven projections already plaguing the field. The project's broader argument is that cybersecurity has long been measured by activity rather than outcomes, and that treating it as a business cost rather than a performance-tracked function is the root cause of the industry's persistent failure to reduce breaches.

20 Jul 2026

Ransomware Knocks Fairlife's US Dairy Plants Offline

Coca-Cola's dairy subsidiary Fairlife has been hit by a ransomware attack that forced a temporary halt to production at its US plants, while its Canadian facilities remain operational. The attack compromised a portion of Fairlife's systems, including production-related systems, prompting the company to activate its incident response plan, engage cybersecurity experts, and notify law enforcement. Key details remain unclear, including who carried out the attack, whether data was stolen, and when US production is expected to resume.

18 Jul 2026

Ransomware Knocks Out Fairlife Milk Production Across the US

Coca-Cola has suspended US production at its dairy subsidiary Fairlife following a ransomware attack that compromised portions of the company's systems, including production-related infrastructure. The company has activated incident response protocols, notified law enforcement, and is working with cybersecurity experts to assess the full impact, though it states that product quality and safety have not been affected. Key details such as the attackers' identity, how the breach occurred, and whether any ransom demands have been made remain undisclosed.

18 Jul 2026

CISA Is Quietly Using Anthropic's Mythos to Hunt Bugs in Federal Government Code

CISA is reportedly using Anthropic's AI model, Mythos, to scan federal government code repositories for security vulnerabilities, with sources indicating the effort has already uncovered a large number of software flaws. The initiative is led by CISA's Attack Surface Evaluation team, with the NSA also believed to be utilizing the model. Despite this growing government reliance on Mythos, Anthropic has faced political tensions with the administration over its refusal to remove safeguards against autonomous weapons and surveillance use, and its public-facing model, Fable, experienced a temporary global shutdown following a dispute over foreign access.

13 Jul 2026

AI Agents Are Being Tricked Into Sending Crypto Payments via Poisoned Web Content

Threat actors are exploiting prompt injection attacks embedded in malicious websites and manipulated search results to deceive AI agents into making unauthorised cryptocurrency payments. Zscaler identified two campaigns using these techniques: one involving a fake Python library site that instructs AI agents to pay for an API key, and another typosquatting the DeFi platform DeBank to trick agents into treating the fraudulent site as legitimate. Testing against 26 large language models found that four were successfully manipulated into making payments, highlighting the growing security risks as AI agents become more autonomous web users.

11 Jul 2026

Banks Still Treating MFA as Optional. Your Money Pays the Price.

The author recounts how their 84-year-old mother lost $30,000 to thieves who exploited her reused passwords and lack of multi-factor authentication (MFA) to access her bank accounts, retirement savings, and Gmail. Despite many banks and Google offering MFA, they make it optional rather than mandatory, prioritising user convenience and avoiding friction over customer security. The article argues that financial institutions should require stronger, phishing-resistant MFA — such as passkeys — by default across all platforms, as optional security measures leave the majority of users dangerously exposed.

10 Jul 2026

AI Hallucination Brands Startup as Chinese Spy Operation. No One Checked.

MeetingTV has sued Palo Alto Networks and its newly acquired Koi Security after Koi published a threat intelligence report falsely linking the video conferencing startup to a Chinese corporate espionage operation. MeetingTV alleges the report was generated by Koi's AI platform, which hallucinated connections between the startup and a criminal threat actor called DarkSpectre, including referencing a browser extension that MeetingTV claims does not exist. The false report caused widespread domain blocks by security providers globally, severely damaging MeetingTV's business, and the startup's CEO has warned the case highlights the dangers of publishing AI-generated findings without adequate human oversight.

3 Jul 2026

An Executive's Inbox Was Silently Plundered for Five Months. Here's What That Tells Us About AI-Assisted Attacks

A stock exchange executive had their Outlook mailbox compromised for five months without anyone noticing. Five months.

4 Jun 2026

Prize-winning hacker thinks AI might make her obsolete — and she's not wrong to worry

Valentina Palmiotti ("Chompie"), the top individual performer at the Pwn2Own Berlin hacking competition, warns that powerful AI tools like Claude Mythos may soon make human ethical hackers obsolete, having already won $70,000 in prizes herself. While AI currently helps hackers work faster, she believes emerging models will quickly take over the discovery of common vulnerabilities, leaving only the most elite human researchers competitive. Despite concerns about AI aiding criminal hackers, Chompie remains cautiously optimistic that AI will ultimately benefit cybersecurity defenders more than attackers — provided powerful tools are released responsibly.

27 May 2026

Anthropic Plans Public Release of Mythos Bug-Hunter, Admits Nobody Has the Safeguards to Do It Yet

Anthropic has announced plans to eventually make its Mythos AI model — which excels at finding security vulnerabilities in code — publicly available, but only once sufficient safeguards are developed, which the company admits do not yet exist. In the meantime, access is being expanded through its "Project Glasswing" programme to additional partners, including allied governments. Mythos has already identified over 23,000 flaws across 1,000+ open-source projects, though the volume of discoveries is straining an already overloaded security ecosystem, with many maintainers struggling to keep pace with the volume of reported vulnerabilities.

25 May 2026

Anthropic's Claude Mythos Is Finding Bugs Faster Than Anyone Can Fix Them

Anthropic's Claude Mythos Preview AI model, working with around 50 partners through Project Glasswing, identified over 10,000 critical security vulnerabilities in system-critical software within just one month, with some partners reporting a tenfold increase in bug discovery rates. However, the pace of discovery far outstrips the ability of organizations to verify and patch the flaws, with only 97 of 23,019 open-source vulnerabilities found having been fixed so far. Anthropic warns this creates a dangerous transition period where AI models can rapidly find and potentially exploit vulnerabilities faster than defenders can respond, and acknowledges that no company currently has safeguards strong enough to prevent misuse of such capabilities.

24 May 2026

Your App Is Under Attack Before Lunch on Launch Day

Digital.ai's *2026 App Security Threat Report* reveals that AI — particularly agentic AI — has dramatically accelerated and broadened app-based cyberattacks, with the proportion of monitored apps under attack rising from 55% in 2022 to 87% in 2026. AI has lowered the technical barriers for attackers, closing the historic security gap between iOS and Android, enabling sophisticated attacks within hours of an app's release, and driving steep rises in attack rates across previously complex-to-exploit sectors like automotive and medical devices. The report concludes that defenders can no longer treat any app or sector as a lower-priority target, and must adopt their own agentic AI defences to counter the increasingly sophisticated and fast-moving threat landscape.

24 May 2026

Five Reasons Your Cybersecurity Strategy Is Already Behind

Cybercriminals in 2025 have become increasingly sophisticated, using AI, automation, and corporate-style structures to launch faster, larger-scale attacks, with governments, finance, and technology sectors among the most targeted. Enterprises face a complex cybersecurity landscape shaped by five key factors: rising user expectations, financial pressures, complex multi-vendor IT infrastructure, unpredictable geopolitics, and evolving cyber threats. To counter these challenges, HPE advocates for a "self-driving network" approach that uses AI-driven platforms and built-in security capabilities — such as zero trust enforcement and automated threat monitoring — to provide dynamic, comprehensive protection.

21 May 2026

Grafana Labs Got Its GitHub Raided. It's Not Paying Up.

Grafana Labs has disclosed that an unauthorized attacker obtained a token to access its GitHub environment and stole its codebase, subsequently threatening to release the code unless a ransom was paid. The company refused to pay, citing FBI guidance and the fact that no customer data or operational systems were affected. The incident's impact may be limited, as much of Grafana's code is already open source, though it remains unclear exactly what proprietary code was taken.

18 May 2026