Daily Recap, Hugging Face reported that an autonomous AI agent contributed to a breach exposing internal datasets and credentials, while Ernst & Young disclosed a data breach impacting personal and financial information. In exploited-vulnerability news, attackers are leveraging critical ServiceNow code execution flaws, WP2Shell WordPress issues, and a new 7-Zip flaw involving XZ archives, alongside updates including Microsoft’s KB5121767 for affected Dell PCs and Chrome 150 patches for severe memory-safety bugs.
#HuggingFace #ErnstAndYoung #ServiceNow #WP2Shell #7Zip #XZ #KB5121767 #Dell #ViPNet #AI_SOC
#HuggingFace #ErnstAndYoung #ServiceNow #WP2Shell #7Zip #XZ #KB5121767 #Dell #ViPNet #AI_SOC
AI & Data Breaches
- Hugging Face says an autonomous AI agent helped expose internal datasets and credentials in a breach at the world’s largest AI model repository – AI Breach, Hugging Face
- Ernst & Young disclosed a data breach affecting personal and financial information, while a new index is tracking major breaches without tallying total losses – EY Breach, Breach Index
Exploited Vulnerabilities
- A critical ServiceNow code execution flaw is now being exploited in attacks, raising urgent patching concerns – ServiceNow RCE
- WP2Shell WordPress vulnerabilities are being exploited in the wild, increasing risk for exposed sites – WP2Shell
- A new 7-Zip vulnerability could let crafted XZ archives run code during extraction – 7-Zip Flaw
Vendor Patches
- Microsoft confirmed WSUS sync delays and released KB5121767 to fix shutdowns affecting some Dell PCs – WSUS Delays, Windows Fix
- Chrome 150 patches severe memory safety bugs in the browser – Chrome Update
Threat Activity
- Hackers are abusing ViPNet software to target Russian government agencies – ViPNet Abuse
AI Security
- A new guide helps security leaders evaluate AI SOC tools and adoption risks for modern security operations – AI SOC Guide