U.S. biotech giant Amgen confirms July hack, and says proprietary data, patients' health data, and other information was exfiltrated from its cloud environments (Amgen runs largely on AWS). Amgen says volume & types of data stolen "could be sensitive." Amgen says it serves 17 million patients. 🫠
Профиль
Zack Whittaker
Профиль VivelySecurity editor, TechCrunch Signal: zackwhittaker.1337 My stories: techcrunch.com/author/zack-whittaker My newsletter/blog: this.weekinsecurity.com
A reader of my newsletter this.weekinsecurity.com emailed in to ask about how the use of AI chatbots and LLMs can get disclosed in court, even when used for legal defense. It raises important questions about where a user's data goes once it's submitted to an AI chatbot, and who has access to it.
Keen to see if any of the companies that were hacked by OpenAI or Anthropic will sue them. Someone has to take responsibility for this, and the blame is almost entirely on the leaders of these AI companies. Alternatively, hacking is just legal now until a court says otherwise? What a fucking mess.
Daragh Ó BriainSorry: they only did reviews to see if their software had unlawfully and without authorisation accessed networks of third parties? This wasn’t a defined control *during* their “testing”? This is extreme negligence at least. cyberscoop.com/anthropic-cl...
CareCloud, which stores patients' medical records for 45,000+ hospitals & healthcare providers across the U.S., has begun notifying hundreds of thousands of people that their data was stolen in a March breach. That number is expected to rise. Bypass for ad-blockers: web.archive.org/web/20260730...
The U.S. FTC has sued Hims & Hers, which prescribes for sexual wellness and mental health conditions, alleging the company shared customers' sensitive medical data with advertising giants Meta and Snap through hidden website pixels. Bypass for ad-blockers: web.archive.org/web/20260730...
Really appreciate @brianhonan.bsky.social sharing in his newsletter my guide on how to read a data breach notification, and how to parse the bullshit, even when there's very little disclosed. I wrote this for my paying subscribers following years of work investigating & reporting on data breaches.
Over on Mastodon (I strongly recommend), @doublepulsar.com asked fellow defenders what's on their radars and how much of what they're actively dealing with is AI-related. The responses are overwhelmingly, no. ClickFix attacks and phone calls/social engineering remain among the top threats.
Kevin Beaumont (@GossiTheDog@cyberplace.social)Sense check for people working in cybersecurity in operations roles in the trenches: I’m not finding or seeing cyber incidents off the back of Generative AI still. Are you? Not ones you’ve read about...cyberplace.socialIn today's this.weekinsecurity.com: OpenAI admits to hacking Hugging Face, millions of cars with hidden alarms vulnerable to hacking, Iran's hacking water and energy systems, Russia's targeting nuclear scientists with an email zero-day, a healthcare hack sparks data theft fears, and much more.
This has been a busy (and wild!) week in cybersecurity, but keeping up can be a challenge. Every Sunday, I wrap up the most pressing and important cyber news you need to know and more in my free weekly newsletter this.weekinsecurity.com so you can stay ahead. Oh, and cats. 🐈⬛ Sign up and find out!
Incredibly detailed reporting by @raphae.li et al at Reuters on the OpenAI hack of Hugging Face, revealing new details on how it went down and how it took a week for OpenAI to notice one of its AI models was hacking into the company, citing multiple sources.
New, by me: The Justice Department is prosecuting an American for allegedly providing U.S. border agents with a "duress" passcode that wiped the contents of his phone when they entered it. We've confirmed the phone was running GrapheneOS. Bypass for ad-blockers: web.archive.org/web/20260724...
U.S. says Iranian hackers are upping their hacks on American water and energy providers to "cause disruptive effects within the United States." FBI, NSA & CISA say the critical infrastructure breaches are in response to the Iran war (no shit). Bypass for ad-blockers: web.archive.org/web/20260723...
Justice Department is dropping the subpoenas served on several NYT reporters seeking the identities of their sources into the Qatari-donated plane that Trump now uses. The subpoenas were an obvious attempt to squash reporting into Trump's corruption.
Inner City Press3:11 pm Buckley: The Government is prepared unilaterally to withdraw the subpoenas at this time. If under Gonzalez we find it appropriate to seek new subpoenas, we'll come to the court. Judge: Moving forward, we would have the issues that have plagued it so far