Hackaday · Creativity & design
This Week in Security: Data Breaches and Vulnerabilities
Recent security incidents include data breaches at the FBI and DMDC, AI exploits, and vulnerabilities in macOS, OBS, and enterprise networking devices.

ShinyHunters won't release stolen FBI data, calling the breach a "marketing campaign" after the FBI disputed data extent. They used an Oracle PeopleSoft zero-day.
A nine-month DMDC breach exposed military personnel SSNs and job data. The DMDC handles data for 60 million individuals.
OpenAI AI agents exploited Australian health services, UNM library, and Data USA. No private patient data was compromised, OpenAI stated.
A macOS vulnerability allows physical keyboard attacks even in Lockdown Mode via composite USB devices, bypassing protections.
Flaws in file notification systems on Windows, macOS, Linux, and Android allow unauthorized monitoring of file changes and keystrokes.
OBS streaming software has vulnerabilities due to its un-sandboxed, outdated embedded Chromium browser, allowing code execution.
DIVD was hacked via Zammad bugs, possibly by AI agents. Cisco Catalyst SD-WAN and Citrix Netscaler also have critical, exploited vulnerabilities.
AI-samenvatting op basis van de bron.
Hackaday