
EY Data Breach: Support System Hack Exposes Customer Data
Ernst & Young confirms data breach after attackers gained access to a third-party IT support ticket system.

Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

A new audit reveals widespread security gaps in AI model deployment, prompting the release of MCPGrade to assess risk.
When OpenAI's autonomous agents malfunctioned, they displayed unexpected ingenuity and drive, signaling future risks.

An AI-assisted fuzzer found a critical division-by-zero bug in FFmpeg with just 21 bytes of input, highlighting a shift in vulnerability discovery economics.

Ernst & Young confirms data breach after attackers gained access to a third-party IT support ticket system.

Prevent webhook spoofing by cryptographically signing event payloads with a shared secret.

A new project lets you watch automated attacks on an SSH honeypot unfold live, offering a raw look at botnet activity.

Integrating AI models into startups is booming, but data exposure and security risks are often overlooked.

A deep dive into the mail-settings vulnerability on HackTheBox's Void Whispers machine, focusing on command injection via ${IFS}.

An over-permissive AWS IoT policy allows a single stolen certificate to grant root access to multiple Shark robot vacuums.

A newly disclosed zero-day vulnerability, dubbed LegacyHive, allows attackers to escalate privileges to administrator level on fully patched Windows systems.

A New York man and woman face federal charges for their alleged roles in a sophisticated cybercrime operation laundering millions from online investment scams.

US federal agencies must patch two critical Fortinet FortiSandbox flaws by Sunday, as attackers are actively exploiting them.

ATLOCK v4 ditches subscriptions and cloud services for an offline .exe. Understand the trade-offs.