Tag

Unauthorized Access

All articles tagged with #unauthorized access

Anthropic probes unauthorized access to its Mythos cyber tool
technology1 month ago

Anthropic probes unauthorized access to its Mythos cyber tool

Anthropic says it is investigating reports of unauthorized access to its Claude Mythos cybersecurity model, allegedly gained via a third-party vendor portal and online sleuthing; the group reportedly targeted testing rather than malicious use, and Mythos Preview was limited to trusted partners and praised for identifying vulnerabilities, prompting ongoing debate about AI-enabled cyber threats as DoD risk designations and demand from banks and government agencies persist.

Anthropic's Mythos AI falls into unauthorized hands, fueling weaponization fears
technology1 month ago

Anthropic's Mythos AI falls into unauthorized hands, fueling weaponization fears

Anthropic says Claude Mythos Preview, a powerful cybersecurity AI capable of identifying and exploiting vulnerabilities, was accessed by a small, unauthorized group via a third‑party vendor. The attackers, tied to a private Discord channel and reportedly using data from a Mercor breach to locate the model, have demonstrated Mythos with screenshots and a live demo, and reportedly not for cybersecurity to avoid detection. Access to Mythos is restricted to a handful of firms under Project Glasswing (including Nvidia, Google, AWS, Apple, Microsoft) with governments eyeing the tech. Anthropic is investigating and says there’s no evidence of impact on its systems; the company has no plans to publicly release Mythos due to weaponization concerns.

Unknown Group Allegedly Accesses Claude Mythos, Anthropic Investigates Security Hole
artificial-intelligence1 month ago

Unknown Group Allegedly Accesses Claude Mythos, Anthropic Investigates Security Hole

Anthropic says an unknown group accessed Claude Mythos—an unreleased, highly restricted model—via a third‑party vendor environment. Bloomberg reports, citing a live demo and screenshots, that the group used data from a Mercor breach and other intel to pinpoint Mythos and has been experimenting with it since April 7. The group claims no malicious intent, but Anthropic is investigating the breach and the security hole remains a concern.

"15,000+ Roku Accounts Compromised: What You Should Do"
technology2 years ago

"15,000+ Roku Accounts Compromised: What You Should Do"

More than 15,000 Roku accounts were compromised in a data breach, with hackers gaining access to stored financial information and attempting to purchase streaming subscriptions using stolen credentials. The breach was likely due to hackers finding credentials exposed in other company data breaches. While sensitive personal information was not accessed, affected customers were urged to reset their passwords and review their account activity for any fraudulent charges.

"Roku Data Breach: 15,000 Accounts Compromised and Sold Online"
cybersecurity2 years ago

"Roku Data Breach: 15,000 Accounts Compromised and Sold Online"

Hackers breached over 15,000 Roku accounts by obtaining login details from third-party sources, then used the data to subscribe to streaming services. The breach occurred between Dec. 28 and Feb. 21, with the company becoming aware of it between Jan. 4 and Feb. 21. While sensitive personal information was not accessed, the hackers attempted to sign up for paid streaming subscriptions in some cases. Roku has taken steps to secure the affected accounts, cancel unauthorized subscriptions, and refund any unauthorized charges, and is actively monitoring for suspicious activity.

"Roku Data Breach: 15,000 Accounts Hijacked for Unauthorized Purchases"
technology2 years ago

"Roku Data Breach: 15,000 Accounts Hijacked for Unauthorized Purchases"

Roku disclosed a breach affecting over 15,000 streaming accounts, with unauthorized individuals attempting to purchase subscriptions using stolen credentials. The company secured the affected accounts and investigated unauthorized activity, assuring users that sensitive personal information was not accessed. Roku recommended affected users reset their passwords and provided guidance on creating secure passwords, emphasizing their commitment to privacy and security.

"Vendor Data Breach Exposes American Express Credit Cards"
cybersecurity2 years ago

"Vendor Data Breach Exposes American Express Credit Cards"

American Express warns customers of a data breach at one of its service providers, potentially exposing credit card account numbers, names, and expiration dates. The breach impacted an undisclosed number of customers, and the company is working to notify affected individuals and regulatory authorities. American Express reassures customers that they will not be held responsible for fraudulent charges and advises them to monitor their accounts for suspicious activity, enable instant notifications, and consider requesting a new card number if their information was stolen.

"Recall Issued for 120K Biometric Gun Safes Over Serious Injury Risk"
safety-recall2 years ago

"Recall Issued for 120K Biometric Gun Safes Over Serious Injury Risk"

More than 120,000 biometric gun safes from Bulldog Cases, Machir, MouTec, and Awesafe have been recalled due to faulty biometric systems that may allow unauthorized access, posing a risk of serious injury or death. Consumers are advised to stop using the biometric feature, remove the batteries, and use the key for storing firearms until they receive a free replacement safe or repair kit from the respective companies.

Google Workspace's Design Flaw Exposes Organizations to Unauthorized Access
data-security-data-breach2 years ago

Google Workspace's Design Flaw Exposes Organizations to Unauthorized Access

Cybersecurity researchers have discovered a "severe design flaw" in Google Workspace's domain-wide delegation feature that could be exploited by attackers to gain unauthorized access to Workspace APIs without super admin privileges. The flaw, codenamed DeleFriend, allows threat actors to manipulate existing delegations in the Google Cloud Platform and Google Workspace. By creating numerous JSON web tokens, attackers can pinpoint successful combinations of private key pairs and authorized OAuth scopes, enabling them to perform API calls on behalf of other identities in the domain. Successful exploitation of the flaw could result in the theft of emails, data exfiltration, and unauthorized actions within Google Workspace APIs.

GBI Releases Full Report on Coffee Co. Investigation
politics2 years ago

GBI Releases Full Report on Coffee Co. Investigation

The Georgia Bureau of Investigation (GBI) has completed its 13-month investigation into allegations of unauthorized access to voting equipment in Coffee County, Georgia. The investigation was prompted by a breach in January 2021, where a computer forensics team allegedly handled, scanned, and copied the state's voting software and equipment without lawful authority. The GBI report, which has been released in full, focuses on individuals physically present during the breach and does not analyze how the findings align with criminal laws or recommend pursuing charges. Two individuals charged in a separate criminal probe related to the breach have recently pleaded guilty to unauthorized access to voting systems. The report also reveals that multiple third parties accessed the copied data after the breach occurred.

Massive Gun Safe Recall Issued Following Tragic Shooting Fatality
consumer-safety2 years ago

Massive Gun Safe Recall Issued Following Tragic Shooting Fatality

The U.S. Consumer Product Safety Commission has recalled over 60,000 biometric gun safes due to a programming flaw that can allow unauthorized access. At least one person has died, and there have been 39 incidents of unauthorized access reported. Consumers are advised to stop using the biometric feature, remove batteries, and use the key instead. The recalled safes were sold under various brand names and were available at multiple retailers nationwide.

Massive Recall of 60,000 Gun Safes Following Tragic Child Fatality
safety2 years ago

Massive Recall of 60,000 Gun Safes Following Tragic Child Fatality

Over 60,000 biometric gun safes manufactured by Fortress Safe are being recalled due to concerns of unauthorized access, with at least 39 reported breaches. The recall comes after a lawsuit alleged that a 12-year-old boy died from a firearm obtained from a breached safe. The safes, sold under various brand names including Fortress, Cabela's, and Gettysburg, were found to have a default open mode that can allow unauthorized users, including children, to access the safe. Consumers are advised to stop using the biometric feature, remove the batteries, and rely on the key for recalled safes used to store guns.