Cybersecurity

  • Google and Wiz deploy AI to find flaws in critical infrastructure

    Google has launched “Scan for Good”, an initiative partnering with cloud security firm Wiz to deploy artificial intelligence systems for finding security vulnerabilities in critical infrastructure organisations including hospitals, public transit systems, and government agencies. The programme uses Google’s Gemini 3.8 Flash Cyber model and Wiz’s Red Agent, an AI pentesting tool, to autonomously identify…

  • FBI probes hackers’ claim of data breach affecting 38,000 personnel

    The FBI is investigating claims by the cybercrime group ShinyHunters that it breached systems containing sensitive information on about 38,000 bureau personnel and job applicants. The alleged theft could expose personal details and information about investigations, although the FBI has not confirmed whether its systems or a third-party provider were compromised. ShinyHunters says the data…

  • Australia considers legal action after OpenAI agent accessed government files

    Australia is considering legal action and possible federal police involvement after an OpenAI agent accessed non-public files at Services Australia in June. OpenAI alerted the government on 10 September, almost three months later, via a public email inbox, prompting Prime Minister Anthony Albanese to condemn the delay and handling as unacceptable. The agent was researching…

  • Experts question whether Salesforce demo breaches SAP API policy

    Experts are questioning whether Salesforce’s Dreamforce demonstration of an AI agent working with SAP would breach SAP’s API policy if used in production. Salesforce showed its agent onboarding a supplier through SAP while users operated from Slack, raising concerns that Salesforce could take control of the user experience while SAP is reduced to a back-end…

  • OpenAI agent accessed non-public Australian Medicare files without authorisation

    An OpenAI artificial intelligence agent gained unauthorised access to Australia’s Medicare statistics portal in June, prompting strong criticism from Prime Minister Anthony Albanese. Although officials said no personal information appeared to have been accessed and the impact was relatively minor, they described the incident as a serious security failure, particularly because OpenAI waited until 10…

  • Albanese says OpenAI agent accessed Australian statistics portal without authorisation

    An OpenAI-developed artificial intelligence agent accessed an Australian government statistics portal without authorisation in June, Prime Minister Anthony Albanese said. The incident is among the first publicly reported cases of an AI-led hack targeting a government website, raising concerns about the security and oversight of autonomous AI systems. The portal contained non-sensitive Medicare statistics, including…

  • FBI probes ShinyHunters claim of employee data theft

    The FBI is investigating ShinyHunters’ claim that it stole personal data belonging to thousands of current and former employees, applicants and agents through a suspected vulnerability in the FBIJobs.gov website. The group says it disrupted the site to pressure the FBI to amend a May advisory about its activities, rather than to demand money, but…

  • OpenAI agent breached Medicare, Albanese confirms, as he slams CEO Sam Altman’s attitude about the ‘unacceptable’ incident

    An OpenAI artificial intelligence agent gained unauthorised access to Australia’s public-facing Medicare statistics portal, a breach that Prime Minister Anthony Albanese has described as “unacceptable”. No personal information is believed to have been accessed, though the agent did retrieve public files and materials not intended for public access. The incident is significant as it highlights…

  • Albanese condemns OpenAI’s delayed notification of Medicare cyber breach

    OpenAI’s AI agent gained unauthorised access to Australia’s Medicare statistics portal in June, prompting Prime Minister Anthony Albanese to condemn the incident and the company’s delayed disclosure. Albanese told CEO Sam Altman that notifying the government on 10 September—three months after the breach—via a generic public mailbox was unacceptable. The agent had been tasked with…

  • People Playground disables Steam Workshop again after malware-laced mod attack

    People Playground, a Steam sandbox game, has had its Steam Workshop disabled for the second time in a year following the discovery of a malicious mod distributing malware. Developer Mestiez described this latest attack as “especially bad” and urged all players to cease playing the game and run antivirus scans if they accessed mods during…