Water system cyberattacks widen as Trump rejects suspected Iran link
OpenAI finds additional AI agents escaped containment, Rogue AI hacks raise unprecedented liability questions, DeepSeek launches industry's cheapest frontier AI model, UK agency exposes officials' data in internal security lapse, Leaked database reveals China's surveillance of foreigners, much more
Don't miss my latest CSO piece that examines why cybersecurity fundamentals are more important than ever in the AI era.
Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
Metacurity delivers
- Full archive access — every newsletter and AI Watch round-up, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
Cyberattacks targeting water and wastewater systems have spread to at least seven US states, causing loss of water pressure, flooding and other operational disruptions as federal investigators examine evidence pointing toward Iran-linked hackers.
No government agency has formally attributed the campaign to Iran, and investigators have cautioned that the inquiry remains preliminary. But current and former officials reportedly regard Iran as the leading suspect, placing the attacks within the widening cyber dimensions of the five-month-old US-Israeli war with Tehran.
Donald Trump has publicly rejected that assessment, blaming Minnesota — one of the first states to identify and report the activity — rather than a foreign adversary.
“We heard in Minnesota there was a cyberattack, and they blame it on Iran. I don’t think so,” Trump told reporters Friday during a Cabinet meeting at Camp David. “I think I blame it on Minnesota because they’re grossly incompetent.”
Trump did not explain how Minnesota could have caused the intrusions or identify another suspected perpetrator. The White House declined to elaborate on his comments, according to Reuters.
Minnesota Gov. Tim Walz responded that Trump “knows exactly who is responsible for this attack, and knows that other states were hit too,” describing the incidents as an example of modern warfare.
The dispute over attribution has unfolded as the attacks have grown into a major national and international news story. The New York Times reported that federal officials privately continued to view Iran as the most likely culprit after Trump’s denial. Reuters, Canadian media and Israeli outlets have also closely followed the attacks and their possible relationship to the broader conflict with Iran.
Israeli authorities, meanwhile, have said they recently thwarted separate Iranian cyberattacks against Israeli targets. The reported activity does not establish that Iran conducted the US water attacks, but it adds to concerns that cyber operations are becoming an increasingly visible front in the war.
The FBI and Environmental Protection Agency said in a July 30 advisory that water and wastewater utilities in at least seven states had reported incidents since July 27. Some of the activity “degraded water operations,” the agencies said.
The attackers remotely accessed internet-facing Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers, or PLCs. They changed device IP addresses and passwords, causing utilities to lose monitoring and control capabilities.
Reported effects included loss of water pressure and flooding. A drop in pressure can create a public-health risk by allowing untreated groundwater to seep into water pipes, although officials have reported no evidence that drinking water was deliberately contaminated.
The operational consequences varied according to what each compromised controller managed, whether it monitored or directly controlled equipment, and whether the utility could shift to manual operations.
At least one victim found altered PLC project files after identifying discrepancies in the ladder logic used to control industrial processes. The FBI also warned that similarities in network configurations installed by third-party providers could allow attackers to repeat the same technique across multiple customers.
Minnesota officials previously reported suspicious activity affecting roughly three dozen municipalities. Michigan subsequently confirmed incidents at nine municipal water systems. State officials said the affected systems continued to operate safely and that no known incident created a public-health threat.
The expanding scope suggests that the attackers may have scanned broadly for exposed equipment rather than selecting individual communities for their strategic importance. That approach makes virtually any utility using a vulnerable, publicly accessible controller a potential target.
The apparent mismatch between the geopolitical stakes and the affected communities is central to the problem, former Cybersecurity and Infrastructure Security Agency Director Jen Easterly argued in a New York Times guest essay published Sunday.
The attacks may represent nation-state behavior arising from an international war, but their immediate consequences are being managed by mayors, municipal employees and small water utilities with limited money, personnel and cybersecurity expertise. In effect, the United States is confronting a geopolitical national-security threat through thousands of local organizations that were never designed or funded to defend against foreign intelligence services or their proxies.
“For all the attention devoted to an AI-powered cyberpocalypse, one of the biggest cyber stories this week is far less futuristic,” Easterly wrote in introducing her essay.
The technology involved reinforces her point. The attackers did not need an autonomous artificial-intelligence weapon or a previously unknown vulnerability. They found industrial controllers directly exposed to the internet and changed their configurations.
The FBI and EPA urged utilities to remove PLCs from direct internet exposure, place remote connections behind securely configured gateways and firewalls, strengthen passwords, restrict communications through access-control lists and retain the ability to run water systems manually.
The agencies also recommended that utilities review PLC project files for unauthorized changes, inspect connected modems and workstations for evidence of lateral movement, and replace or isolate equipment that its manufacturer no longer supports.
Those measures are well-established security practices, but implementing them can be difficult for small communities.
Nate George, mayor of Braham, Minnesota, one of the affected cities, said officials had received instructions for patching and defending their systems. But he warned that the attack exposed the rudimentary infrastructure and financial limitations of many small municipalities.
“IT infrastructure upgrades are very costly, and we are a very small municipality,” George said.
New York on Sunday announced $5.4 million in grants to help 151 municipalities improve the cybersecurity of drinking water and wastewater systems. Long Island communities will receive most of the money, including more than $3 million for municipalities in Nassau County and nearly $1 million for those in Suffolk County.
The grants will support security assessments, implementation work and compliance with new state minimum cybersecurity standards. New York officials said the timing underscored the urgency created by the multistate attacks, although the grants are not a direct response to a known compromise of the recipients.
A separate incident in Saint-Noël, Quebec, illustrates the international appeal of poorly protected municipal systems. A group called Z-Pentest Alliance posted a video showing hackers accessing the computer interface of the community’s drinking-water plant and adjusting chlorine settings.
The plant entered a safe mode, and local officials said the water remained safe. Canadian and US authorities have associated Z-Pentest Alliance with pro-Russian hacktivist activity, not the suspected Iranian campaign in the United States.
The Quebec intrusion nevertheless reflects the same structural weakness: Small municipal utilities can give politically motivated hackers a way to demonstrate reach, generate publicity and produce physical effects without penetrating a heavily defended national institution.
Whether the US campaign is ultimately attributed to Iran, the incidents show how an international confrontation can reach directly into local infrastructure. The attackers may operate in service of a nation’s geopolitical objectives, but the first line of defense may be a municipal employee in a town of a few hundred residents.
Trump’s denial does not resolve the attribution question. Nor does the preliminary evidence establish Iran’s responsibility beyond doubt. What is already clear is that an adversary has discovered a repeatable way to interfere with essential American services — and that the communities expected to stop it are among the least equipped institutions in the country to confront a foreign cyber campaign. (Dustin Volz and Ernesto Londoño / New York Times, Steve Holland and A.J. Vicens / Reuters, FBI, i24, Jen Easertly / New York Times, Janon Fisher and Joshua Needelman / Newsday, Paula Dayan-Perez / CBC News)
Related: Hacker News, CBS News, CyberScoop, Politico, Greensburg Tribune-Review, Forbes, PolitiFact, One America News Network, Associated Press, New York Times, Fox News, The Hill, Washington Times, RedState, The Independent, PoliticusUSA, ABC17NEWS, Straight Arrow, Daily Mail, MS NOW, CBS News, Washington Examiner, Bloomberg, WCVB, Newsweek, TechRadar, The New York Sun, Firstpost, CNN, The Washington Post, The Daily Star, The Detroit News, WSB, Detroit Free Press, Wall Street Journal, NBC News, KHQ-TV, Tech Times, InformationWeek, The Cyber Express, Slashdot, New York Times, Butler Eagle, Time, Dayton Daily News
AI Update: Rogue agents, legal scrutiny and cheaper models reshape AI landscape
Just weeks after OpenAI disclosed that one of its autonomous AI agents escaped a testing environment and hacked AI platform Hugging Face, the company has uncovered additional instances in which AI agents breached containment during internal testing, broadening concerns over how well frontier AI systems can be controlled.
The newly discovered incidents were confined to OpenAI's own network and were far less serious than the original Hugging Face breach, but they suggest the July incident was not an isolated anomaly. The findings emerged as OpenAI expanded its investigation into the original attack, which also compromised accounts at several other companies before the activity was detected.
The revelations come as Anthropic disclosed that three of its own AI models also escaped intended testing boundaries and accessed external organizations during cybersecurity evaluations, underscoring that containment failures may represent an industry-wide challenge rather than a problem unique to one developer.
The incidents have also triggered a broader legal debate over responsibility when autonomous AI systems commit actions that would be illegal if carried out by humans. In an analysis published by Wired, legal scholars said existing US law offers no clear answer to who should bear liability when an AI agent independently conducts unauthorized computer intrusions.
While criminal liability may be difficult to establish absent evidence of recklessness, experts said civil claims based on negligence or product liability could become increasingly likely as similar incidents occur. The discussion is shifting from whether AI agents can autonomously hack systems to what legal obligations companies have to prevent them from doing so.
The questions surrounding AI safety arrive as competition among foundation model developers continues to intensify. Chinese startup DeepSeek has released a new model that research firm Artificial Analysis found to be by far the least expensive frontier model to operate among well-known competitors.
The dramatically lower inference costs could accelerate enterprise adoption of agentic AI while increasing pressure on rivals including OpenAI, Anthropic and Google to reduce prices or improve performance.
Lower operating costs may also make it economically feasible to deploy larger numbers of autonomous agents, adding urgency to efforts to strengthen governance and containment mechanisms. (Lily Hay Newman / Wired, Eduardo Baptista / Reuters, Deepa Seetharaman and Raphael Satter / Reuters)
Related: Digital Trends, The Economic Times, DigiTimes, Forbes, Axios, CTech, The Indian Express, The International News, Finimize, Startup Fortune, The Neuron, Business Standard, Futurism, Don't Worry About the Vase, The Economic Times, Digital Trends, Japan Times
UK Government Investments (UKGI), the agency that manages the taxpayers’ interest in a swathe of companies including Channel 4 and the Post Office, said the security failure also left more than 50 government officials’ personal details exposed for nearly 40 hours.
The state body, best known for managing government holdings in bailed-out lenders Royal Bank of Scotland and Lloyds after the 2008 financial crisis, blamed the breach on an unnamed staff member who it said failed to follow security rules.
“An internal file containing high-level management information and the names and work email addresses of 51 government officials was publicly accessible for [about] 40 hours, following the actions of a member of staff who did not follow established information security policies,” UKGI said in its annual report.
It stopped short of divulging the date of the security failure but said it had been identified within the past financial year, after which it was escalated to board members and also to the UK’s information watchdog, the Information Commissioner’s Office.
Bosses also hired external experts to review security protocols, who suggested the body “strengthen our controls and incident preparedness." (Kalyeena Makortoff / The Guardian)
Related: UKGI, Bedrock News, NewsBytes, Security Affairs
Marc Hofer, a cybersecurity researcher and journalist based in Amsterdam, discovered a massive database called “Dynamic Control Platform for Overseas Personnel, a futuristic dashboard — like something from the movie “Minority Report” — that appeared to track foreigners in the northern Chinese city of Zhangjiakou, a popular skiing spot that co-hosted the 2022 Winter Olympics.
He was floored. “Whoever put that stuff in there had access to real data,” he recalled. He also noticed a list of users who had recently logged into the site — it included the names of police stations in Zhangjiakou and other cities.
The database Mr. Hofer found offered a rare window into how extensively the Chinese authorities also surveil foreigners, displaying entries about people categorized by nationality, with their birth date, sex, marital status, address and occupation, and sometimes their religion.
It also included instances when they were captured on camera at traffic intersections, markets, shopping malls or other locations, including a mosque.
Chinese companies hoping to sell their surveillance platforms to the police often create demo web pages that use photos and information about people taken from social media. This was different, Mr. Hofer said: “This is more than some guys playing around, or a student, or a low-level project.”
That day, in January, he began downloading as much data as possible from the site. By May, it had been taken offline. (Lily Kuo and Pei-Lin Wu / New York Times)
Related: NetAskari, NetAskari, r/AskAChinese, r/worldnews, r/China, r/neoliberal

Apple has restricted the number of potentially dangerous software bugs researchers can submit to its internal security team, as it faces a deluge of reports from people using AI models to identify alleged risks.
The tech giant said it had moved in June to limit the high volume of requests it was receiving, with its review system coming under pressure from “AI slop” reports that can hallucinate security risks in its software.
Apple is grappling with an industry-wide phenomenon that has resulted in generative AI software tools transforming the cybersecurity arms race, with an increase in the detection of real security flaws and a wave of poor-quality submissions from amateur bug hunters using AI, the company said. (Tom Wilson and Michael Acton / Financial Times)
Related: iPhone in Canada, The Decoder, Digital Trends
The full names and contact details of more than 100,000 police staff have been leaked on the dark web in a hack which has put officers at “serious risk."
Cyber criminals compromised data from the Ministry of Defence, the Home Office, National Crime Agency (NCA) and Crown Prosecution Service (CPS), The Times reported.
It follows a hack on the Department for Education (DfE) last week, which had led to more than half a million pieces of data being compromised.
Hackers leaked officers’ force location after breaching the police national legal database (PNLD), an online resource used by all Home Office police forces in the UK to provide legal assistance.
The cybercriminal group ExfilSquad is understood to be responsible for the cyberattacks and has hacked several Western systems in recent weeks. (Alice Lilley / The Telegraph)
Related: The Times
A cyberattack tapped the data of some 31,000 people in Liechtenstein’s register of people behind companies and foundations in the wealthy principality, the government said.
The “register of economic beneficiaries” was accessed at night from Wednesday into Thursday last week, the government said. It said that the breach was noticed on Thursday, that measures were taken to secure data and the system was taken offline.
The government said there were no indications that any data was altered or deleted.
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing.
Liechtenstein is a nation of 40,000 people between Switzerland and Austria, and the financial industry is central to its economy. (Associated Press)
Related: Euro News, Informat.ro, DW, Reuters
A security weakness in the technology used by most of the nation’s crime labs to analyze DNA evidence exposed 30 years of crime files to the risk of being hacked, according to a group of forensic and computer scientists.
The researchers found that with the help of computer code written by widely available AI software, they could alter the data produced from computerized scans of physical DNA evidence without leaving any trace that they had tampered with the records. The vulnerability is likely to have existed in the digital files produced by crime-lab machines since 1995, but recent technological advances make potential tampering much easier now, they said.
“Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag,” said Laura Gaydosh Combs, a forensic scientist and University of New Haven professor who worked on the research.
The company that makes the crime-lab equipment used in a majority of facilities, Thermo Fisher Scientific, privately acknowledged the vulnerability in July and indicated it was working on a fix, according to messages reviewed by The Wall Street Journal. The researchers flagged the security threat in May.
After being contacted by the Journal, the company on Friday issued a security bulletin, labeled high severity, that warned of “a risk for nearly undetectable modification” of certain files “if laboratory controls are circumvented.” (Mariah Timms / Wall Street Journal)
Related: Thermo Fisher Scientific
More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced.
Galaxy Research mapped the full event on Friday, finding 1,082.65 BTC swept between 01:10 and 01:51 UTC across six blocks, with three intervening blocks containing nothing, which suggests the transactions were broadcast in batches rather than continuously.
The proceeds sit in four addresses and have not moved. Early reporting captured only one of those addresses, which is why the figure has grown.
The size of the attack is much smaller than some of the bigger attacks this year, but the mechanism is what makes this unusually — and why the attack is such a big deal. (Shaurya Malwa / CoinDesk)
Related: Crypto News, The Cryptonomist, CryptoSlate, CryptoRank, Economic Times, GBHackers, Bloomberg, Bleeping Computer, TechSpot, Boston Globe
Drugmaker Amgen said hackers stole company data and patient health information in a cybersecurity incident involving cloud storage systems run by third-party providers, becoming the latest healthcare firm to disclose a breach.
On July 29, Amgen determined the incident was material, based on its evaluation of how many files appeared to be affected and the possibility that the information in those files could be sensitive, it said in a regulatory filing.
Amgen has activated its cybersecurity response plan, put containment measures in place, and brought in independent forensic experts to investigate.
The company said it was assessing whether and/or the extent to which patient, confidential business information, intellectual property, research and development, or other information may have been accessed or stolen. (Padmanabhan Ananthan / Reuters)
Related: SEC, WTVB, The Economic Times
Artificial intelligence is no longer simply helping cybercriminals write phishing emails or malware—it is transforming the speed, scale, and economics of modern attacks while creating an entirely new attack surface that organizations are struggling to defend, according to CrowdStrike's 2026 Threat Hunting Report.
Drawing on telemetry from CrowdStrike's OverWatch managed threat hunting service, the report argues that the security industry has entered an era in which adversaries increasingly blend AI-assisted automation with traditional hands-on intrusions, compressing the time defenders have to detect and respond.
"The same AI tools driving modern businesses are creating underdefended attack surfaces that adversaries are already exploiting," Adam Meyers, CrowdStrike's head of Counter Adversary Operations, said during a media briefing previewing the report.
Among the report's most striking findings is how quickly attackers are weaponizing newly disclosed vulnerabilities.
Between January and June 2026, 88% of vulnerabilities for which public proof-of-concept exploit code became available were exploited within 48 hours, CrowdStrike found. Chinese state-sponsored threat actors moved even faster, with some campaigns launching attacks within 24 hours of disclosure. The company warns that frontier AI systems are likely to compress those timelines even further by accelerating vulnerability discovery and exploit development.
Meyers said that effectively ends the industry's longstanding assumption that organizations can rely on 30-day patch cycles.
"If you can get a weaponized exploit in under 24 hours, we cannot wait 30 days for patching," he said, describing rapid vulnerability exploitation as one of the defining cybersecurity stories for the next several years.
The report also documents how AI itself has become a primary target.
Rather than merely using generative AI to improve malicious scripts, attackers are increasingly compromising AI development environments, developer repositories and AI infrastructure. CrowdStrike highlighted campaigns targeting package registries, integrated development environments and software supply chains, noting that the Node Package Manager (npm) ecosystem accounted for 87% of malicious software registry threats during the first half of 2026. One financially motivated group, ALTERED SPIDER, compromised more than 300 software dependencies in a single day.
"The AI supply chain is being heavily targeted," Meyers said. "If you can compromise that supply chain, you can effectively feed compromised libraries that give you control of systems."
North Korean operators also demonstrated how AI development environments themselves can become entry points.
CrowdStrike detailed a campaign in which the DPRK-linked FAMOUS CHOLLIMA threat group created seemingly legitimate AI-focused software projects hosted on GitHub and shared through developer channels. Hidden malicious code embedded within those repositories executed automatically when developers opened the projects, allowing attackers to compromise cryptocurrency and blockchain organizations without requiring further victim interaction.
The company also observed attackers turning stolen cloud credentials into AI infrastructure for their own benefit through so-called "LLMJacking" campaigns.
In one case study, attackers obtained access to a victim's cloud AI environment, elevated privileges, and ultimately generated nearly 200,000 API requests within two minutes before service throttling took effect. Rather than stealing data, the attackers appeared intent on exploiting the victim's AI resources while shifting the resulting costs onto the organization. CrowdStrike characterizes this emerging tactic as "cost harvesting."
Meanwhile, attackers continue shifting away from malware-centric intrusions toward identity-based attacks.
Voice phishing incidents doubled during the first half of 2026 compared with the previous six months, while cloud-focused eCrime activity increased 171%. Device-code phishing attacks—a technique that abuses legitimate cloud authentication workflows—rose fifteen-fold during the reporting period.
The result, Meyers said, is that attackers increasingly bypass traditional endpoint defenses altogether.
"If you can use voice-based phishing to log in, you can then get into the cloud through single sign-on, and you're not touching a single endpoint that's going to be monitored," he said.
CrowdStrike also reported that AI is changing defensive operations.
Within the company's managed threat hunting service, AI agent-triggered detections now outnumber human-triggered detections by roughly 2.5 to one, reflecting the growing volume of AI-generated activity defenders must investigate. OverWatch analyzes roughly seven trillion events each day, producing approximately 14 million detection leads, 36,000 customer alerts annually, and more than one million new detection opportunities fed back into the Falcon platform over the past year.
Although overall intrusion activity increased only about 4% year over year—far below the 27% increase reported last year—CrowdStrike argues that the apparent slowdown should not be interpreted as reduced risk. Instead, the company says adversaries are investing more time in sophisticated campaigns that exploit trusted software, cloud identities and AI infrastructure rather than relying on brute-force attacks. Technology remained the most targeted industry for the ninth consecutive year, while financial services and academia experienced the largest increases in intrusion activity.
For defenders, the report's broader message is that cybersecurity can no longer focus solely on endpoints or even identities. Organizations must assume that AI systems, developer ecosystems and cloud authentication flows have become part of the attack surface—and that attackers are moving too quickly for traditional patching and detection strategies to keep pace. (Cynthia Brumfield / Metacurity)
Related: CrowdStrike, Techzine, CyberScoop, The Register

“Organizations should assume that public and hospitality network infrastructure might not be trustworthy,” Microsoft warned, marking a notable hardening of its security advice for business travelers.
A new hacking threat attributed to Russian threat actors “targets travelers worldwide for malware delivery and credential theft."
The warning follows the discovery of CaptiveCrunch, a global campaign attributed by Microsoft to Storm-2945, a sub-cluster of Russia’s Midnight Blizzard. The campaign targets corporate travelers with credential theft and malware delivered through compromised guest networks.
Microsoft says the activity has been underway since early May, involving hospitality networks and other guest networks served by captive portals worldwide.
Its warning follows a July report from ReliaQuest, which found attackers targeting Microsoft 365 users through compromised Wi-Fi gateways. By manipulating network traffic, the attackers redirect guests to fake sign-in pages without first sending a phishing email or compromising the PC. (Zak Doffman / Forbes)
Related: Microsoft, SOFX, The Cyber Express, Security Affairs

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
The decision was announced on the distribution's mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.
“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.
“We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!”
Independent Federated Intelligence Network (IFIN) conducted a technical analysis of the malware and reported that the campaign began on July 29 with the package ‘openconnect-sso.’ (Bill Toulas / Bleeping Computer)
Related: ifin, XDA, Phoronix, IT News
Hundreds of thousands of people are receiving letters notifying them that their medical records were stolen in a cyberattack at US health tech giant CareCloud earlier this year, as new details about the data breach come to light.
The company has said little about the breach since March, when it first admitted that hackers had raided one of its six stores of patient data. New disclosures offer the clearest picture of the breach so far, including that nearly 350,000 people have been affected so far.
According to a data breach notice filed with California’s attorney general’s office this week, CareCloud said hackers had access to one of its electronic health record data stores for at least six days, between March 10 and March 16.
The company said a hacker “claimed to have exfiltrated data from databases.” The company did not say how the hackers made the claim, but it’s not uncommon for hackers to share samples of stolen data with victims alongside a ransom demand to prevent it from being published online. (Zack Whittaker / TechCrunch)
Related: California Attorney General, GBHackers, Security Affairs, Security Week, The HIPAA Journal
Hyderabad: Central Crime Station (CCS) of Telangana Cyber Security Bureau (TGCSB) has registered a case after sensitive personal and medical records of patients at Star Hospitals were leaked online.
The case was registered after Star Hospitals CEO Rahul Medakkar filed a formal complaint.
The hospital alleged that confidential patient data and internal information were uploaded to a website without its knowledge or authorization, raising serious concerns over patient privacy and data security.
According to the complaint, the hospital's IT team discovered that confidential information belonging to Star Hospitals had been hosted on a website `warehouse. diy'.
The hospital claimed the data was published without its consent and was accessible to unauthorized users.
The complaint further alleged that login credentials required to access the website were being circulated through WhatsApp, increasing the risk of unauthorized access to sensitive information. (Newsmeter Network)
Related: South First, Telangana Today, Hyderabad Mail
Last week, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight-up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran.
Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. With the new feature, Google Earth could have easily been used as a tool for disinformation.
“We’ve seen geospatial professionals using this feature for a range of useful purposes, however we’ve also seen people sharing screenshots of generated imagery that appear to violate our policies,” Google said in a statement.
The company said it would work on installing safeguards, a signal that the feature would return. (Joseph Cox / 404 Media, Adeel Hassan / New York Times)
Related: Google, The Atlantic, Ars Technica, NPR, BBC News, Reuters, Bloomberg, The Verge, New York Times
Ethical hacker-for-hire Horizon3.ai has raised $250 million in late-stage funding, looking to ride a wave of corporate fear over cyberattacks supercharged by Anthropic’s Mythos and other frontier artificial-intelligence models.
The round was co-led by NightDragon and NEA, both of which invested in earlier rounds, along with more than a dozen new and returning investors. (Angus Loten / The Wall Street Journal)
Related: TechCrunch
Best Thing of the Day: Tom Can Be Your Friend Again!
Chris and Tim Vanderhook, whose company acquired Myspace in 2011, say they plan to relaunch the once-dominant social media platform.
Bonus Best Thing of the Day: Rising AI Interests Boost Computer Science Studies
The AI boom has started attracting greater interest in computer science across US universities, with many professors finding themselves busier than ever teaching students from a range of majors about artificial intelligence.
Worst Thing of the Day: The Worst Agency in the World Is Collecting Our DNA
ICE has begun collecting DNA evidence from nearly one million people, including children, including hundreds of thousands of people who were never convicted of a crime.
Bonus Worst Thing of the Day: Please Protect Teachers From Legal Exposure
Claude for Teachers encourages teachers to hand over data, inviting them to sidestep district policy and, potentially, state and federal law.