Top stories.
- Hugging Face discloses an autonomous agentic breach.
- Abbott Laboratories investigates another alleged breach.
- FBI arrests a Florida man accused of spreading malware through video games.
Hugging Face discloses an autonomous agentic breach.
Open-source AI model repository Hugging Face has disclosed that attackers used an autonomous AI agent to breach part of its production infrastructure, gaining access to a limited number of internal datasets and service credentials, PCMag reports. The autonomous agent was "built on an agentic security-research harness" and executed "many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services."
Hugging Face explained, "The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline. A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend."
The company said it fixed the root vulnerability by closing the dataset code-execution paths used for initial access, and will notify customers if it finds that their data was affected.
Abbott Laboratories investigates another alleged breach.
US-based healthcare technology company Abbott Laboratories is investigating a second alleged breach after confirming last week that a threat actor gained access to internal systems in its Cancer Diagnostics business, BleepingComputer reports. The ShinyHunters group claimed responsibility for the attack against the Cancer Diagnostics unit, while another extortion group calling itself "ShadowByt3$" claimed the second incident. The latter attack allegedly affected Abbott's laboratory diagnostics business through its LabCentral customer portal, and the threat actor claims to have stolen confidential business documents and intellectual property.
An Abbott spokesperson confirmed that the company is investigating the incident but disputed the threat actor's claims about the stolen data, telling BleepingComputer that the LabCentral portal "houses publicly available technical product reference documents, including operating manuals, troubleshooting checklists and product specifications, and does not contain proprietary/sensitive customer or business information."
FBI arrests a Florida man accused of spreading malware through video games.
The US Federal Bureau of Investigation (FBI) has arrested a 21-year-old Florida man, Zyaire Wilkins, for allegedly spreading malware-laden video games on Steam, TechCrunch reports. When victims installed the games, the malware would steal their passwords and drain their cryptocurrency wallets. Prosecutors accused Wilkins and co-conspirators of infecting around 8,000 computers and stealing at least $220,000 from eighty cryptocurrency wallets. Wilkins has been charged with conspiracy to obtain information from computers for financial gain.