❌

Normal view

Carhartt Data Breach Reportedly Exposes Millions. What to Know This Week in Scams

4 September 2026 at 12:00

A data breach doesn’t have to expose your password or credit card number to create problems. Sometimes, scammers just need enough information to make you believe they know you.

That’s the concern after data reportedly stolen from Carhartt was published online. Here’s what happened, why it matters, and what consumers should watch for next.

What Happened in the Carhartt Data Breach?

The cybercriminal group ShinyHunters published data it claims was stolen from Carhartt after an alleged $3.3 million extortion demand was rejected, according to TechRadar. Security researcher Troy Hunt analyzed the leaked information and determined that the compromised data was associated with roughly 12.9 million accounts, although the dataset also reportedly contained millions of synthetic records that did not correspond to real people.

For affected consumers, the important part is what was reportedly exposed: names, email addresses, phone numbers, and postal addresses.

This is also a useful example of how cyber extortion has evolved.

Traditional ransomware typically involves criminals getting inside an organization, encrypting its files so they can’t be accessed, and then demanding payment to restore them.

In this case, the reported strategy was different. ShinyHunters has increasingly focused on data exfiltration — security jargon for stealing or copying data out of a system — and then using the threat of publishing that information as leverage.

In plain English: Criminals don’t necessarily need to lock up a company’s computers anymore. Stealing its data can be valuable enough.

How Scammers Might Use This Information

The immediate question after any breach is usually, “Was my financial information stolen?” That’s important, but it isn’t the only risk.

A combination of your name, email, phone number, and home address can help scammers create a message that sounds much more believable than generic spam.

Instead of: “There’s a problem with your account. Click here.” you could receive something that appears to know your name, where you live, or which company you’ve done business with.

That context can lower your guard.

And scammers don’t necessarily have to pretend to be Carhartt. Stolen contact information can potentially be combined with information from other breaches, data brokers, or public sources to build a more complete picture of someone.

That’s why leaked personal information can remain useful to criminals long after the original breach disappears from the headlines.

Key Takeaways

  • Personal information can be valuable to scammers even when passwords or payment information aren’t exposed.
  • Names, emails, addresses, and phone numbers can make phishing attempts more personalized.
  • Be particularly cautious of unexpected messages claiming there is a problem with an order, refund, account, or payment.
  • A company knowing personal details about you is not proof that the person contacting you actually represents that company.

How McAfee Protects Against Breaches 

Before a breach  

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.  

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.  

During a breach  

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.   

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.  

After a breach  

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even

Other Scam and Security News This Week

A Lenovo Login Flaw Exposed About 5,000 Dropbox Accounts

Dropbox says approximately 5,000 accounts were accessed after attackers exploited a flaw involving Lenovo ID authentication; fewer than a third reportedly had files viewed or downloaded. Dropbox has expired sessions authenticated through Lenovo IDs and changed the login process, while the incident is another good reason to enable two-factor authentication on cloud accounts.
Sources: BleepingComputer

Amazon Adds a New Way to Check Suspicious Messages

Amazon has added a feature to Alexa for Shopping that lets U.S. customers ask whether an email, text, phone call, or other message actually came from Amazon; the company says roughly 360,000 customers contact customer service each year with that question. It’s a useful reminder of one of the best scam-fighting habits: instead of trusting the message in front of you, verify it through a separate, official channel.
Sources: TechCrunch

Fake Late-Night TV Clips Show How Easily AI Can Borrow Someone’s Credibility

NPR reports that AI-generated videos impersonating late-night hosts including Jimmy Kimmel and Jon Stewart have accumulated significant audiences online, sometimes without obvious AI labels. The bigger consumer lesson goes beyond politics or entertainment: seeing a familiar face and hearing a familiar voice is no longer enough to prove that a video — or the product, investment, or claim it promotes — is authentic.
Source: NPR

This Week’s Safety Tips

✓ Treat unexpected personalization as information, not proof. A caller knowing your name, address, or other details doesn’t mean they’re legitimate.

✓ Turn on two-factor authentication. This can provide another barrier when someone tries to access an account without permission.

✓ Verify messages outside the message itself. Open the official app, type the website yourself, or contact the company using information you independently know is legitimate.

✓ Slow down when something feels urgent. Whether it’s a breach alert, delivery problem, suspicious login, or celebrity video, scammers benefit when you react before you verify.

And we’ll be back next week with more cybersecurity news and scam alerts.

The post Carhartt Data Breach Reportedly Exposes Millions. What to Know This Week in Scams appeared first on McAfee Blog.

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

4 September 2026 at 02:18
Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it’s an improper access control problem that covers “improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization.” Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2 The company’s advisory says the company found the flaws after “a comprehensive internal security review,” language that perhaps hints at Cisco dabbling with Mythos and/or other bug-finding models. The fix is in: Cisco has published new versions of IOS XR that fix the problems and “strongly recommends” customers adopt them. Cisco’s support organization spotted the third critical flaw it revealed on Wednesday. CVE-2026-20212 is a tad embarrassing because the cause is a bad integration with Cisco’s own Silicon One networking processors that means some Nexus 9000 Series Switches “could allow an unauthenticated, remote attacker to execute code with root privileges.” “This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF),” according to Cisco’s advisory. A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.” Ten Nexus 9000 devices have the problem, which Cisco suggests owners mitigate by using infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. “Alternatively, the iACLs may be used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211,” the company advises. The networking giant suggests that approach because it hasn’t yet created a software update to fix the flaw once and for all. The company has, however, delivered a download that helps to implement the mitigation. Cisco hasn't seen attacks on these flaws. That may change, fast, now that evildoers can use AI to whip up nastyware. ®

OpenAI commits $1B in AI credits to frontline cyber defenders

3 September 2026 at 23:47
OpenAI has pledged $1 billion in credits to subsidize access to its services and training for resource-strapped cyber defenders around the world. The AI giant expects organizations to use the subsidized credits over the next six months as part of its Daybreak for Frontline Defenders initiative, announced Thursday. Critical infrastructure organizations, community banks, nonprofits, and open-source maintainers can apply for access credits online. These are the defenders tasked with securing critical services that people rely on every day, but don’t have the budgets or staff to use advanced models and agentic technology to harden their cybersecurity. This makes water systems, electrical utilities, and hospitals attractive targets for ransomware operators looking to halt operations and force extortion payments, as well as government-backed cyber operatives set on disrupting critical services and causing mass chaos. Many national security and cybersecurity experts say these disruptions will likely become more severe as attackers increasingly use autonomous agents and other AI tools to carry out their attempted intrusions. “I've spent a lot of time over the past couple weeks talking to CISOs, and I think that we're at a place where the median response is that we might be heading to a world where critical infrastructure outages are just a way of life,” OpenAI president Greg Brockman said during a live event on Thursday. “Water in your city being out for a week, it just kind of happens, and that's quite scary. We have to act, and that's one of the reasons we're really putting our money where our mouth is.” The new initiative also comes as OpenAI faces scrutiny over its models’ safety after admitting that two of them went rogue, spawned a swarm of agents that interpreted their instructions as allowing them to break out of sandboxes, and hacked Hugging Face earlier this summer. Tatyana Bolton, cybersecurity lead at public affairs firm Monument Advocacy, said it’s “excellent” to see OpenAI commit resources to operational tech - not just IT. “AI in (operational technology) OT is inevitable, so operators must get prepared now,” Bolton told The Register. “Initiatives like this help OT personnel get familiar with AI tools, learn how to operationalize them safely, and develop proactive defense strategies before threats escalate.” But she added, software credits alone will not solve the underlying challenges. “OT environments suffer from legacy technology limitations, a shortage of engineering resources, and severe risk-aversion toward automated changes or rapid patching,” Bolton said. “To put this in context, OpenAI's single pledge is more than 20 times larger than a $50 million federal (State and Local Cybersecurity Grant Program) SLCGP infrastructure allocation, and over 85 times larger than the (United States Environmental Protection Agency's) EPA's most recent $11.75 million dedicated cybersecurity and resilience grant pool for midsize and large water utilities.” MS-ISAC pilot focused on water In addition to doling out model credits, Brockman said OpenAI will also increase its training and hands-on support for defenders in essential sectors. This week, the company held a meeting with utility companies from more than 40 states that collectively provide services to more than half of the people who live in the US. Also as part of the new initiative, OpenAI is launching a pilot program with the Multi-State Information Sharing and Analysis Center (MS-ISAC) to train and support state, local, tribal, and territorial cyber defenders, beginning with public-sector and water-system defenders. “The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” according to a Thursday OpenAI blog. Just in time for Astra's debut All of this civic-minded work comes as OpenAI debuts its latest Astra model, which researcher Eric Wallace called “world's most capable model for cybersecurity” during the Thursday event. Wallace leads OpenAI’s efforts on training and evaluating models’ cybersecurity capabilities. Earlier in the week, OpenAI said Astra reached its “critical” cybersecurity capability threshold. This means the new model is so good at finding and exploiting zero-day bugs that it poses a significant risk to critical systems, both from malicious users and even from the model itself, which is capable of carrying out harmful cyber actions “if misaligned.” Because of this, OpenAI released Astra with a restricted level of cybersecurity capabilities that Wallace said the company will enforce through various safeguards. “We have things like system level mitigations that block certain prompts from going through,” he explained. “We have things like model level refusals that prevent certain types of tasks.” This also means participants in OpenAI’s Daybreak Blue and Daybreak Red programs won’t have access to Astra on day one. Daybreak Blue is a restricted access tier for select partners who are allowed to use GPT-5.6 Sol for defensive cybersecurity workflows. Daybreak Red requires additional layers of approval and uses GPT-5.6 Cyber for authorized offensive security actions such as proof-of-concept exploit development, exploit-chain validation, penetration testing, and red teaming. The AI giant is working to make Astra available to both programs’ participants “at a later date,” Wallace said.®

Prediction Market Betting Is Getting People Banned and Arrested

3 September 2026 at 21:48
This week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agents

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

3 September 2026 at 18:08
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse said in a GitHub README. “Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. Security sleuth Kevin Beaumont confirmed this exploit works, along with several others Nightmare released over the past week. Beaumont told us that he’s not surprised to see Nightmare digging into other, non-Microsoft zero-days. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.” FalconFlank follows other vulnerabilities in various endpoint and antivirus products that Nightmare has found and published in the last several days. These include HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product. “So the problem is now leaking outside of Microsoft,” Nightmare said when they published the HardBreacher PoC last week. “There was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.” Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges," Gen Digital told The Register. "We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly." Kaspersky did not immediately respond to The Register’s requests for comment. Nightmare also recently released an Nvidia memory corruption zero-day vulnerability dubbed GreenSection, but according to Beaumont, this one just crashes the system. Nvidia did not respond to our inquiries.® Updated to add at 0905 PT on September 4, 2026 "Kaspersky has resolved the HardBreacher issue. The corresponding fix is delivered via an automatic update, or users can trigger a database update manually," the company told The Register. "During our investigation into the reported issue, we identified an opportunity to enhance our existing behavior-based detections to ensure overall stability and prevent system freezes under certain configurations."

Drowning in CVEs and thirsty for answers? Try CTEM

3 September 2026 at 15:00
A decade or two ago, board executives asked "why should I care about cybersecurity?" Five years ago, they were asking "Are you patching our software vulnerabilities?" Now, they're starting to ask: "Are we actually secure?" They might want a simple 'yes' or 'no' initially, but eventually they'll say the most dreaded thing of all, and it'll be a demand, not a question: "Prove it". Traditional vulnerability management and patching, won't survive that conversation. It's why a relatively new approach is gaining traction: Continuous Threat Exposure Management (CTEM). What's wrong with vulnerability management We define security flaws using Common Vulnerabilities and Exposures (CVEs), and we tell each other how bad they are by assigning the Common Vulnerability Scoring System (CVSS) to them. There are three problems with that. There's a firehose of CVEs, the CVSS scores aren't helpful when triaging them, and AI is about to make the whole thing much worse. CISOs are drowning in CVEs. The industry has spent decades creating tools that churn out vulnerability data and others that consume it. Few if any tell you which vulnerabilities an attacker could use to hurt you in your environment. The volume of CVEs is making traditional vulnerability management (patch it and forget it) less tractable every year, says Drew Vanover, principal security strategist at Horizon3. "Think about the last patch release that Microsoft put out," he says. "There were over 500 fixes in one patch cycle. That is incomprehensible. Nobody is going to be able to go through, vet, prioritize, and deploy all of those in a way that is truly considered safe." The number of CVEs created each year has been soaring, putting more pressure on the US’ National Institute for Standards and Technology's National Vulnerability Database, which has now been backlogged for years. NIST threw up its hands in April and effectively declared CVE bankruptcy. The US Department of Commerce highlighted the second issue (that current severity metrics aren't useful) as part of a report this May. Aside from launching a zinger at the NIST by saying that the NVD was poorly managed, it also suggested that it stop assigning CVSS scores altogether. These are highly subjective, it said. They also depend on exactly what the exposed system is doing in a particular organization's infrastructure. Is a critical severity score in a product important if only one sandboxed system ever interacts with it? Or could an attacker chain three apparently innocuous vulns to cause damage that a business executive would care about? AI will make vulnerability management harder These complex problems are a headache, but AI is about to turn it into a full-on migraine. Frontier LLMs like Claude's Mythos are already surfacing zero-days at scale, heralding a flood of CVEs. They don't just find bugs at scale; they also work much more quickly than their human counterparts to create and weaponize exploits. This makes it even more important that organizations patch the right bugs quickly. The Cloud Security Alliance now describes an asymmetric vulnerability cycle in which attackers can use AI to discover and exploit vulnerabilities more quickly, (increasingly before patches are even released), while organizations are taking longer to patch them. What is CTEM? Something has to change. Gartner figured this out in 2023, when it named CTEM a top cybersecurity trend. This is a way of staying on top of your vulnerabilities by triaging them properly. To do that, you have to go beyond the technical implications of a security flaw and understand what it really means for your business. Gartner lays out five steps to CTEM: ● Scoping Find the assets that carry significant business impact and prioritize them. ● Discovery Find how they're exposed by analyzing their weaknesses in depth. ● Prioritization Rank those exposures based on real business risk. ● Validation Test out the vulnerabilities to see if they're exploitable. ● Mobilization Fix them with a proper incident response plan. How automated pen testing helps manage vulnerabilities This approach promises to nail the security flaws that matter to an organization, but it's also more complex than traditional vulnerability management. It needs automation, which is what Horizon3 is providing with NodeZero. Scoping out systems is a commodity practice these days. So is discovery. Horizon3 is leaving those to partners so it can focus on the parts of the CTEM framework that aren't yet easy for customers to solve. Those are prioritization by business impact, and mobilization. NodeZero runs penetration tests across an organization's infrastructure and documents the exploitable paths with evidence a defender can follow. The output is the wheat sifted from the chaff; a shorter list of exposures that security teams and developers can focus on. The impressive part here is the chain-of-attack behavior. NodeZero probes for weaknesses, exploits them, and then pivots based on what it finds. This means it adapts to the environment to extend its attack, just as a real attacker adapts attacks and moves laterally through systems. This approach is based on a deterministic machine learning expert system rather than a general LLM, explains Vanover. "A good analogy is to think about the medical profession," he says. "A GP is your general LLM trying to cover everything. They know a little bit about a lot, but they aren't the experts, and that's where you start having hallucinations and guesses and misses." The company only uses generative AI for specific tasks. Using it to parse a two petabyte S3 blob looking for sensitive data or identifying high-value credentials, with data staying inside the customer's boundary via AWS Bedrock, for example. What it doesn't do is run amok spawning rogue agents in your system. Vanover says the value here is in proving that you've clobbered load-bearing security bugs. "If we say that we can exploit something, it's because we did, and we'll show you the proof in the platform," he says. The next step is closing the loop by retesting the exploit after it's been dealt with. Teams get to close tickets because NodeZero can no longer traverse the attack path. That is a testable definition of "fixed" and one that translates into a risk metric a CFO can read. Horizon3 also wants to solve customers' tool sprawl problems with a single product that handles all of the heavy CTEM lifting. A common failure mode of enterprise CTEM programs is a stack of vendors whose handoffs create precisely the blind spots the framework was meant to eliminate. That disappears when it's all under one service. Is automated penetration testing safe? CISOs might be nervous letting an autonomous penetration testing system loose on production systems. It sounds like something that could break running processes. Why not just test against a digital twin instead? Testing in production is the safest way to find bugs, retorts Vanover. That's because environments drift frequently, especially in an agile world driven by short development sprints and automated changes to code. If a user changes a password or a team pushes a feature fragment, a digital twin system won't reflect reality. So Horizon3 focuses on strong production guardrails instead. "I don't need to ransom your system to prove to you that I can ransom it," Vanover says. "If I can get on the system, install a remote access tool, create a file, encrypt the file, and delete that file, I've just proven that I can ransom your system." He says Horizon3 has run more than 320,000 production tests across customer organizations. These include some that are especially nervous about what's poking around in their systems, such as the NSA and the largest medical records processor on the planet, along with a couple of large healthcare providers. Where can I start with CTEM? Gartner's CTEM framework is powerful, but it might also be daunting for CISOs. Vanover advises them to begin by picking one thing and doing it well. "No organization is going to implement CTEM in a year. That is a recipe for failure," he says. "Break it down. Look at places for the low-hanging fruit." You could do worse than look at what systems are actually reachable instead of blindly trusting an asset inventory that might be out of date. The race is on to embrace CTEM, because metrics like the number of patches applied won't satisfy the board for much longer. They don't describe how much exploitable surface still exists. The point of running the CTEM loop is to move reporting from activity to outcomes, so that the board gets to see fewer exploitable paths and a smaller blast radius. The new goal is to prove that a security control worked, not just that you paid for it. Want to operationalize CTEM but don’t know where to start? Check out this whitepaper from Horizon3 Sponsored by Horizon3

UK's Online Safety Act has made 'absolutely no difference,' kids say

3 September 2026 at 09:14
Children have told England's Children's Commissioner, Dame Rachel de Souza, that the UK's Online Safety Act (OSA) "has made absolutely no difference" to their ability to access harmful content online. More than a year after the OSA's key child protection duties took effect, de Souza told MPs and peers that young people had little understanding of the legislation or how it was intended to change their online experiences. De Souza made the comments during the opening evidence session of the House of Lords Communications and Digital Committee's inquiry into the OSA's implementation and impact. Central to de Souza's criticism was the legislation's focus on moderating harmful content rather than addressing potentially harmful platform design features. UK politicians had pushed for controls covering such features, either through the OSA or separate legislation, but none has materialized. De Souza said she was "really cross" that there was no hard evidence showing the OSA had meaningfully changed how social media platforms operate. She contrasted that with the US, where legal pressure recently pushed Meta toward significant child safety concessions. Concerns about addictive platform design are not new, but they have returned to prominence following Meta's proposed $18 billion settlement in a US child safety case. Without admitting wrongdoing, Zuckercorp would under the proposed settlement introduce two-hour daily limits for users under 18 on Facebook and Instagram, prompts intended to discourage endless scrolling, and measures addressing use during school hours and at night. The proposal would also let children opt out of algorithmically ranked feeds, directly addressing concerns raised by de Souza and other UK lawmakers. Discussing the proposed Meta settlement, de Souza said the OSA had "not been flexible enough" and had not "kept up with the time." She argued that Ofcom and lawmakers should seek results comparable to those achieved through the US legal system, even if that required the legislation to evolve. 'Furious' with Ofcom De Souza said she planned to exercise her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of the safety risk assessments submitted by technology companies. The commissioner said Ofcom had refused to share the assessments with her, despite her position as "the most senior safeguarding person in this country for children," and had indicated that it would resist disclosure even if she invoked those powers. "One thing I did want to ask this committee was for your assistance in this matter, because I am planning to use my powers," De Souza said. "If we cannot even see the risk assessments that may well have put these [safety] mechanisms into place, or may not have, how on earth can we judge the efficacy of it? "So I'll leave that one with you, but I'm pretty furious about that." The obstacle is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions. Ofcom may disclose such information if the business concerned consents or if one of the statutory gateways in section 393(2) applies. Asked whether compelling tech companies to complete risk assessments was enough to ensure meaningful change or whether further legislation was needed, the Children's Commissioner said "we need a few things," including for Ofcom to "use its teeth." Ofcom has materially upped its presence in the tech regulation landscape during the past year, stepping in on multiple occasions when needed. Perhaps most notably this was at the height of the Grok nudifying furore, but also its sprawling list of investigations into pornography companies allegedly violating age verification requirements. De Souza acknowledged all of this, and the fact that since the introduction of the latest US administration, UK politicians have not given the regulator the "air cover" needed to relentlessly pursue offenders. Nevertheless, she said Ofcom had failed to bare its teeth as forcefully as the current technology landscape demanded and accused it of reacting to harms rather than anticipating them. "If Ofcom is going to be the vehicle to protect our children… we need them to be getting ahead of the harms. And I don't think they have. "So when I talk around the country to children, what's worrying them are things around AI, things around the nudifying apps… there are new harms, and we need Ofcom to be getting ahead of those. I don't think they are." De Souza called on UK politicians "to be really strong and direct" in empowering Ofcom to pursue offending organizations. "But how effective do I think they've been? Not effective enough." The commissioner also criticized Ofcom's child safety codes under the OSA, which she said read more like technical documents for technology companies than protections designed for children. She also called on Ofcom to "use all their powers," impose "some big fines," and act before new harms become entrenched. The Register asked Ofcom to respond. A spokesperson said: "We work closely with the Children's Commissioner and share her objectives to ensure children are safe online. "In December, we published our analysis of risk assessments from the first year of the Online Safety Act being in force, and the improvements we expected to see from platforms. "Our action has resulted in material improvements being made to risk assessments, ensuring that tech companies must implement all measures necessary to address the risks identified on their sites and apps. "We are subject to laws that mean we're restricted in what information we can disclose relating to businesses." ®

Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

3 September 2026 at 07:00
PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled ex-employee who had the means and opportunity to wreak havoc. Our story comes courtesy of Yad Senapathy, who serves as CEO of the Project Management Training Institute in Dallas, Texas. He recalls a time many years ago when he used to work in IT at a company with more than 1,000 employees. While Senapathy was working there, the company terminated an employee, but nobody cut off his access to internal systems. The angry worker logged back in, then deleted files, locked out other people's accounts, and even corrupted a database. "Several days passed where the person was no longer on payroll, but their credentials were still active," Senapathy said. "Nobody had been clearly assigned to shut them off. HR thought IT would handle it once the termination was processed. IT was waiting for HR to send a formal request. I've learned that when nobody is clearly responsible and there is no set deadline, these things can easily get missed until there is already a problem." This lapse in responsibility meant the terminated employee had access to shared admin credentials, account controls, and project tracking systems. Each of these, in turn, granted permission to other systems, leading to a domino effect of inappropriate access, which the former worker used to wreak revenge on the whole organization. According to Senapathy, the damage amounted to hundreds of thousands of dollars. Just as bad were the weeks of delay added to an important project. As an added irony, recovery was particularly difficult because the systems were damaged by the very person who best knew how to repair them. “The employee wasn't some genius hacker. They just still had access after they left and nobody changed the credentials or reviewed admin rights,” Senapathy told The Register. “We'd let one person collect so much system knowledge that shutting the door behind them took longer than it should have.” Senapathy recommends that offboarding checklists and access reviews should be right next to “return the laptop” on that list. The problem in this case is that the terminated employee had more access than most people, and so IT didn't know what they needed to cut off. “Sadly, it could've been prevented by same-day deletion of access, forced re-review of shared account access and zero tolerance for one person owning a whole system alone,” he said. This writer can identify with this situation. At a previous job, after I quit, I lost email, chat, and shared drive access, but months later my former boss asked if I could still log into an important database that was hosted externally and show him how to use it. I had no problems getting in. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.®

Claude Mythos only model to complete full cyber kill chain, experts say

2 September 2026 at 21:31
Despite what we saw with OpenAI’s models going rogue, creating message boards, and breaking into Hugging Face, only one advanced AI model - Anthropic’s Claude Mythos - completed the full cyber kill chain autonomously in Booz Allen’s tests. This doesn’t mean autonomous AI attacks are overhyped. And we should point out that the models tested don’t include OpenAI’s soon-to-be-released Astra, which OpenAI on Tuesday said reached its “critical” cybersecurity capability threshold. This means the new model is so good at finding and exploiting zero-day bugs that it poses a significant risk to critical systems, both from malicious users and even from the model itself, which is capable of carrying out harmful cyber actions “if misaligned.” Booz Allen asserts that most of the other 17 US and Chinese models it tested will achieve Mythos’ same level of weaponization within six months, and it calls mainstream AI attacks from both financially motivated criminals like ransomware gangs and government-backed goons “imminent.” In its first-ever Cyber Weapon Index, the consulting and tech firm calls on the US to set and enforce sector-specific deadlines for critical infrastructure to demonstrate resilience against AI-enabled attacks. Booz Allen also calls on the US to develop what it calls “overmatch” for both cyber offense and defense. “We must aggressively develop agentic capabilities that accelerate authorized offensive cyber operations while simultaneously building AI-enabled defenses that detect, decide, and respond at machine speed,” the report says. “The strategic opportunity is to master both - giving the United States the ability to impose costs on adversaries while making US systems faster to defend, harder to compromise, and more resilient when attacked.” The Cyber Weapon Index evaluated 18 models, nine from American and nine from Chinese developers, under identical conditions, and scored them on how well they autonomously identify vulnerabilities, create offensive capabilities, and execute attacks. Each model’s CWI score combines its vulnerability research score (VRS), which measures whether a model can identify planted and/or novel vulnerabilities, and a kill chain attainment score (KCAS), which awards points based on how far a model progresses through an end-to-end intrusion, tested both with and without credentials. Cyber Weapon Index scores The 18 models, ranked from highest to lowest based on their CWI score, are: Anthropic’s Claude Mythos (80), xAI’s Grok-4.5 (49), OpenAI’s GPT-5.6 Sol (46), Meta’s Muse Spark 1.1 (38), Moonshot AI’s Kimi K3 (38), Z.ai’s GLM-5.2 (37), Anthropic’s Claude Opus 4.8 (36), OpenAI’s GPT-5.5-Cyber (34), Nvidia’s Nemotron-Ultra (33), DeepSeek-V4-Pro (23), DeepSeek-V4-Flash (17), Alibaba’s Qwen3.5-397B (17), MiniMax-M3 (15), Nvidia’s Nemotron-Super (15), Anthropic’s Claude Sonnet 5 (13), Z.ai’s GLM-4.5-Air (11), Alibaba’s Qwen3.6-35B (9), and Alibaba’s Qwen3-Coder (4). Claude Mythos’ performance was especially impressive or concerning, depending on one’s views of autonomous AI attacks. When the testers gave the model stolen employee credentials, it successfully broke into its target network and gained administrator-level control in every attempt. Plus, it independently identified how to gain higher-level access based on what it found within the network - not by following a predetermined attack plan. Even without credentials, Claude Mythos still gained access to the network and ultimately achieved full domain compromise. While only Claude Mythos executed the entire cyber kill chain without any human assistance, three other models - Grok-4.5, Muse Spark 1.1, and GLM-5.2 - reached full domain access and control. Four others - GPT-5.6 Sol, Kimi K3, GPT-5.5-Cyber, and DeepSeek-V4-Pro - achieved lateral movement across the controlled network environment. Claude Opus 4.8 and Qwen3.5-397B obtained credentials, which allowed the models to expand access and privileges. And all but one - Qwen3-Coder - autonomously gained initial access to the network. While advanced models are exceedingly good at offensive cyber capabilities, “their real-world impact depends heavily on the vulnerabilities they face and the systems built around them,” according to the report. When the testers intentionally introduced vulnerabilities, US, Chinese, open-weight, and closed models all scored near ceiling on the VRS component. When tested against real bugs, however, all nine of the frontier API models scored zero. One unnamed leading model even correctly analyzed the vulnerable component, but then dismissed it as safe. Only Claude Mythos exploited it. “That concentration of capability creates a national-security imperative: protect the most advanced models and prevent their highest-risk cyber capabilities from being operationalized by adversaries,” the authors wrote. This is one of the areas where defenders still have an opportunity to outpace the attackers, Booz Allen suggests: “Real-world offensive capability still trails benchmark performance, giving defenders valuable time to strengthen defenses before that gap closes.” Why attack harnesses matter Another interesting finding is that the attack harness matters at least as much as, if not more than, the model itself. The attack harness - this is the software that connects a model to hacking tools and the orchestration logic wrapped around the artificial intelligence model to automate offensive cyber actions - can “dramatically amplify” the model’s ability to stay focused, adapt and change course as needed, recover from failure, and chain individual actions into a multi-stage attack, the authors found. “The result is not a ‘smarter’ model but rather a system that makes its intelligence far more actionable while also lowering the expertise required to use it,” the report says. “Our testing demonstrates the effect: when paired with an attack harness, Claude Sonnet rivaled Claude Mythos’ performance.” However, it also exposes a blind spot, they note. “We do not yet know the full kill-chain capability of open-weight or Chinese models when paired with optimized harnesses, but our results strongly suggest that fully capable model-and-harness combinations exist today,” according to Booz Allen. Similarly, the index’s findings suggest that Chinese frontier and open-weight models, while still trailing leading American frontier models, aren’t that far behind in their offensive security skills and could be deployed in real-world attacks. This means “the United States may neither control nor fully understand the capabilities it could face,” the report says. “And, as cyber agents become more autonomous, defenders must prepare not only for deliberate attacks but for agents that exceed their intended mission or continue operating beyond an adversary’s control.”®

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

2 September 2026 at 18:28
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human operators around two weeks. The human attacker then told negotiators that they used frontier models and agentic attack frameworks with AI agents carrying out each step in the intrusion, including leaving an 80-page security audit for the victim company. “What made the attack stand out was AI-assisted operational efficiency, without the need for a novel zero-day or super elite tradecraft,” Unit 42 incident responders said in a Wednesday report. “The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain.” The security shop did not immediately answer The Register’s questions about the intrusion, including which models and frameworks the attacker used. Breaking down the attack In a first step, the human attacker employed AI agents to perform reconnaissance, then gained access by breaching a public API endpoint to tunnel into the enterprise network. Upon breaking in, the attacker deployed an automated recon agent to map internal microservices. Additional subagents scraped code repositories to steal hard-coded tokens and service passwords. Using these tokens, the AI intruders accessed the org's secret-management system and stole the master administrative credentials to gain root system access. “Specialist pivot agents” then validated access to the company’s cloud, identity, CI/CD, container, and SaaS environments. The attacker also hijacked CI/CD workflows to steal cloud access keys and turn the victim’s cloud AI services into post-compromise infrastructure. This allowed the attacker to consume the victim’s compute resources while hiding orchestration traffic among legitimate activity. After achieving the human operator’s goals, an agent left the victim an 80-page report on its security failings, detailing “dozens of exploited findings,” the incident responders wrote. Not surprisingly, Palo Alto Networks says the only way defenders can protect their environments against machine-speed attacks is to use AI agents themselves. “Deploy automated playbooks that simultaneously revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines and isolate cloud accounts across all operational planes,” the authors advise. The incident response team also suggests companies treat AI as core infrastructure. This requires taking inventory of every model endpoint, API key, Model Context Protocol (MCP) gateway, and AI tool integration, and applying rate limits and least-privilege policies – or risk an unexpected and very large token bill. ®

SonicWall's SMA1000 boxes under active attack again

2 September 2026 at 16:05
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no workarounds. The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. SonicWall attributed it to an unintended alternative access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the vendor said. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance. The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes. SonicWall advised customers to contact its technical support team for help identifying indicators of compromise. If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens. NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways. "Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers," it stated. "The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain." The disclosures continue a difficult run for SonicWall and its SMA1000 product line stretching back through 2025. In July, the vendor disclosed an eerily similar pair of vulnerabilities. That pair also comprised a pre-authentication SSRF vulnerability, this time in the SMA1000 Appliance WorkPlace interface, and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens. CISA later added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns. Throughout 2025, SonicWall patched a succession of SMA1000 vulnerabilities, including OS command injection and privilege escalation flaws, while investigating zero-days linked to ransomware attacks. ®

Is That TikTok Ad Legit? How to Spot Fake Ads on Social Media During Major Sales Events

2 September 2026 at 15:50

Labor Day weekend means sales. And if you spend any time on Facebook, Instagram or TikTok, some of the biggest discounts may find you before you even start shopping.

That convenience comes with a catch: Not every deal in your feed is really from the brand it appears to be.

Scammers can create polished social media ads that impersonate familiar retailers, advertise steep discounts and send shoppers to convincing lookalike websites. According to the Federal Trade Commission, nearly 30% of people who reported losing money to a scam in 2025 said that it started on social media. And the reported losses hit a whopping $2.1 billion last year.

So before a Labor Day “80% off” deal stops your scroll, give it a second look.

How Fake Social Media Shopping Ads Work

A fake shopping ad often starts with something completely ordinary: a product you actually want.

Maybe it’s sneakers from a familiar brand. Patio furniture you’ve been researching. A handbag, grill or appliance marked down for Labor Day.

The ad may use the real company’s logo, product photography and branding. Click it, and the website can look remarkably similar to the retailer’s actual site.

That’s the trick.

This is a form of brand impersonation: A scammer copies the appearance of a company people already know and trust. Instead of convincing you to trust an unfamiliar store, the scammer borrows the reputation of a familiar one.

Sometimes these ads lead to completely fake storefronts. Other times shoppers receive counterfeit products, something dramatically different from what they ordered or nothing at all.

The FTC recently warned consumers specifically about social media ads advertising brand-name products at unusually low prices. And the problem isn’t limited to one platform. A convincing ad can reach you wherever you scroll.

A scam shopping site that looks close to the real thing.
Here’s an example of a scam Louis Vuitton website previously detected by McAfee. Users get an ad on social media, and land on a realistic-looking shopping site. But it’s not the real vendor.

She Thought She Bought $800 Patio Chairs for $135

One shopper who shared her story with McAfee learned just how convincing these scams can be.

A few years ago, Jen was scrolling through Facebook when she spotted an ad for the exact Wayfair patio chairs she and her husband had been considering. Normally around $800, the chairs were advertised at 80% off — just $135 with free shipping.

She clicked.

The experience looked enough like Wayfair that she continued with the purchase, even though a few things started to feel strange. A new tab opened when she tried to buy the chairs. The checkout mentioned PayPal even though she was using her credit card. Then she learned the order would be shipping from China and could take six to 12 weeks.

When she checked her credit card, the charge wasn’t from Wayfair. It appeared in Chinese characters.

Weeks later, a package finally arrived.

It wasn’t a set of patio chairs. Inside the small package was a ceiling-fan chain with a cheap ring.

Her credit card company eventually reversed the charges. But the experience illustrates something important about fake shopping ads: You don’t necessarily land on an obviously fake website filled with misspellings and broken images. A scammer’s goal is to make the experience feel normal long enough for you to complete the purchase.

7 Signs a Social Media Ad or Shopping Site Could Be Fake

Before buying something you find through Facebook, Instagram, TikTok or another social platform, look for these warning signs:

1. The discount is dramatically better than everywhere else.
A legitimate sale can be generous. But if one ad offers a popular $800 product for $135 while reputable retailers are nowhere close, investigate before buying.

2. The website address doesn’t match the retailer.
A fake site can copy a logo much more easily than it can copy a company’s official domain. Look carefully for extra words, misspellings or unusual endings in the web address.

3. Clicking takes you somewhere unexpected.
Watch for redirects, new tabs or checkout pages on a different domain. A change doesn’t automatically mean fraud, but it’s a reason to verify where you are before entering payment information.

4. The checkout process feels off.
Pay attention when the payment method, merchant name or checkout experience doesn’t match what the site told you to expect.

5. There’s pressure to buy immediately.
Countdown timers and “only two left” warnings can push you to act before checking the seller. Urgency is useful to scammers because it shortens the time you spend thinking.

6. You can’t independently verify the sale.
Open a new browser window or the retailer’s official app and search for the product yourself. If the incredible sale exists only through the social ad, that’s a warning sign.

7. The merchant on your credit card doesn’t match the company you thought you paid.
Check the transaction after buying. An unfamiliar merchant name or unexpected international charge deserves immediate attention.

The Safest Way to Shop a Deal You See on Social Media

Here’s a simple safety checklist for Labor Day weekend:

✓ Leave the social app and find the retailer yourself. Don’t let the ad choose your destination.

✓ Compare the price elsewhere. A discount that’s wildly out of line with other retailers deserves extra scrutiny.

✓ Check the URL and merchant name. Make sure you’re dealing with the company you think you’re dealing with.

✓ Use a credit card when possible. And save screenshots, receipts and order confirmations in case you need to dispute the purchase.

What If You Already Bought Something From a Fake Ad?

Act quickly, but don’t panic.

Save screenshots of the ad, website, receipt and any emails or messages from the seller. Check your credit card or bank statement to see how the transaction appears.

If you believe the purchase was fraudulent, contact your card issuer or financial institution and explain what happened. Ask about disputing the transaction and whether your card information should be replaced.

If you created an account on the fake website and reused a password you use elsewhere, change that password anywhere you’ve used it. Unique passwords matter because a scammer who captures one password may try the same email-and-password combination on other accounts.

You can also report fraudulent ads to the social platform and report the scam to the FTC.

How McAfee Helps You Shop More Safely

Spotting every fake yourself is getting harder. Scammers can copy legitimate branding, product photos and storefront designs closely enough that a quick visual check isn’t always enough.

McAfee Scam Detector can help identify suspicious links, messages and websites and alert you when something may be a scam. Plus it has social media tools to help detect scams originating from your favorite platforms. That can provide another check when an attractive offer lands in a social message or sends you toward a questionable site.

Web Protection can also help warn you about risky websites as you browse, adding protection at the moment a convincing ad tries to move you away from the social platform and onto a malicious destination.

The goal isn’t to stop shopping the sales you see online. It’s to make sure the store getting your money is the store you intended to pay.

The post Is That TikTok Ad Legit? How to Spot Fake Ads on Social Media During Major Sales Events appeared first on McAfee Blog.

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

2 September 2026 at 14:25
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password. The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users. Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd. Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled. After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo. In its email, the company advised affected users to change their Dropbox and personal email passwords and enable 2FA. Lenovo told Reuters that its customers were unaffected and that its investigation was continuing. The Register asked Dropbox and Lenovo for more information. ®

UK cyber bill targets AI users, not the vendors building it

2 September 2026 at 09:44
The UK government has rejected proposals from members of the the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill. Cybersecurity minister Baroness Lloyd of Effra argued that regulating AI vendors and frontier model developers through the bill would not prevent hostile actors from misusing their products. Addressing the Grand Committee on Tuesday, she said: "Bringing providers of AI services, those companies which are at the cutting edge of frontier AI development and their products, into the scope… would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors." The minister said the UK was instead taking "firm action" to secure AI through other channels. These include supporting the AI Security Institute (AISI), which works with vendors to test the security of models before their release. Lloyd also pointed to the voluntary AI Cyber Security Code of Practice, which informed the first global AI cybersecurity standard, ETSI EN 304 223. "This demonstrates our global leadership and commitment to shaping international technical standards which go wider than some of the issues raised in this bill," she claimed. Members of the House of Lords - the upper house in UK parliament - offered numerous arguments for bringing AI within the bill's scope. They cited reports of rogue agentic behavior involving Anthropic and OpenAI, as well as Bill Gates' concerns that commercial incentives are pushing AI development forward without adequate safeguards. Lawmakers also questioned whether companies unable to prevent their agents from misbehaving should be trusted to follow voluntary ethical guidelines that they can rewrite at will. "Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?" asked Baroness Kidron, a Crossbench peer and campaigner for online safety and digital rights. Similarly, Lord Tarassenko, a Crossbench peer and veteran AI researcher, pointed to the recent open letter penned by OpenAI warning that there will soon come a time when AI-orchestrated cyberattacks will become too prevalent to handle. Although the letter was criticized for employing alarmist language while carrying the signatures of companies that profit from AI, peers argued that its warning strengthened the case for regulatory intervention. Kidron and Lloyd also clashed after the minister used a hypothetical healthcare organization to illustrate how the bill would require regulated bodies to secure systems containing AI. Kidron asked: "If I might ask the noble Lady, the Minister, if I've understood what she said, the NHS must protect itself, but the AI that is attacking it has no requirement under the Bill, no duties, no obligations under the Bill to check itself before it's used in these ways." Lloyd said the bill was designed to be technology-agnostic and to impose stricter cybersecurity requirements on key organizations, rather than regulate individual technology providers. She nevertheless said the government was willing to continue discussing AI after Kidron predicted that the issue would return during later stages of the bill's passage. The minister rejected several other amendments, including one that would require certain AI vendors to demonstrate that their products could not cross specified red lines, such as evading human oversight or assisting with the development of chemical weapons. She also dismissed a proposal that would give the Secretary of State last-resort powers to order the shutdown of a datacenter or widely deployed AI system during a security or operational emergency. Lloyd said the bill would instead allow the government to direct regulated entities, including datacenter operators but not AI vendors, to take or cease specified actions when their systems presented a qualifying risk. A power station could, for example, be instructed to stop using a particular AI model. "We believe this is a more proportionate and effective response, as datacenters operate in highly complex ecosystems and AI systems are often distributed across different datacenters and jurisdictions," said Baroness Lloyd. "It's much less desirable to direct multiple datacenters to shut down, and the impact this could have on services that rely on them, than to direct them to cease using an AI model." Despite rejecting the amendments, Lloyd said the government remained willing to discuss AI regulation because of the technology's economic significance. The Grand Committee is scheduled to resume discussions of the CSR Bill when it reconvenes on Thursday. The bill's background The CSR Bill was first proposed in the 2024 King's Speech and introduced in Parliament in November 2025. It attracted attention over the £100,000 daily fines initially proposed for in-scope organizations that failed to protect against specific threats. The legislation builds on the existing categories of operators of essential services and relevant digital service providers while extending the regime to organizations including managed service providers, datacenter operators, and designated critical suppliers. Managed service providers were previously due to be brought within scope through the abandoned 2022 update to the NIS regulations. The broad intention of the bill is to update the NIS 2018 regulations and future-proof the UK's critical infrastructure from cyber threats. However, this week's Grand Committee scrutiny is not the first time the bill has been criticized. In January, shadow deputy PM Sir Oliver Dowden called on the government to rethink its exclusion of local and central government from the CSR bill. The UK's Government Cyber Action Plan, launched hours before the former digital secretary's remarks, promised to hold government to the same standards proposed in the CSR Bill. Like the AI Cyber Security Code of Practice, the action plan lacks any legal obligations. ®

Another Artifactory CVE under attack by AI agents or humans

1 September 2026 at 21:07
Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone is human. Artifactory is a widely used tool for managing software artifacts, packages, binaries, and AI models. It’s also popular with AI agents that go rogue and need to communicate with each other while remaining undetected by their human babysitters. In July, OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting Artifactory zero-days, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet. JFrog disclosed CVE-2026-82329 on Friday, and by Tuesday, attackers had already begun exploiting internet-exposed systems, according to exposure-management biz watchTowr’s threat-intel team, which reported “attackers minting themselves admin tokens.” In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” Yordan Ganchev, principal threat intelligence specialist at watchTowr, told The Register. “Right now, we’re observing exploitation from a small number of IP addresses from varying geographies exploiting multiple of our honeypots,” Ganchev said. “Broad-scale scanning and mass exploitation has not been observed, but that is unlikely to stay the case for long.” Ganchev urged organizations running vulnerable versions to “urgently patch” internet-exposed systems, and treat them as being potentially compromised - so inspect audit logs, rotate credentials, and investigate connected systems for any unusual changes or backdoor implants. “When attackers gain admin level access to a central software supply chain system, they can do what every engineering team does best - build, ship and distribute software fast,” he said. “From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers.” JFrog did not immediately respond to The Register’s inquiries. We will update this story when we receive any response. ®

❌