|
🤖 OpenAI bots triggered a Wikipedia outage
LINK
|
- Wikipedia has blamed a rare partial outage on 7 May on "rogue" OpenAI agents, whose automated traffic overwhelmed its systems, with host Wikimedia Foundation saying AI firms must do more to protect the public from harm.
- The OpenAI agents crawled millions of pages and made hundreds of thousands of data queries to the Wikidata Query Service through public APIs, and even made unauthorised, "potentially malicious" edits to the citation tool Etherpad on Wikipedia sites.
- Wikimedia warned this strain adds server and staffing costs and can block human visitors by overloading systems; OpenAI said it is working with Wikimedia to analyse its bots' activity and will share relevant information as that work progresses.
|
🏥 Oracle health breach hit 20M people
LINK
|
- Oracle's Cerner health unit suffered a breach now said to affect 20 million people, according to information released by the Texas attorney general and reported by Bloomberg yesterday, far more than the 6 million records first claimed.
- The intruder, using the handle rose87168, pulled data from an old legacy server that had not yet been migrated to the Oracle Cloud, with access traced to on or around February 20, 2025; exposed data included medical details, addresses, and Social Security numbers.
- Oracle's medical clients include the Department of Defense and the Department of Veterans Affairs, and a source told Bloomberg last year the hack aimed to hold the data hostage and extract ransoms from U.S. medical providers.
|
🏨 Russian hackers hijack hotel WiFi logins
LINK
|
- Russian state-linked hackers tracked as Midnight Blizzard (also Cozy Bear, APT29) have compromised public WiFi networks at hotels, airports, conference centers, and casinos, redirecting travelers to fake login pages that steal their credentials or install malware, Microsoft warns.
- The campaign, dubbed "Captive Crunch" and ongoing since at least June 2026, works by compromising three North American providers managing WiFi for 7 of the top 10 US hotel chains, then controlling the WiFi gateway to tamper with DNS and HTTP traffic and push victims to spoofed captive portals.
- At least 70 victim networks were hit, with attackers using ClickFix tricks, fake Windows updates, browser updates, driver repairs, or CAPTCHAs, to make users run the malware themselves, including Windows remote access trojans that spy on audio and video; Microsoft urges travelers to avoid public WiFi prompts and use mobile hotspots, cellular data, or VPNs.
|
🏦 South Korea suspects AI in bank hacks
LINK
|
- South Korea's president said on Tuesday that AI models are suspected of having been used in recent hacking attacks against the country's banks, which exposed customers' personal information and prompted a full-scale police investigation.
- Shinhan Bank, KB Kookmin Bank, Hana Bank and Woori Bank have all reported cyberattacks, according to the Financial Services Commission and Yonhap, though authorities have not disclosed what AI tools were used or the full scale of the breaches.
- The FSC chairman convened an emergency meeting with financial associations, regulators and affected institutions on Sunday, warning the sector to respond with the highest vigilance, as the president called for cybersecurity methods suited to the AI era.
|
🔓 Atlassian flaw lets hackers read files
LINK
|
- A critical flaw in 8 self-hosted Atlassian Data Center products lets an attacker with no login read specific files in each product's web application root directory, which Atlassian disclosed yesterday.
- The bug, CVE-2026-21589, rated critical (9.3 out of 10), is a path traversal: a request uses a specially built file path to reach files it should not, but the attacker must already know a file's exact name and path and cannot list the directory's contents.
- Atlassian's cloud products are already patched and no exploitation has been found, but self-hosted customers must upgrade to the listed fixed versions for Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye, or apply temporary firewall or Tomcat blocking rules and restrict public internet access until then.
|
|