< ciso
brief />
Tag Banner

All news with #news tag

348 articles

Microsoft Exchange Online outage causes email failures

πŸ› οΈ Microsoft is investigating a widespread service issue causing authentication errors and email delays or failures for Exchange Online customers. The incident (EX1464935) was first acknowledged at 5:30 PM UTC after a surge of user reports; Downdetector indicates tens of thousands affected. Reported symptoms include delayed or failed message delivery, authentication errors, administration access issues, and intermittent mailbox operation failures. Microsoft says it has isolated a common failure pattern tied to authentication and protocol connectivity and is analyzing telemetry to determine remediation and scope.
read more β†’

OpenAI confirms ChatGPT outage affecting Work users

πŸ› οΈ OpenAI has acknowledged a partial outage affecting ChatGPT Work that began around 11:04 AM ET on Monday, August 31. Users across multiple subscription plans are seeing elevated latency and errors, with Plus subscribers particularly impacted because Work mode is unavailable for some. The company reported the issue on its status page and said engineers are working on mitigation, with the outage still ongoing as of 12:02 PM ET.
read more β†’

UK man jailed for running large illegal IPTV service

πŸ” A 68-year-old UK resident, Milan Ibrahim, has been sentenced to over six years in prison after running an illegal IPTV service that generated Β£980,812 over three years. The Police Intellectual Property Crime Unit (PIPCU) described the operation as sophisticated, involving 80 servers and offering pirated broadcasts from major rights holders including BBC, ITV, Sky, the Premier League and the Motion Picture Association. Authorities seized and shut down all servers, potentially exposing users who accessed the service to fines or other consequences, and will pursue Proceeds of Crime Act actions to recover funds.
read more β†’

Small generators expose critical infrastructure risk

πŸ”’ A recent cyber incident that took a small UK electricity generator offline for days β€” without causing national outages β€” highlights a weakness across Western critical infrastructure: thousands of small, internet-exposed industrial control devices lack the security protections of larger utilities. Governments and security firms are investigating attribution and impacts while urging operators to remove PLCs from direct internet access, secure cellular modems, and test manual-operation procedures. The episodes mirror attacks on US water systems and underscore how modest targets can create disproportionate disruption.
read more β†’

ATF Confirms Major Security Incident After Qilin Claim

πŸ”’ The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a breach of a standalone system after the Qilin ransomware gang added the agency to its dark web leak portal. The ATF says the compromised system is separate from its enterprise network and critical systems, and it immediately terminated connections and launched an incident-response and forensic investigation with the Department of Justice. The agency reported no operational impact and requested public tips while the investigation continues.
read more β†’

INTERPOL Operation Jackal IV Targets West African Crime

πŸ›‘οΈ An eight-month INTERPOL operation has led to 58 arrests and the identification of 263 suspects linked to West African organized crime groups, including Black Axe. The effort, involving 22 countries across six continents, targeted cyber-enabled fraud, romance and investment scams, and money laundering. Investigations uncovered a major crime-as-a-service network and disrupted call-center and syndicate operations responsible for large-scale thefts and laundering.
read more β†’

LACMA breach exposed Social Security and medical data

πŸ”’ The Los Angeles County Museum of Art (LACMA) disclosed a data breach discovered in July 2025 after suspicious activity began four days earlier. The investigation, updated in February 2026 and finalized over a year later, determined that attackers may have accessed sensitive customer and employee records. Exposed elements include full names, dates of birth, Social Security numbers, government IDs, partial financial and card data, health insurance details, and medical treatment information. LACMA has notified law enforcement and affected individuals, offered one year of identity protection through Financial Shield, and set up a dedicated support line while recommending monitoring and credit protections.
read more β†’

OpenAI Confirms ChatGPT Outage Affecting Logins

πŸ”΄ OpenAI confirmed a global ChatGPT outage that began around 8:00 PM ET on Wednesday, August 19, preventing users from signing in, creating accounts, or loading chats. Affected users encounter loading animations and "too many concurrent requests" errors, and new signups and logins on chatgpt.com fail. The incident also impacts the OpenAI API, with up to 12 endpoints reported as problematic on the status page, and the company is implementing a mitigation.
read more β†’

Microsoft addresses Microsoft 365 search outage bug

πŸ”Ž Microsoft reported that some users experienced search failures across Microsoft 365 services including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. An internal incident (MO1456424) traced the problem to a recent deployment that caused resource utilization inefficiencies on affected infrastructure. Microsoft said it developed and deployed a fix to reduce resource pressure and restore service for impacted users. The company has not disclosed which regions were affected but categorized the event as an incident.
read more β†’

SafePal order-tracking flaw exposed customer data

πŸ”’ SafePal disclosed an authorization flaw in an order-tracking plug-in that exposed names, emails, shipping addresses, phone numbers, and purchase details for about 39,798 customers. The company said no wallet credentials or payment card data were included and that affected customers were notified on August 16. SafePal fixed the flaw, reduced retention, purged affected records from active servers, and engaged an independent firm to validate fixes and review systems.
read more β†’

GitHub outage confirmed β€” widespread service errors

⚠️ GitHub confirmed a widespread outage on August 17, 2026, reporting elevated error rates across the website, API, Actions, Pull Requests, and related services. The company observed ~20% error rates for web and API traffic, and roughly 50% errors for archive and raw repository downloads. Authentication services such as SAML and OIDC, plus SCIM and Team Sync, are affected, and GitHub Actions and Copilot reported degraded availability. The incident is under investigation and the root cause has not been disclosed.
read more β†’

Solar eclipse caused measurable internet traffic dips

πŸŒ‘ Cloudflare Radar analyzed HTTP request volumes during the August 12 total solar eclipse that crossed Iceland, northern Spain and Portugal, comparing five-minute slices to a same-weekday baseline. The data show pronounced traffic declines aligned with maximum obscuration, with regions along the path of totality dropping roughly 15–30% and rebounds occurring within minutes. Variations reflect local factors like time of day, cloud cover, and population distribution, while calculations used precise geometric obscuration of the sun and moon.
read more β†’

AI-Generated Books Flooding Amazon Market

πŸ“˜ A New York Times journalist discovered an AI-written biography of herself on Amazon, sparking an investigation into prolific AI authors on Kindle Direct Publishing. The story uncovered retired cybersecurity consultant Bill Johns, who used ChatGPT to produce hundreds of books across diverse topics and sold modest numbers via Amazon’s print-on-demand model. The piece highlights economic incentives behind mass-produced AI books and urges readers to prefer trusted, human-vetted sources for critical information.
read more β†’

White House Authorizes Private Hack-Back Program

πŸ“ The White House issued a National Security Presidential Memorandum directing the National Coordination Center to establish a program allowing vetted private security firms to apply for authorization to conduct cyber operations against foreign transnational criminal organizations. The program, overseen by executive directors from the Justice and Homeland Security departments, requires companies to post a $1 million bond, adhere to strict legal and constitutional safeguards, and immediately halt activities that exceed approved limits, such as accidentally targeting U.S. systems or citizens. It targets disruption of ransomware, phishing, financial fraud, sextortion, and impersonation schemes and aims to leverage private sector capabilities under government control.
read more β†’

US Authorizes Private Help in Offensive Cyber Operations

πŸ”’ The White House has approved a memorandum allowing federal law enforcement to collaborate with private companies on limited offensive cyber operations against foreign actors targeting the US. The National Security Presidential Memorandum (NSPM) signed on August 12 builds on earlier executive actions and tasks the Homeland Security Task Force’s National Coordination Center to oversee the program. Rigorous procedures and legal safeguards are promised, while experts warn about attribution difficulties and escalation risks.
read more β†’

Administration Clears Path for Supervised Private Cyber Operations

πŸ›‘οΈ A presidential memorandum directs the National Coordination Center to establish a program allowing vetted US companies to conduct government-supervised cyber surveillance and cyber effects operations against foreign groups targeting US interests. Participating firms must contract with the DOJ or DHS, undergo vetting, and obtain written approval for each operation, with officials given 60 days to set procedures. The plan raises concerns about collateral damage, attribution errors, corporate liability, and privacy implications for threat intelligence sharing.
read more β†’

July 2026 Cyber Threats: Ransomware and GenAI Risks

πŸ”’ July 2026 saw a marked uptick in cyber incidents, with weekly attacks averaging 2,336 per organization and ransomware victims rising sharply. Education, Latin America, and Business Services were among the most affected, while GenAI use exposed sensitive data through risky prompts. Email remained a primary entry point as organizations confront multi-vector threats and growing operational exposure.
read more β†’

Valve notifies Steam hardware customers of breach

πŸ”” Valve is informing Steam hardware customers in Europe that a breach at shipping partner CEVA Logistics exposed delivery-related data. The company says attackers accessed CEVA systems between July 29 and August 1, 2026, and likely obtained names, addresses, phone numbers, emails, and order details. Valve clarified that payment, passwords, and Steam Guard codes were not exposed and warned customers to watch for phishing attempts using the stolen information.
read more β†’

Anthropic confirms Claude outage affecting users

πŸ› οΈ Anthropic confirmed elevated errors across multiple AI models after users encountered a β€œ529 Overloaded” message causing requests to fail. The company began investigating at 7:49 p.m. UTC on July 29 and by 8:33 p.m. UTC had identified the issue but did not disclose the cause or recovery timeline. The error indicates servers are struggling with request volume, and Anthropic is working on a fix while the outage affects Claude and reliant tools.
read more β†’

Axon adds to license-plate surveillance debate

πŸ“· Municipalities are replacing some Flock license-plate reader arrays with Axon cameras, but the swap may offer little privacy benefit. Vendors claim differences, yet Axon systems still collect extensive personal data beyond plate numbers. Switching brands can be superficial if surveillance capabilities and data use remain similar. The article argues that changing suppliers doesn't necessarily reduce citizen privacy loss.
read more β†’