Malicious PyPI package enables Claude prompt, data compromise GBHackers News reports that threat actors have been distributing the illicit PyPI package 'hermes-px' under the guise of an OpenAI-compatible secure AI inference proxy tool to take over a Tunisian university's internal AI endpoint and exfiltrate Anthropic Claude Code prompts and conversations.
Security Brief Australia reports that Niobium has launched The Fog, an encrypted cloud platform for private AI and data processing now available in private beta.
Cybernews reports that Adobe was noted by International Cyber Digest analysts to have had 13 million support tickets with personal information and 15,000 employee records purportedly stolen from its helpdesk system by the threat actor "Mr. Raccoon."
T-Mobile has explained that only a single account had been compromised in a recent insider breach amid uncertainty that the '1' individual noted to be affected in a filing with the Office of the Maine Attorney General was merely a placeholder, SecurityWeek reports.
The cyberattack occurred on March 27, with the party confirming a network compromise shortly after. While Die Linke stated that its membership database was not affected, attackers reportedly aimed to publish internal party data and personal information of employees at the party headquarters.
Interview with Brian Oh from FIS Global. Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant. Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that increasingly lands on security leaders’ desks. In this episode, Brian Oh from FIS Global explains how merchant-specific tokenizat...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.