OpenAI: Hugging Face Incident a “Warning Shot” to the World
OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach
Rapid7 researchers have uncovered a thriving dark web identity market centered on stolen Social Security numbers of corporate executives, with three dominant marketplaces—Xilo, Bankomat, and PeopleFinder—collectively accounting for over 81% of executive SSN leaks tracked since early 2026. Since SSNs cannot be deactivated like payment cards, they retain permanent value for criminals seeking to commit identity fraud, synthetic identity schemes, and executive impersonation attacks targeting both individuals and their organizations. The research reveals that over 73% of compromised records belonged to top-level leadership, with Financial and Industrial sectors most heavily targeted, and recommends organizations implement dark web monitoring, record removal services, and enhanced verification controls to mitigate executive identity exposure.
Read full article at Rapid7 Blog ↗OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.
Boston Scientific disclosed a cybersecurity incident discovered on Tuesday that has disrupted its shipment processes, according to statements made to the Securities and Exchange Commission. The medical device manufacturer's supply chain operations have been impacted by the attack, though the company has not yet detailed the scope or nature of the threat.
'These are test runs for a larger-scale attack'