AI girlfriend review site's secrets were exposed to the world for three weeks
Even testing and staging sites need protection from prying eyes
Manchester Airports Group confirmed a breach affecting customer data across three UK airports, with attackers accessing an unspecified quantity of personal information. The incident represents a significant compromise of airport infrastructure and the sensitive data of millions of travelers associated with the affected facilities.
Read full article at Help Net Security ↗Even testing and staging sites need protection from prying eyes
Rapid7 researchers have uncovered a thriving dark web identity market centered on stolen Social Security numbers of corporate executives, with three dominant marketplaces—Xilo, Bankomat, and PeopleFinder—collectively accounting for over 81% of executive SSN leaks tracked since early 2026. Since SSNs cannot be deactivated like payment cards, they retain permanent value for criminals seeking to commit identity fraud, synthetic identity schemes, and executive impersonation attacks targeting both individuals and their organizations. The research reveals that over 73% of compromised records belonged to top-level leadership, with Financial and Industrial sectors most heavily targeted, and recommends organizations implement dark web monitoring, record removal services, and enhanced verification controls to mitigate executive identity exposure.
OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.