Archive of

DTU breach exposes data of up to 200,000 people

The Technical University of Denmark (DTU) has disclosed a data breach that may affect up to 200,000 current and former users. Hackers logged into the university's identity and access management system and downloaded a large volume of data.

According to DTU, the attacker used compromised credentials to access DTUBasen, the university's identity and access management (IAM) platform. That system holds user records going back more than 20 years.

In its Friday disclosure, the university said it cannot "determine precisely what information was downloaded or how many people have been affected."

DTUBasen contains records for roughly 40,000 active users and about 160,000 former users. These figures make up the upper estimate of 200,000 potentially affected people.

Read More


doxx.net raises $38M for private network for AI agents

Miami-based doxx.net has closed a $38 million Series A round and launched a networking platform meant to keep AI agents away from malicious destinations while they browse and act for their users.

Andreessen Horowitz led the round, with Animo Ventures and Focal.vc also taking part. The company was founded in 2025 by serial founder Barrett Lyon, who also serves as its CEO, and operates across six continents.

The problem with agents on the open web

AI agents now browse websites, contact services, communicate and take actions on behalf of the people who deploy them. They do this with their users' accounts and authority. The issue, according to doxx.net, is that these agents cannot reliably tell safe information and actions apart from unsafe ones.

Read More


Fortra BoKS update fixes three critical vulnerabilities

Fortra has fixed eight security flaws in Core Privileged Access Manager, better known as BoKS. Three of them are rated critical, including an authentication bypass tied to how the product generates Active Directory service account passwords.

BoKS gives organizations a central way to manage Unix and Linux fleets. Administrators use it to enforce policies and control access across accounts, which makes it a high-value target if something goes wrong.

Predictable passwords open the door

The most severe issue is tracked as CVE-2026-79901 and carries a CVSS score of 9.9. Fortra disclosed it on Thursday, warning that it affects BoKS Manager deployments that rely on BoKS keytab to manage Active Directory service accounts. A keytab is a file that stores credentials so services can authenticate without a person typing a password.

Read More


iCloud spoofing bugs, adblocker spying on AI chats

This week's roundup covers a Microsoft threat report showing a sharp rise in phishing, a pair of iCloud flaws that let attackers send convincing fake emails, and a popular Chrome adblocker that quietly collects users' AI chats. Other items include a Chinese espionage group phishing AI policy specialists, a large batch of Kiteworks advisories, and a data exposure bug in Cloudflare Containers.

Microsoft: phishing triples, exploit windows shrink

Microsoft's 2026 Digital Defense Report covers July 2025 to June 2026. It says AI has pushed the median time between discovering a vulnerability and weaponizing it to well under 24 hours. The company expects a record of roughly 72,000 CVEs this year.

Read More


AI agents aimed SQL injection at US, Canadian gov sites

AI agents that were apparently trying to collect public data ended up probing a US Department of Education website and a Library and Archives Canada service with attack payloads, according to AI research lab Transluce.

The findings were published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation. They build on earlier Transluce research that documented AI agents targeting US government websites.

According to The New York Times, OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites. Its investigation into the Education Department incident is still ongoing.

Transluce said nothing in the data it analyzed suggests the agents obtained non-public information.

Read More