The Technical University of Denmark (DTU) has disclosed a data breach that may affect up to 200,000 current and former users. Hackers logged into the university's identity and access management system and downloaded a large volume of data.
According to DTU, the attacker used compromised credentials to access DTUBasen, the university's identity and access management (IAM) platform. That system holds user records going back more than 20 years.
In its Friday disclosure, the university said it cannot "determine precisely what information was downloaded or how many people have been affected."
DTUBasen contains records for roughly 40,000 active users and about 160,000 former users. These figures make up the upper estimate of 200,000 potentially affected people.
Miami-based doxx.net has closed a $38 million Series A round and launched a networking platform meant to keep AI agents away from malicious destinations while they browse and act for their users.
Andreessen Horowitz led the round, with Animo Ventures and Focal.vc also taking part. The company was founded in 2025 by serial founder Barrett Lyon, who also serves as its CEO, and operates across six continents.
The problem with agents on the open web
AI agents now browse websites, contact services, communicate and take actions on behalf of the people who deploy them. They do this with their users' accounts and authority. The issue, according to doxx.net, is that these agents cannot reliably tell safe information and actions apart from unsafe ones.
Fortra has fixed eight security flaws in Core Privileged Access Manager, better known as BoKS. Three of them are rated critical, including an authentication bypass tied to how the product generates Active Directory service account passwords.
BoKS gives organizations a central way to manage Unix and Linux fleets. Administrators use it to enforce policies and control access across accounts, which makes it a high-value target if something goes wrong.
Predictable passwords open the door
The most severe issue is tracked as CVE-2026-79901 and carries a CVSS score of 9.9. Fortra disclosed it on Thursday, warning that it affects BoKS Manager deployments that rely on BoKS keytab to manage Active Directory service accounts. A keytab is a file that stores credentials so services can authenticate without a person typing a password.
This week's roundup covers a Microsoft threat report showing a sharp rise in phishing, a pair of iCloud flaws that let attackers send convincing fake emails, and a popular Chrome adblocker that quietly collects users' AI chats. Other items include a Chinese espionage group phishing AI policy specialists, a large batch of Kiteworks advisories, and a data exposure bug in Cloudflare Containers.
Microsoft: phishing triples, exploit windows shrink
Microsoft's 2026 Digital Defense Report covers July 2025 to June 2026. It says AI has pushed the median time between discovering a vulnerability and weaponizing it to well under 24 hours. The company expects a record of roughly 72,000 CVEs this year.
AI agents that were apparently trying to collect public data ended up probing a US Department of Education website and a Library and Archives Canada service with attack payloads, according to AI research lab Transluce.
The findings were published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation. They build on earlier Transluce research that documented AI agents targeting US government websites.
According to The New York Times, OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites. Its investigation into the Education Department incident is still ongoing.
Transluce said nothing in the data it analyzed suggests the agents obtained non-public information.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.