Top news stories this week
- Breaking bad. OpenAI models exploit vulnerabilities to escape sandbox and breach Hugging Face
- Food fight. Operations at major food and beverage brands worldwide affected by cyberattacks
- Patch race. Critical WordPress vulnerability exploited within hours disclosure
- Pricey failures. EU regulators issue cyber-related fines following security and disclosure failures
- No-comotive. Swiss rail company rejects ransom demand
- Artificial intent. Threat actors leverage AI to scale attacks and maximise returns
1. OpenAI models exploit vulnerabilities to escape sandbox and breach Hugging Face
OpenAI disclosed that two of its AI models escaped a restricted testing environment during a cybersecurity evaluation and breached the production systems of Hugging Face, the AI development platform hosting machine learning models, to obtain answers to the benchmark they were being tested on. Although the models demonstrated multiple attack techniques and were evaluated in a sandboxed environment, the system was not completely isolated from the internet, allowing them to exploit a vulnerability in an external-facing component and break out of containment.
So what?
News of the breach has sparked significant debate in the security community. While OpenAI has described the incident as unprecedented and evidence of advancing AI cyber capabilities, security experts have argued the breach primarily reflected failures in the oversight and governance of agentic AI models and insufficient isolation of testing infrastructure.
[Researcher: Milda Petraityte]
2. Operations at KFC and Coca Cola affected by supply chain cyberattacks
Nichirei, Japan’s leading cold chain logistics provider, disclosed a cyberattack that impacted its ability to carry out deliveries to its clients, among them KFC, Glico and Kura Sushi. KFC Japan warned that its restaurants could face shortages leading to some menu items being unavailable, or even stores being temporarily closed. In the US, both Chick-fil-A and Coca Cola’s dairy subsidiary Fairlife reported cyber incidents, with the latter shutting down production operations across the country.
So what?
Corporates should validate business continuity and incident response plans to test their dependence on suppliers and assess capabilities for scenarios which involve a complete halt to their business.
[Researcher: Lester Lim]
3. Critical WordPress flaws exploited within hours of disclosure
Two newly disclosed WordPress vulnerabilities, dubbed WP2Shell, are being targeted by threat actors. The flaws affect WordPress versions 6.9.0-6.9.4 and 7.0.0-7.0.1 and can be chained to achieve unauthenticated remote code execution on default WordPress installations without requiring plugins or user interaction, effectively allowing attackers to take control of vulnerable websites. Security researchers observed exploitation attempts shortly after disclosure, with public proof-of-concept code emerging within hours.
So what?
The incident highlights the accelerating pace at which vulnerabilities are being exploited following disclosure and may point towards an increasing use of AI-assisted vulnerability research and automated reconnaissance.
[Researcher: Gabriella Nolan]
4. Swiss manufacturer Stadler Rail rejects multi-million ransom demand
Swiss rail vehicle manufacturer Stadler Rail has publicly rejected a ransom demand of over USD 12.3 million following a breach of a data platform it shared with a supplier. The company claimed the ransomware group Everest had only compromised technical data, and that the incident did not cause interruptions to production.
SO WHAT?
Organisations facing cyber extortion should engage specialist support and guidance when considering their options. S-RM’s data shows that originations with viable backups are far less likely to pay a ransom, highlighting the importance of disaster recovery testing ahead of time.
[Researcher: Houren Lee]
5. EU regulators issue cyber-related fines following security and disclosure failures
Spain’s data protection authority fined 23andMe EUR 2.4 million after determining that inadequate security controls, like the lack of mandatory MFA, contributed to the 2023 breach of sensitive genetic and health data. The regulator also cited delays in breach notification, reinforcing expectations for timely reporting and stronger protection of high-risk personal information. Similarly, the German regulator BaFin imposed a EUR 240,000 fine on TeamViewer for failing to promptly disclose a 2024 cyberattack as insider information under market abuse regulations.
So What?
The regulatory fines highlight the growing regulatory focus on cyber incident transparency and the expectation that publicly listed companies report material cyber events without delay.
[Researcher: Jenny Eysert]
6. Threat actors leverage AI to scale attacks and maximise returns
In a campaign known as ‘FakeGit’, threat actors have used malicious GitHub repositories to distribute malware, including over 1,400 fake AI tools, agents and workflows designed to attract developers and AI agents - a technique dubbed "agentbaiting".
Separately, a new Windows information stealer has been discovered that uses an AI-powered profiling tool to identify and prioritise the most valuable victims from more than 300 targeted applications.
SO WHAT?
Together, these cases highlight how attackers are leveraging AI both to automate and optimise their operations, while also increasingly targeting organisations' AI infrastructure and data as a valuable attack surface.
[Researcher: James Tytler]
