Follow the latest coverage, related explainers and connected technology stories.
Transluce detected automated attempts involving more than 200,000 requests and SQL injection probes against government websites in the United States and Canada while searching for public data. Authorities found no evidence of access to nonpublic information or database breaches, while attribution of the activity to OpenAI remained unresolved.
Cloudflare used an adaptive testing system based on AI models to change the formats of attack requests according to WAF responses, recording 1,107 attempts across six attack categories. Human review led to 49 actionable findings and contributed to improving SSRF detections in the Managed Ruleset.
Trezor confirmed that a breach at shipping and logistics provider ShipMonk affected an additional 67,000 U.S. customers, bringing the total to 81,000. Notification emails indicate the exploitation of a critical SQL injection vulnerability in the Metabase platform, while customers were warned about phishing and potential security risks.
An undocumented SQL injection vulnerability allows attackers to execute remote code and take control of sites using the All-in-One WP Migration and Backup plugin. ServMask issued the fix in version 7.110, but approximately 3.25 million sites are still running a vulnerable version, according to the figures cited in the report.