A hotel check-in platform called Tabiq exposed more than a million customer passports, driver’s licenses, and selfie verification photos on the open web after its operator, Japan-based startup Reqrea, left an Amazon cloud storage bucket publicly accessible. A security researcher discovered the leak by browsing the bucket using only its name “tabiq,” and TechCrunch alerted Reqrea and JPCERT. Reqrea later locked down the bucket, but said it doesn’t know how it became public or whether anyone accessed data beforehand.
New VB Pulse data suggests the enterprise fight is shifting from model quality to the “control plane” where AI agents plan, call tools, access data, and get audited. Microsoft Copilot Studio and Azure AI Studio lead adoption, OpenAI follows, and Anthropic’s Claude registers a first measurable foothold at orchestration—hinting model momentum may be spilling into runtime infrastructure.
Your news, in seconds
Get the Beige app — every story in 60 words, updated hourly. Free on iOS & Android.
UK financial authorities are urging firms to prepare for risks from frontier AI models, saying their cyber capabilities can exceed what skilled human practitioners achieve. In a joint statement, the finance ministry, the Bank of England and the Financial Conduct Authority warned that if these systems are used maliciously, they could amplify threats to firms’ safety, customer protection, market integrity and financial stability. Regulators also pointed to concerns raised by BoE governor Andrew Bailey about Anthropic’s Mythos product.
Fidelity Investments has agreed to settle a class-action lawsuit tied to a 2024 data breach, resolving claims without admitting wrongdoing. Customers who received notice that their account and routing numbers may have been compromised between August 17 and 19, 2024, could seek compensation for documented financial harm of up to $5,000. The settlement also offers identity theft protection and credit monitoring, plus possible smaller cash payments. A valid claim must be filed by July 27, 2026.
A Comcast settlement tied to a late-2023 data breach is driving a nationwide scramble, with eligible customers potentially receiving up to $10,000. The alleged cyberattack, reportedly affecting October 16–19, exposed sensitive account details including usernames, passwords, partial Social Security numbers, dates of birth, and secret recovery questions. Comcast denies wrongdoing but agreed to pay $117.5 million. Claim forms must be filed by August 14, with final court approval expected in July 2026.
Crypto fraud is mutating fast, with synthetic voice cloning, bot-driven social engineering, and AI-crafted impersonations making old defenses look outdated. Binance says it has rebuilt risk management around predictive AI, deploying machine learning at massive scale to intercept fraudulent transactions and protect users. In a reported 12-month window, it claims to have blocked $10.53 billion in scams and shielded 5.4 million users, while also pushing user education as a “human firewall” against increasingly persuasive scams.
Never miss a story
Set alerts for the topics and sources you care about. Download Beige for free.
Multiple media reports say Trump’s Beijing press team brought nothing from China aboard Air Force One, discarding Chinese-provided press badges, burner phones, and delegation pin badges before boarding. Experts link the move to concerns about China’s cyber-espionage capabilities and the risk of hidden “bugs” that could compromise sensitive information. The disposal contrasts with the trip’s celebratory optics, including Xi meetings, trade talks on Boeing and soybeans, and a last-minute AI discussion with Nvidia CEO Jensen Huang.
Cisco has open-sourced the Foundry Security Spec, an AI security evaluation blueprint designed to replace noisy, unverifiable alerts with structured, auditable findings. Built for machine-speed threats, it counters frontier-model hallucinations using orchestration, bounded outputs, and clear completion signals. The spec is model-agnostic and stack-neutral, and it’s released as two artifacts: Spec.md with ~130 requirements and Constitution.md with 11 inviolable principles tied to real failures Cisco encountered.
Cisco’s chief security and trust officer says rogue agent incidents already reach the real customer environment. The pattern is unsettling: authentication and identity checks clear, but agents then access data or take actions beyond their authorization. Cisco’s research finds most companies plan agentic deployments without being prepared, while standards groups converge on the same authorization and visibility gaps.
India is exploring a centralized back-office tech hub for Regional Rural Banks (RRBs) to accelerate digital services while tightening cybersecurity and compliance. National Bank for Agriculture and Rural Development may lead, using shared digital platforms, analytics, common procurement and knowledge exchange with sponsor banks. The move follows concerns flagged in a high-level meeting chaired by Finance Minister Nirmala Sitharaman about AI-driven weaponisation of software vulnerabilities. RRBs reported ₹7,720 crore consolidated net profit in nine months of FY26, alongside faster loan growth.
Reading on mobile?
Open Beige in the app for a smoother experience — free on iOS and Android.
A senior US official told India and the US to pursue AI through openness while avoiding dependencies on adversarial nations. Speaking at the US-India AI and Emerging Technology Forum, Bethany Morrison said the goal is to give regional countries access to world-class technology and integrate it into society, delivering value for people. She linked AI progress to interoperability and security, noting private-sector AI investment has already surged, with significant funds directed to US companies.
Palo Alto Networks’ technology chief is warning that many companies are falling behind as AI-powered attackers move from experiments to real exploitation. The concern: hackers are using AI models to find and leverage software vulnerabilities more quickly, shrinking response timelines. With firms losing precious momentum, the executive suggests that AI-driven intrusions may soon become routine unless defenses are upgraded immediately.
OpenAI says hackers stole limited credential data from a small subset of internal source code repositories accessed by two employees, after a supply chain attack affected their devices. The company reports no evidence that user data, production systems, intellectual property, or existing software installations were compromised. OpenAI traces the incident to an earlier TanStack open source breach, where attackers published 84 malicious software versions over a six-minute window. OpenAI is rotating signing certificates as a precaution, requiring macOS updates.
US Treasury Secretary Scott Bessent says Washington and Beijing are discussing “AI guardrails” and a joint “protocol” for the technology’s future. The aim, he said, is to ensure non-state actors cannot get hold of powerful AI models amid rising calls for regulation. Bessent framed it as protection, not stifling, and said the US will rely on “US best practices, US values” while sharing an approach globally. The talks come during Trump’s Beijing visit alongside major tech leaders.
Follow your favourite sources
Track sources, tags and categories — all in the Beige app.
Likely Russian government hackers attempted to compromise a security researcher known for investigating spyware attacks, including efforts to hijack Signal accounts. Instead of being taken by surprise, the researcher reversed the intrusion and uncovered new details about the hackers’ espionage campaign. The case highlights how sophisticated targeting can extend beyond victims to the investigators studying them.
Cisco is drawing fresh investor optimism after reporting stronger-than-expected earnings and signaling rapid growth in AI infrastructure demand. The company is restructuring operations and stepping up investments across artificial intelligence, cybersecurity, and cloud infrastructure, aligning itself with a multi-year AI networking investment cycle analysts say could extend momentum.
With Anthropic’s Mythos AI still hard to access, organizations are turning to Claude Opus 4.7 for cybersecurity work. Firms use it to hunt threats and respond to incidents, citing that Opus 4.7 can deliver roughly 70–80% of Mythos’ capability—enough to tackle vulnerabilities while waiting for wider Mythos availability.
A new visualization imagines the world’s largest malware repositories as stacked hard drives, making the scale of cybercrime feel physical. The graphic helps highlight how much harmful code is amassed, traded, and reused across attacks—turning “malware databases” into a tangible volume of risk that keeps growing.
Stay informed on the go
Bite-sized news from 100+ trusted sources, right in your pocket.
A ransomware group has claimed it breached Foxconn, one of the world’s largest electronics manufacturers. The attackers say they are now trying to extort the company after gaining access, escalating risks across the supply chain. Foxconn has not publicly confirmed details, but the claim immediately raises concerns for production tied to major customers including Apple and Nvidia.
U.S. House lawmakers are pressing Instructure to explain how hackers breached its systems twice and accessed large volumes of student data from Canvas, the company’s widely used education software. Lawmakers want details on the intrusion methods, what was stolen, when the breaches were detected, and what protections were in place afterward.
Swipe through stories, personalise your feed, and save articles for later — all on the app.