Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Supabase Data Exposure | 16,000+ Open Databases and What Security Teams Can Do

We found more than 16,000 Supabase databases sitting wide open, and over half held personal data like names, phone numbers and passwords. The organizations behind them ranged from a valet service to a government consulate, and in many cases the owners never checked the settings AI wrote. What is the Supabase data exposure? Anyone visiting these sites could read the data in their databases. Many belong to vibe-coded apps, where AI coding tools often handle the database setup.

ASOS Cyber Incident: CYJAX on the Third-Party Risk Facing UK Retailers.

On 6 October 2026, ASOS customers received an extortion message through the retailer's own app claiming its Snowflake instance had been compromised. CYJAX looks at what happened, why third-party and cloud platform risk sits at the centre of the incident, and how organisations can monitor their extended supply chain before attackers do. By now, most people in the UK will have heard about the cyber incident that hit ASOS on 6 October 2026.

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling.

ASOS Cyber Attack: What IT Leaders Can Learn About Third-Party Risk

The ASOS cyber attack reported on 6 October 2026, has raised fresh questions about third-party access, SaaS security and how modern organisations manage an increasingly connected attack surface. The incident became public in an unusual way: customers received an unauthorised mobile push notification through the ASOS app claiming the retailer had been compromised. ASOS later confirmed that basic personal information, including names and contact details, may have been accessed.

Autonomous Attacks Are Already Here. The Defense Has to Match Their Speed.

Last week, Snyk CTO Manoj Nair sat down with Alon Krifcher, Head of Applied AI from Anthropic, for a live discussion on the coming wave of autonomous attacks. Manoj kept landing on one thing: the AI Hurricane has already arrived, and what's left is deciding whether your defense runs at the same speed as the threat.

Continuous Attacker Emulation: Testing Controls Between Annual Assessments

Security controls are built to stop attackers, but most organizations only find out whether those controls actually work once a year, during a scheduled assessment. In the months between those engagements, configurations change, new tools get deployed, and remediation work from the last test either holds up or quietly fails without anyone noticing. Continuous attacker emulation exists to close that gap, giving security teams an ongoing read on their actual exposure rather than a single snapshot frozen in time.

Frontier AI Impact Series, Part 1: Why Attackers Stopped Waiting for Zero-Days | Bitsight

Frontier AI can shrink weeks of vulnerability research into exploitation in hours. What does that mean for the flaws your team deprioritized years ago? Bitsight’s Emma Stevens, Senior Threat Intelligence Advisor, breaks it down in the first video of our new series.

Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers

Modern frontier AI models deploy safety classifiers. These are second AI models that sit between the user and the frontier model, evaluating every request in real time. If a request is flagged as harmful, the classifier blocks it before the model can respond. Significant investment and safety model expertise have made these classifiers effective. Anticipating how adversaries circumvent these systems is a security problem that requires different expertise.

[Cybersecurity Awareness Month] Cyber Espionage: When the Attacker's Best Asset Is You

Spies have always relied on technology, disguises, secret communications and clever gadgets, at least if the movies are to be believed. But some of the most effective tools in the espionage business have always been people. Convince the right person to open a door, reveal a secret or trust someone they should not, and suddenly bypassing the sophisticated security system becomes unnecessary.