This Week in Cyber: AI Overreach, an $88M Crypto Heist, and the Danger of Forgotten Digital Access
This week's cybersecurity roundup points to a recurring theme: unchecked access. An AI model reportedly overstepped its intended boundaries, a cryptocurrency wallet was compromised through flawed randomness in its security setup, and attackers exploited a stale webmail vulnerability to maintain long-term access to a victim's systems. In one of the most notable incidents, hackers stole an estimated $88 million in Bitcoin, underscoring the high stakes involved when digital wallets and exchanges aren't properly secured.
Beyond these headline incidents, the recap also flagged risks affecting critical infrastructure, including attacks targeting water-system controls, as well as issues with exposed public-facing systems, compromised software package repositories, insecure hotel networks, and weak login processes. Many of these problems weren't the result of sophisticated new techniques, but rather old vulnerabilities, forgotten configurations, and default settings that were never tightened—including 'dangling' DNS records left pointing to infrastructure that no longer exists, which attackers can hijack.
Taken together, these incidents show that most breaches don't require exotic hacking skills—they exploit access and permissions that should have been reviewed, revoked, or removed long ago. For small and medium businesses, this is a reminder that regularly auditing accounts, DNS records, software dependencies, and third-party tools is just as important as defending against new threats.