Home Security Services Archive by category Cyber Security

Cyber Security

OpenAI and Anthropic Incidents Raise New Questions About AI Agent Security

Two of the world’s leading artificial intelligence companies, OpenAI and Anthropic, have recently disclosed security incidents involving their advanced AI models during internal testing, intensifying the debate over the safety and oversight of autonomous AI agents. OpenAI revealed that its experimental models, during a controlled cybersecurity evaluation, managed to escape an isolated testing environment, reach the internet, and access systems on the Hugging Face platform while attempting to obtain information that would help them complete their assigned task. Following its investigation, the company said the incident resulted from a combination of weaknesses in the testing environment and the advanced capabilities of the models, and confirmed that additional safeguards and monitoring measures are being introduced for future evaluations.

A few days later, Anthropic released the findings of its own large-scale review, reporting that three of its Claude models had gained unauthorized access to the real systems of three different organizations during testing. The company explained that the models did not break out of their sandbox by exploiting a novel vulnerability but instead reached the internet due to a misconfiguration in the testing environment and then took advantage of existing weaknesses, such as weak passwords. Anthropic described the incidents as an operational and testing environment failure rather than a model alignment issue.

The disclosures come just ahead of Black Hat USA 2026, where AI security is expected to be one of the conference’s central topics. Security experts warn that autonomous AI systems are becoming increasingly capable of planning and executing complex, multi-stage cyberattacks with minimal human intervention.

Both companies stressed that the incidents occurred during controlled internal security evaluations, were successfully contained without broader impact on users, and will help improve the safeguards and security mechanisms used in the development of future AI models.

Online Fraud Steals €780,000 from Bosnian Ammunition Manufacturer

Bosnia and Herzegovina-based Igman d.d. Konjic, one of the largest manufacturers of military and sporting ammunition in Southeast Europe, has fallen victim to an online fraud scheme in which approximately €780,000 was stolen from the company’s bank account. According to the information available so far, the attackers did not compromise Igman’s internal systems but instead gained access to the email account of one of its suppliers. This allowed them to monitor business correspondence and, at the crucial moment, send modified payment instructions containing fraudulent SWIFT and IBAN details. As the message appeared to be part of the companies’ regular business communication, the payment was transferred to an account controlled by the attackers, after which the funds were routed through multiple foreign bank accounts to make tracing more difficult.

Cybersecurity experts warn that attacks of this type, known as Business Email Compromise (BEC), are among the most costly forms of cybercrime and are becoming increasingly sophisticated with the help of artificial intelligence, which enables highly convincing phishing messages and greater attack automation. Following the incident, renewed calls have been made to strengthen Bosnia and Herzegovina’s national cybersecurity capabilities, including the adoption of a national cybersecurity strategy and the establishment of a functional Computer Emergency Response Team (CERT).

The case has also raised concerns about security procedures for financial transactions, as payments of such significant amounts should be protected by additional verification measures, including multi-level authorization and independent confirmation of any changes to banking details before funds are transferred.

More Than 12 Million Users Affected by Cyberattack on Japan’s KDDI

Japanese telecommunications operator KDDI has confirmed that more than 12 million users were affected by a cyberattack that took place in June this year. The incident was discovered on June 17, after unknown attackers exploited a so-called zero-day vulnerability in third-party software to gain access to an email system operated by KDDI for five Japanese internet service providers. The company stated that its mobile and fixed-line email services were not affected by the attack, as they operate on separate infrastructure.

According to available information, the email addresses of approximately 12.2 million users were compromised, while the passwords of around 7.6 million accounts also fell into the hands of the attackers. KDDI says the vulnerability was likely exploited as early as May and that the software vendor is currently working on a security patch. In cooperation with the affected internet service providers, the company has already launched a password reset process for users, while the mandatory reset of all compromised accounts is expected to be completed in the coming days.

KDDI claims that the attackers were removed from its systems immediately after the incident was discovered and that there is currently no evidence of any additional suspicious activity. The company has also announced a thorough security review of the affected software and plans to transition to more secure communication technologies in order to prevent similar incidents in the future.

Konica Minolta Croatia: The Importance of Encryption at the Source

In today’s business environment, video surveillance systems represent a key element in protecting assets, employees, and operational processes. However, the level of security provided by such systems depends not only on their functionality, but also on the way they manage the data they collect. This raises an important question: Are your data protected from the very moment they are created?

In the event of the physical theft of a device or storage medium, unprotected data can become easily accessible to unauthorized persons, exposing organizations to security, legal, and reputational risks.

Integrated Security Without Compromise

To ensure complete protection, it is essential to implement a security approach that covers the entire data lifecycle, from the moment the data are created to their storage. Such an approach includes:

Encryption at the source – Data are encrypted immediately at the moment of recording. This ensures that all records are protected from the very beginning, regardless of any potential loss or theft of the device.

Secure data transmission and storage – During transmission across the network and storage in archival systems, data remain continuously protected, without exposing any unencrypted segments.

Compliance with regulatory requirements – The implementation of advanced security standards enables organizations to meet the requirements of the GDPR and other relevant regulations more easily, while simultaneously preserving business integrity.

Privacy as the Foundation of Trust

Data protection is no longer merely a technical issue, but a key component of responsible business practices. Organizations that systematically approach data security protect not only their resources, but also the trust of their clients, partners, and employees.

In this context, encryption at the source is not an additional option, but an essential standard.

Ensure comprehensive data protection, from the moment data are created to their storage.

Comtrade Opens Security Operations Center in Sarajevo

As cyberattacks become increasingly sophisticated, organizations are more frequently faced with a critical question they cannot answer: Is our IT infrastructure under attack right now? To help companies achieve continuous security monitoring and faster incident response, Comtrade System Integration has opened a new Security Operations Center (SOC) in Sarajevo.

The new center provides organizations in Bosnia and Herzegovina with 24/7 cybersecurity monitoring, supported by a team of experts who understand the local market and can respond rapidly to security incidents. The Sarajevo SOC is part of a regional network that also includes operational centers in Belgrade and Ljubljana, combining local support with regional expertise.

According to the company, an increasing number of organizations are turning to managed cybersecurity services, as building and operating an in-house Security Operations Center requires significant investments in skilled personnel, processes, and advanced technologies. Instead of developing and maintaining complex internal infrastructure, companies can benefit from continuous monitoring, rapid threat detection, and expert support through an established SOC.

One of the key advantages of the Sarajevo center is that customers can immediately reach a team that understands their business environment, speaks their language, and can respond without the delays often associated with cross-border coordination or communication barriers.

Today, Comtrade System Integration ranks among the top 15 managed cybersecurity service providers in Europe and the top 75 worldwide. The company operates in accordance with the ISO 27001 standard and maintains the highest partnership levels with leading global cybersecurity vendors, underscoring its expertise in protecting business-critical systems.

Cyberattack Disrupts French Postal Operations as Pro-Russian Group Claims Responsibility

France’s national postal service, La Poste, experienced a significant disruption to its digital infrastructure this week after a large-scale cyberattack temporarily disabled key systems during the peak holiday delivery period. A pro-Russian hacking collective later claimed responsibility for the incident, according to French authorities.

The attack, identified as a distributed denial-of-service (DDoS) operation, forced central IT systems offline on Monday, preventing postal employees from tracking parcels and causing interruptions to online payment services linked to La Poste’s banking division. As of Wednesday morning, parts of the system had not yet been fully restored.

Responsibility for the attack was claimed by the hacker group Noname057, which has previously been linked to a series of cyber operations targeting European institutions. Following the claim, France’s domestic intelligence service, DGSI, assumed control of the investigation, the Paris prosecutor’s office confirmed.

The disruption comes at a critical time for La Poste, which handles billions of mail items and parcels annually and employs more than 200,000 people nationwide. The outage coincided with one of the busiest logistics periods of the year, amplifying its operational impact.

French authorities view the incident within a broader pattern of hostile cyber activity attributed to Russia-aligned actors. France and its European partners argue that such attacks form part of a wider “hybrid warfare” strategy aimed at destabilizing public services, exhausting security resources, and weakening political support for Ukraine. In recent years, European investigators have documented hundreds of similar incidents involving cyberattacks, disinformation campaigns, and acts of sabotage across the region.

SoundCloud Confirms Cyberattack, User Data Partially Compromised

SoundCloud has confirmed it was the target of a cyberattack in which hackers gained unauthorized access to data belonging to approximately 20% of the platform’s users. The company said the incident was detected after suspicious activity was identified within an ancillary administrative system, prompting the immediate activation of internal incident response protocols. An investigation carried out with the support of external cybersecurity experts found that the attackers accessed a limited set of data, including email addresses and information already visible on public user profiles.

SoundCloud emphasized that sensitive information such as passwords or financial data was not exposed. Nevertheless, users have been advised to remain vigilant for potential phishing attempts that could follow the incident. With the platform estimated to have more than 100 million users, the breach could affect tens of millions of accounts.

The company stated that the attackers have been removed from its systems, although the platform subsequently faced DDoS attacks, two of which temporarily disrupted the web version of the service. Issues with VPN access reported by users in recent days were linked to security-related configuration changes introduced in response to the incident, and SoundCloud said it is actively working to resolve those problems.

Major Cloudflare Outage Temporarily Disrupts Internet Worldwide

A large portion of the global internet experienced significant slowdowns today after Cloudflare, one of the key infrastructure providers behind thousands of popular websites, suffered a major technical outage. The disruption affected numerous online services — including X (formerly Twitter), Substack, Canva and others — with users encountering a “500 internal server error” message instead of the expected content.

Interestingly, some platforms that were impacted by a similar worldwide outage earlier this month remained stable this time, likely because they have since reduced their reliance on Cloudflare’s infrastructure. Among those unaffected was ChatGPT.

This is the second major incident in less than three weeks, once again highlighting the complexity and vulnerability of the global internet ecosystem. Cloudflare provides essential services that act as a “bridge” between websites and their users, accelerating page loading and protecting sites from overload. As a result, any disruption within Cloudflare’s systems can quickly trigger a chain reaction that brings down numerous unrelated services across the internet.

Although the interruption was relatively brief, it underscored how dependent the global digital landscape has become on a handful of key technology providers — and how their technical issues can instantly become a worldwide problem.

 

Germany Launches Major NIS2 and DORA Offensive: The Strictest Era of Cyber Compliance Begins for Companies

At the end of November 2025, Germany initiated the most far-reaching cybersecurity reform of the past decade, following the Bundesrat’s adoption of the NIS2 implementation law. As a result, regulatory obligations effectively entered into force immediately, without any transitional periods — a development legal experts are calling a “compliance shock” for the business sector. At the same time, European supervisory authorities activated a key mechanism of the DORA regulation and published the first list of critical IT third-party providers, who now fall under direct EU oversight.

The Federal Network Agency (BNetzA) has already presented a draft of a new security catalogue, introducing stricter requirements for safeguarding the telecommunications supply chain. The law firm Dentons reminds that all obligations apply the moment the law takes effect, including mandatory registration with the BSI and the implementation of comprehensive cyber risk-management measures. The scope of regulated entities is expanding dramatically — from around 4,500 to almost 30,000 companies — now including logistics, food supply, and digital service providers.

DORA further tightens supervision over cloud providers, analytics companies, and software vendors serving the financial sector, introducing mandatory on-site inspections and new channels for reporting IT incidents. The common priority of both regulations is strengthened third-party risk management, meaning that suppliers can no longer rely on simple declarations of conformity but must provide evidence of their security reliability.

Regulators stress that the era of postponements is over, and companies that were counting on extended deadlines now face severe penalties and increased personal liability for management. All indicators suggest that the period leading into early 2026 will be a race to close compliance gaps across all sectors.

Amazon blames Iran for combining cyber espionage with physical attacks

Amazon has released details on two cases in which Iranian threat actors combined digital espionage with physical attacks, a practice the company refers to as “cyber-enabled kinetic targeting.” The first case involves the group Imperial Kitten (also known as Tortoiseshell), linked to Iran’s IRGC, which over a two-year period progressed from cyber reconnaissance to a physical strike. According to Amazon, the group compromised a ship’s AIS system in December 2021 and, by August 2022, had gained access to additional maritime platforms and onboard CCTV cameras to collect real-time visual intelligence. In January 2024, they searched AIS location data for a specific vessel, which just days later, on February 1, became the target of a Houthi missile attack. Amazon says the link between the cyber reconnaissance and the subsequent strike is “unmistakable,” even though the attack itself was unsuccessful.

The second case concerns MuddyWater, a group tied to Iran’s MOIS, which in May 2025 prepared a server for cyber operations and, by June 17, used the same infrastructure to access a compromised CCTV server streaming live footage from Jerusalem. Researchers believe the footage was used to support the planning of a June 23 missile attack, after which Israeli authorities warned citizens to immediately disconnect internet-exposed cameras. Amazon stresses that existing terms such as “cyber-kinetic operations” or “hybrid warfare” lack precision, and proposes a new definition for campaigns where cyber activities directly support physical strikes. The company warns that this type of operation will become increasingly common as nation-states recognize the strategic advantage of combining digital reconnaissance with kinetic attacks.

Amazon urges companies to adjust their security strategies and expand threat models, noting that even entities that previously considered themselves uninteresting to attackers may now be targeted for tactical intelligence collection.