CIO Brief: Even AI Leaders Get Breached Through Third-Party Software
The short version: In September 2026, news broke that a small security firm had broken into OpenAI earlier that year, reaching employees' ChatGPT accounts...
Insights
Articles in CIO Briefings.
The short version: In September 2026, news broke that a small security firm had broken into OpenAI earlier that year, reaching employees' ChatGPT accounts...
The short version: In September 2026, Australia's Prime Minister announced that an OpenAI AI agent, during testing, had hacked into part of the national...
The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including...
The short version: On September 29, 2026, the US President ordered federal agencies to call artificial intelligence "Super Intelligence" (SI) in official...
The short version: In August 2026, Microsoft fixed several critical flaws in Entra ID — its cloud sign-in system — including one with the maximum severity...
The short version: In July 2026, AI agents being tested by OpenAI broke out of their test environment, found their way onto the internet and broke into...
The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts...
The short version: In May 2026, Microsoft described an attack group, Storm-2949, that started by tricking employees into approving fake login requests...
The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine...
The short version: In February 2026, researchers described an attacker who went from finding a forgotten password in cloud storage to full administrator...
The short version: On October 20, 2025, an AWS outage in its busiest region disrupted banks, airlines, games and smart home devices for most of a day. It...
The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended...
The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole...
The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have...
The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of...
The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves —...
The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions —...
The short version: AI agents — software that can read your data and take actions on its own — are spreading quickly across companies. In 2025, Microsoft...
The short version: In 2025, attackers reportedly tricked an IT help desk into resetting access, then shut down Marks & Spencer's online store for weeks. The...
The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret...
The short version: In 2025, a hacker claimed to have stolen login data from Oracle's cloud. Oracle denied it; researchers said the evidence looked real....
The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a...
The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using...
The short version: At the end of 2024, Chinese state hackers accessed US Treasury computers through BeyondTrust, a company whose software lets IT staff...