AUTO-UPDATED

Week in review: Accenture data breach, great open-source cybersecurity tools

Accenture is investigating a potential data breach following claims that a threat actor stole 35GB of source code, while security researchers highlight emerging risks from autonomous AI agents.

Key Points

  • Accenture confirmed a security incident after a threat actor claimed to have stolen 35GB of source code in July 2026.
  • Attackers are actively exploiting a critical Adobe ColdFusion vulnerability (CVE-2026-48282) and a Langflow flaw (CVE-2026-55255).
  • Microsoft released a security update for the Windows Malware Protection Engine to address the RoguePlanet privilege escalation vulnerability (CVE-2026-50656).
  • Researchers warn that malicious AI agent skills can bypass scanners to steal credentials, install malware, or access sensitive source code.
  • The Pink extortion crew is targeting Microsoft 365 accounts by tricking employees into completing fake passkey enrollment requests via vishing calls.

Why it Matters

The rapid integration of autonomous AI agents into corporate workflows is creating new, unmonitored attack surfaces that traditional security tools are currently ill-equipped to defend. Organizations must now prioritize governance over AI access and update their patch management strategies to counter the accelerated exploitation timelines enabled by these advanced technologies.
Help Net Security Published by Help Net Security
Read original