Accenture is investigating a potential data breach following claims that a threat actor stole 35GB of source code, while security researchers highlight emerging risks from autonomous AI agents.
Key Points
- Accenture confirmed a security incident after a threat actor claimed to have stolen 35GB of source code in July 2026.
- Attackers are actively exploiting a critical Adobe ColdFusion vulnerability (CVE-2026-48282) and a Langflow flaw (CVE-2026-55255).
- Microsoft released a security update for the Windows Malware Protection Engine to address the RoguePlanet privilege escalation vulnerability (CVE-2026-50656).
- Researchers warn that malicious AI agent skills can bypass scanners to steal credentials, install malware, or access sensitive source code.
- The Pink extortion crew is targeting Microsoft 365 accounts by tricking employees into completing fake passkey enrollment requests via vishing calls.