Cybernews by abat

Cybersecurity is a critical success factor for businesses of all sizes today. Here you’ll find the latest news, insights, and background information on IT security, cyber threats, and digital resilience. Our goal is to provide clear context for complex developments and highlight relevant trends early on. 

AI Carries Out Autonomous Cyberattack

On July 21, 2026, OpenAI and Hugging Face disclosed a security incident. During an internal audit, several of OpenAI’s AI models independently constructed an attack chain. Using an unknown zero-day vulnerability, they escaped the test environment and penetrated Hugging Face’s production systems. OpenAI describes this as an unprecedented cyber incident. Critics view this as a staged, PR-driven stunt – one that nonetheless demonstrates the already formidable capabilities of such models.

The incident confirms the BSI’s latest warning: AI reduces the effort and barriers to entry for attacks and is increasingly able to find vulnerabilities autonomously, even in real-world systems without source code. As a result, what matters most for companies is not so much whether vulnerabilities exist, but how far an automated attacker could go. Expansive SAP landscapes, in particular, offer a large attack surface for this purpose.

The BSI is not stopping at issuing a warning. With the AI Audit and Assurance Assessment Architecture (A5), it has presented a modular audit architecture for AI systems, currently in the form of a community draft. It is aimed at all stakeholders along the AI value chain – from development to operations to procurement—and provides criteria and a methodology for systematically evaluating the trustworthiness of AI systems. abat, as a provider of AI architectures and solutions, also incorporates security from the very beginning: through secure development, consistent monitoring, AI-assisted penetration tests, and thorough hardening.

Sources: 
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kuenstliche-Intelligenz/A5/A5_node.html

 

AI is changing the cybersecurity landscape – the BSI sees a fundamental shift.

In a new IT security bulletin, the BSI warns: Artificial intelligence is significantly accelerating the discovery and exploitation of vulnerabilities. Current systems are increasingly able to find and analyze security vulnerabilities largely on their own and turn them into effective attacks – no longer limited to simply crafting convincing phishing emails.
 
The problem is structural: AI reduces the effort, time, and barriers to entry for attacks. Attackers benefit from speed and automation, while defenses remain constrained by real-world operational limits.
 
This is exactly what we’re seeing at abat: In our cybersecurity division, we use the Frontier models of current LLMs to evaluate the impact on IT security and, above all, the threat landscape for SAP environments. This includes, on the offensive side, assisted penetration testing and the development of penetration testing tools and exploits, as well as, on the defensive side, the secure architecture of AI infrastructures and secure development with the help of AI.
 
The BSI’s recommendation against such current threats: reduce the attack surface, accelerate patching processes, and strengthen response capabilities.
 
But how can you reduce and harden the attack surface while simultaneously strengthening response capabilities? Especially when it comes to SAP environments, it’s helpful to look at things from the attacker’s perspective. How far could a potential attacker get with phished credentials? What business risks does this pose, and how seriously do they threaten the company? Such questions can be answered with a penetration test, which not only provides transparency into vulnerabilities that can actually be exploited but also offers prioritized recommendations for action with a clear business impact. At abat, we specialize in these tests – feel free to contact us for more information.

Infostealer Malware: 124 Million Passwords Compromised

On June 15, 2026, the data breach check service HaveIBeenPwned (HIBP) added approximately 56.3 million email addresses and 124 million passwords to its database. The data comes from so-called “stealer logs” – log files generated directly on victims’ devices by infostealer malware. The dataset is based on hundreds of millions of individual log entries; HIBP does not provide any information about their specific origin.

For companies with unhardened SAP environments, this creates several attack vectors: For example, via the proprietary SAP GUI client, operating system commands can be executed on the computers of all logged-in users on a compromised SAP system, using their respective local privileges. An attacker could exploit this vulnerability to install infostealers on end devices and thus attack virtually all of a company’s SAP workstations simultaneously. Compromised credentials and an insecure SAP system are therefore mutually reinforcing.

To proactively prevent attacks using these compromised credentials, companies should identify affected accounts via HIBP, implement security measures as necessary, and consistently roll out multi-factor authentication across all accounts. It is also recommended to actively scan the SAP system landscape for vulnerabilities. An SAP penetration test can determine whether an attacker could gain access to critical systems via these attack vectors.

AI Carries Out Autonomous Cyberattack

On July 21, 2026, OpenAI and Hugging Face disclosed a security incident. During an internal audit, several of OpenAI’s AI models independently constructed an attack chain. Using an unknown zero-day vulnerability, they escaped the test environment and penetrated Hugging Face’s production systems. OpenAI describes this as an unprecedented cyber incident. Critics view this as a staged, PR-driven stunt – one that nonetheless demonstrates the already formidable capabilities of such models.

The incident confirms the BSI’s latest warning: AI reduces the effort and barriers to entry for attacks and is increasingly able to find vulnerabilities autonomously, even in real-world systems without source code. As a result, what matters most for companies is not so much whether vulnerabilities exist, but how far an automated attacker could go. Expansive SAP landscapes, in particular, offer a large attack surface for this purpose.

The BSI is not stopping at issuing a warning. With the AI Audit and Assurance Assessment Architecture (A5), it has presented a modular audit architecture for AI systems, currently in the form of a community draft. It is aimed at all stakeholders along the AI value chain – from development to operations to procurement—and provides criteria and a methodology for systematically evaluating the trustworthiness of AI systems. abat, as a provider of AI architectures and solutions, also incorporates security from the very beginning: through secure development, consistent monitoring, AI-assisted penetration tests, and thorough hardening.

Sources: 
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kuenstliche-Intelligenz/A5/A5_node.html

 

AI is changing the cybersecurity landscape – the BSI sees a fundamental shift.

In a new IT security bulletin, the BSI warns: Artificial intelligence is significantly accelerating the discovery and exploitation of vulnerabilities. Current systems are increasingly able to find and analyze security vulnerabilities largely on their own and turn them into effective attacks – no longer limited to simply crafting convincing phishing emails.
 
The problem is structural: AI reduces the effort, time, and barriers to entry for attacks. Attackers benefit from speed and automation, while defenses remain constrained by real-world operational limits.
 
This is exactly what we’re seeing at abat: In our cybersecurity division, we use the Frontier models of current LLMs to evaluate the impact on IT security and, above all, the threat landscape for SAP environments. This includes, on the offensive side, assisted penetration testing and the development of penetration testing tools and exploits, as well as, on the defensive side, the secure architecture of AI infrastructures and secure development with the help of AI.
 
The BSI’s recommendation against such current threats: reduce the attack surface, accelerate patching processes, and strengthen response capabilities.
 
But how can you reduce and harden the attack surface while simultaneously strengthening response capabilities? Especially when it comes to SAP environments, it’s helpful to look at things from the attacker’s perspective. How far could a potential attacker get with phished credentials? What business risks does this pose, and how seriously do they threaten the company? Such questions can be answered with a penetration test, which not only provides transparency into vulnerabilities that can actually be exploited but also offers prioritized recommendations for action with a clear business impact. At abat, we specialize in these tests – feel free to contact us for more information.

Infostealer Malware: 124 Million Passwords Compromised

On June 15, 2026, the data breach check service HaveIBeenPwned (HIBP) added approximately 56.3 million email addresses and 124 million passwords to its database. The data comes from so-called “stealer logs” – log files generated directly on victims’ devices by infostealer malware. The dataset is based on hundreds of millions of individual log entries; HIBP does not provide any information about their specific origin.

For companies with unhardened SAP environments, this creates several attack vectors: For example, via the proprietary SAP GUI client, operating system commands can be executed on the computers of all logged-in users on a compromised SAP system, using their respective local privileges. An attacker could exploit this vulnerability to install infostealers on end devices and thus attack virtually all of a company’s SAP workstations simultaneously. Compromised credentials and an insecure SAP system are therefore mutually reinforcing.

To proactively prevent attacks using these compromised credentials, companies should identify affected accounts via HIBP, implement security measures as necessary, and consistently roll out multi-factor authentication across all accounts. It is also recommended to actively scan the SAP system landscape for vulnerabilities. An SAP penetration test can determine whether an attacker could gain access to critical systems via these attack vectors.

Contact our expert for cybersecurity