AI has enabled the hackers to also attack in newer ways and the AI infrastructures & applications have become new attack vectors for Hackers. AI enabled Adversaries are causing a race with shrinking runway to detect these breaches and address them as quickly as they are seen. Adversaries who are AI enabled have resulted in 89% more attacks recently . Here are a few examples:
PyPI Supply Chain Attack Compromises LiteLLM, Enabling the Exfiltration of Sensitive Information: https://www.infoq.com/news/2026/03/litellm-supply-chain-attack/
Axios Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads : https://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html
Top Cyber Security Threats to watch out for in 2026: Here
Incidents to draw our lessons to secure our Infrastructure, Applications & Users! http://www.foxbusiness.com/features/2017/09/22/cyber-hack-hall-shame.html
Mt Goh 2011: https://en.wikipedia.org/wiki/Mt._Gox
PLaystation Hack: https://www.extremetech.com/gaming/84218-how-the-playstation-network-was-hacked
Linked in 2012: https://en.wikipedia.org/wiki/2012_LinkedIn_hack (passwords were stolen)
Yahoo hacks (2012 to 2017): 2012: Yahoo Voices - poor infra, 2013 Mail: Phishing - account hijacking, 2014 Mail: Password breach, 2016: Server hack giving away personal info, 2016: forged cookies to gain access to user accounts without needing password.
Neiman Markus Hack 2014: http://abcnews.go.com/Business/hackers-steal-credit-card-data-neiman-marcus-customers/story?id=21499430
https://www.sans.org/reading-room/whitepapers/breaches/case-study-home-depot-data-breach-36367
https://www.csoonline.com/article/2130877/the-biggest-data-breaches-of-the-21st-century.html (including the attacks on Adobe , Adult Friend Finder, Canva, Dubsmash, eBay, Equifax, Heartland Payment Systems, LinkedIn, Marriott International, My Fitness Pal, MySpace, NetEase, Sina Weibo, Yahoo, Zynga)
https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents: Site provides a timeline of significant cyber incidents since 2006. We focus on cyber attacks on government agencies, defense and high tech companies, or economic crimes with losses of more than a million dollars
https://www.yahoo.com/finance/news/anonymous-wifi-data-still-privacy-160025823.html
With the rise of all-seeing and all-knowing tech, security is no longer achieved by simply placing a strip of tape over your laptop camera. In the case of Amazon Echoes and Google Homes, it’s not feasible to upturn a Dutch oven over your Alexa every time you want privacy, nor would you want to. With Google’s execution of the headphone jack, following Apple’s footsteps, wireless audio protocol will doubtless explode, and with it countless more stress points ripe for abuse. Here are a couple of examples to learn from:
https://en.wikipedia.org/wiki/WannaCry_ransomware_attack
https://www.huffingtonpost.com/healthline-/parental-warning-your-bab_b_11668882.html
Comprehensive List of Hacking incidents: https://en.wikipedia.org/wiki/List_of_security_hacking_incidents
Spectre & Meltdown: https://meltdownattack.com && https://www.csoonline.com/article/3247868/vulnerabilities/spectre-and-meltdown-explained-what-they-are-how-they-work-whats-at-risk.html.
Foreshadow: The vulnerability is a speculative execution attack on Intel processors that may result in the disclosure of sensitive information stored in personal computers and third party clouds. Great information available at https://en.wikipedia.org/wiki/Foreshadow_(security_vulnerability). Mitigation is through software patches at the moment but these patches bring with them a severe decrease in compute power. Real fix is expected to be next generation of Intel chips. To figure out the steps to protect your PC - please see https://www.howtogeek.com/362797/how-to-protect-your-pc-from-the-intel-foreshadow-flaws/. Pls Note that only PCs with Intel chips are vulnerable to Foreshadow in the first place. AMD chips aren’t vulnerable to this flaw. Most Windows PCs only need operating system updates to protect themselves from Foreshadow, according to Microsoft’s official security advisory. Just run Windows Update to install the latest patches. Microsoft says it hasn’t noticed any performance loss from installing these patches. Some PCs may also need new Intel microcode to protect themselves. Intel says these are the same microcode updates that were released earlier this year. You can get new firmware, if it’s available for your PC, by installing the latest UEFI or BIOS updates from your PC or motherboard manufacturer. You can also install microcode updates directly from Microsoft.
Cisco Smart Install Client Vulnerability: https://blog.talosintelligence.com/2018/04/critical-infrastructure-at-risk.html. Implication of this issue: https://www.bankinfosecurity.com/200000-cisco-network-switches-reportedly-hacked-a-10788
Cisco ASA Issue: https://arstechnica.com/information-technology/2018/02/that-mega-vulnerability-cisco-dropped-is-now-under-exploit/
Vulnerability Scan Inputs reported as part of US Govt certs: https://www.us-cert.gov/ncas/bulletins/SB18-092
2018 BGP Hijacking cases: Suspicious event hijacks Amazon traffic for 2 hours, steals cryptocurrency (almost 1,300 addresses for Amazon Route 53 rerouted for two hours). More on https://www.noction.com/blog/bgp-hijacking. A comprehensive BGP hijack scenarios to be protected against are also available at https://www.slideshare.net/apnic/learning-from-recent-major-bgp-routing-leaks
2016 US election hacks have been enabled by sphear
POLICY recommendations to Implement: Mutually Agreed Norms for Routing Security: Learn more about MANRS here. Implement the four actions for network operators and join the community of security-minded operators working together to make the Internet safer for everyone.
Here are a few examples:
Comprehensive List of Data Hacks: https://en.wikipedia.org/wiki/List_of_data_breaches
Equifax Breach: https://www.wired.com/story/equifax-breach-no-excuse/
HBO 2017 breach: https://www.scmagazine.com/hbo-breach-accomplished-with-hard-work-by-hacker-poor-security-practices-by-victim/article/680568/
irs 2015 breach: https://qz.com/445233/inside-the-irss-massive-data-breach/
Ashley Madison Hack: https://en.wikipedia.org/wiki/Ashley_Madison_data_breach
Sony Pictures Hack: https://en.wikipedia.org/wiki/Sony_Pictures_hack. One Lesson learnt: When you entrust your personal and sensitive information to someone else, what control do you have over where it goes next?https://www.huffingtonpost.com/david-m-kirby/lessons-from-the-sony-pic_b_11800356.html
Target 2014: http://bgr.com/2014/03/13/target-data-hack-how-it-happened/. http://www.zdnet.com/article/anatomy-of-the-target-data-breach-missed-opportunities-and-lessons-learned/
Hackers are constantly looking for ways to scan and attack vulnerable users. Here are a few examples:
Malware & USer device Vulnerabilities as well as Annoying User social media engineering across various industry verticals: Statistics
Spear-Phishing has enabled the following malicious attacks on countries https://www.cnbc.com/2017/10/11/north-korean-hackers-target-us-electric-companies-with-malicious-emails.html, https://www.axios.com/the-details-on-how-the-russian-election-hacking-operation-1531524151-65e6fab7-e61e-43c7-93e4-42361590c4b1.html
Ransomware attack: WannaCry ransomware attack infected hundreds of thousands of computers worldwide and crippled parts of Britain’s National Health Service.
Other such High Profile Cyber Attacks: Here
CY2025-2026 Breaches: Here
To find ways to avoid these "oops" in your Organization, pls contact our Sarsu Team: info@sarsu.org