HackMyIP
← Back to News
2026-06-12 SecurityWeek

Google Cybersecurity Layoffs, $400M Coupang Fine & LiteLLM Patch

Data BreachRegulationAI Security

This week in cybersecurity saw a wave of high-impact developments spanning government accountability, corporate breaches, and AI security. A former IBM cybersecurity executive has filed a whistleblower lawsuit accusing IBM and AT&T of concealing repeated foreign government-linked intrusions from federal regulators. The complaint alleges the companies issued false security assurances to retain lucrative government contracts, in violation of U.S. disclosure requirements. Separately, the University of Oxford disclosed a data breach affecting its CareerConnect alumni platform, where attackers accessed names, email addresses, and encrypted passwords belonging to alumni, research staff, and employer accounts. Students were not impacted because they authenticate through Single Sign-On. Anyone concerned about exposure can verify their credentials using an email breach checker, and should immediately rotate any reused passwords by running them through a password checker that flags weak or compromised credentials.

In the corporate security space, Google Cloud has reportedly begun layoffs targeting its Mandiant team and the Google Threat Intelligence Group (GTIG), though the company has not confirmed specific numbers or responded to press inquiries. The reductions come as defenders face an evolving AI threat surface. To help incident responders keep pace, Microsoft published a new practitioner's playbook outlining structured methodologies for investigating security incidents in Microsoft 365 Copilot and Azure AI Services, mapping traditional response workflows onto the unique telemetry generated by modern AI platforms.

On the regulatory and vulnerability front, CISA added CVE-2026-42271, a critical command injection flaw in the BerriAI LiteLLM AI gateway, to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild exploitation, mandating federal agency patching. The disclosure highlights the rapidly expanding attack surface of LLM infrastructure, where a single gateway flaw can expose downstream AI applications. Rounding out the week, South Korea's Personal Information Protection Commission imposed a record $400 million fine on e-commerce giant Coupang for systemic security failures that exposed the personal data of more than 30 million customers. The penalty, among the largest data protection fines ever issued in Asia, signals escalating regulatory consequences for negligent data stewardship. Users can audit their own digital exposure with a privacy checkup to identify where their information may be circulating online.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →