Spain Reports an AI-Agent Data Breach, Plus 4 Stories
An AI agent is now part of a real data-breach report
Spain’s data-protection regulator has received what it says is its first notification of a personal-data breach allegedly carried out by an AI agent. That sentence needs two qualifiers right away: the affected organization reported the incident to the regulator, and the regulator is still reviewing what happened. We don’t know the organization, the language model involved, or how many people were affected.
Even with those caveats, this is worth paying attention to.
According to Spain’s AEPD, the agent used a well-known large language model, successfully logged into the target system, searched for application weaknesses, found one, altered personal information and accessed billing records. The part that makes this different from “somebody asked ChatGPT how to hack a website” is autonomy. The regulator says the agent carried out multiple stages of the attack with limited human intervention.
That does not mean the model broke loose, that the AI provider was compromised, or that somebody built the model for cybercrime. AEPD explicitly says none of those conclusions follows from this report. It also says one incident is not enough to establish a trend.
What it does show is why I think “AI attacks” is often the wrong mental model. The underlying jobs here are familiar: authenticate, inspect, find a weakness, exploit it, move to the next step. AI didn’t invent any of those. It potentially compressed them into one faster, more adaptable workflow.
That changes the defensive clock. If an attacker can hand an agent a goal and let it work through a chain of ordinary weaknesses faster than a human operator would, security teams get less time between “something odd happened” and “the attacker is already doing the next thing.” The practical response is not an AI panic button. It’s boring security done faster: tightly scoped credentials, fewer unnecessary agent permissions, rapid patching, useful logging, automated detection, and the ability to shut down a suspicious identity or process quickly.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
CenterPoint confirms customer information was stolen
CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through one of the utility’s external-facing systems.
That is the confirmed part.
A hacker posting on a cybercrime forum claims to have taken nearly 7.5 million customer records and released a 2.5-gigabyte archive. SecurityWeek says it could not independently verify that archive, and CenterPoint has not confirmed the attacker’s number. So “7.5 million CenterPoint customers breached” is still a claim, not a fact.
CenterPoint’s SEC filing says electric and natural-gas delivery were not disrupted. The company is still determining which customers and which kinds of personal information were affected, has brought in outside cybersecurity experts, reported the incident to law enforcement, and says it will notify affected customers and regulators as required.
That separation matters because an attack on a utility sounds immediately like an attack on the grid. This one, based on what CenterPoint has disclosed so far, is a customer-data incident involving an internet-facing system, not an interruption of electricity or gas service.
For customers, there isn’t enough public detail yet to justify guessing about which identity documents or financial accounts might need action. The sensible move is to watch for a direct notice from CenterPoint and be skeptical of anyone who uses the breach as an excuse to call, text or email asking you to “verify” account information. A real breach creates a very convenient story for the next scammer.
A third-party WooCommerce plugin is under active attack
This one needs a naming correction before anything else: WooCommerce itself is not the vulnerable software.
Attackers are exploiting CVE-2026-27540 in a premium third-party WordPress plugin called WooCommerce Wholesale Lead Capture. Wordfence rates the flaw critical and says versions through 2.0.3.1 are vulnerable. The fix, version 2.0.3.2, has actually been available since February.
The vulnerability is an unauthenticated arbitrary-file upload. The plugin exposes an AJAX upload action and then trusts a user-controlled setting to tell it which file extensions are allowed. An attacker can essentially add PHP to the guest list, upload a PHP webshell without logging in, and gain a foothold that can be used to run code and upload more malicious files.
Wordfence says it has blocked more than 100,000 exploitation attempts, with attack spikes stretching back into June. That makes this another good example of why “a patch exists” and “the problem is over” are very different statements.
If a site uses WooCommerce Wholesale Lead Capture, update it to 2.0.3.2 or newer now. But if an older version was publicly exposed during the attack window, don’t stop at the version number. Wordfence recommends checking upload directories for unexpected PHP files, reviewing logs for requests to wp-admin/admin-ajax.php that invoke the vulnerable upload handler, and looking for unfamiliar administrator accounts. If the site is actually compromised, restoring from a known-good backup may be safer than trying to guess whether every backdoor was removed.
And again: this is a plugin that integrates with WooCommerce. It is not a core WooCommerce vulnerability. That distinction is boring right up until somebody reads a headline and starts updating the wrong thing.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
Microsoft issued emergency Windows updates after Patch Tuesday broke RDS
Last week’s Windows security updates fixed two vulnerabilities already being exploited in the wild. They also managed to break Remote Desktop Services badly enough that Microsoft has now released out-of-band updates.
On affected systems, RDS can become unstable, causing Remote Desktop connections and sign-ins to fail or, in some cases, leaving servers unresponsive. Related tools including Microsoft Management Console, the RDS Licensing Diagnoser, File Explorer and the Windows Update page can also hang. Microsoft says the September updates also caused separate Hyper-V folder-sharing and USB-audio problems on some systems.
The important part for administrators is not to “fix” this by uninstalling the September security update and leaving the machine exposed. Microsoft now has out-of-band fixes for current Windows 10 and Windows 11 releases and for Windows Server 2019, 2022 and 2025. Windows 11 24H2 and 25H2 get KB5129195.
There is still a wrinkle: Microsoft says the emergency update fixes some multichannel USB Audio Class 1.0 failures, but not every audio problem introduced by the September update. It is still working on the remaining no-audio and device-start failures.
So if Remote Desktop fell apart after Patch Tuesday, there is now a proper repair path. Use the out-of-band update rather than rolling back security fixes and hoping nobody notices the window you reopened.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
The memory shortage is becoming a small-vendor problem
Ten days ago I wrote about AI data centers helping drive up memory prices. The next stage is showing up now: for smaller phone and laptop makers, this is becoming less about what memory costs and more about whether they can get enough of it at all.
Reuters spoke with Fairphone, Framework and Finnish phone maker Jolla. Executives said availability is becoming the binding constraint, and some expect the shortage to remain ugly through 2027. SK Hynix’s CEO said in July that 2027 could be the worst supply year in the industry’s history, with demand exceeding capacity beyond 2030.
The smaller companies are adapting in very physical ways. Jolla designed two motherboard variants so it can swap between combined and discrete memory packages. Framework’s modular design lets customers reuse RAM from older machines. Jolla is testing samples from every incoming batch to make sure supposedly new chips are not refurbished parts being resold into a hot market.
That last part is where a supply shortage turns into a security and quality problem. Scarce, expensive components create an incentive for questionable inventory to enter the channel. Small manufacturers also can’t always buy years of supply in advance the way a giant vendor can.
For consumers and small businesses, this doesn’t mean every laptop is about to disappear. It does mean the cheap end of the market is under pressure, lead times can get weird, and assuming next year’s equivalent hardware will automatically cost less is still a bad budgeting strategy. If a business has a predictable refresh coming, I’d plan around the useful life of the machines it already owns, keep replacement options flexible, and avoid waiting until a dead laptop forces a same-day purchase.
The AI boom still looks like software on a screen. Increasingly, its constraints look like factories, power plants, cables, memory chips and whoever managed to reserve the parts first.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Spanish Data Protection Agency: First notification of a personal-data breach caused by an attack executed through an AI agent
- Reuters: Spanish data watchdog publicises first AI agent-linked data breach report
- CenterPoint Energy: September 14, 2026 Form 8-K
- SecurityWeek: CenterPoint Energy confirms breach after hacker leaks data
- Wordfence: CVE-2026-27540 vulnerability details
- BleepingComputer: Hackers target WordPress sites via third-party WooCommerce plugin
- Microsoft: KB5129195 out-of-band Windows 11 update
- BleepingComputer: Microsoft releases emergency Windows updates to fix RDS failures
- Reuters: Smaller phone and laptop makers dig in for years of memory scarcity
