frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Major security breach at Austrian AI startup localmind.ai

https://localmind.ai/
9•tobwen•2h ago

Comments

tobwen•2h ago
I just came across this incident involving localmind.ai, a small AI startup out of Innsbruck, Austria (founded in early 2024). The company stated that internal processes and control mechanisms failed and accepted full responsibility for the incident.

This summary outlines the key events and remediation actions from the official incident reports published by Localmind.ai between October 5 and October 9, 2025.

Incident overview and initial response (October 5)

On October 5, 2025, at 05:43 CEST, Localmind detected unauthorized access to its systems. The immediate response was to take all affected systems, including internal platforms and customer instances, offline to contain the breach. Initial measures included:

  - Resetting all passwords and regenerating API keys (e.g., for Notion, SendGrid, Hetzner).
  - Deactivating all user accounts, restricting access to a minimal number of administrators with mandatory two-factor authentication (2FA).
  - Initiating a forensic investigation.
Root cause analysis (October 5, Update #2)

The breach originated from a misconfiguration in an externally accessible beta-test instance. The flaw granted administrator privileges by default to a newly registered account. The attacker used this access to:

  - Access the integrated automation platform (n8n).
  - Retrieve an unrestricted API key for the internal Notion knowledge base, which contained infrastructure documentation and credentials.
  - Use the compromised information to escalate access further and send emails from an internal account.
The company stated that internal processes and control mechanisms failed and accepted full responsibility for the incident.

Impact assessment and forensic Updates

  - Scope: The core Localmind platform was not compromised. The attack was confined to administrative interfaces and test environments. A limited number of customer systems were accessed, while on-premise instances showed no signs of unauthorized access.
  - Forensics: Unauthorized logins were traced to IP addresses from VPN providers, complicating attribution. Login activity occurred outside regular business hours (nights, weekends). As of October 8, no evidence of large-scale data exfiltration was found.
  - Data transparency: Localmind offered data exports to customers to conduct their own audits for potential GDPR breach notifications.
Remediation and security hardening measures

The company initiated a comprehensive infrastructure rebuild and security overhaul.

  1. New infrastructure: A migration of virtual machines to new, Tier IV, ISO 27001/27018 certified data centers with a fully isolated infrastructure was nearly complete as of October 8. Systems are being rebuilt from clean data volumes (e.g., Docker volumes) onto new, hardened hosts.
  2. Access security:
    - Implementation of an F5 Web Application Firewall (WAF) with pre-authentication for each customer instance.
    - Mandatory two-factor authentication (2FA) for all application logins.
    - Deployment of the Wazuh security agent for centralized login monitoring and anomaly detection.
    - All previous service accounts and credentials within automation workflows were deleted, requiring a re-issue.
  3. Automation restriction: Critical automation nodes in n8n (e.g., Execute Command, Read/Write File to Disk) were disabled and will be unavailable in cloud environments going forward.
  4. Enhanced monitoring: Additional security agents were deployed for endpoint security, configuration assessment, file integrity monitoring, and threat intelligence.
  5. Process change: Each customer instance undergoes a manual audit and documentation before restart, with the audit protocol provided to the customer.
Subsequent Attack Attempt (October 9)

On October 9, Localmind reported a renewed attempt to gain unauthorized access. The new security measures successfully blocked these attacks. The only confirmed impact was a brief, unauthorized text modification on a separately hosted, external development website, which was promptly reverted. The company attributes this attempt to the same threat actor.

Status as of latest update (October 9, 2025)

Systems were in a phased, controlled restart process, with customers being kept informed. The company continues to work on audits and security fortifications.

Sources (as Mementos)

<https://web.archive.org/web/20250000000000*/https://www.loca...> <https://web.archive.org/web/20250000000000*/https://security...>

Show HN: Compression-Resistant Data Transfers

https://github.com/ianling/steg-experiments
1•iaaan•3m ago•0 comments

Ksmbd – Exploiting CVE-2025-37947

https://blog.doyensec.com/2025/10/08/ksmbd-3.html
2•Bogdanp•11m ago•0 comments

PSOS-C and the Full Attribution Chain

https://www.aivojournal.org/closing-the-loop/
1•businessmate•14m ago•1 comments

Not Another GPT Wrapper

https://genorimo.com
1•robbschmidt•21m ago•1 comments

BalCCon2k25: Syd, an Advanced Introduction to Secure Application Sandboxing [video]

https://www.youtube.com/watch?v=B5cN9LrUYTE
1•hayali•29m ago•0 comments

A Tokyo commuters' poetic take on life [video]

https://www.youtube.com/watch?v=FM1GtQuSXP4
1•pbd•33m ago•0 comments

Spyware maker NSO Group confirms acquisition by US investors

https://techcrunch.com/2025/10/10/spyware-maker-nso-group-confirms-acquisition-by-us-investors/
18•corvad•33m ago•2 comments

Symposium: Exploring New AI Workflows

https://smallcultfollowing.com/babysteps/blog/2025/09/24/symposium/
2•aktuel•34m ago•0 comments

IPv6 neighbor discovery on EdgeRouter is not usable in real scenarios

https://github.com/urnetwork/ndppd
5•mulchpower•35m ago•1 comments

Thinking Machines Lab Co-Founder Andrew Tulloch Heads to Meta

https://techcrunch.com/2025/10/11/thinking-machines-lab-co-founder-andrew-tulloch-heads-to-meta/
1•jkw•43m ago•0 comments

The Alignment Problem Isn't Theoretical

https://www.lesswrong.com/posts/TKTijrrwtEFytAbhh/the-alignment-problem-isn-t-theoretical
1•AustinLikesAI•44m ago•0 comments

Famous Last Words Dr. Jane Goodall

https://www.netflix.com/title/82053197
1•rasengan0•46m ago•0 comments

Art about Mathematics (Rinus Roelofs)

https://www.nytimes.com/2025/10/10/science/mathematics-art-roelofs.html
2•gtsnexp•1h ago•2 comments

Monads are too powerful: The Expressiveness Spectrum

https://chrispenner.ca/posts/expressiveness-spectrum
2•hackandthink•1h ago•0 comments

The Case for Separating Thinking (GPU) and Compute (CPU)

https://www.gojiberries.io/decoupling-reasoning-from-compute/
1•neehao•1h ago•0 comments

Long Beach mandates staffing ratios at self-checkout lanes

https://www.latimes.com/business/story/2025-10-11/long-beach-checkout-lane-ordinance
2•ilamont•1h ago•0 comments

Pipelining in psql (PostgreSQL 18)

https://postgresql.verite.pro/blog/2025/10/01/psql-pipeline.html
5•tanelpoder•1h ago•0 comments

Gemini CLI Extensions for Figma

https://aicloudlab.substack.com/p/gemini-cli-extensions-for-figma
3•arjunprabhulal•1h ago•0 comments

Figure 03 [video]

https://www.youtube.com/watch?v=Eu5mYMavctM
2•LordNibbler•1h ago•1 comments

The Boundless Deep by Richard Holmes review – wild times with young Tennyson

https://www.theguardian.com/books/2025/oct/06/the-boundless-deep-by-richard-holmes-review-wild-ti...
5•lermontov•1h ago•0 comments

Welcome Floating design, Goodbye Flat design

https://blog.terrydjony.com/welcome-floating-design/
3•terryds•1h ago•1 comments

Free software engineer cover letter and resume tips generator

https://trylockedin.app/software-engineer/cover-letter
2•irfahm_•2h ago•0 comments

Zaparoo – Launch your digital collection through NFC cards

https://zaparoo.org/
4•novoreorx•2h ago•0 comments

Show HN: Radiopuppy.com – Minimal Web App for Listening to Online Radio

https://radiopuppy.com
3•devrundown•2h ago•1 comments

To what extent is the war in Gaza justified?

https://mathsandsoundingoff.wordpress.com/2025/06/23/to-what-extent-is-the-war-in-gaza-justified/
3•sxzygz•2h ago•3 comments

The iPhone Air is too pure for this world

https://www.creativebloq.com/design/product-design/the-iphone-air-is-too-pure-for-this-world
2•wahvinci•2h ago•0 comments

Show HN: Munshig – catches the API bug that cost Facebook 50M accounts

2•shaikhzaynsaif•2h ago•1 comments

Neighbor shielded 7-year-old during South Shore federal raid

https://chicago.suntimes.com/immigration/2025/10/10/neighbor-shielded-7-year-old-during-south-sho...
33•perihelions•2h ago•5 comments

Major security breach at Austrian AI startup localmind.ai

https://localmind.ai/
9•tobwen•2h ago•1 comments

Coral Protocol Open Infrastructure Connecting the Internet of Agents

https://arxiv.org/abs/2505.00749
6•joj333•2h ago•0 comments