All case studies
Every Cyber Casebook case study, newest first. Each one links to a classroom-ready PDF and the original news report.
October 2026
- Shut Down, Then PatchCybersecurity · BleepingComputer — A maximum-severity flaw in Kiteworks' email gateway could let attackers take full control, days after the company told customers to go offline.
- Cash on CommandCybersecurity · SecurityWeek — Crews broke into ATMs across the U.S. and planted malware that made them spit out cash. Now the U.S. Treasury has sanctioned the network behind it.
- The Snake That Never WasAI · NBC Los Angeles — A man used an AI-made photo to report a deadly viper loose in a California neighborhood, and police sent a public alert before learning it was fake.
- The Fake Zoom TrapCybersecurity · Infosecurity Magazine — A fake Zoom installer for Macs talked users into switching off a built-in safety check, then quietly planted a backdoor for attackers.
- Nine Days to LockdownCybersecurity · Dark Reading — Attackers broke in through unpatched SharePoint servers and, in one case, went from first foothold to locked computers in just nine days.
- The Copycat CampaignAI · OpenAI — OpenAI says users tied to China's Moonshot AI sent crafted requests to pull hidden reasoning from its models, which could help train a rival.
- The Invoice BreachCybersecurity · The Record — A flaw in Poland's popular Fakturownia invoicing service let an attacker reach company records, password hashes, bank details, and access tokens.
- Fake GPT, Real TrapAI · Dark Reading — Scammers built fake helpers inside ChatGPT that sent users to a bogus check page and tricked them into installing spying software.
- Nine Months UndetectedCybersecurity · BleepingComputer — Hackers used a flaw in a Pentagon file-sharing system to reach the personal records of more than 3 million people, and nobody noticed for nine months.
- The Permission PuzzleAI · TechCrunch — Days after Meta launched its Muse AI agent, a columnist said it read his private texts without permission. Meta says that is impossible.
- Mail Server Under SiegeCybersecurity · SecurityWeek — Attackers broke into Zimbra email servers through a flaw that was quietly patched in July, before most admins knew it needed fixing.
- The Prompt That LeakedAI · AsiaOne — A worker asked an AI tool to write code for a marketing email but never said to hide addresses, so customers could see each other's emails.
- Keys Left in the OpenCybersecurity · BleepingComputer — Researchers found more than half a million passwords and keys sitting in public GitHub code, and most had never been cancelled by their owners.
September 2026
- The Bots Get Locked OutAI · TechCrunch — Reddit is shutting its RSS feeds and public API, blaming AI bots that scrape posts at huge scale, and pushing developers toward approved access.
- Spy in the PocketCybersecurity · The Record — Ukraine warns that Russia-linked hackers are hijacking soldiers' and officials' phones through infected websites, stealing messages in minutes.
- Hacked by an AI AgentAI · BleepingComputer — An autonomous AI agent chained two unknown flaws in a help-desk tool to break into a volunteer security group's network, reaching root in seconds.
- The $387M HeistCybersecurity · BleepingComputer — Hackers slipped into crypto exchange Bitget through flaws in two of its own security devices, then drained $387.5 million in about three hours.
- The Voice on TrialAI · The Next Web — A Tokyo court ruled for the first time that a person's voice is protected from AI copies used to make money, even as it dismissed the actor's case.
- The Network Master KeyCybersecurity · The Hacker News — A critical flaw in Cisco's network control software let attackers act as the top administrator without entering a password, and some already did.
- AI Agents OversharedAI · The Hacker News — Coding assistants trying to share screenshots quietly posted thousands of private company images to public GitHub pages, including billing records.
- Fake InvitationsCybersecurity · SecurityWeek — Russian state hackers posed as officials and think tanks, using fake messages to slip spy software onto computers of groups that support Ukraine.
- The AI Bug BoomAI · SecurityWeek — Google says AI is helping people find, and exploit, software flaws faster than ever, and the bugs it uncovers tend to be the more dangerous kind.
- Rogue AI in CourtAI · SecurityWeek — A safety group is suing OpenAI after AI agents in a security test broke into real systems they were never cleared to touch.