Tag: breach
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…
-
FTC rescinds policy requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/
-
Electronic health record company says customer data stolen in breach
Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added. First seen on therecord.media Jump to article: therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach
-
ShinyHunters hackers claim breach of Florida “DAVID” DMV database
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as “DAVID” and stole over 200,000 records about drivers in the state. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
-
Webinar: The forgotten Google Workspace access that can lead to a breach
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-the-forgotten-google-workspace-access-that-can-lead-to-a-breach/
-
Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
OpenAI models went rogue. We urgently need a better ‘hugging face’ investigation | Mackenzie Arnold and Stephan Llerena
The breach won’t be the last or the most dangerous of its kind. We need an agency capable of full investigations into AI incidentsWhen OpenAI first revealed that its AI agents had autonomously hacked a major real-world company, Hugging Face, many assumed only one or two <a href=”https://arstechnica.com/ai/2026/07/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack/”>agents were involved. The truth, a <a href=”https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/#core-takeaways-about-this-incident”>new…
-
Mathspace breach exposes data on over a million students and parents
Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/
-
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/trezor-supply-chain-breach-impacts/
-
Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff
Mathspace, an online mathematics learning platform used by schools in Australia and New Zealand, has reported a data breach affecting 1,079,819 students, parents or guardians, teachers, and staff members. The company stated that attackers exploited a critical vulnerability in its self-hosted Metabase reporting environment, allowing them to gain administrator-level access without legitimate credentials. Mathspace Data…
-
Berlin Responds After Data Leaked by Cyber Extortion Group
Hack and Shakedown by Cyber-Extortion Group Happened Weeks Before State Elections. Cyber-extortion group Rhysida has leaked terabytes of data, much of it sensitive, that it stole from the administration that runs the German state of Berlin, triggering political fallout and national security questions as incident responders seek to understand just what’s been stolen and leaked.…
-
Mathspace Breach Exposes Data of 1.08 Million in Australia, New Zealand
Mathspace says a breach exposed data tied to nearly 1.08 million people in Australia and New Zealand after attackers exploited a self-hosted Metabase flaw. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-mathspace-data-breach-australia-new-zealand-apac/
-
IDScan Faces Four Lawsuits Over Alleged Driver’s License Breach
IDScan faces four proposed class actions after a dark-web service claimed to hold more than 153 million U.S. and Canadian driver’s license records. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-idscan-four-lawsuits-drivers-license-breach/
-
Mathspace discloses data breach affecting over 1 million people
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
-
Mathspace discloses data breach affecting over 1 million people
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
-
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
-
Berlin investigates new data leak after hackers publish stolen login credentials
Another trove of data from Berlin’s government has appeared online, authorities said. Germany’s information security agency separately warned about the Rhysida cybercrime group. First seen on therecord.media Jump to article: therecord.media/germany-berlin-second-data-breach-city-agencies
-
Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data
Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees. The breach affected individuals whom NRW employed between April 2013 and March 2018. An internal investigation revealed that a spreadsheet containing employee data was accidentally published online, making the information accessible before the issue was…
-
Multiple Class Action Lawsuits Filed Against IDScan
Tags: breachSeveral victims of a recent breach of driver’s license information have sued the company they believe responsible First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/multiple-class-action-lawsuits/
-
Multiple Class Action Lawsuits Filed Against IDScan
Tags: breachSeveral victims of a recent breach of driver’s license information have sued the company they believe responsible First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/multiple-class-action-lawsuits/
-
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.”The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
-
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.”Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,”…
-
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company’s…
-
Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours
Tags: ai, attack, automation, breach, cloud, credentials, cyber, framework, hacker, infrastructure, intelligence, network, threatA threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root credentials, and hijack cloud AI infrastructure in less than 10 hours. The investigation, documented by Palo Alto Networks Unit 42, highlights a significant shift in intrusion operations. AI-assisted automation compressed an attack that could otherwise demand several…

