Tag: data-breach
-
Vektorisierung und Abliteration als KI-Risiken
Die Zahl der Kompromittierungsversuche auf öffentlich zugängliche KI-Modelle und eigenentwickelte LLMs nimmt zu. Laut den Ergebnissen des aktuellen Cost of a Data-Breach-Reports von IBM stieg die Zahl der KI-gestützten Angriffe im Vergleich zum Vorjahr um 56 Prozent. Die finanziellen Folgen waren nicht unerheblich. KI-gestützte Angriffe verursachten pro Sicherheitsvorfall durchschnittlich 1 Million US-Dollar an Kosten, da Angreifer…
-
GTA 6 leak hunt could expose data belonging to thousands of Discord users
Take-Two is demanding IP addresses, phone numbers, device IDs, and other data as it tries to identify whoever leaked GTA 6 footage. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/gta-6-leak-hunt-could-expose-data-belonging-to-thousands-of-discord-users/
-
Alibaba’s AliExpress Uses Hidden Audio to Fingerprint Devices
Tags: data-breachResearcher Says Bluetooth Routing Error Exposed a Probe Designed to Run Invisibly. AliExpress used silent WebAudio signals to help fingerprint devices for security and anti-abuse purposes, but an implementation error exposed the normally invisible tracking when Bluetooth headsets detected an active PC audio stream. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/alibabas-aliexpress-uses-hidden-audio-to-fingerprint-devices-a-32646
-
Thousands of Leaked AWS Access Keys Are Still Active
Truffle Security found 9,308 leaked AWS keys still active, including 768 corporate credentials with full administrative control of cloud accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-leaked-aws-access-keys-still-active/
-
âš¡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.Plenty to clean up. Here’s…
-
South Korean startup platform breach exposes key management failures
A breach at South Korea’s government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/
-
Researchers Uncover Thousands of Leaked AWS Keys
Tags: data-breachTruffle Security says it found over 9000 publicly accessible and active AWS key pairs First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/researchers-thousands-eaked-aws/
-
Apollo Data Breach Shows the Risk Behind a Simple Phone Call
Apollo Global Management has disclosed a data breach involving sensitive personal information after attackers gained access to parts of its cloud environment. The breach occurred between July 6 and July 10, 2026. Apollo later determined that the affected information may include names, dates of birth, contact details, home addresses, and Social Security numbers. The company……
-
Hospital for Sick Children discloses employee data breach due to third-party software flaw
First seen on scworld.com Jump to article: www.scworld.com/brief/hospital-for-sick-children-discloses-employee-data-breach-due-to-third-party-software-flaw
-
Thousands of active AWS access keys remain publicly exposed
First seen on scworld.com Jump to article: www.scworld.com/brief/thousands-of-active-aws-access-keys-remain-publicly-exposed
-
US Bank investigates LockBit ransomware claims of data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/us-bank-investigates-lockbit-ransomware-claims-of-data-breach
-
768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts
Tags: access, cloud, corporate, credentials, cyber, data, data-breach, iam, infrastructure, risk, theftA large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include 526 root access keys and 242 IAM user keys attached to AWS’s AdministratorAccess managed…
-
91 Spring CVEs: The AI Vulnerability Consumption Problem
Tags: access, advisory, ai, attack, cloud, cve, cvss, data, data-breach, framework, guide, injection, intelligence, open-source, risk, service, software, tool, update, vulnerability<div cla TL;DR Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects. At the time of publishing, Sonatype Guide currently identifies 209,569 software components affected by the security event. The disclosure comes amid a dramatic rise in AI-assisted vulnerability discovery. Broadcom…
-
Apollo discloses data breach from ongoing wave of attacks hitting financial sector
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. First seen on cyberscoop.com Jump to article: cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/
-
MLflow Flaw Opens a Path to Cloud Credentials Theft
CISA Sets Sept. 2 Deadline to Patch, Amid Active Exploitation. Attackers are exploiting a flaw in exposed MLflow servers to reach systems that are normally closed to the internet. The bug may reveal cloud credentials without requiring a login. CISA has not disclosed the victims, attackers or results of the intrusions. First seen on govinfosecurity.com…
-
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/
-
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified,…
-
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants
The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
Medical records, SSNs, and bank details exposed in CareCloud data breach
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/medical-records-ssns-and-bank-details-exposed-in-carecloud-data-breach/
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
SickKids data breach exposes employee and job applicant info
Toronto’s Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
Over 50,000 Stripe API keys exposed, highlighting fraud risks
First seen on scworld.com Jump to article: www.scworld.com/brief/over-50000-stripe-api-keys-exposed-highlighting-rapid-fraud-risks
-
Breach Roundup: Grandoreiro Returns
Also, French Tax Agency Breach and Accused Ransomware Developer in Swiss Court. This week: Grandoreiro returns, Swiss prosecutors sought a 12-year sentence for ransomware developer, a Medusa ransomware warning, Ransom Busters demanded up to $60,000 from victims, French tax agency disclosed a breach, a Fuxa vulnerability, Stripe vendors exposed in 33 gigabytes data leak. First…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…

