Tag: data
-
Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
AI agents can misuse legitimate access. Learn why action-level security, trusted policy enforcement and verified approvals are critical to stop data leaks First seen on hackread.com Jump to article: hackread.com/authenticated-safe-ai-agents-action-level-security/
-
Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data
Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website. First seen on therecord.media Jump to article: therecord.media/atb-ukraine-cyberattack-ransomware
-
IQVIA fined $7.8 million for failing to properly anonymize health data
Italy’s Data Protection Authority (GPDP) has fined IQVIA Euro7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iqvia-fined-78-million-for-failing-to-properly-anonymize-health-data/
-
Denmark population registry data breach affects 8.8 million people
Denmark’s Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/
-
Radeon RX 7000 Auch Gigabyte schließt Sicherheitslücken per vBIOS-Update
Neben Sapphire verteilt auch Gigabyte ein neues vBIOS für Grafikkarten der Serie Radeon RX 7000 aufgrund eines Sicherheitsproblems. First seen on computerbase.de Jump to article: www.computerbase.de/news/grafikkarten/radeon-rx-7000-auch-gigabyte-schliesst-sicherheitsluecken-per-vbios-update.99683
-
Key ShinyHunters Suspect Reportedly Detained in Jordan
Detention of Saif al-Din Khader, 16, Follows Amsterdam Arrest of an Alleged Leader. Sixteen-year-old Saif al-Din Khader, a suspected member of the ShinyHunters digital extortion group, has reportedly been detained in Jordan and is assisting the FBI. After amassing over 140 victims, ShinyHunters last month breached the FBI, stealing voluminous amounts of data on employees.…
-
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and…
-
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it’s taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.”Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems”, including files, mail, messages, and even browsing…
-
Modernizing data security with DSPM, AI and fewer tools
For organizations, the proper safeguards—such as controls or restrictions—must be put in place. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/modernizing-data-security-with-dspm-ai-and-fewer-tools/831578/
-
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
The company’s latest report previews how AI is changing threat activity, including by automating ransomware attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-cyberattacks-automation-identity-data-microsoft-report/832020/
-
Iranian hacker accused of draining 31TB from university inboxes extradited to the US
Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old,…
-
Frontline Education Breach Impacts K-12 School District Staff
A breach at school software provider Frontline Education has exposed employee data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/frontline-education-breach-k12/
-
South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks
South Korean President Lee Jae Myung has ordered a comprehensive investigation into a series of data breaches impacting major banks and other financial institutions. Concerns have been raised that attackers may have utilized AI-enabled offensive security tools. These incidents have prompted emergency regulatory action and a sector-wide effort to strengthen defenses against increasingly automated intrusions.…
-
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At…
-
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to have stolen data on every FBI employee, was picked up in Jordan this week. The man is Saif al-Din Khader, detained by Jordanian authorities, with two…
-
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to have stolen data on every FBI employee, was picked up in Jordan this week. The man is Saif al-Din Khader, detained by Jordanian authorities, with two…
-
Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/anthropic-asks-claude-users-to-share-voice-data-for-ai-model-training/
-
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI
ShinyHunters hacker “Rey” was detained in Jordan and is reportedly cooperating with the FBI after the group claimed major FBI and corporate data breaches. First seen on hackread.com Jump to article: hackread.com/shinyhunters-hacker-rey-detained-jordan-fbi/
-
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/
-
Sicherheitsprobleme Updates für ältere Nvidia GeForce und Radeon RX 7000
GeForce- und Radeon-Grafikkarten älteren Datums erhalten aufgrund von Sicherheitsproblemen unverhoffte Treiber- und Firmware-Updates. First seen on computerbase.de Jump to article: www.computerbase.de/news/grafikkarten/sicherheitsprobleme-aeltere-grafikkarten-von-amd-und-nvidia-erhalten-updates.99658
-
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response
-
AI Agents Attempt SQL Injection While Searching Government Data
AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, working on what looks like ordinary data retrieval tasks, ended up throwing basic hacking attempts at a U.S. Department of Education site and Library and Archives Canada. Nobody told them…
-
7 Data Security Priorities Before AI Gets Involved
What Security Leaders Want for Their Data Before AI Gets Anywhere Near It Security leaders need full data visibility, accurate classification, stronger governance and real-time controls before AI gains access to sensitive information. The article outlines seven data security priorities and why DLP must be simple, autonomous and complete. First seen on govinfosecurity.com Jump to…
-
Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations
Safari’s History database contains a lesser-known tagging artifact that can help investigators infer a user’s browsing themes. While this feature is not definitive evidence of intent, when correlated with URLs, visit times, cache data, downloads, and network telemetry, it can provide useful context for macOS forensic timelines. Safari History Tags and Browsing Themes Safari’s History.db…
-
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
The healthtech software giant, which makes the widely used MyChart system for accessing medical data, will focus on fixing security bugs for the next few weeks. First seen on techcrunch.com Jump to article: techcrunch.com/2026/10/02/medical-records-giant-epic-pauses-product-development-to-fix-security-bugs-that-risk-patients-data/
-
Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust
A critical vulnerability in Capacitor, identified as CVE-2026-103922, could allow attacker-controlled remote content to execute within vulnerable Android and iOS applications, posing as the application’s own trusted origin. This flaw, assigned a CVSS score of 9.3, affects WebView navigation handling in Capacitor and can expose same-origin data, cookies, local storage, and native functionality available through…
-
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting”, and vulnerable”, target. First seen on wired.com Jump to article: www.wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data/
-
Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
A phishing-as-a-service operation dubbed Milk Dragon, also known as NaiLong, is abusing discount-themed Facebook and TikTok posts to steal payment-card data and intercept multi-factor authentication (MFA) challenges. Group-IB identified 258 phishing pages linked to the kit since October 2025, with victims across 66 countries. Rather than relying on classic delivery-failure notices, bank alerts, or account-lockout…

