Tag: data
-
CEVA Logistics Breach Triggers Customer Data Alerts Across Europe
CEVA Logistics’ data breach exposed customer and order information across European clients, raising phishing and third-party security concerns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-ceva-data-breach-emea-eu/
-
ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]…
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
QA: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage. Geoff White is an award-winning investigative journalist whose reporting has taken him inside global…
-
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
-
Court Sets Strict Security for Change Health’s Stolen Data
Plaintiffs, Experts Face Strict Rules for Handling Data Stolen in 2024 Attack. A federal court last week approved stringent security requirements on how plaintiffs’ attorneys and experts must safeguard a copy of stolen data that Change Healthcare will turn over in class action litigation involving the company’s massive 2024 cyberattack that affected 193 million individuals.…
-
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place…
-
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/logistics-ceva-data-breach/
-
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encrypting enterprise data while threatening publication of stolen material. The encryptor’s pre-encryption routine is built to degrade both prevention and recovery. After XOR-decoding an embedded configuration,…
-
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
Tags: advisory, breach, cisa, credentials, cyber, data, data-breach, encryption, exploit, firewall, infrastructure, international, law, network, organized, ransomware, service, theft, update, vpnCISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to breach enterprise networks. The advisory positions Gunra as an increasingly organized ransomware-as-a-service operation whose affiliates combine data theft, credential compromise and rapid encryption to pressure…
-
Obsidian Secures $85M to Control AI Agents in SaaS Apps
CEO Hasan Imam Says AI Agents Are Already Modifying and Deleting Enterprise Data. Obsidian Security raised $85 million at a $1.1 billion valuation to expand real-time monitoring and enforcement as enterprises give autonomous AI agents access to sensitive data and the ability to modify or delete information inside SaaS and other third-party applications. First seen…
-
Court Sets Tight Security for Change Health’s Stolen Data
Plaintiffs, Experts Face Strict Rules for Handling Data Stolen in 2024 Attack. A federal court last week approved stringent security requirements on how plaintiffs’ attorneys and experts must safeguard a copy of stolen data that Change Healthcare will turn over in class action litigation involving the company’s massive 2024 cyberattack that affected 193 million individuals.…
-
The Art of Detonating Malware: Lessons from a Research Lab
Modern ransomware operators are no longer content to simply encrypt data and hope for a payout. They are actively working to evade every layer of enterprise defense, from sandboxes and EDR to backup infrastructure itself, using techniques observed in Cohesity’s in-house REDLab malware research environment. For security leaders, backup and recovery systems can no longer..…
-
DEF CON 34: RovoBlast Exposes Atlassian Rovo Data Risks
RovoBlast showed how a crafted link could put enterprise data at risk through Atlassian Rovo. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/def-con-34-rovoblast-exposes-atlassian-rovo-data-risks/
-
Exfiltration-Focused ExfilSquad Starts Leaking Stolen Data
Cities of Atlanta and Houston, and Frontier Airlines, Among New Group’s Victims. A fresh cybercrime group called ExfilSquad, which recently debuted with a data-leak site listing over a dozen victims, has begun leaking large quantities of stolen data. The group’s emergence comes as incident responders continue to see fewer victims paying exfiltration ransoms than ever…
-
77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk. The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-open-vsx-extension-risk/
-
Fake The Odyssey Downloads Are Hiding Password-Stealing Malware
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information. The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-the-odyssey-fake-downloads-lumma-stealer/
-
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rovoblast-atlassian-rovo-url/
-
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Companies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
-
Signed up for Klaviyo? Dozens of advertisers may have seen your password
A bug in the tech giant’s website mistakenly shared users’ sign-up information, including personal data and their password, to third-party companies. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/10/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password/
-
9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old
A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire national registry, 9.2 million records covering essentially the whole country. Ransomnews…
-
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/
-
Metabase zero-day exploited to access Framework customer data
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/
-
Blockchain and AI: Why Trusted Data Matters
The internet has crossed a threshold that content teams can no longer ignore. Independent analysis of tens of thousands of web pages found that mostly AI-generated articles accounted for an estimated 49.9% of sampled content published in the first quarter of 2026, a level that has held roughly steady since AI-written material briefly overtook human-written…
-
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
-
Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo’s handling of URL-supplied prompts, enabling attackers to inject malicious instructions into an authenticated user’s AI session. The attack does not require traditional…
-
At A Loss Courts Struggle to Define >>Loss<< Under Computer Hacking Law
Recent CFAA rulings clarify that qualifying “loss” can include reasonable forensic investigation and incident-response costs even when computers or data are not visibly damaged. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/at-a-loss-courts-struggle-to-define-loss-under-computer-hacking-law/
-
New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail services need to display HTML controlled by the sender without compromising the security of the mailbox application. To achieve this,…

