Tag: data
-
2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year”‘over”‘year surge in Qilin activity that reshapes the threat landscape. The data points to a structurally higher operating tempo, a middle”‘market pivot, and attacker visibility that often outpaces defenders’ own understanding of their…
-
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR’s hardware-security…
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high”‘value AI and ML artifacts across an entire stack. A missing”‘authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential…
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
-
Paidwork breach exposes sensitive data of 23 million users
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids
Bit2Watt is a newly disclosed cyber”‘physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid”‘scale threat surface. Measurements on NVIDIA accelerators show sub”‘millisecond power ramps where a single Volta V100 or RTX”‘series GPU swings from low-load phases to near”‘TDP draw,…
-
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026. Paidwork Data…
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
-
JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/
-
Craneware, Abbott Probe Separate Health Data Theft Incidents
Cyberattacks Are Latest to Target Third-Party Healthcare Vendors. Cybercriminals are keeping up with their data theft assaults and other cyberattacks on a favorite target – major third-party vendors and suppliers to the healthcare sector. The most recent victims include U.K.-based software firm Craneware and U.S.-based lab testing and medical device maker Abbott. First seen on…
-
Hugging Face Says Autonomous AI Agents Breached Data, Credentials
Tags: access, ai, cloud, credentials, cyberattack, data, exploit, flaw, framework, infrastructure, vulnerabilityAttackers Exploited Dataset Processing Flaws to Access Internal Clusters. Hugging Face said an autonomous AI agent framework exploited dataset processing vulnerabilities to compromise internal infrastructure, harvest cloud credentials and move laterally across clusters, exposing both the rise of agentic cyberattacks and the limits of AI safety guardrails during incident response. First seen on govinfosecurity.com Jump…
-
Cosmetics giant Estée Lauder victim of mass Oracle breach
Employee data at US-based cosmetics firm Estée Lauder was compromised through a vulnerability in Oracle’s software, likely orchestrated by the Cl0p ransomware gang. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645849/Cosmetics-giant-Estee-Lauder-victim-of-mass-Oracle-breach
-
Hackers steal customer data from major hospital software vendor
The breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/craneware-health-care-data-breach/825643/
-
Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/
-
Banks and Telecoms Are Struggling to Share Scam Data
Canadian Cyber Exchange’s Jennifer Quaid on Privacy Hurdles, Real-Time Fraud Intel. Banks, telecoms and tech platforms all want to share scam data faster, but privacy rules and regulatory limits are standing in the way, said Jennifer Quaid at the Canadian Cyber Threat Exchange. AI-driven fraud could make matters even worse in the next 12 to…
-
Paidwork breach exposes sensitive data of 23 million user
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so…
-
Italy fines WINDTRE Euro1.7 million over security flaws behind two data breaches
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE Euro1.7 million over >>serious data security shortcomings<< … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/italy-windtre-1-7-million-fine/
-
20th July Threat Intelligence Report
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/20th-july-threat-intelligence-report/
-
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.The overflow lets…
-
Your attack surface is bigger than you think
New data reveals where attack surfaces are hiding the most risk. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/your-attack-surface-is-bigger-than-you-think/825160/
-
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…
-
Singapore spells out how personal data can be used in GenAI
New advisory guidelines clarifying when organisations can scrape and reuse personal data to build GenAI models are among a raft of announcements at the inaugural Singapore Data Festival First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645910/Singapore-spells-out-how-personal-data-can-be-used-in-GenAI
-
Weekly Cybersecurity Newsletter The 50 Biggest Cybersecurity Stories Microsoft Patch, AI Attack, Exploits Releases, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 40 most important stories from July 1317, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome […]…

