Tag: data
-
McKesson Data Leak Includes 6.4M Email Addresses After $55.2M Extortion Demand
McKesson breach data includes 6.4 million unique email addresses after ShinyHunters allegedly demanded $55.2 million to keep the records private. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-mckesson-breach-6-4-million-shinyhunters/
-
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
This is the second data breach affecting a company that hardware crypto wallet maker Trezor relies on. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/
-
The Cyber Express Weekly Roundup: Iranian Bounty, Airline Data Leak, and AI-Model Prompt Injection
This weekly roundup covers a bounty offer targeting an alleged Iranian cyber official, a massive data-exposure incident affecting airline travelers, a breach of an education platform used by students, a flaw exposing ChatGPT users’ Gmail data, and a new EU compliance deadline for connected-product manufacturers. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-iran-bounty-airline-leak/
-
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of…
-
Hackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft
Threat actors increasingly deploy AI agents as operational systems for cyberattacks, moving beyond simple chatbot assistants. These AI systems automate various stages of the cyber kill chain, including reconnaissance, phishing, exploitation, persistence, and bulk data theft. Anthropic reported disrupting multiple such operations between December 2025 and August 2026, involving groups suspected to be linked to…
-
SIEM Software
Modern organizations generate enormous amounts of security data from endpoints, servers, applications, cloud environments, network devices, identity systems, and security tools. The challenge is not simply collecting this information. Security teams need to determine which events matter, identify relationships between… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/siem-software/
-
SIEM Software
Modern organizations generate enormous amounts of security data from endpoints, servers, applications, cloud environments, network devices, identity systems, and security tools. The challenge is not simply collecting this information. Security teams need to determine which events matter, identify relationships between… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/siem-software/
-
TRM Labs Lands $2B Valuation as AI Expands Investigations
TRM Platform Uses AI to Marry Blockchain Data With Registries, Threat Intelligence. TRM Labs reached a $2 billion valuation as it uses AI to combine blockchain transactions with ownership, corporate and threat intelligence data, giving investigators a broader view of criminal and nation-state networks and potential points for disruption. First seen on govinfosecurity.com Jump to…
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Threat actors are leveraging Microsoft’s Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data
-
Cisco Firewall Bugs Let in Sandworm, Qilin
Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws. Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cisco-firewall-bugs-let-in-sandworm-qilin-a-32793
-
Quantum’s Bigger Threat: Forged Identities, Not Data Theft
Applied Quantum’s Marin Ivezic on Why Forged Signatures Beat Stolen Data as a Risk. Data theft dominates quantum risk planning, but a quieter threat could prove even worse. Marin Ivezic, CEO at Applied Quantum, says quantum computers used to forge digital signatures at some point in the future could undermine trust across IT and OT…
-
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected. First seen on therecord.media Jump to article: therecord.media/idscan-data-breach-notice-drivers-licenses
-
NextGen Mirth Connect Flaws Expose Downstream System Logins
Attackers Could Steal Credentials Used to Reach Connected Hospital Systems. Three high-severity NextGen Connect flaws can expose administrator data, plain-text connector passwords and server files, potentially giving attackers credentials for databases, clinical endpoints and other downstream healthcare systems. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/nextgen-mirth-connect-flaws-expose-downstream-system-logins-a-32789
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak”, no phishing email, no malicious click, just a document the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mapping-cequence-ai-gateway-controls-to-owasps-top-10-for-agentic-applications/
-
IDScan confirms breach tied to 153 million stolen driver’s licenses
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver’s license scans. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/
-
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
The ID checking company said the data breach included people’s full names and driver’s licenses and other government-issued identity documents. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/
-
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Tags: credentials, crypto, cyber, cybercrime, data, exploit, malware, password, ransomware, theft, threatThreat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one…
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…
-
Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows, using AI-assisted scripting, troubleshooting, and proxy deployment to accelerate post-exploitation and data theft. The campaigns show that AI is no longer limited to phishing, content generation, or reconnaissance. Instead, attackers appear to be using LLMs as an…
-
AI adoption brings new security headaches for already stretched CISOs
CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/proofpoint-ciso-ai-security-risks-report/
-
AdaptHealth confirms 4.1 million people exposed in July cyberattack
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/
-
ChatGPT Flaw Let Attackers Secretly Hijack a Victim’s AI Session
Check Point researchers found a ChatGPT flaw that let attackers run hidden tasks and retrieve connected Gmail data through a cross-account channel. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-chatgpt-cross-account-data-leak-flaw/

