Tag: data
-
ChatGPT Flaw Let Attackers Secretly Hijack a Victim’s AI Session
Check Point researchers found a ChatGPT flaw that let attackers run hidden tasks and retrieve connected Gmail data through a cross-account channel. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-chatgpt-cross-account-data-leak-flaw/
-
Electronic health record company says customer data stolen in breach
Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added. First seen on therecord.media Jump to article: therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach
-
No More Reconciliation: Hyperview’s Agentless Auto-Discovery Delivers Live, Device-Level Truth
Manual data entry drags down your infrastructure management. Every rack change or device swap means hours lost reconciling spreadsheets before anyone trusts the numbers. Hyperview’s agentless auto-discovery flips that script by delivering live, device-level insights across your entire infrastructure. Say… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/no-more-reconciliation-hyperviews-agentless-auto-discovery-delivers-live-device-level-truth/
-
Your AI Didn’t Lie to You: It Was Just Being Manipulated
Hidden AI Activity Creates Security Gaps That Traditional Controls Can’t Detect As AI agents gain access to critical business systems, prompt injection, shadow AI and poisoned data can manipulate decisions without triggering traditional controls. Full-pipeline telemetry and continuous testing can help security teams investigate incidents while maintaining human accountability. First seen on govinfosecurity.com Jump to…
-
What Benchmark Data Says About Deterministic SAST and Agentic Code Scanning
Much of the debate about agentic code scanning revolves around three core questions: Do more capable models find more vulnerabilities? Where does deterministic, rules-based SAST still fit? What does the cost and performance balance look like? We ran two benchmarks… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-benchmark-data-says-about-deterministic-sast-and-agentic-code-scanning/
-
What Benchmark Data Says About Deterministic SAST and Agentic Code Scanning
Much of the debate about agentic code scanning revolves around three core questions: Do more capable models find more vulnerabilities? Where does deterministic, rules-based SAST still fit? What does the cost and performance balance look like? We ran two benchmarks… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-benchmark-data-says-about-deterministic-sast-and-agentic-code-scanning/
-
The US military just turned off ad tracking on its phones. Maybe you should too
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices – and you can do the same on yours. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones
-
ChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another Account
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user’s question as usual.In the company’s proof of concept, that hidden work read data from the user’s connected Gmail account and passed it to a…
-
OnDemand |Law Enforcement in the Public Sector: Breaking Data Silos for Faster, Smarter Policing
A Public Sector Session from Elastic. Watch this session with Elastic and public sector leaders to explore how the Elasticsearch Platform is transforming law enforcement operations by unifying diverse data sources, enhancing collaboration, and enabling mission-critical insights at scale. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ondemand-law-enforcement-in-public-sector-breaking-data-silos-for-faster-a-32767
-
Before You Paste Anything Into ChatGPT, Check This List
Before pasting passwords, medical records, source code, or company data into ChatGPT, use this checklist to decide what should stay private. The post Before You Paste Anything Into ChatGPT, Check This List appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-what-not-to-share-chatgpt-ai-chatbots/
-
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
esearch by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user…
-
Grindr Settles UK Data Privacy Claims for £26m
Grindr settled UK claims over alleged unlawful processing of sensitive user data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/grindr-settles-uk-data-privacy/
-
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting…
-
Bug Bounty vs Penetration Testing: What the Data Shows
Key TakeawaysHackerOne’s own data shows the average pentest surfaces 12 vulnerabilities with 16 percent rated high or critical, while bug bounty programs average a higher 25 percent high or critical rate.Pentests tend to surface more systemic and architectural issues, like… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/bug-bounty-vs-penetration-testing-what-the-data-shows/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
North Korea-linked Hackers Hide a Backdoor Inside HAProxy
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s…
-
IT Help Desk Impersonation Lets Hackers Bypass MFA
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social…
-
Mathspace breach exposes data on over a million students and parents
Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/
-
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/trezor-supply-chain-breach-impacts/
-
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users’ personal information, including their HIV status, with third-parties.Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive…
-
Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff
Mathspace, an online mathematics learning platform used by schools in Australia and New Zealand, has reported a data breach affecting 1,079,819 students, parents or guardians, teachers, and staff members. The company stated that attackers exploited a critical vulnerability in its self-hosted Metabase reporting environment, allowing them to gain administrator-level access without legitimate credentials. Mathspace Data…
-
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé…
-
Berlin Responds After Data Leaked by Cyber Extortion Group
Hack and Shakedown by Cyber-Extortion Group Happened Weeks Before State Elections. Cyber-extortion group Rhysida has leaked terabytes of data, much of it sensitive, that it stole from the administration that runs the German state of Berlin, triggering political fallout and national security questions as incident responders seek to understand just what’s been stolen and leaked.…
-
Mathspace Breach Exposes Data of 1.08 Million in Australia, New Zealand
Mathspace says a breach exposed data tied to nearly 1.08 million people in Australia and New Zealand after attackers exploited a self-hosted Metabase flaw. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-mathspace-data-breach-australia-new-zealand-apac/
-
Activist takes data protection watchdog to court after Europol ‘unlawfully’ processed personal data
Tags: dataEurope’s data protection supervisor (EDPS) faces court action over claims it failed to properly investigate Europol for ‘unlawfully’ processing the data of a human rights activist First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650034/Activist-takes-data-protection-watchdog-to-court-after-Europol-unlawfully-processed-personal-data
-
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.The activity, which mainly singles out directors, vice presidents, and other executive staff First seen on thehackernews.com Jump to…
-
31st August Threat Intelligence Report
Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/31th-august-threat-intelligence-report/

