Tag: data
-
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators. First seen on therecord.media Jump to article: therecord.media/nutex-health-data-breach
-
Top 5 Tools to Repair MySQL Database
A MySQL database contains tables, indexes, views, and more. However, even with preventive measures in place, database corruption and data loss can still occur. When the database becomes corrupted, you face random errors or the MySQL service may fail to… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/top-5-tools-to-repair-mysql-database/
-
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025,…
-
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/
-
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/
-
Your workday has too many tabs How HIX AI brings research, writing and slides together
A simple work task can quickly turn into a screen full of browser tabs. You can begin with topic research and open a tab to write, a tab for data, and another tab for presentation design. It does not take long before you are wasting more time moving through the tools than doing the job…
-
Retired Devices, Active Risks: How an ITAD Company Protects Data After Decommissioning
A laptop can be removed from an employee’s desk, disconnected from the network and marked retired in an asset system within the same afternoon. None of those steps means the data risk has disappeared. Retired technology often sits in storage rooms or staging locations before reaching its final destination. During that period, devices still contain…
-
Healthcare Giant McKesson Investigates Data Breach Incident
ShinyHunters claims to have stolen 284 million records from McKesson First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/healthcare-mckesson-investigates/
-
Berlin refuses to be blackmailed after network breach
Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/berlin-data-breach-rhysida-ransomware/
-
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/
-
McKesson copes with fallout from data theft extortion attack
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. First seen on cyberscoop.com Jump to article: cyberscoop.com/mckesson-data-theft-extortion-attack-shinyhunters/
-
ShinyHunters Threatens to Leak Millions of McKesson Records
Medical Products Supplier Reports Hack to SEC as Tuesday Data Leak Deadline Looms. Medical product and pharmaceutical distributor McKesson is the latest healthcare sector supplier responding to a recent data theft incident. Extortion gang ShinyHunters is threatening to leak 284 million records of sensitive McKesson data, including patient information, unless a ransom is paid. First…
-
CrowdStrike Looks to Operationalize Project QuiltWorks AI Initiative
CrowdStrike today unveiled a platform, dubbed Falcon IQ, that operationalizes vulnerability discovery and remediation using data collected from partners participating in a Project QuiltWorks initiative the company launched earlier this year. Announced at its Fal.Con 2026 conference, CrowdStrike also revealed that Abnormal AI, Artemis Security, AttackIQ, ExtraHop, HackerOne, Horizon3, Netskope, Picus Security, Rubrik, SafeBreach, Terra..…
-
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to…
-
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
The company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/
-
Berlin says it won’t pay ransom after hackers steal government data
Governing Mayor Kai Wegner said on Friday that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August. First seen on therecord.media Jump to article: therecord.media/berlin-says-it-wont-pay-ransom-after-hackers-steal-gov-data
-
External input cannot be trusted: input validation and encoding strategies
External data should be treated as hostile until it has been checked, constrained, and transformed for the specific place it will be used. That applies whether the data comes from a browser form, a mobile app, an API client, a file upload, an integration partner, or another internal service. In practice, many security issues start……
-
PCI DSS 4.0 Audits: Continuum GRC Cybersecurity Assessments 2026
PCI DSS 4.0 compliance audits demand a fundamental shift from periodic checkbox exercises to continuous, risk-based cybersecurity assessments. Organizations preparing for 2026 assessments must address new requirements around targeted risk analyses, multi-factor authentication expansion, and automated security monitoring that directly impact how cardholder data environments are protected and validated. Key Takeaways: PCI DSS 4.0 introduces”¦…
-
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin’s city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/
-
Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
A Magecart campaign dubbed HexMage has compromised more than 40 e-commerce storefronts across at least 15 countries, using Ethereum smart contracts as a resilient delivery mechanism for payment-card skimmers. The operation blends traditional client-side checkout theft with EtherHiding, allowing attackers to conceal and rotate skimmer infrastructure through Ethereum’s Sepolia testnet. Because the malicious code is…
-
Halo-record: Open-source audit trails for AI agents
Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/halo-record-open-source-ai-agent-audit-trail/
-
HIPAA Risk Assessments 2026: Continuum GRC Healthcare Audits
In 2026, healthcare organizations face increasing pressure to maintain robust data protection measures under evolving regulatory landscapes. HIPAA risk assessments remain a cornerstone of compliance, helping providers identify vulnerabilities and safeguard protected health information. As cyber threats grow more sophisticated, proactive compliance assessments become essential for decision-makers seeking to minimize liability and ensure operational resilience.”¦…
-
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole…
-
Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports. The post Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uk-airport-cyberattack-8-7-million-customers-emea/
-
LACMA Data Breach: A 4-Day Attack, a Year of Fallout
LACMA says a four-day cyberattack may have exposed Social Security, financial, and medical data, prompting public disclosure and a proposed lawsuit. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-lacma-data-breach-four-day-attack-year-fallout/
-
Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports. The post Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uk-airport-cyberattack-8-7-million-customers-emea/
-
Randall Munroe’s XKCD ‘The Princess and the Pea’
via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/randall-munroes-xkcd-the-princess-and-the-pea/
-
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ai-is-accelerating-vulnerability-discovery-can-defenders-keep-up/
-
You Need Cyber Deception for OT
The frustrating reality after an OT cyberattack: no data, no trail, and no history. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/you-need-cyber-deception-ot
-
AI Governance Has a Control Problem, Not a Policy Problem
Tags: access, ai, business, control, credentials, cybersecurity, data, finance, governance, identity, least-privilege, risk, technology, toolWe’re getting good at writing policies about how AI should be used. Responsible AI principles. Acceptable-use policies. AI risk frameworks. Approval processes. Governance committees. All of these have a place. But there is a harder question that I think organisations need to start asking: What evidence proves those controls actually work? Because AI is changing…

