Tag: data
-
Top 10 Best PCI DSS Compliance Solutions For 2026
In the ever-evolving landscape of digital commerce, safeguarding cardholder data is paramount. The Payment Card Industry Data Security Standard (PCI DSS) sets the benchmark for protecting this sensitive information, and compliance is not just a requirement it’s a cornerstone of trust for businesses that handle credit card transactions. As we look towards 2026, the complexity…
-
Top 10 Best PCI DSS Compliance Solutions For 2026
In the ever-evolving landscape of digital commerce, safeguarding cardholder data is paramount. The Payment Card Industry Data Security Standard (PCI DSS) sets the benchmark for protecting this sensitive information, and compliance is not just a requirement it’s a cornerstone of trust for businesses that handle credit card transactions. As we look towards 2026, the complexity…
-
Top 10 Best Cyber Insurance Providers For Businesses in 2026
Tags: breach, cyber, cyberattack, cybersecurity, data, defense, insurance, phishing, ransomware, threatIn the fast-paced digital world of 2026, cyberattacks are no longer a matter of if, but when. The increasing sophistication of threats like ransomware, phishing, and data breaches means that even businesses with robust cybersecurity defenses are at risk. As a result, cyber insurance has evolved from a niche product into a critical component of…
-
UK Information Commissioner Resigns After Workplace Investigation
Tags: dataThe UK’s data protection regulator the information commissioner has resigned after his position became “untenable” First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/information-commissioner-resigns/
-
AI is transforming enterprise data risk. Here’s how security leaders are responding.
New research from 1,700 security leaders reveals 3 imperatives for securing AI adoption. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/ai-is-transforming-enterprise-data-risk-heres-how-security-leaders-are-re/823180/
-
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks. ESET published a detailed breakdown of The Gentlemen’s technical infrastructure on June 18, the result of months of incident-level investigation corroborated by the group’s own internal data leak from May 2026. Since emerging in late…
-
Hackers Claim to Leak Stolen Madison Square Garden Data
Plus: Gay bars in San Francisco using face scanners, France quits Palantir, Apple plans to change its private email and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-hackers-claim-to-leak-stolen-madison-square-garden-data/
-
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens First seen…
-
HIPAA’s No Joke: Gag Gift Firm’s Health Plan Pays $450K Fine
Investigation of Spencer’s Gifts Ransomware Breach Unearths Data Privacy Violations. The employer-sponsored health plan of novelty merchandise retailer Spencer Gift has paid a $450,000 HIPAA penalty and agreed to implement a corrective action plan to resolve findings of a federal breach investigation into a 2021 attack by now-defunct ransomware gang Conti. First seen on govinfosecurity.com…
-
ShinyHunters Threatens to Leak Amazon One Medical Records
Extortion Gang Claims It Stole 8.8TB of Healthcare Firm’s Data. Prolific digital extortion gang ShinyHunters is threatening to dump on the darkweb 8.8 terabytes of data it allegedly stole from One Medical, a unit of Amazon that provides onsite and virtual primary care services for employees of more than 8,500 U.S. clients. First seen on…
-
INC Ransomware Uses Double Extortion and Printer Ransom Notes to Pressure Victims
INC has matured from an emerging RaaS operation into one of 2026’s most active ransomware families, claiming more than 800 victims since 2023 and capitalizing on disruption among competitors to expand its affiliate base. The group’s recent campaigns demonstrate both incremental tooling refinement and novel pressure tactics: double extortion of stolen data combined with automated…
-
Forget Data Leakage: Shadow AI’s Real Threat Is Access Control
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time.It doesn’t fit the problem anymore.Shadow AI has shifted from a data leakage concern to an…
-
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026.To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert published…
-
The Cyber Express Weekly Roundup: Cybersecurity Weekly Round on Emerging Threats, Data Breaches, and Global Policy Shifts
This week’s weekly roundup of cybersecurity developments highlights an expanding intersection of cyber risk, regulatory action, and enterprise vulnerability. Across healthcare, technology platforms, gaming companies, and government policy, organizations continue to confront a rapidly evolving cybersecurity landscape where data exposure, advanced intrusion tactics, and platform security failures are interconnected. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/tce-weekly-roundup-global-threats/
-
Nintendo Confirms Employee Data Exposed in TinyPulse Cyberattack
Nintendo of America has confirmed that employee survey data was exposed in the recent TinyPulse cyberattack, although the company emphasized that its own systems were not breached and that no customer or financial information was accessed. The disclosure follows claims by the threat actor Shadowbyt3$, which alleged it had stolen sensitive information linked to Nintendo employees. First…
-
Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse
Nintendo America employee records were exposed via TinyPulse after Shadowbyt3 claimed theft of HR files, tax forms, bank data, and staff survey responses. First seen on hackread.com Jump to article: hackread.com/nintendo-america-employee-data-shadowbyt3-tinypulse/
-
Peter Thiel ‘s Secret Society Leak Creates a Perfect Target List for Espionage, Influence Operations, and Blackmail
A simple website flaw exposed members, political profiles, login tokens, and dating data from Peter Thiel ‘s secretive Dialog network. Dialog, a private invitation-only organization cofounded in 2006 by billionaire tech investor Peter Thiel, has spent two decades refusing to disclose its membership. That position became harder to maintain last week when Swiss hacktivist maia…
-
24 Billion Stolen Credentials Exposed in Massive Data Leak
24 Billion Records Left Open Online: Passwords, Emails, and Everything Else Exposed database with 24 Billion records revealed stolen credentials from infostealers, Telegram channels, and breach collections, risking account takeovers. Cybernews researchers found an exposed Elasticsearch cluster on June 12th containing 24 billion records and more than 8.3 terabytes of data. They triple-checked the numbers.…
-
Klue Confirms OAuth Token Theft Led to Salesforce Data Heist
‘Compromised Legacy Credential’ Wielded by Extortion Group Calling Itself Icarus. Marketing intelligence platform Klue confirmed an attacker breached its infrastructure, saying they used a compromised legacy credential to obtain OAuth access tokens for integrated services and stole data directly from Klue customers’ Salesforce and Gong instances. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/klue-confirms-oauth-token-theft-led-to-salesforce-data-heist-a-32024
-
Klue breach lead to Salesforce data theft, Huntress affected
Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/19/klue-salesforce-data-breach-huntress/
-
Your browser tab could become encrypted storage for someone else’s files
Decentralized storage networks already hand pieces of people’s data to strangers’ machines. The lasting question across these networks is whether the machine … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/19/safecloud-browser-based-encrypted-storage/
-
24B Records Exposed in Massive Leak of Emails, Passwords, and Login Data
Cybernews researchers found an exposed database with 24 billion credential records, raising fresh risks from password reuse and credential stuffing. The post 24B Records Exposed in Massive Leak of Emails, Passwords, and Login Data appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-24-billion-credential-records-exposed-database/
-
Alibaba Cloud Bets on France as Europe Seeks More Control Over AI
Alibaba Cloud opened two Paris availability zones as European enterprises weigh data sovereignty, resilience, and AI infrastructure needs. The post Alibaba Cloud Bets on France as Europe Seeks More Control Over AI appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-alibaba-cloud-ai-sovereignty-emea-france/
-
Texas govt data breach exposes over 3 million driver’s licenses
The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/
-
Every AI Agent Is an Identity. Most Organizations Don’t Treat Them That Way
AI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down why AI agents are becoming a new identity and governance challenge. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/every-ai-agent-is-an-identity-most-organizations-dont-treat-them-that-way/
-
CISA warns Fortinet users to secure devices after FortiBleed leak
Tags: cisa, credentials, cybersecurity, data, data-breach, firewall, fortinet, infrastructure, leak, vpnThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed “FortiBleed.” First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-fortinet-users-to-secure-devices-after-fortibleed-leak/
-
Companies are discarding the logs they need to catch a breach
Many large enterprises discard most of the log data their systems generate, and they do it on purpose to keep costs down. A Dynatrace survey of 450 senior IT leaders at large … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/19/report-log-management-security-risk/
-
State Digital Surveillance Puts Foreign Travelers and Businesses at Risk Across 31 Countries
A new state-surveillance assessment finds that foreign travelers and business staff face high or very high digital risk in 31 countries, where governments increasingly use telecom interception, spyware, AI-enabled monitoring, and data aggregation with little meaningful oversight. The concern is not just espionage in the classic sense; it is the routine conversion of travel, communications,…
-
AI-Driven Threats, Zero-Days, and Data Breaches Define This Week in Cybersecurity for June 2026
Weekly summary of Cybersecurity Insider newsletters First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/ai-driven-threats-zero-days-and-data-breaches-define-this-week-in-cybersecurity-for-june-2026/

