Tag: data
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Passenger data stolen from major UK airports
Identifying data on passengers who flew from East Midlands, Stansted and Manchester airports has been stolen by an unnamed threat actor. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649662/Passenger-data-stolen-from-major-UK-airports
-
Manchester Airports Group says hackers stole travelers’ data
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/
-
What IBM’s Latest Breach Report Says About Data Security in an AI-Centric World
<div cla IBM has been charting the data breach landscape now for over two decades. But you’d be hard pressed to find any point over the past 21 years as volatile as today. AI is rewriting the rules of the game for network defenders and their adversaries, simultaneously arming attackers and creating a dangerous new…
-
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of First…
-
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. >>Two West…
-
AI Agents Used by 68% of Top-Performing Cybersecurity Teams
AI agents are already finding their way into the working methods of some of the highest-performing cybersecurity teams, according to new three-year benchmark data from Hack The Box (HTB). The 2026 Global Cyber Skills Benchmark found that 68% of the top 25 teams included an AI agent, despite AI agents accounting for just 2.7% of…
-
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Tags: attack, cybercrime, data, extortion, group, hacker, identity, malicious, open-source, software, supply-chainAuthorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were…
-
Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
A spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an email address. First seen on therecord.media Jump to article: therecord.media/cyberattack-on-manchester-airports-group-exposes-millions-customer-info
-
AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks
AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and DNS activity in Route 53 Resolver query logs. The approach turns isolated alerts into an attack narrative spanning credential abuse, reconnaissance, privilege escalation, lateral movement and data exfiltration. A suspicious GetCallerIdentity request…
-
Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency
Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data, personnel files, and encryption key material from a Philippine nuclear research organization. Hunt.io discovered an exposed file directory on August 13, 2026, hosted at 31.58.209[.]241:8000, an Amsterdam-based server registered to CGI Global Limited. The directory was served through…
-
What the Data Says About AI in Security Operations in 2026
AI is officially mainstream in security operations. According to Prophet Security’s State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it.For the teams already using…
-
Three UK airports hit by cyber-attack with data of 8.7m customers accessed
Company that runs Manchester, Stansted and East Midlands hubs says passenger safety is unaffected<ul><li><a href=”https://www.theguardian.com/business/live/2026/aug/27/asian-technology-shares-ride-high-ai-optimism-nvidias-stunning-results-jackson-hole-live-updates”>Business live latest updates</li></ul>Manchester, London Stansted and East Midlands airports have been hit by a cyber-attack, with hackers accessing the data of about 8.7 million customers.Hackers obtained their email addresses, phone numbers, vehicle registration numbers and postcodes, as the incident affected…
-
UK airports operator hit by cyber-attack and customer data accessed
Company that runs Manchester, Stansted and East Midlands airports says passenger safety is unaffected<ul><li><a href=”https://www.theguardian.com/business/live/2026/aug/27/asian-technology-shares-ride-high-ai-optimism-nvidias-stunning-results-jackson-hole-live-updates”>Business live latest updates</li></ul>Three UK airports have been hit by a “cybersecurity incident” in which the data of about 8.7 million customers was accessed, Manchester Airport Group (Mag) has said.The company, which operates Manchester Airport, London Stansted and East Midlands airport,…
-
Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power
AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways, RAGFlow retrieval platforms, and Kestra workflow orchestration environments to steal model-provider credentials, establish persistence, access backend data, and deploy cryptominers. The appeal is clear. AI gateways often centralize OpenAI, Azure, Anthropic, Gemini, and other provider API keys; retrieval platforms hold…
-
Public wary of UK government ‘backdoor’ surveillance following Apple row, poll reveals
A poll of 2,000 UK citizens taken after the government issued a secret order seeking access to Apple users’ encrypted data finds that the public is sceptical of government surveillance powers First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649780/Public-wary-of-UK-government-backdoor-surveillance-following-Apple-row-poll-reveals
-
Public wary of UK government ‘backdoor’ surveillance following Apple row, poll reveals
A poll of 2,000 UK citizens taken after the government issued a secret order seeking access to Apple users’ encrypted data finds that the public is sceptical of government surveillance powers First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649780/Public-wary-of-UK-government-backdoor-surveillance-following-Apple-row-poll-reveals
-
Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
Secure coding principles explained for product teams
For many UK SMEs, software is now part of the business model rather than just a support tool. It handles customer data, takes payments, automates operations, and shapes the customer experience. That means coding mistakes are not just technical issues. They can lead to downtime, data loss, customer complaints, rework, and damage to reputation. Secure……
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
Cellebrite launches portable field kit for military data extraction
First seen on scworld.com Jump to article: www.scworld.com/brief/cellebrite-launches-portable-field-kit-for-military-data-extraction
-
Carhartt data breach claims inflated by synthetic data, analysis finds
First seen on scworld.com Jump to article: www.scworld.com/brief/carhartt-data-breach-claims-inflated-by-synthetic-data-analysis-finds
-
Unified vision: An executive playbook for data risk management
First seen on scworld.com Jump to article: www.scworld.com/resource/unified-vision-an-executive-playbook-for-data-risk-management
-
LACMA data breach exposes customer and employee information
First seen on scworld.com Jump to article: www.scworld.com/brief/lacma-data-breach-exposes-customer-and-employee-information

