Tag: data
-
Scattered Lapsus$ Hunters Demand Google Fire Security Experts or Face Data Leak
Scattered Lapsus$ Hunters threaten Google, demanding that two security experts, Austin Larsen of Google’s Threat Intelligence Group and Charles Carmakal of Mandiant, be fired or they will leak alleged stolen Google data. First seen on hackread.com Jump to article: hackread.com/scattered-lapsus-hunters-google-fire-experts-data-leak/
-
Scattered Spider-Linked Group Claims JLR Cyber-Attack
JLR said it is investigating following claims by the actor “Scattered Lapsus$ Hunters” that it had stolen data from the firm and had issued an extortion demand First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/scattered-spider-claims-jlr-cyber/
-
Palo Alto Networks disclosed a data breach linked to Salesloft Drift incident
Palo Alto Networks hit by Drift-linked supply-chain attack, exposing Salesforce customer data and support cases via stolen OAuth tokens. Palo Alto Networks is another victim of the Salesloft Drift incident, which allowed attackers to access its Salesforce account, as per BleepingComputer. The company discloses a breach after attackers used stolen OAuth tokens from Salesloft Drift,…
-
Google Fined $379 Million by French Regulator for Cookie Consent Violations
The French data protection authority has fined Google and Chinese e-commerce giant Shein $379 million (Euro325 million) and $175 million (Euro150 million), respectively, for violating cookie rules.Both companies set advertising cookies on users’ browsers without securing their consent, the National Commission on Informatics and Liberty (CNIL) said. Shein has since updated its systems to comply…
-
Why a CIAM Platform is Central to Your Identity Strategy
Discover how a CIAM platform centralizes customer identities, eliminates data silos, and powers secure, personalized experiences across 150+ integrations. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/why-a-ciam-platform-is-central-to-your-identity-strategy/
-
Critical Linux UDisks Daemon Vulnerability (CVE-2025-8067) Exposes Privileged Data to Local Attackers
A newly disclosed security flaw in the Linux UDisks daemon has been reported. Tracked as CVE-2025-8067, the out-of-bounds read vulnerability allows local, unprivileged users to access files and data owned by privileged accounts, a serious breach with potentially far-reaching implications. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/linux-daemon-vulnerability-cve-2025-8067/
-
Pressure on CISOs to stay silent about security incidents growing
Tags: access, breach, business, cio, ciso, corporate, credentials, credit-card, crowdstrike, cybersecurity, data, data-breach, email, finance, framework, group, hacker, iam, identity, incident response, insurance, law, mfa, ransomware, sap, security-incident, software, theft, threat, training‘Intense pressure’ to keep quiet about security incidents: CSO spoke to two other former CISOs who reported pressures to stay silent about suspected security incidents. Both CISOs requested to remain anonymous due to end-of-contract confidentiality agreements made with previous employers.”While working inside a Fortune Global 500 company in Europe, I witnessed this multiple times,” one…
-
Salesloft Drift Breach Rolls Up Cloudflare, Palo Alto, Zscaler and Others
Cloudflare, Palo Alto Networks, and Zscaler are the latest among hundreds of victims of an expanding data-stealing attack by the UNC6395 threat group that is exploiting compromised OAuth tokens associated with Salesloft’s Drift app to access organizations’ Salesforce tenants and exfiltrate customer data. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/salesloft-drift-breach-rolls-up-cloudflare-palo-alto-zscaler-and-others/
-
Salesloft Drift Breach Rolls Up Cloudflare, Palo Alto, Zscaler and Others
Cloudflare, Palo Alto Networks, and Zscaler are the latest among hundreds of victims of an expanding data-stealing attack by the UNC6395 threat group that is exploiting compromised OAuth tokens associated with Salesloft’s Drift app to access organizations’ Salesforce tenants and exfiltrate customer data. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/salesloft-drift-breach-rolls-up-cloudflare-palo-alto-zscaler-and-others/
-
How Kingman USD Secures Google Workspace on a K-12 Budget with Cloud Monitor
Arizona district gains real-time threat visibility and protects student data while within budget by partnering with ManagedMethods Claire Sexton, Cybersecurity Administrator for Kingman Unified School District located in Kingman, Arizona, describes her role as the district’s “digital bodyguard.” With a small IT team supporting roughly 7,000 students and 850 staff members, her mission is clear:…
-
European Court rejects challenge to EU-US data transfer agreement
The General Court of the Court of Justice of the European Union ruled against a French lawmaker who had challenged the EU-U.S. Data Privacy Framework, citing the fact that a U.S. data protection court provides independent oversight of U.S. intelligence agencies and their potential surveillance of Europeans’ data. First seen on therecord.media Jump to article:…
-
Ensuring Compliance and feeling reassured in the Cloud
How Can Non-Human Identities (NHIs) Enhance Cloud Security? Is your organization leveraging the power of Non-Human Identities (NHIs) and Secrets Security Management to fortify cloud security? If not, you could be leaving yourself vulnerable to potential cyber threats. The management of NHIs and secrets can significantly reduce the risk of security breaches and data leaks,……
-
California Tax Refund Mobile Phish
A new round of mobile phish is imitating the State of California’s “Franchise Tax Board” in a round of phishing sites that are gaining prominence in the past few days. I visited ftb.ca-gov-sg[.]top/notice from a burner phone to see how the scheme works (the page doesn’t load from the Windows browsers I tested.) After harvesting…
-
European court upholds EU-US Data Privacy Framework data-sharing agreement
EU General Court upholds EU-US Data Privacy Framework, bringing certainty to businesses that exchange data with the US for now. An appeal may be in the offing First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366630156/European-court-upholds-EU-US-Data-Privacy-Framework-data-sharing-agreement
-
Dutch Lab Cancer Screening Hack Balloons to 941,000 Victims
Ransomware Gang Nova Poised to Leak Patient Data, Lab Stays Mum on Negotiations. With ransomware gang Nova threatening to leak patient data on the darkweb, a Dutch laboratory that performs cervical cancer tests for a government screening program is mum about the ransom negotiations, but it says the cyberattack in July has affected 941,000 patients.…
-
EU Court Preserves EU-US Data Privacy Framework
The EU General Court Gives Victory to Backers of Trans-Atlantic Data Flows. The European Union General Court on Wednesday dismissed a plea by a French politician to annul the legal framework underpinning commercial data flows across the Atlantic, rejecting claims that a U.S. intelligence agency oversight body is not independent of the federal government. First…
-
Russia’s APT28 Targets Microsoft Outlook With ‘NotDoor’ Malware
The notorious Russian state-sponsored hacking unit, also known as Fancy Bear, is abusing Microsoft Outlook for covert data exfiltration. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/apt28-outlook-notdoor-backdoor
-
Salesloft Drift Breach Rolls Up Cloudflare, Palo Alto, Zscaler, and Others
Cloudflare, Palo Alto Networks, and Zscaler are the latest among hundreds of victims of an expanding data-stealing attack by the UNC6395 threat group that is exploiting compromised OAuth tokens associated with Salesloft’s Drift app to access organizations’ Salesforce tenants and exfiltrate customer data. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/salesloft-drift-breach-rolls-up-cloudflare-palo-alto-zscaler-and-others/
-
Randall Munroe’s XKCD ‘Archaeology Research’
Tags: datavia the cosmic humor & dry-as-the-desert wit of Randall Munroe, creator of XKCD Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2025/09/randall-munroes-xkcd-archaeology-research/
-
Relief for European Commission as court upholds EU Data Privacy Framework agreement with US
ex post judicial oversight by the [US Data Protection Review Court],” the judgment said.A key issue is whether the agreement achieves ‘adequacy’, the extent to which US laws offer the same level of protection as EU equivalents.”Today’s EU General Court judgement will bring relief and reassurance to the thousands of US companies and their European…
-
Cloudflare Joins List of Salesloft Drift Breach Victims
Full Breach Scope Remains Unclear; Hundreds of Organizations Reportedly Affected. The scope of the Salesloft Drift data breach continues to expand, now counting Cloudflare, Zscaler, Palo Alto Networks as victims and what investigators say are many hundreds more organizations that connected their Salesforce, Google Workspace or other tools to Salesloft’s AI chatbot. First seen on…
-
Hacked Routers Linger on the Internet for Years, Data Shows
While trawling Internet scan data for signs of compromised infrastructure, researchers found that asset owners may not know for years their devices had been hacked. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/hacked-routers-linger-on-the-internet-for-years-data-shows
-
The Full Lifecycle Imperative: Why >>Shift Left<>Shift Right<<
Tags: access, ai, api, attack, authentication, automation, business, cloud, compliance, data, detection, framework, governance, HIPAA, mitre, nist, PCI, risk, siem, strategy, threat, tool, vulnerability, wafIn this series, we examined the vital connection between AI and APIs, highlighting what makes a leader in the API security market through the 2025 KuppingerCole Leadership Compass. Now, we turn to the core strategy of true API security: the full-lifecycle approach, where security is a continuous, integrated process rather than a single action. The…
-
US sues robot toy maker for exposing children’s data to Chinese devs
The U.S. Department of Justice has sued toy maker Apitor Technology for allegedly allowing a Chinese third party to collect children’s geolocation data without their knowledge and parental consent. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-sues-robot-toy-maker-for-exposing-childrens-data-to-chinese-devs/
-
SaaS giant Workiva discloses data breach after Salesforce attack
Workiva, a leading cloud-based SaaS (Software as a Service) provider, notified its customers that attackers who gained access to a third-party customer relationship management (CRM) system stole some of their data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/saas-giant-workiva-discloses-data-breach-after-salesforce-attack/
-
Data masking and data governance: Ensuring data integrity
Safeguarding data is a fundamental function of data governance”, and that extends to the data used by developers. But how do you maintain test data utility when masking sensitive information? First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/data-masking-and-data-governance-ensuring-data-integrity/
-
5 Cybersecurity Vendors Impacted In Salesloft Drift Breach
The attacks have involved stolen authentication tokens for Salesloft-owned Drift, which threat actors have used to steal data from Salesforce CRM systems. First seen on crn.com Jump to article: www.crn.com/news/security/2025/5-cybersecurity-vendors-impacted-in-salesloft-drift-breach
-
FTC announces settlement with toy robot makers that tracked location of children
Apitor collected data without informing parents or asking for permission, the FTC said, violating federal parental consent requirements. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-settlement-apitor-childrens-privacy-violation/
-
FTC fines toy manufacturer for allowing Chinese third-party to collect kids’ data
The complaint alleges that the toy manufacturer Apitor published a privacy policy saying that it complied with the Children’s Online Privacy Protection Rule, but in reality violated the law by collecting the location data from children without parental consent. First seen on therecord.media Jump to article: therecord.media/chinese-toy-manufacturer-fine-ftc-kids-data

