Tag: data
-
South Korean startup platform breach exposes key management failures
A breach at South Korea’s government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/
-
Gunra ransomware: what you need to know
The ransomware gang Gunra has been creating havoc – exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. First seen on fortra.com Jump to article: www.fortra.com/blog/gunra-ransomware-what-you-need-know
-
Mimecast CEO on why AI risk starts with the user
Ranjan Singh talks up the security supplier’s focus on human risk management, the behavioural data he believes rivals can’t match, and why having a local datacentre is a condition of doing business in APAC First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649561/Mimecast-CEO-on-why-AI-risk-starts-with-the-user
-
Slovakia Warns of Cyber Risks in Road Speed Cameras
Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about…
-
TikTok Settles U.S. Child Privacy Case for $400 Million
TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. >>Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance,…
-
The Rise of Service-Centric Credential Compilations
How Cybercriminals Are Repackaging Infostealer Data Over the last year, the underground economy has undergone a significant transformation. Cybercriminals are no longer focused on distributing massive collections of raw infostealer logs, they are increasingly investing time in organizing and enriching stolen information into service-specific compilations. These datasets are no longer random collections of credentials extracted……
-
Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/black-kite-mid-market-ransomware-risk-report/
-
Apollo Data Breach Shows the Risk Behind a Simple Phone Call
Apollo Global Management has disclosed a data breach involving sensitive personal information after attackers gained access to parts of its cloud environment. The breach occurred between July 6 and July 10, 2026. Apollo later determined that the affected information may include names, dates of birth, contact details, home addresses, and Social Security numbers. The company……
-
Access Control for High-Stakes Enterprise SaaS: What Board Portals and Data Rooms Get Right
Discover how top-tier board portals and virtual data rooms master complex access control. Learn to secure your enterprise SaaS with these proven strategies. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/access-control-for-high-stakes-enterprise-saas-what-board-portals-and-data-rooms-get-right/
-
Hospital for Sick Children discloses employee data breach due to third-party software flaw
First seen on scworld.com Jump to article: www.scworld.com/brief/hospital-for-sick-children-discloses-employee-data-breach-due-to-third-party-software-flaw
-
US Bank investigates LockBit ransomware claims of data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/us-bank-investigates-lockbit-ransomware-claims-of-data-breach
-
AI supplier assurance and governance expectations for UK SMEs
For many UK SMEs, the biggest risk with artificial intelligence is not whether the tool looks impressive in a demo. It is whether the supplier can be trusted to handle your data, support your business safely, and behave predictably when something goes wrong. That is where AI supplier assurance and governance expectations matter. In plain……
-
Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection
A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially exposing a user’s name, approximate location, subscription tier, and active conversation history. Security researchers at Adversa AI have dubbed the technique >>Cryptographic Context Injection.<< The attack targets Grok's ability to…
-
768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts
Tags: access, cloud, corporate, credentials, cyber, data, data-breach, iam, infrastructure, risk, theftA large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include 526 root access keys and 242 IAM user keys attached to AWS’s AdministratorAccess managed…
-
Who Is REvil’s Ransomware Developer Anatoly Sergeevitsch Kravchuk?
Dear blog readers. This is Dancho. A reader recently approached me with a detailed research and analysis for Quake3 a XSS forum moderator where he connected the dots that Quake3 is also the main developer of the REvil ransomware where he asked me to go ahead and publish it. So who’s Anatoly Sergeevitsch Kravchuk? Dark…
-
AI Analytics Hits a Trust Barrier
Widespread Experimentation Has Yet to Produce Enterprise-Scale Adoption. Enterprises are pushing AI analytics into production, but most employees still rely on dashboards and manual requests. A new survey finds limited confidence in AI-generated answers is holding back organization-wide adoption and changing the skills required of data teams. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-analytics-hits-trust-barrier-a-32632
-
91 Spring CVEs: The AI Vulnerability Consumption Problem
Tags: access, advisory, ai, attack, cloud, cve, cvss, data, data-breach, framework, guide, injection, intelligence, open-source, risk, service, software, tool, update, vulnerability<div cla TL;DR Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects. At the time of publishing, Sonatype Guide currently identifies 209,569 software components affected by the security event. The disclosure comes amid a dramatic rise in AI-assisted vulnerability discovery. Broadcom…
-
Apollo discloses data breach from ongoing wave of attacks hitting financial sector
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. First seen on cyberscoop.com Jump to article: cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/
-
Randall Munroe’s XKCD ‘Offside’
via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/randall-munroes-xkcd-offside/
-
New Manic Android Malware Uses Offline Networks to Drain Bank Accounts
Manic Android malware steals banking credentials and can relay stolen data through nearby infected phones, complicating traditional device isolation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/
-
U.S. Bank says breach claims related to fourth-party incident
The bank said there is no evidence that its own systems, networks or data repositories were compromised. First seen on therecord.media Jump to article: therecord.media/us-bank-says-breach-claims-related-to-fourth-party-incident
-
Critical Patches, AI-Driven Attacks, and Data Theft Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters in August 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/critical-patches-ai-driven-attacks-and-data-theft-define-the-week-in-august-2026/
-
Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off
Amazon’s less-detailed order emails protect purchase data but may make phishing harder to spot. Learn how to verify order messages safely online. The post Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-amazon-order-email-privacy-phishing-trade-off/
-
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children, which was hit in a ransomware incident in 2022 that disabled some of its systems, released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application. First seen on therecord.media Jump to article: therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data
-
PCI DSS v4.0 Deadline: 5-Step Gap Assessments Now
Organizations handling cardholder data face an urgent imperative in 2026: transitioning to PCI DSS v4.0 requires immediate, structured gap assessments rather than reactive remediation. Lazarus Alliance brings first-hand audit experience across high-stakes sectors to highlight why a proprietary 5-step methodology outperforms traditional checklists, integrating risk management with cross-framework alignment to CMMC, NIST 800-53, and ISO”¦…
-
Data Privacy Regulations: Unified Compliance by Continuum GRC
Data privacy regulations continue to evolve rapidly, demanding that organizations adopt unified compliance approaches to manage overlapping requirements efficiently. Continuum GRC delivers integrated risk management solutions that align multiple frameworks while addressing the technical and organizational realities faced by CISOs and compliance teams. Why Unified Compliance Matters for Data Privacy Regulations Fragmented compliance efforts often”¦…
-
Palo Alto, NTT Data Set $1B Goal for Expanded Security Partnership
Palo Alto Networks and NTT Data have expanded their existing cybersecurity partnership into a multi-year global alliance, setting a goal of generating $1 billion in joint business by 2029. The agreement brings the companies into closer engineering and delivery work, including giving NTT Data early access to new Palo Alto Networks platform features. Palo Alto..…
-
Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-online-privacy-possible-how-digital-identities-can-help/

