Tag: data
-
Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms.Yet despite this abundance of information, many organizations continue to face a fundamental challenge: sifting through the noise to understand who is behind…
-
UK data regulator slammed over lack of action on complaints
Tags: dataThe UK data regulator is being threatened with legal action after it was accused of ‘ignoring’ thousands of data protection complaints, with critics describing its new approach to complaint triage and investigation as akin to a ‘digital bin’ for the public’s concerns First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366644403/UK-data-regulator-slammed-over-lack-of-action-on-complaints
-
Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Sensitive Enterprise Data
A newly disclosed SearchLeak vulnerability in Microsoft 365 Copilot Enterprise exposed a critical pathway for attackers to steal sensitive organizational data through a specially crafted URL. The flaw chain, now tracked as CVE-2026-42824, was patched by Microsoft earlier this month and assigned a critical severity rating due to its potential impact. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/searchleak-vulnerability-microsoft-365-copilot/
-
iRhythm discloses data breach, says hackers stole patient info
Digital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients’ personal and health information stored on third-party-hosted business applications. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/
-
Microsoft 365 Copilot Vulnerability Exposes Sensitive Data Through One-Click Attack
Microsoft 365 Copilot has been found vulnerable to a critical one-click data exfiltration attack chain dubbed “SearchLeak,” exposing sensitive enterprise data through a combination of AI-specific and traditional web vulnerabilities. Discovered by Varonis Threat Labs, the flaw, tracked as CVE-2026-42824 and rated critical, demonstrates how modern AI integrations can unintentionally expand attack surfaces by linking…
-
A $2 trillion revenue shift hinges on AI data governance
Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/16/ai-data-governance-revenue-shift/
-
Leading job sites sell user data, Incogni report reveals
First seen on scworld.com Jump to article: www.scworld.com/brief/leading-job-sites-sell-user-data-incogni-report-reveals
-
SearchLeak vulnerability allows data theft from Microsoft 365 Copilot Enterprise
First seen on scworld.com Jump to article: www.scworld.com/brief/searchleak-vulnerability-allows-data-theft-from-microsoft-365-copilot-enterprise
-
Nintendo Alleged Data Breach: Threat Actor Demands $2M Ransom
Nintendo faces an alleged data extortion incident involving HR records, internal reports, and potential exposure of third-party vendors. The post Nintendo Alleged Data Breach: Threat Actor Demands $2M Ransom appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-nintendo-alleged-data-leak-third-party-risk/
-
Copilot ‘SearchLeak’ Attack Allows 1-Click Data Theft
The critical, three-stage attack is now patched, but it’s part of a new group of AI prompt-injection issues that use hidden URLs and other variables. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/copilot-searchleak-attack-1-click-data-theft
-
Google exposes China espionage group that’s been lurking in networks undetected since 2023
The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to intercept research and steal data with national security implications. First seen on cyberscoop.com Jump to article: cyberscoop.com/google-unc6508-china-espionage-threat/
-
Labcorp Agrees to Pay $35M to Settle AMCA Data Breach
Diagnostics Lab Reported 10.3M Patients Affected by Collection Agency’s Hack. Medical laboratory testing giant Labcorp has agreed to pay $35 million to settle class action litigation stemming from a 2018 hacking incident on now-defunct American Medical Collections Agency. Labcorp reported the vendor breach in 2019 as affecting nearly 10.3 million patients. First seen on govinfosecurity.com…
-
Why AI Defenses Fail Without Data and Identity Fundamentals
RPC’s Spencer Scott on Why Security Basics Must Come Before Agentic AI Adoption. Organizations are racing toward agentic AI defenses, but without clean data, identity and asset management in place, those defenses will fall short. Security fundamentals must come first, said Spencer Scott, head of information security at RPC. First seen on govinfosecurity.com Jump to…
-
Maine closes data breach portal to the public after fake reports
Maine is still allowing companies to report breaches, but won’t make the portal easily available to the public until after it completes an audit of its procedures to stop such incidents, according to a press release from the Maine attorney general’s office. First seen on therecord.media Jump to article: therecord.media/maine-turns-off-breach-portal-fake-reports
-
Hackers Demand $2M From Nintendo Over Alleged Data Breach
A threat actor claims to have stolen Nintendo data and is demanding $2 million. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/hackers-demand-2m-from-nintendo-over-alleged-data-breach/
-
Council of Europe investigates ShinyHunters data breach claims
The Council of Europe, the continent’s oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/
-
Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security Risks
How the Anubis ransomware group stole and leaked an Italian Adriatic port authority’s data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/anubis-ransomware-adriatic-port/
-
Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security Risks
How the Anubis ransomware group stole and leaked an Italian Adriatic port authority’s data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/anubis-ransomware-adriatic-port/
-
15th June Threat Intelligence Report
The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/15th-june-threat-intelligence-report/
-
Chinese hackers breach REDCap servers, steal medical research
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-hackers-breach-redcap-servers-steal-medical-research/
-
Maine forced to take down data breach portal after fake notices filed with authorities
The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/maine-take-down-data-breach-portal
-
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target’s mailbox, OneDrive, or SharePoint account through a specially crafted URL. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/
-
Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/
-
SHADOWBYT3$ Allegedly Claims Nintendo Breach and Theft of Sensitive Data
Threat intelligence sources have flagged a potential cybersecurity incident involving Nintendo after threat actor “SHADOWBYT3$” allegedly claimed responsibility for breaching internal systems and exfiltrating sensitive data. The claim surfaced on June 13, 2026, via underground monitoring channels and was later amplified by threat intelligence platform Hackmanac. At the time of writing, the incident remains unverified,…
-
PromptSnatcher Browser Extensions Abuse AI Platforms to Capture Full Chat Conversations
PromptSnatcher (internal identifier: Panel 231) is a modern, stealthy data collection operation embedded inside two browser extensions that masquerade as ad”‘blockers while harvesting full chat conversations and account metadata from major AI platforms. The extensions deliver genuine ad”‘blocking and cookie”‘banner suppression by ingesting legitimate public filter lists such as EasyList and I Don’t Care About…
-
Maine Shuts Down Breach Reporting Portal Following Fake VRChat and Discord Submissions
The Office of the Maine Attorney General has temporarily taken its public data breach reporting portal offline following the discovery of fraudulent submissions falsely claiming security incidents at VRChat and Discord. The incident, disclosed in an official statement on June 12, 2026, highlights growing concerns over the integrity and potential abuse of publicly accessible breach…

