Tag: data
-
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants
The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified,…
-
Medical records, SSNs, and bank details exposed in CareCloud data breach
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/medical-records-ssns-and-bank-details-exposed-in-carecloud-data-breach/
-
SOC 2 vs HIPAA Pentest Requirements for HealthTech Startups
Key Takeaways SOC 2 does not explicitly name penetration testing as mandatory, but auditors expect one in practice for any company handling sensitive data at scale. HIPAA does not name penetration testing as a required control either, it requires a risk analysis, and a pentest is the most common way companies demonstrate one was performed…The…
-
SOC 2 vs HIPAA Pentest Requirements for HealthTech Startups
Key Takeaways SOC 2 does not explicitly name penetration testing as mandatory, but auditors expect one in practice for any company handling sensitive data at scale. HIPAA does not name penetration testing as a required control either, it requires a risk analysis, and a pentest is the most common way companies demonstrate one was performed…The…
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed to detect multi-session misuse without exposing the underlying prompts or responses to OpenAI personnel. Announced on August 19, 2026, this initiative addresses a critical challenge in…
-
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below – First…
-
SickKids data breach exposes employee and job applicant info
Toronto’s Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/
-
Black Hat 2026: What should you be allowed to talk to AI about? FireTail Blog
Tags: ai, attack, business, conference, control, cybersecurity, data, detection, edr, framework, LLM, strategy, technology, tool, vulnerability, vulnerability-managementAug 21, 2026 – Jeremy Snyder – If you were at RSA Conference last year, you probably remember the goats. Or the puppies. Or the miniature petting zoos. It was a year of “over-the-top” spectacle. A bit of a circus, if I’m being honest.Coming into RSAC 2026, the vibe shifted. The show floor was noticeably…
-
Principle of least privilege explained in plain English
If a staff account, supplier login, or application account has more access than it needs, the business takes on unnecessary risk. A single mistake, stolen password, or poorly managed admin account can then affect more systems, more data, and more customers than it should. That is why the principle of least privilege matters. In plain……
-
Best Cloud Security Platform
Cloud computing has transformed how organizations build, deploy, and operate digital services. Businesses can launch applications faster, scale infrastructure on demand, support remote workforces, and access powerful computing resources without maintaining traditional data-center infrastructure for every workload. However, the advantages of cloud computing also introduce new cybersecurity challenges. Modern cloud environments can include: Public cloud…
-
Best Cloud Security Platform
Cloud computing has transformed how organizations build, deploy, and operate digital services. Businesses can launch applications faster, scale infrastructure on demand, support remote workforces, and access powerful computing resources without maintaining traditional data-center infrastructure for every workload. However, the advantages of cloud computing also introduce new cybersecurity challenges. Modern cloud environments can include: Public cloud…
-
Enterprise Network Security Solution
A traditional corporate network may once have consisted primarily of office computers, servers, switches, routers, and a centralized data center. Today, organizations operate across cloud platforms, remote offices, SaaS applications, mobile devices, IoT systems, endpoints, APIs, data centers, and operational technology environments. Employees can access business resources from almost anywhere. Applications may be distributed across…
-
Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind DN, granting them the ability to read or modify data stored in an application’s in-memory LDAP directory. This issue, tracked as CVE-2026-59270, was disclosed on August 20,…
-
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring…
-
Backup, Recovery, Cyber-Resilienz und Storage-Optimierung – Pink Elephant stärkt neue TDN-Einheit ‘Data Resilience Services”
First seen on security-insider.de Jump to article: www.security-insider.de/pink-elephant-staerkt-neue-tdn-einheit-data-resilience-services-a-0a50766c05258d5246c7a2bacc0ab1ab/
-
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers and implants emerging in late May. Manic has rapidly evolved through July, incorporating stronger anti-analysis protections, in-memory DEX loading, lock-screen phishing, and…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
Anxiety over war, wildfires and cyber-attacks leads to growth in cash stocks in EU
Value of banknotes in circulation rises from Euro1bn in 2016 to Euro1.6bn in 2026 as people advised to keep stash of cashThe number of banknotes in circulation in the EU is increasing despite widespread smartphone payments, new data shows, with wildfires ripping through parts of Europe fuelling demand for an emergency stash of cash.While cash…
-
Brazil’s data authority orders halt to facial recognition in Paraná schools
Tags: dataFirst seen on scworld.com Jump to article: www.scworld.com/brief/brazils-data-authority-orders-halt-to-facial-recognition-in-parana-schools
-
Researchers Social-Engineered Copilot Into Exposing Flaw
Varonis Calls CoSnitch Its Third Critical Copilot Exfiltration Flaw This Year. Research firm Varonis found flaws in Microsoft Copilot that allowed it to hack itself and move data elsewhere without raising obvious red flags, which it dubbed CoSnitch. This is the third critical exfiltration flaw Varonis found in Copilot this year alone. First seen on…
-
Breach Roundup: Grandoreiro Returns
Also, French Tax Agency Breach and Accused Ransomware Developer in Swiss Court. This week: Grandoreiro returns, Swiss prosecutors sought a 12-year sentence for ransomware developer, a Medusa ransomware warning, Ransom Busters demanded up to $60,000 from victims, French tax agency disclosed a breach, a Fuxa vulnerability, Stripe vendors exposed in 33 gigabytes data leak. First…
-
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development…
-
Cryptohack Roundup: Harmony’s Post-Exploit Blockchain Rollback
Also: Fake Web3 Interview Led to Wallet Theft, Delio CEO’s 15-Yr Sentence. This week, Harmony to roll back blockchain after exploit, Delio CEO sentenced to 15 years in South Korea, an alleged Ponzi promoter deported to the United States, SafePal and Trezor customers’ data exposed, and attackers exploited a Mac flaw to mine Monero. First…
-
OpenAI Unveils Private Safety Processing to Detect AI Misuse Without Storing Enterprise Data
OpenAI announced Wednesday that it is testing a new security protocol designed to protect enterprise privacy without compromising system safety. The feature, Private Safety Processing, would allow businesses to deploy highly advanced frontier artificial intelligence (AI) models while maintaining a policy of Zero Data Retention (ZDR). The move highlights a growing rift between Silicon Valley’s..…

