Tag: data
-
Grok exfiltrates user data when malicious instructions are encrypted
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/
-
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud access keys, SSH material, and sensitive user files. Earlier research by RST Cloud identified MacSync infrastructure and observed command-and-control replacement after public disclosure. Microsoft’s subsequent telemetry-led…
-
AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/aws-ai-agents-access-controls/
-
New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/
-
OpenAI previews privacy-focused system for detecting AI misuse
OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/openai-private-safety-processing-zdr/
-
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that…
-
Data protection through encryption and secure channels for UK SMEs
Key takeaways Start with the data that would hurt most if exposed, then apply encryption where it reduces the biggest business risk. Protect both stored data and data in transit, because laptops, backups, websites, and system connections all carry different risks. Encryption only works properly when keys, passwords, certificates, and access rights are managed carefully….…
-
Identity Is Broken. Stop Trying to Fix It.
Tags: access, authentication, credentials, cryptography, data, identity, infrastructure, mfa, zero-trustFrom the earliest days of public-key cryptography and systems like Rivest-Shamir-Adleman (RSA), organizations have relied on identity and credentials to determine who can access IT environments, data, and applications. Over the decades, this infrastructure has undergone innovations like multi-factor authentication, single sign-on, identity providers, and zero-trust architectures. Then, there has been the emergence of various..…
-
US charges 17 Iranian hackers over 31-terabyte academic data theft
The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/us-iranian-hackers-mabna-institute-charged/
-
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted
A broad Firefox add-on campaign that includes 13 malicious Rabby Wallet impersonators engineered to exfiltrate wallet keyring data before the application encrypts it locally. The activity is part of a larger operation, provisionally tracked as “Offside Wallet Theft Factory,” which links 77 Firefox extension identities through cloned code, reused infrastructure, deceptive listings, stable add-on IDs,…
-
Heights Finance data breach impacts over 700,000 customers
First seen on scworld.com Jump to article: www.scworld.com/brief/heights-finance-data-breach-impacts-over-700000-customers
-
Heights Finance data breach impacts over 700,000 customers
First seen on scworld.com Jump to article: www.scworld.com/brief/heights-finance-data-breach-impacts-over-700000-customers
-
EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack
CareCloud Said Compromise Involved One of Its AWS Cloud Environments. CareCloud, a provider of cloud-based, artificial intelligence-powered electronic health records, is notifying nearly 3.8 million individuals that their personal and health information was potentially stolen in a March hacking incident involving one of its Amazon Web Services environments. First seen on govinfosecurity.com Jump to article:…
-
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/
-
Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/
-
Sakura Internet hack exposes data of up to 1.36 million accounts
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/
-
Healthtech firm CareCloud data breach impacts 3.7 million patients
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/
-
Rising Number of Cyberattacks Have AI-Assisted Fingerprints
Claude Code Especially Tied to Semi-Automated Intrusions, Data Theft, Ransomware. Attackers’ operational security fails reveal they’re increasingly wielding artificial intelligence tools in semi-autonomous ways to help them conduct reconnaissance and perpetrate ransomware infections and data exfiltration at greater speed and scale than ever before – albeit with mixed results. First seen on govinfosecurity.com Jump to…
-
The Hidden Risk in Data Transfer
Cybersecurity has become one of the most defining business challenges of recent times. Organisations have invested heavily in protecting their networks, securing cloud environments and strengthening identity and access management. At the same time, organisations are under increasing pressure to prove they are handling sensitive information securely, not just storing it safely but protecting it…
-
DoD Regulatory Pause: No Excuse to Weaken Supply Chain Trust
IonQ CIO Katie Arrington on Unclassified Info, CMMC’s Third-Party Supplier Audits. At CIO.inc’s Business Transformation Summit in New Delhi, CXOs from Cars24, Mastercard AI Garage and ISMG argued the real AI model decision isn’t build versus buy, it’s data readiness, evaluation rigor and who owns the outcome. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/dod-regulatory-pause-no-excuse-to-weaken-supply-chain-trust-a-32603

