Tag: data
-
Pentagon personnel database breach exposes personal data of millions
A Pentagon personnel database was breached for nine months without anyone noticing. Over three million people are affected. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/pentagon-personnel-database-breach-personal-data-millions
-
Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
An Amazon Prime phishing campaign is using fake payment alerts to steal account logins, personal data and complete credit or debit card details from unsuspecting customers. First seen on hackread.com Jump to article: hackread.com/amazon-prime-phishing-fake-billing-steal-login-card/
-
Quantum Readiness Means It’s Time To ‘Elevate’ Your Cryptography Experts: Optiv Field CISO
As businesses prepare for potentially unprecedented data security risks posed by quantum computing, a key part of the preparations should involve providing in-house cryptography specialists with greater attention and support as soon as possible, according to Optiv Field CISO Kristin Lowery. First seen on crn.com Jump to article: www.crn.com/news/security/2026/quantum-readiness-means-it-s-time-to-elevate-your-cryptography-experts-optiv-field-ciso
-
OpenSSL Flaw Could Expose Heap Memory and Crash Applications
OpenSSL has disclosed a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation. The flaw could let a remote peer read unintended plaintext heap memory during handshake data transmission, or cause a denial-of-service condition. Tracked as CVE-2026-84782, it stems from an out-of-bounds read in how DTLS handshake message retransmissions are handled. First seen on…
-
Everpure survey: 88% of executives fear data sovereignty failures
An Everpure survey of 2,100 C-suite and IT leaders across eight countries finds 90% recognise the risk, yet 64% lack a formal strategy to close ‘the sovereignty gap’ First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651384/Everpure-survey-88-of-executives-fear-data-sovereignty-failures
-
Security tools can now scan Claude Enterprise chats and uploads for sensitive data
More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/claude-compliance-api-integrations/
-
OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext
OpenSSL has announced a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation that could allow a remote peer to read unintended plaintext heap memory during handshake data transmission or trigger a denial-of-service condition. This vulnerability, tracked as CVE-2026-84782, stems from an out-of-bounds read when handling DTLS handshake message retransmissions. The issue affects various…
-
FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader
The FBI and Dutch National Police have announced the arrest of a 24-year-old man from Amsterdam who is suspected of playing a major role in the ShinyHunters cybercrime group. This development marks a significant step forward in an international investigation into a widespread data theft and extortion operation. The suspect was arrested on September 15,…
-
In this new SME cybersecurity service, the AI assists and the consultants decide
BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized enterprises (SMEs) … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/bh-haven-sme-cybersecurity-service/
-
Most open critical and high flaws are over 90 days old
Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/
-
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France’s tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July.Neither the tax administration nor France’s national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on…
-
Only 30% of Metropolitan Police officers have completed mandatory data training
Metropolitan Police senior officers admit that only 30% of the force has completed mandatory data protection training following a series of high-profile data incidents First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651475/Only-30-of-Metropolitan-Police-officers-have-completed-mandatory-data-training
-
Why AI won’t fix your cybersecurity problem
James Gillies, Head of Cyber Security at Logicalis UKI There is no escaping the fact that AI is creating significant opportunities for cybersecurity teams, from analysing security data and identifying suspicious activity to accelerating detection, response and remediation. However, the same capabilities are also changing the threat landscape. This comes at a time when security…
-
Arizona Supreme Court says hackers stole residents’ personal data
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday. First seen on therecord.media Jump to article: therecord.media/arizona-supreme-court-says-hackers-stole-data
-
Arizona Supreme Court says hackers stole residents’ personal data
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday. First seen on therecord.media Jump to article: therecord.media/arizona-supreme-court-says-hackers-stole-data
-
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
A teen hacker found an authentication flaw in Microsoft’s Titan analytics service, where metadata indicated an estimated 17.3… First seen on hackread.com Jump to article: hackread.com/teen-hacker-microsoft-auth-flaw-data-rows/
-
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
A teen hacker found an authentication flaw in Microsoft’s Titan analytics service, where metadata indicated an estimated 17.3… First seen on hackread.com Jump to article: hackread.com/teen-hacker-microsoft-auth-flaw-data-rows/
-
Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Hackers stole patient data from Qbusoft, a Polish medical software maker, weeks after a breach at another provider exposed records of nearly 19 million people in the country. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/29/qbusoft-medyc-data-breach-poland/
-
Keio Railway Confirms Ransomware Attack Disrupted Business Systems
Keio Corporation has confirmed that a ransomware attack has caused a system failure within parts of its group infrastructure, disrupting certain business systems at its affiliated companies. The Japanese railway operator stated that train services continue to operate and that it has not yet confirmed any data breach. In a public notice issued on September…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…

