Tag: data
-
US charges Iranian hackers over $3.4 billion intellectual property theft
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-charges-iranian-hackers-over-34-billion-intellectual-property-theft/
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…
-
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. First seen on cyberscoop.com Jump to article: cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/
-
Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign. First seen on therecord.media Jump to article: therecord.media/latvia-cyberattack-vehicle-data
-
Blinde Flecken bei der Absicherung von KI-Rechenzentren
TrendAI veröffentlicht den Report ‘An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers”. Die Untersuchung zeigt: Während die Server von KI-Rechenzentren mit leistungsstarken Firewalls und Zero-Trust-Architekturen gesichert werden, bleibt eine andere Angriffsfläche oft unbeachtet die physische Gebäudetechnik, die Kühlung, Stromversorgung und Klimaregelung steuert. Forscher von TrendAI fanden 6.300 solcher Systeme, […]…
-
CareCloud confirms 3.7M patients had their medical records stolen in data breach
The cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/
-
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.”The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software…
-
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments…
-
659 Stripe Merchant API Keys Leaked Online, Exposing 688,000 Customer Records
A data leak published on a cybercrime data-trading forum has exposed live Stripe API credentials for 659 merchant accounts, along with approximately 35 GB of customer- and payment-related data. The exposure affects an estimated 688,363 customer records across merchants in 42 countries, but available evidence indicates that Stripe’s own infrastructure was not breached. The dataset…
-
ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts
The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ico-police-data-governance-facial/
-
UK Fraud Cases Hit Record High in 2026
Cifas data finds account takeover and identity fraud are driving a surge in fraud cases First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-fraud-cases-hit-record-high/
-
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest.The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault…
-
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration.The tech giant said it required multiple endpoint and network behaviors to align before First seen on…
-
50,000 Stripe Secrets Leaked in Public Code
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research…
-
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from…
-
RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors
The RAVEN offensive framework can turn compromised Elasticsearch and Kibana environments into durable data-theft and persistence operations. RAVEN, short for Reconnaissance & Attack on Vulnerable Elasticsearch Nodes, is an open-source modular framework built to assess Elasticsearch and Kibana security posture across reconnaissance, exploitation, exfiltration, persistence, and cleanup workflows. Its latest walkthrough focuses on post-exploitation against…
-
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn’t going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/prison-data-analyst-extort-employer
-
Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data
Tags: credentials, cve, cvss, cyber, data, exploit, extortion, hacker, ransomware, remote-code-execution, vulnerabilityThe Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can harvest credentials, map engineering data vaults, and exfiltrate files without requiring additional attacker tooling. Tracked as CVE-2026-12569, the vulnerability is a CVSS 9.3 remote code execution issue affecting PTC Windchill PDMlink and…
-
Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click
A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. This flaw could enable an attacker to trigger malicious Copilot prompts, access data from connected OAuth applications, and silently transmit that information to an attacker-controlled server. Microsoft addressed this issue on August 18, 2026, following Varonis’s responsible disclosure in December 2025.…
-
Internet users increasingly frustrated by AI slop and data leaks
First seen on scworld.com Jump to article: www.scworld.com/brief/internet-users-increasingly-frustrated-by-ai-slop-and-data-leaks
-
Hackers Expose Data of 1.2 Million Heights Finance Customers
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance…
-
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim’s Copilot session.The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that…
-
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a fee ranging from $20,000 to $60,000.”In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,”…
-
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/
-
Law Firms Increasingly Targeted By Ransomware/Vishing Attacks
Law firms face growing ransomware and data-theft threats as attackers target privileged client information, exposing firms to cybersecurity, ethical and legal risks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/law-firms-increasingly-targeted-by-ransomware-vishing-attacks/
-
Broken Access Control Is Still Winning: 2025 OWASP Data
Key Takeaways Broken access control remains the number one category in OWASP’s Top 10 2025 release, the fourth consecutive edition where it has held the top spot. Security misconfiguration jumped from fifth place to second, driven largely by cloud configuration complexity rather than code level bugs. OWASP’s own reported average incidence rate for broken access…The…
-
Critical MLflow SSRF Flaw Exploited in the Wild
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure, according to watchTowr. This flaw affects MLflow versions before 3.15.0 and can expose cloud credentials, internal services, and other sensitive data to remote attackers. MLflow SSRF Flaw The vulnerability exists in MLflow’s model-registry…

