Tag: data
-
Google settles nearly $1.4B Texas case for collecting personal data
First seen on scworld.com Jump to article: www.scworld.com/news/google-settles-nearly-14b-texas-case-for-collecting-personal-data
-
Randall Munroe’s XKCD ‘Pascal’s Law’
via the inimitable Daniel Stori at Turnoff.US! Permalink First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2025/05/randall-munroes-xkcd-pascals-law/
-
Marks and Spencer confirms data breach after April cyber attack
Marks and Spencer (M&S) confirms that threat actors stole customer data in the ransomware attack that hit the company in April. In April, Marks and Spencer Group plc (M&S) announced it had been managing a cyber incident in recent days with the help of external cyber security experts. Customers report outages affecting card payments, gift…
-
CISA Warns of TeleMessage Vuln Despite Low CVSS Score
Though the app claims to use end-to-end encryption, hackers have reportedly accessed archived data on the app’s servers via a new vulnerability. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/cisa-warns-telemessage-vuln-low-cvss-score
-
M&S says hackers gained access to customer data in April cyberattack
The UK retailer said the payment data was masked and therefore not usable. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ms-hackers-customer-data-cyberattack/747956/
-
PrepHero-Linked Database Exposed Data of 3M Students and Coaches
A security lapse on PrepHero, a college recruiting platform, exposed millions of unencrypted records, including sensitive personal details… First seen on hackread.com Jump to article: hackread.com/prephero-database-exposed-students-coaches-data/
-
Australian data breaches hit record high in 2024
More than 1,100 data breaches were reported in Australia last year, a 25% jump from 2023, prompting calls for stronger security measures across businesses and government agencies First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366623874/Australian-data-breaches-hit-record-high-in-2024
-
New Intel CPU flaws leak sensitive data from privileged memory
A new “Branch Privilege Injection” flaw in all modern Intel CPUs allows attackers to leak sensitive data from memory regions allocated to privileged software like the operating system kernel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-intel-cpu-flaws-leak-sensitive-data-from-privileged-memory/
-
China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures
Tags: access, api, apt, attack, authentication, backdoor, backup, breach, business, china, cloud, control, cve, cyber, data, data-breach, detection, dns, encryption, endpoint, espionage, exploit, finance, firewall, fortinet, google, government, group, infection, infrastructure, intelligence, Internet, ivanti, linux, malicious, malware, mandiant, military, network, open-source, programming, rat, remote-code-execution, reverse-engineering, risk, rust, sap, service, strategy, tactics, threat, tool, update, vmware, vpn, vulnerability, windows, zero-dayExecutive Summary EclecticIQ analysts assess with high confidence that, in April 2025, China-nexus nation-state APTs (advanced persistent threat) launched high-temp exploitation campaigns against critical infrastructure networks by targeting SAP NetWeaver Visual Composer. Actors leveraged CVE-2025-31324 [1], an unauthenticated file upload vulnerability that enables remote code execution (RCE). This assessment is based on a publicly…
-
PowerSchool data breach leads to school extortion attempts
A threat actor has contacted multiple school districts demanding payments related to student and staff data stolen in a December breach. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/powerschool-data-breach-school-extortion-attempts/747801/
-
Varonis erweitert sein MDDR-Team um KI-Agenten für eine noch schnellere Vorfallsreaktion
Der Spezialist für datenzentrierte Cybersicherheit, Varonis Systems, ergänzt seinen Managed-Data-Detection and Response (MDDR)-Service durch agentenbasierte KI. Diese arbeitet autonom und führt eine Reihe von Aktionen selbstständig durch. Auf diese Weise werden Triage, Untersuchungen und die Eindämmung beschleunigt, bevor die priorisierten Vorfälle an einen menschlichen Experten des Varonis-MDDR-Teams weitergeleitet werden. Moderne Angreifer setzen künstliche Intelligenz als…
-
M&S says customer data stolen in cyberattack, forces password resets
Marks and Spencer (M&S) confirms that customer data was stolen in a cyberattack last month, when ransomware was used to encrypt servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mands-says-customer-data-stolen-in-cyberattack-forces-password-resets/
-
Marks Spencer Confirms Customer Data Breach in Recent Cyber Attack
British retail giant Marks & Spencer has officially confirmed that customer personal data was compromised during a cyber attack that began three weeks ago. The retailer revealed that the breach affects potentially millions of customers whose information has been stolen, though payment card details remain secure. The company is still struggling to restore its online…
-
Marks & Spencer confirms customer data stolen in cyberattack
M&S said that some customer data, but not payment card details or passwords, had been breached in a recent cyberattack. First seen on therecord.media Jump to article: therecord.media/marks-spencer-confirms-customer-data-breach
-
Marks Spencer confirms customers’ personal data was stolen in hack
A ransomware gang reportedly took credit for the data breach. First seen on techcrunch.com Jump to article: techcrunch.com/2025/05/13/marks-spencer-confirms-customers-personal-data-was-stolen-in-hack/
-
APT group exploited Output Messenger Zero-Day to target Kurdish military operating in Iraq
A Türkiye-linked group used an Output Messenger zero-day to spy on Kurdish military targets in Iraq, collecting user data since April 2024. Since April 2024, the threat actor Marbled Dust (aka Sea Turtle, Teal Kurma, Marbled Dust, SILICON and Cosmic Wolf) has exploited a zero-day flaw (CVE-2025-27920) in Output Messenger to target Kurdish military-linked users…
-
PupkinStealer Targets Windows Users to Steal Browser Login Credentials
A newly identified information-stealing malware dubbed PupkinStealer has emerged as a significant threat to Windows users, with its first sightings reported in April 2025. Written in C# using the .NET framework, this malicious software is engineered to pilfer sensitive data, including browser credentials, messaging app sessions from platforms like Telegram and Discord, desktop documents, and…
-
Exploring CNAPP Options for Cloud Security in 2025
Cloud adoption continues to rise, and with it comes increased complexity. Organizations use multiple cloud platforms, creating challenges that traditional security tools struggle to handle. Cloud-Native Application Protection Platforms (CNAPPs) have emerged as vital solutions. CNAPPs offer integrated security across cloud-native environments, from applications and workloads to data and infrastructure. As organizations look to optimize…
-
M&S Confirms Customer Data Stolen in Cyber-Attack
M&S Chief Executive, Stuart Machin, said that the firm has written to customers to inform them that some personal information was accessed by threat actors First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ms-customer-data-stolen-attack/
-
M&S says some personal data was taken in cyber-attack
Details taken are names, addresses and Marks & Spencer order histories, the Guardian understands<ul><li><a href=”https://www.theguardian.com/business/live/2025/may/13/uk-wage-growth-slows-payrolls-vacancies-drop-thames-water-mps-us-inflation-business-live-news”>Business live latest updates</li></ul>Marks & Spencer has said for the first time that some personal customer information was taken in the <a href=”https://www.theguardian.com/business/marksspencer”>cyber-attack that has crippled its online operation for more than three weeks.Since the retailer’s IT systems were hit by…
-
GenAI’s New Attack Surface: Why MCP Agents Demand a Rethink in Cybersecurity Strategy
Anthropic’s Model Context Protocol (MCP) is a breakthrough standard that allows LLM models to interact with external tools and data systems with unprecedented flexibility. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/05/genais-new-attack-surface-why-mcp-agents-demand-a-rethink-in-cybersecurity-strategy/
-
Deepfake attacks are inevitable. CISOs can’t prepare soon enough.
Tags: advisory, ai, attack, authentication, awareness, blockchain, business, ciso, compliance, control, cybersecurity, data, deep-fake, defense, detection, espionage, finance, fraud, governance, grc, identity, incident response, jobs, law, mfa, north-korea, password, privacy, resilience, risk, scam, software, strategy, tactics, technology, threat, tool, training, updateReal-world fabrications: Even security vendors have been victimized. Last year, the governance risk and compliance (GRC) lead at cybersecurity company Exabeam was hiring for an analyst, and human resources (HR) qualified a candidate that looked very good on paper with a few minor concerns, says Kevin Kirkwood, CISO.”There were gaps in how the education represented…
-
Google to pay Texas nearly $1.4 billion over alleged data privacy violations
The payout far outstrips any other state settlements against the tech giant over data privacy. First seen on therecord.media Jump to article: therecord.media/google-texas-privacy-violations-billions
-
Google to pay $1.375 billion to settle Texas data privacy violations
Google has agreed to a $1.375 billion settlement with the state of Texas over a 2022 lawsuit that alleged it had been collecting and using biometric data of millions of Texans without properly acquiring their consent. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/legal/google-to-pay-1375-billion-to-settle-texas-data-privacy-violations/
-
Majority of Browser Extensions Pose Critical Security Risk, A New Report Reveals
99% of enterprise users have browser extensions but over half carry high-risk permissions. LayerX’s 2025 report reveals how everyday extensions expose sensitive data, and what security teams must do now. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/majority-of-browser-extensions-pose-critical-security-risk-a-new-report-reveals/
-
Threat Actors Leverage DDoS Attacks as Smokescreens for Data Theft
Distributed Denial of Service (DDoS) attacks, once seen as crude tools for disruption wielded by script kiddies and hacktivists, have undergone a sophisticated transformation in today’s complex, hybrid-cloud environments. No longer just blunt instruments aimed at overwhelming systems, DDoS attacks are increasingly being deployed as strategic smokescreens to mask more insidious breaches. Recent data indicates…
-
“PupkinStealer” .NET Malware Steals Browser Data and Exfiltrates via Telegram
A new information-stealing malware dubbed “PupkinStealer” has emerged as a significant threat to individuals and enterprises. Developed in C# using the .NET framework, this 32-bit GUI-based Windows executable targets sensitive user data with a focused and efficient approach. First observed in April 2025, PupkinStealer is designed to harvest a specific range of data, including browser…
-
Phishing Campaign Uses Blob URLs to Bypass Email Security and Avoid Detection
Cybersecurity researchers at Cofense Intelligence have identified a sophisticated phishing tactic leveraging Blob URIs (Uniform Resource Identifiers) to deliver credential phishing pages directly to users’ inboxes while evading traditional email security measures. Blob URIs, typically used by browsers to handle temporary data like images, audio, or video files, are now being weaponized by threat actors…

