Tag: data
-
77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk. The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-open-vsx-extension-risk/
-
Fake The Odyssey Downloads Are Hiding Password-Stealing Malware
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information. The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-the-odyssey-fake-downloads-lumma-stealer/
-
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rovoblast-atlassian-rovo-url/
-
Signed up for Klaviyo? Dozens of advertisers may have seen your password
A bug in the tech giant’s website mistakenly shared users’ sign-up information, including personal data and their password, to third-party companies. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/10/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password/
-
9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old
A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire national registry, 9.2 million records covering essentially the whole country. Ransomnews…
-
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/
-
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Companies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
-
Metabase zero-day exploited to access Framework customer data
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/
-
Blockchain and AI: Why Trusted Data Matters
The internet has crossed a threshold that content teams can no longer ignore. Independent analysis of tens of thousands of web pages found that mostly AI-generated articles accounted for an estimated 49.9% of sampled content published in the first quarter of 2026, a level that has held roughly steady since AI-written material briefly overtook human-written…
-
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
-
Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo’s handling of URL-supplied prompts, enabling attackers to inject malicious instructions into an authenticated user’s AI session. The attack does not require traditional…
-
At A Loss Courts Struggle to Define >>Loss<< Under Computer Hacking Law
Recent CFAA rulings clarify that qualifying “loss” can include reasonable forensic investigation and incident-response costs even when computers or data are not visibly damaged. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/at-a-loss-courts-struggle-to-define-loss-under-computer-hacking-law/
-
New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail services need to display HTML controlled by the sender without compromising the security of the mailbox application. To achieve this,…
-
20 Flaws in Fertility Tracker Risked Data Loss, Fake Results
Mira Ultra 4 Fixes Vulnerabilities After University Team Hacked Bluetooth, Firmware. Multiple vulnerabilities identified in a popular at-home fertility tracking device could have allowed attackers to impersonate the device, manipulate hormone readings, access sensitive health information and reverse engineer production firmware, said the researchers who made the discovery. First seen on govinfosecurity.com Jump to article:…
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
ExfilSquad Targets New Victims, Shares Data via Torrents
Tags: dataFirst seen on resecurity.com Jump to article: www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
-
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
-
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It…
-
Data Poisoning: Warum vergiftete Daten eine wachsende Gefahr für die IT-Sicherheit sind
Tags: dataFirst seen on t3n.de Jump to article: t3n.de/news/data-poisoning-warum-vergiftete-daten-eine-wachsende-gefahr-fuer-die-it-sicherheit-sind-1756214/
-
The Hidden Risks of Ignoring API Security During Mobile Application Security Testing
Mobile applications don’t operate in isolation. Behind every login screen, payment flow, and push notification sits a network of APIs quietly moving data between the app, the backend, and third-party services. Yet when organizations plan mobile application security testing, API security is often treated as an afterthought, something to “get to later” once the app’s……
-
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered…
-
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Tags: access, authentication, business, cve, data, exploit, flaw, intelligence, software, sql, vulnerability, zero-dayMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain…
-
Forcepoint’s Ronan Murphy on securing the data layer AI just set on fire
First seen on scworld.com Jump to article: www.scworld.com/resource/forcepoints-ronan-murphy-on-securing-the-data-layer-ai-just-set-on-fire
-
Practice Management Firm Notifies 3.8M of 2025 Breach
Ohio-Based Unlimited Technology Systems Serves Thousands of Medical Practices. Practice management and financial software firm Unlimited Technology Systems is notifying 3.8 million people of an October 2025 data theft. The third-party vendor hack currently ranks as the largest health data breach reported to federal regulators so far in 2026. First seen on govinfosecurity.com Jump to…
-
ISMG Editors: AI Is Supercharging Attackers
Also: CIOs Rethink Data in AI Rollouts, ShinyHunters Hits Biotech. In this week’s panel, four ISMG editors discussed new research showing how AI is making cyberthreat actors more capable, why the technology is forcing CIOs to rethink data platforms they spent years modernizing and a string of attacks in the biotech sector. First seen on…
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
Snowflake Hacker Pleads Guilty After Breaches Exposed Data of at Least 100 Million People
A hacker tied to the 2024 Snowflake customer breaches pleaded guilty after attacks exposed data tied to at least 100 million people. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-snowflake-hacker-guilty-data-breach/
-
Financial Services Under Fire From Rebranded Extortionists
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon. Data theft extortion group BlackFile claimed retire in May. Threat researchers at Google said telemetry and attack infrastructure shows that the group has carried on using a variety of new brand names and shifted its focus to targeting financial services. First seen on…

