Tag: data
-
Financial Services Under Fire From Rebranded Extortionists
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon. Data theft extortion group BlackFile claimed retire in May. Threat researchers at Google said telemetry and attack infrastructure shows that the group has carried on using a variety of new brand names and shifted its focus to targeting financial services. First seen on…
-
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
-
Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
-
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.”…
-
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671.”UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
Computer maker Framework notifies ‘all customers’ of a data breach
Framework told “all” of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
-
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks
This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. First seen on thecyberexpress.com Jump…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
French rugby club Stade Français restores systems after cyberattack, probes data leak
The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational. First seen on therecord.media Jump to article: therecord.media/french-rugby-club-restores-systems-after-cyberattack
-
NSFOCUS LAS: Comprehensive Log Management for Security Visibility and Compliance
The Log Management Challenge Most enterprises accumulate log sources the same way they accumulate infrastructure: one device at a time, each generating data in its own proprietary format. The result is logs scattered across security appliances, network devices, servers, databases, middleware, applications, and cloud workloads, with no unified view and unknown device status. Any issue……
-
Frontier AI Has a Cybersecurity Expertise Problem
First OpenAI’s model went rogue and broke out of testing containment to hack real systems, then Anthropic, and now Meta AI. Do you see a trend? Here is what it means: Although these frontier AI companies employ some of the world’s brightest engineers, architects, and developers, technical excellence is not the same as deep cybersecurity…
-
Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident
The Updoc data breach has raised fresh concerns about cybersecurity in Australia’s healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/updoc-data-breach/
-
What Is Cyber Security Risk Assessment? A Complete Guide (2026)
A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it is”, so leaders can decide which risks to fix, transfer,…
-
Europa stark bei der Sicherheit, doch schwach bei der KI-Governance
29 % der europäischen Unternehmen nennen die KI-Regulierung ihre größte Compliance-Sorge, der höchste Wert aller Regionen. Kiteworks hat seinen 2026 Data Security and Compliance Risk: Annual Survey Report veröffentlicht [1]. Die Analyse wurde zum fünften Mal in Folge durchgeführt und basiert auf einer Befragung von 459 Sicherheits-, Compliance-, Risiko- und IT-Fachleuten in zehn Branchen… First…
-
Cloudflare Builds Business on Surge in Bot Traffic and AI Workloads
CEO Matthew Prince Says Non-Human Traffic Could Reach 1,000 Times Human Use. Cloudflare says explosive growth in AI agents and other machine traffic is creating a larger opportunity in bot management, agent security and micropayments than in building AI data centers, as non-human activity begins to dominate internet traffic. First seen on govinfosecurity.com Jump to…
-
UK data watchdog criticizes Metropolitan Police for data handling failures
Tags: dataFirst seen on scworld.com Jump to article: www.scworld.com/brief/uk-data-watchdog-criticizes-metropolitan-police-for-data-handling-failures
-
Salesforce’s Agentforce 360 platform approved for sensitive Defense Department data
First seen on scworld.com Jump to article: www.scworld.com/brief/salesforces-agentforce-360-platform-approved-for-sensitive-defense-department-data
-
Beacon CRM confirms cyberattack exposed UK charity data
First seen on scworld.com Jump to article: www.scworld.com/brief/beacon-crm-confirms-cyberattack-exposed-uk-charity-data
-
Brazil’s health system data exposed online
First seen on scworld.com Jump to article: www.scworld.com/brief/brazils-health-system-data-exposed-online
-
Top 10 Vulnerability Assessment and Penetration Testing Companies 2026
In today’s interconnected digital world, no organization is truly safe from cyber threats. A single unpatched vulnerability can become an open door for a devastating cyberattack, leading to data breaches, financial losses, and irreparable damage to a brand’s reputation. To stay ahead of sophisticated attackers, businesses must be proactive, not reactive. This is where vulnerability…
-
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
-
Court Tosses Web Tracker Suit Against CRH Healthcare
Judge Says Patient Wasn’t Harmed, Showing Inconsistencies in Web Tracker Claims. A federal court dismissed a proposed class action lawsuit alleging Georgia-based CRH Healthcare unlawfully shared patient data through website tracking technologies, underscoring the challenges plaintiffs face in proving injury despite a growing wave of tracker-related litigation. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/court-tosses-web-tracker-suit-against-crh-healthcare-a-32447
-
Google says hackers are calling financial firm employees to hack and extort victims
Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/06/google-says-hackers-are-calling-financial-firm-employees-to-hack-and-extort-victims/
-
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files,…
-
Hacker pleads guilty to stealing data from more than 165 Snowflake customers
Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/06/hacker-pleads-guilty-to-stealing-data-from-more-than-165-snowflake-customers/

