Tag: data
-
Carla car rental data exposed in unsecured AWS bucket
First seen on scworld.com Jump to article: www.scworld.com/brief/carla-car-rental-data-exposed-in-unsecured-aws-bucket
-
North Korean IT Worker Scams Fueling Ukrainian Invasion
Leaked Payment Server Data Lets Researchers Trace Money Flows. Salaries paid to North Korean IT workers end up converted to ammunition used against Ukraine, warns new research based on a trove of leaked payment server data. North Korea has for years smuggled remote and contract IT workers onto Western payrolls. First seen on govinfosecurity.com Jump…
-
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-controlled webpage to silently steal a visitor’s WhatsApp chats, contacts, profile name,…
-
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/
-
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
-
Federal agencies broaden alert on Iran-linked OT attacks
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says. First seen on therecord.media Jump to article: therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks
-
New Data Shows Suno Breach Affected 55M Accounts
New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information. The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-suno-breach-affected-55-million-users/
-
Anubis Ransomware Halts Fairlife Milk Production in the US
Gang Claims 1TB of Stolen Data and Sets Deadline for Ransom Talks. Anubis claims it encrypted Fairlife’s production systems and stole 1 terabyte of data, forcing the Coca-Cola-owned dairy brand to suspend U.S. milk production while investigators assess the ransomware incident and work to restore operations. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/anubis-ransomware-halts-fairlife-milk-production-in-us-a-32297
-
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data.The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability First…
-
White House accuses Chinese company of distilling Anthropic’s Fable
While distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught. First seen on cyberscoop.com Jump to article: cyberscoop.com/white-house-accuses-moonshot-ai-anthropic-model-distillation/
-
Pixels Tracking Every Loan You Take on EU Bank Websites
Jscrambler Detects Cookies Exporting Detailed View of Customer Financial Intent. Many European and American bank websites are quietly – and perhaps unwittingly – sending sensitive customer data to third parties such as TikTok without user consent or sufficient anonymization, the cybersecurity firm Jscrambler found. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/pixels-tracking-every-loan-you-take-on-eu-bank-websites-a-32296
-
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/
-
Chick-fil-A Data Breach Linked to Credential Stuffing Attack
Chick-fil-A is notifying customers after credential stuffing attacks compromised loyalty accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/chick-fil-a-data-breach-linked-to-credential-stuffing-attack/
-
Azure DevOps Prompt Injection Targets AI Coding Agents
Hidden prompt injections in Azure DevOps can manipulate AI coding agents into accessing sensitive data using a developer’s permissions. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/azure-devops-prompt-injection-targets-ai-coding-agents/
-
OpenAI Presence connects AI agents to enterprise data with built-in guardrails
OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/openai-presence-ai-agent-platform/
-
Adobe Chrome extension flaw let sites access private WhatsApp chats
The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
-
Period tracker Stardust shares users’ health data with analytics firm, says new research
One period tracker app tested by the Mozilla Foundation was ‘squeaky clean,’ while another app was seen sharing users’ health data with an analytics company, underscoring vast differences in user privacy among these apps. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/16/period-tracker-stardust-shares-users-health-data-with-analytics-firm-says-mozilla-research/
-
EU Financial Institutions Leak Data Through Cookie Trackers
European banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns. First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/eu-financial-institutions-cookie-trackers
-
Chick-fil-A discloses data breach after credential stuffing attacks
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
-
Military-focused apps contain foreign-sourced code, raising data security concerns
First seen on scworld.com Jump to article: www.scworld.com/brief/military-focused-apps-contain-foreign-sourced-code-raising-data-security-concerns
-
Estée Lauder customer data compromised in Oracle E-Business Suite breach
First seen on scworld.com Jump to article: www.scworld.com/brief/estee-lauder-customer-data-compromised-in-oracle-e-business-suite-breach
-
Mithra AI launches to verify data before AI models produce answers
First seen on scworld.com Jump to article: www.scworld.com/brief/mithra-ai-launches-to-verify-data-before-ai-models-produce-answers
-
Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts
First seen on scworld.com Jump to article: www.scworld.com/brief/ecopetrol-confirms-ransomware-attempt-data-stolen-from-3300-accounts
-
Craneware confirms customer and employee data exposed in security incident
First seen on scworld.com Jump to article: www.scworld.com/brief/craneware-confirms-customer-and-employee-data-exposed-in-security-incident
-
How to Build Faster, More Scalable AI Applications with Elastic and NVIDIA
An OnDemand Webinar. AI applications are only as powerful as the infrastructure behind them. Discover how leading organizations are accelerating search, eliminating performance bottlenecks, and building AI applications that scale with enterprise data demands. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-to-build-faster-more-scalable-ai-applications-elastic-nvidia-a-32284
-
Services Firm ApolloMD Settles Hack Lawsuit for $4M
Settlement With Revenue Cycle Vendor Stems From Qilin Gang Attack Affecting 627,000. Revenue cycle management services firm ApolloMD Business Services has agreed to pay just over $4 million to settle proposed class action litigation stemming from a 2025 data theft claimed by ransomware gang Qilin that affected nearly a dozen physician practices and 627,000 of…
-
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/
-
CMMC: 5 Things To Watch Amid Pause On Upcoming Requirements
The pause on the next phase of the Cybersecurity Maturity Model Certification (CMMC) program has prompted major questions about how the government plans to verify the protection of sensitive data by defense contractors. First seen on crn.com Jump to article: www.crn.com/news/security/2026/cmmc-5-things-to-watch-amid-pause-on-upcoming-requirements
-
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
A new type of malware can worm deep into AI coding systems to steal data and logins”, and can flip a “death switch” to destroy files and keep out real users. First seen on wired.com Jump to article: www.wired.com/story/a-sneaky-hacking-tool-targeting-ai-infrastructure-is-lurking-in-victims-blind-spots/

