Tag: data
-
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread, and a fake comment can make it run a stranger’s command on your computer.Neither trick hijacks the agent’s…
-
Sicherheitslücken für Backups in nur 15 Minuten aufgedeckt
Grau Data ergänzt sein Angebot für Ransomware-Schutz für Backups um den neuen Service ‘Repository Security Check für Windows”. Dieser kann unabhängig vom Einsatz von <> genutzt werden und identifiziert potenzielle Schwachstellen, über die Angreifer auf lebenswichtige Backups zugreifen könnten. In durchschnittlich nur 15 Minuten erhalten Unternehmen Klarheit darüber, wie sicher ihre Backup-Repositories sind. […] First…
-
OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
Kaspersky says OkoBot targets crypto users through fake software, stealing wallet files, seed phrases and passwords while recording activity inside wallet apps. First seen on hackread.com Jump to article: hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/
-
Romania’s land registry hit by cyber attack, data allegedly for sale
Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/romania-ancpi-cyber-attack/
-
‘Keys to the kingdom’: hackers who gained access to heart of London transport network jailed
Thalha Jubair, 20, and Owen Flowers, 19, sentenced to five and a half years each for cyber-attack that cost Transport for London £39mThe data of millions of commuters was stolen, Londoners were left out of pocket and 27,000 Transport for London staff were forced to reset their passwords.Over four days in 2024 a pair of…
-
The Hunter’s Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can’t be fully trusted. David discusses the merits of both and muses on what the future might look like. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/the-hunters-paradox-is-it-time-to-embrace-automated-threat-hunting/
-
New Spirals ransomware encrypts victim network in under 24 hours
A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/
-
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data collection rather than a single targeted objective. Its collection scope includes macOS Keychain files, Safari…
-
Partnered Health Cyberattack Exposes Patient Data Across Australia
The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/partnered-health-cyberattack/
-
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory…
-
AI impacting stress levels among cyber professionals
AI is impacting the day-to-day careers of cyber security pros in regard to stress levels, but respondents to an ISC2 data-gathering exercise are split over whether or not their stress levels are going up, or down. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645892/AI-impacting-stress-levels-among-cyber-professionals
-
Finland issues wanted notice for hacker behind massive psychotherapy data breach
The defendant’s lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland. First seen on therecord.media Jump to article: therecord.media/finland-issues-wanted-notice-for-hacker-vastaamo-breach
-
CMMC Is ‘Not Dead’ Despite Pause On Next Phase Of Requirements: MSP Execs
The move by the U.S. Department of War to pause the next phase of requirements around the Cybersecurity Maturity Model Certification (CMMC) program does not mean the program’s underlying data security obligations are being relaxed for U.S. defense contractors, MSP executives told CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/cmmc-is-not-dead-despite-pause-on-next-phase-of-requirements-msp-execs
-
New macOS malware steals passwords by posing as Apple’s crash-reporting tool
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/crashstealer-macos-infostealer-password-theft/
-
Hackers steal Lidl customer data from external service provider
The retailer said the incident did not affect its online shopping platform itself but involved a separately stored customer database maintained by a third-party provider. According to notifications sent to Lidl’s German, Belgian and Dutch customers on Friday, the attackers briefly accessed the file and exfiltrated part of its contents. First seen on therecord.media Jump…
-
Lidl Notifies Customers of Third-Party Data Breach
Supermarket giant Lidl has revealed details of a supplier breach impacting customer data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/lidl-notifies-customers-of/
-
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Fake smart home residents could stand in for real ones in security research
Tags: dataSmart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/iot-smart-home-security-research/
-
ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data
A series of high-impact campaigns linked by overlapping tradecraft to ShinyHunters, in which attackers abused trusted Salesforce OAuth relationships to bypass conventional MFA protections, establish persistence, and exfiltrate CRM data at scale. The activity, observed from mid-202520252025 through mid-202620262026, affected organizations in retail, education, and manufacturing. Microsoft emphasized that the campaigns did not exploit an…
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft
ModHeader version 7.0.187.0.187.0.18, a popular Chrome extension used for modifying HTTP headers, contained dormant code capable of collecting and exfiltrating browsing history data from an estimated 900,000 users, according to research disclosed on July 13, 2026. Google removed the extension from the Chrome Web Store on Friday, July 10, following a responsible disclosure. Organizations should…
-
Sentra CEO: Small AI Models Cut Cost of Data Classification
Yoav Regev Says Small LMs Deliver High Accuracy Without Large Infrastructure. Sentra co-founder and CEO Yoav Regev says advances in small language models enable organizations to classify unstructured data with high accuracy inside customer environments, improving privacy, reducing infrastructure costs and strengthening AI-driven data governance. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/sentra-ceo-small-ai-models-cut-cost-data-classification-a-32217
-
Bipartisan House Bill Pushes AI for Pediatric Cancer Care
Measure Would Create Federal AI Coordinator, Expand Data Interoperability Efforts. A bipartisan House bill would create a federal coordinator to accelerate the use of artificial intelligence, standardized health data and interoperable research platforms in an effort to speed pediatric cancer research, improve clinical trial design and expand treatment options for children. First seen on govinfosecurity.com…
-
Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach
Lidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data had been stolen in an attack on an external IT service provider.…
-
Vectra AI CEO: Network Data Drives Predictive Security
Hitesh Sheth: Cloud, SaaS, Data Center Visibility Boosts Enterprise Risk Assessment. Vectra AI CEO Hitesh Sheth says comprehensive network observability provides the most reliable foundation for predictive cybersecurity because it spans cloud, SaaS and on-premises infrastructure while offering telemetry that attackers are far less able to manipulate than endpoint logs. First seen on govinfosecurity.com Jump…

