Tag: data
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
Wireshark 4.6.7 patches a dozen security flaws
Network analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/wireshark-4-6-7-released/
-
Accenture Confirms Security Incident After Hacker Claims Data Haul
Accenture acknowledged that it suffered a data breach, but said it has remediated it with no impact on operations or service delivery. First seen on crn.com Jump to article: www.crn.com/news/security/2026/accenture-confirms-security-incident-after-hacker-claims-data-haul
-
Mount Royal University confirms breach as hackers claim attack
Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university’s network. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mount-royal-university-confirms-breach-as-hackers-claim-attack/
-
A Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach
Accenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale. A threat actor using the handle >>888<>Today […] First seen on securityaffairs.com Jump to article: securityaffairs.com/194962/data-breach/a-hacker-claims-35-gb-of-accenture-source-code-the-company-discloses-the-data-breach.html
-
Accenture Confirms Breach After Hacker Claims 35GB Data Theft
The Accenture breach reinforces the need to secure development environments. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/accenture-confirms-breach-after-hacker-claims-35gb-data-theft/
-
Vidar Infostealer Hammers SMBs via Malvertising Campaign
A financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/vidar-infostealer-smb-malvertising-campaign
-
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders.The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack.Decrypting…
-
Another massive data breach exposed millions of driver’s license numbers
The cyberattack targeting a U.S. insurance giant is the largest known breach of driver’s license numbers so far in 2026. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/
-
Accenture faces massive data breach that could put clients at risk
The threat actor claiming responsibility says it stole source code, encryption keys and more. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/accenture-data-breach-access-keys-source-code/824694/
-
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365…
-
Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle >>888<< posted on the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/
-
Telco giant KDDI says data breach affects over 12 million people
Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/
-
Thousands of malicious AI skills found capable of stealing data, running malware
AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/eset-ai-threat-trends-report/
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials
Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July 6, 2026, alleges that the breach resulted in the exfiltration of proprietary assets, including source…
-
New TrojPix technique uses screen pixels to exfiltrate data from air-gapped computers
First seen on scworld.com Jump to article: www.scworld.com/brief/new-trojpix-technique-uses-screen-pixels-to-exfiltrate-data-from-air-gapped-computers
-
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as >>GitLost<< has been discovered in GitHub's newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be manipulated to bypass conventional access controls and leak confidential information across repository boundaries. GitLost Vulnerability…
-
Accenture confirms breach after hacker offers stolen data for sale
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
-
Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft
Varonis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft
-
Selling Cyber: Anthropic’s Fable 5 Raises Security Tradeoffs
Panel Examines Costs, Security Limits, Enterprise Adoption of Fable 5 and Mythos 5. Anthropic’s Claude Fable 5 and Mythos 5 demonstrate major advances in coding and reasoning while raising new questions about exploit generation, enterprise AI spending, data governance and the growing urgency of faster vulnerability remediation, according to the panelists on Selling Cyber. First…
-
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A critical flaw in Google’s Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project.From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.Security…
-
Google Search Uploads Can Train AI Unless You Opt Out
Google Search uploads may be used to train AI unless users opt out, raising privacy and data governance concerns for businesses. The post Google Search Uploads Can Train AI Unless You Opt Out appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-search-uploads-train-ai-opt-out/
-
‘GitLost’ Flaw Leaks Private Data From GitHub’s Agentic Workflows
The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org’s public repository and then silently pull data from its private repos, too. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows
-
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown.The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across…
-
Mike Winston on Why Jet.AI Shifted From Aviation to AI Infrastructure
Private aviation runs on tight margins and tighter schedules. The AI tools Jet.AI built to optimize both placed the company in an unusual vantage point: watching production inference workloads run against real operational constraints, before the data center power shortage became a mainstream story. Mike Winston, investor and founder of Jet.AI (NASDAQ: JTAI), built those…
-
Check Point Brings Cloud Firewall to AWS European Sovereign Cloud
Check Point Software has announced that its Cloud Firewall offering is now available on the AWS European Sovereign Cloud, as the cybersecurity giant becomes an official partner for Amazon’s new independent European cloud infrastructure. The move is designed to help European organisations meet increasingly stringent data residency and operational autonomy requirements under EU regulatory frameworks,…
-
GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
Noma Labs details GitLost, a prompt injection flaw that made GitHub’s AI agent expose private repo data through a crafted public issue and guardrail failures. First seen on hackread.com Jump to article: hackread.com/gitlost-github-ai-agent-leaking-repository-data/
-
Attackers Exfiltrate AnyDesk Configuration Data via Blat SMTP in Aerospace Phishing Campaign
A targeted spear-phishing campaign that configures AnyDesk for silent, persistent remote access and exfiltrates its configuration using the Blat SMTP utility. The campaign uses an aerospace-themed invoice lure that impersonates the Russian research institute VNIIR via a freshly registered spoof domain (vniir-avia.space) and delivers a password-protected archive that, when opened, triggers a multi-stage dropper and…
-
Veeam erneut als Gartner-Leader ausgezeichnet: Warum Backup im KI-Zeitalter zur Vertrauensfrage wird
Solche Kennzahlen sind im hart umkämpften Backup-Markt relevant, weil Unternehmen bei Data Protection nicht nur auf Funktionsumfang achten. Entscheidend sind Vertrauen, Stabilität, Integrationsfähigkeit First seen on infopoint-security.de Jump to article: www.infopoint-security.de/veeam-erneut-als-gartner-leader-ausgezeichnet-warum-backup-im-ki-zeitalter-zur-vertrauensfrage-wird/a45689/

