Tag: data
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Estonia Tests ‘Sovereign AI’ on National Health Data
Owkin’s Agentic AI Will Support Biomed Research While Preserving Data Sovereignty. Estonia, through Metrosert – the European country’s state-owned technical and scientific research organization – has forged a collaborative partnership with agentic artificial intelligence firm Owkin for the use of sovereign AI to advance biomedical and other related scientific research. First seen on govinfosecurity.com Jump…
-
Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends
ShinyHunters tells Hackread it never planned to publish or sell stolen FBI data and says its ultimatum was part of a marketing campaign to counter FBI claims. First seen on hackread.com Jump to article: hackread.com/exclusive-shinyhunters-fbi-data-wont-be-leaked/
-
Nvidia Alliance to Tackle Security Across AI Agent Stack
Independent Controls Aim to Contain Agents Regardless of Model Decisions. Nvidia and 100 industry, research and public-sector organizations are building layered controls to constrain AI agents across applications, runtimes and infrastructure, as autonomous systems gain access to sensitive enterprise data, APIs, tools and credentials. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/nvidia-alliance-to-tackle-security-across-ai-agent-stack-a-32960
-
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
-
AI Accounts Are Becoming the New Target for Infostealers
Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent…
-
Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
-
AI May Be Dominating Cybersecurity, But Quantum Preparations Can’t Wait: Analysis
The quantum threat posed to existing data encryption is not something the channel can afford to put off until the AI challenges are addressed. First seen on crn.com Jump to article: www.crn.com/news/security/2026/ai-may-be-dominating-cybersecurity-but-quantum-preparations-can-t-wait-analysis
-
Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe
Dutch police arrested convicted hacker Pepijn van der Stap in the ShinyHunters probe into the Odido breach, which exposed data belonging to millions of customers. First seen on hackread.com Jump to article: hackread.com/convicted-dutch-hacker-arrest-shinyhunters-odido-probe/
-
New Mexico jury finds Meta deceived consumers about data privacy practices
A New Mexico jury found Facebook violated the law nearly 44 million times by lying to consumers about its data privacy practices. First seen on therecord.media Jump to article: therecord.media/facebook-new-mexico-privacy
-
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/28/fbi-reportedly-declares-cyber-security-incident-after-hackers-steal-agents-personal-data/
-
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data
A flaw in Titan, an internal Microsoft analytics service, could have let an attacker read employee records and Bing search analytics, a 16-year-old security researcher has … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/
-
Cyberattack on Polish medical software provider exposes patient data
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months. First seen on therecord.media Jump to article: therecord.media/poland-cyberattack-medical-medyc
-
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website. The District of Columbia Department of Health Care Finance is notifying nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information may have been exposed. The incident affects people who enrolled between…
-
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure
Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website. The District of Columbia Department of Health Care Finance is notifying nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information may have been exposed. The incident affects people who enrolled between…
-
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Tags: ai, breach, control, credentials, cyber, cybercrime, data, data-breach, infrastructure, Internet, phishing, toolAn internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation. Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications. The exposure is notable not only for the scale of the material recovered, but also for its irony. Weeks later, infrastructure attributed…
-
NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI Agents
NVIDIA has launched its Open Agent Safety Platform, a security architecture designed for out-of-band monitoring, runtime policy enforcement, and hardware-backed control for autonomous AI agents. This platform combines the open-source NVIDIA OpenShell runtime with NVIDIA Sentry protections on BlueField-4 data processing units (DPUs), aiming to prevent agents from exceeding their authorized access or operating limits.…
-
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems”, often without the same controls applied to human users.According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent…
-
Context matters when it comes to cybersecurity’s agentic operating model
AI agents need context-aware security beyond traditional models. Workflow data provides the governance guardrails that make AI safe and scalable. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/spons/context-matters-when-it-comes-to-cybersecuritys-agentic-operating-model/830973/
-
Ex-US soldier gets 70 months for role in ATT, Snowflake data thefts
A former U.S. Army soldier who was part of a group that stole data from telecom companies, including ATT, has been sentenced to 70 months in prison. Cameron John … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/us-army-soldier-snowflake-breaches-extortion/
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Welche Cyberangriffs-Akteure fürchten Unternehmen am meisten?
Wenn Beschäftigte an mögliche Cyberangriffe auf ihr Unternehmen denken, stehen organisierte Cyberkriminelle ganz oben auf der Liste. 46 Prozent sehen sie als größte Bedrohung. Das ist ein Ergebnis des aktuellen Reports Cybersicherheit in Zahlen 2026/2027, der von G DATA in Zusammenarbeit mit Statista veröffentlicht worden ist. Mit deutlichem Abstand folgen so genannte Hacktivisten: 14 Prozent……
-
Welche Cyberangriffs-Akteure fürchten Unternehmen am meisten?
Wenn Beschäftigte an mögliche Cyberangriffe auf ihr Unternehmen denken, stehen organisierte Cyberkriminelle ganz oben auf der Liste. 46 Prozent sehen sie als größte Bedrohung. Das ist ein Ergebnis des aktuellen Reports Cybersicherheit in Zahlen 2026/2027, der von G DATA in Zusammenarbeit mit Statista veröffentlicht worden ist. Mit deutlichem Abstand folgen so genannte Hacktivisten: 14 Prozent……
-
New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, browsing history and active session cookies. The malware is delivered through a builder framework that enables operators to generate customized Windows payloads and configure their own data-exfiltration webhook. The archive included a “TokenGrabber Builder” folder containing…

