Tag: data
-
Medtronic Notifies 3.8 Million After ShinyHunters Data Breach
Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026, Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed…
-
Security Affairs newsletter Round 584 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $1M to Data Extortion Group Kairos FBI: TeamPCP Compromised Dev Tools to…
-
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Tags: blockchain, data, data-breach, extortion, government, group, ransom, ransomware, theft, threatA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment.…
-
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
Tags: blockchain, breach, data, data-breach, extortion, government, group, ransom, ransomware, theftA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left.The odd part: the group that took the money calls itself Kairos, but it may not be…
-
The Elephants in the Technology Room – Part 4
Why IT and Security Teams Can No Longer See What They’re Supposed to Protect Shadow IT has evolved into shadow SaaS, shadow AI, shadow data and autonomous agents that operate beyond security’s view. Traditional governance models can no longer keep pace. Organizations must transition from blocking technology to making its use visible, monitored and data-controlled.…
-
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.According to JFrog, the packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” mimic the legitimate “rollup-plugin-polyfill-node” project, down to the description, repository metadata, and First seen on thehackernews.com Jump…
-
New PamStealer Malware Targets macOS Users via Fake Maccy Clipboard App
The newly spotted PamStealer is spreading through a fake Maccy clipboard app and steal Mac passwords, browser data and clipboard content. First seen on hackread.com Jump to article: hackread.com/pamstealer-malware-macos-fake-maccy-clipboard-app/
-
JADEPUFFER: First EndEnd AI-Driven Ransomware Operation
Sysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans. Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end by a large language model. The operator, which Sysdig calls JADEPUFFER, broke into a server, harvested…
-
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Vercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticated nation-state infrastructure implant. Instead, it unfolded when an…
-
Breach of IBM-managed environment exposes personal data of 70,000 in Singapore
Unauthorised access to a development and testing environment managed by IBM has exposed the names, NRIC numbers and property addresses of about 70,000 people held by the Singapore Land Authority First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645414/Breach-of-IBM-managed-environment-exposes-personal-data-of-70000-in-Singapore
-
Hackers Use Fake API Documentation to Trick AI Agents Into Sending Crypto Payments
Hackers are now weaponizing documentation and site metadata to mislead autonomous AI agents into executing cryptocurrency payments. The attack leverages indirect prompt injection (IPI): malicious instructions hidden in web content and structured data that influence an AI agent’s reasoning during automated tasks. By combining SEO poisoning, JSON”‘LD abuse and CSS concealment, attackers create seemingly legitimate…
-
Datensicherung und Cloud-Verschlüsselung – FAST LTA startet Data-Protection-Kooperation mit Eperi
First seen on security-insider.de Jump to article: www.security-insider.de/fast-lta-startet-data-protection-kooperation-mit-eperi-a-1bcc90f56c1c46591667da9addf5dc93/
-
EU-US Data Privacy Framework Under Threat After Supreme Court Ruling
EU-US Data Privacy Framework First seen on thecyberexpress.com Jump to article: thecyberexpress.com/eu-us-data-privacy-framework/
-
SAESL turbocharges aircraft engine maintenance with data and AI
The world’s largest supplier of Rolls-Royce engine maintenance services is working with Kyndryl to modernise its IT infrastructure, build a single source of truth for data and scale up the use of AI across its business First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645474/SAESL-turbocharges-aircraft-engine-maintenance-with-data-and-AI
-
Organizations struggle to prioritize known cyber risks
Organizations collect more cyber risk data than ever, with many still struggling to build a unified view of their exposure. The latest State of Threat Management report from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/03/cyber-risk-exposure-report/
-
Breach Roundup: DeepSeek Sparks Browser Ransomware
Tags: ai, attack, breach, cisa, data, data-breach, fraud, india, iphone, oracle, penetration-testing, ransomwareAlso, False Negatives Causes Trust in AI Pentest to Drop. This week: a DeepSeek browser-only ransomware path, AI pen testing trust dropped, Mustang Panda targeted India, Tata breach exposed iPhone 18 data, CISA flagged BlueHammer in ransomware attacks, 950 Oracle EBS systems exposed, Amazon to pay U.S. Federal Trade Commission penalty over fraud records. First…
-
Supreme Court decision threatens EU-US data transfer agreement
In a Tuesday letter, Max Schrems, the founder of the Vienna-based privacy advocacy organization noyb, told European officials he plans to sue to invalidate the EU-U.S. Data Privacy Framework (DPF) that allows for the transfer of personal data from the EU to U.S. companies. First seen on therecord.media Jump to article: therecord.media/supreme-court-decision-threatens-eu-us-data-sharing
-
When Too Much Security Data Became the Risk
Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/too-much-security-data-risk
-
When Too Much Security Data Became the Risk
Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/too-much-security-data-risk
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
-
Data dive: Kill switch and catch-up can Europe close the sovereignty gap?
As the US demonstrates it can wield an AI ‘kill switch’, the EU and UK unleash a wave of sovereign tech measures. Can state-led industrial policy bridge a $2tn revenue chasm? First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645336/Data-dive-Kill-switch-and-catch-up-can-Europe-close-the-sovereignty-gap
-
FTC-Entscheidung bringt EU-US Data Privacy Framework unter Druck
Mit der aktuellen US-Entscheidung zur Unabhängigkeit der Federal Trade Commission wackelt eine zentrale Grundlage des EU-US Data Privacy Framework: die Annahme, dass Datenschutzverstöße in den USA unabhängig kontrolliert und überprüft werden können [1]. Damit wird aus einer vermeintlichen juristischen Detailfrage ein handfestes Risiko für Unternehmen, Behörden und Betreiber kritischer Infrastrukturen in Europa. Dazu sagt… First…
-
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs.Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker…
-
Aflac Japan: Hack Detected Last Week Affects Nearly 4.4M
Incident Is Insurance Giant’s Second Major Data Breach Since June 2025. Aflac is notifying regulators and nearly 4.4 million Aflac Life Insurance Japan customers of a hacking incident detected last week potentially affecting their personal and financial information. The data breach is Aflac’s second hacking incident affecting millions of people over the past year. First…
-
Workers Withdraw Claims in Stryker Wiper Attack Lawsuit
Action Comes After Stryker Contends Employees’ Personal Data Wasn’t Compromised. Eight current and former Stryker employees of medical tech company voluntarily withdrew their lawsuits against the manufacturer, which publicly disclosed it had been hacked in a February wiper attack. The lawsuits were filed within days of Stryker’s first breach disclosure in March. First seen on…
-
New ChocoPoC malware targets researchers via trojanized PoC exploits
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/

