Tag: data
-
iRhythm Hit by Cyberattack, Patient Data Stolen and Ransom Demanded
iRhythm disclosed a cyberattack via third-party apps where patient and proprietary data was stolen, followed by a ransom demand. iRhythm Technologies is a U.S.-based digital healthcare company specializing in remote cardiac monitoring and arrhythmia detection. Its best-known product is the Zio, a wearable patch that continuously records a patient’s heart rhythm for up to several…
-
Infinite Campus Incident Exposes Data From 137,000 School Staff Accounts
A breach at Infinite Campus exposed data from 137,000 school staff accounts, highlighting SaaS security risks in education. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/infinite-campus-incident-exposes-data-from-137000-school-staff-accounts/
-
Amos Stealer Targets macOS Keychain Files and Browser Passwords
Amos Stealer targets macOS users through fake downloads, stealing Keychain files, browser passwords, cookies, and developer configs for data theft. First seen on hackread.com Jump to article: hackread.com/amos-stealer-macos-keychain-files-browser-passwords/
-
IBM execs on storage security and operational resiliency
IBM storage leaders Sam Werner and Christopher Vollmar share insights on operational resiliency, AI data protection gaps and security strategies for enterprises. First seen on techtarget.com Jump to article: www.techtarget.com/searchstorage/news/366644107/IBM-execs-on-storage-security-and-operational-resiliency
-
ShinyHunters Claims Council of Europe HR Data, Threatens Leak
ShinyHunters claims it stole 297GB of data from the Council of Europe, including payroll and medical records, but the organization has not confirmed a breach. The post ShinyHunters Claims Council of Europe HR Data, Threatens Leak appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-shinyhunters-council-europe-data-theft-claim-emea/
-
UK to require ID or face scan before you can make social media accounts
Opening a new social media account in the UK will soon mean proving you’re over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security experts warn the age checks are easy to circumvent and create new data-breach risks. First seen on bleepingcomputer.com…
-
‘Lorem Ipsum’ Malware Pivots to ClickFix Delivery
New analysis shows the campaign, which uses compromised WordPress sites, may be linked to the ransomware and data extortion group Vice Society. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/lorem-ipsum-malware-clickfix-delivery
-
Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms.Yet despite this abundance of information, many organizations continue to face a fundamental challenge: sifting through the noise to understand who is behind…
-
Infinite Campus Breach Leaks Personal Information of 137,000 Users
A data breach affecting the widely used K12 student information system, Infinite Campus, has exposed the personal information of approximately 137,000 users. This incident is linked to an extortion campaign that occurred in March 2026 and has been attributed to the ShinyHunters threat group. It was officially recorded on Have I Been Pwned (HIBP). This…
-
UK data regulator slammed over lack of action on complaints
Tags: dataThe UK data regulator is being threatened with legal action after it was accused of ‘ignoring’ thousands of data protection complaints, with critics describing its new approach to complaint triage and investigation as akin to a ‘digital bin’ for the public’s concerns First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366644403/UK-data-regulator-slammed-over-lack-of-action-on-complaints
-
Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Sensitive Enterprise Data
A newly disclosed SearchLeak vulnerability in Microsoft 365 Copilot Enterprise exposed a critical pathway for attackers to steal sensitive organizational data through a specially crafted URL. The flaw chain, now tracked as CVE-2026-42824, was patched by Microsoft earlier this month and assigned a critical severity rating due to its potential impact. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/searchleak-vulnerability-microsoft-365-copilot/
-
iRhythm discloses data breach, says hackers stole patient info
Digital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients’ personal and health information stored on third-party-hosted business applications. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/
-
Microsoft 365 Copilot Vulnerability Exposes Sensitive Data Through One-Click Attack
Microsoft 365 Copilot has been found vulnerable to a critical one-click data exfiltration attack chain dubbed “SearchLeak,” exposing sensitive enterprise data through a combination of AI-specific and traditional web vulnerabilities. Discovered by Varonis Threat Labs, the flaw, tracked as CVE-2026-42824 and rated critical, demonstrates how modern AI integrations can unintentionally expand attack surfaces by linking…
-
A $2 trillion revenue shift hinges on AI data governance
Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/16/ai-data-governance-revenue-shift/
-
Leading job sites sell user data, Incogni report reveals
First seen on scworld.com Jump to article: www.scworld.com/brief/leading-job-sites-sell-user-data-incogni-report-reveals
-
SearchLeak vulnerability allows data theft from Microsoft 365 Copilot Enterprise
First seen on scworld.com Jump to article: www.scworld.com/brief/searchleak-vulnerability-allows-data-theft-from-microsoft-365-copilot-enterprise
-
Nintendo Alleged Data Breach: Threat Actor Demands $2M Ransom
Nintendo faces an alleged data extortion incident involving HR records, internal reports, and potential exposure of third-party vendors. The post Nintendo Alleged Data Breach: Threat Actor Demands $2M Ransom appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-nintendo-alleged-data-leak-third-party-risk/
-
Copilot ‘SearchLeak’ Attack Allows 1-Click Data Theft
The critical, three-stage attack is now patched, but it’s part of a new group of AI prompt-injection issues that use hidden URLs and other variables. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/copilot-searchleak-attack-1-click-data-theft
-
Google exposes China espionage group that’s been lurking in networks undetected since 2023
The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to intercept research and steal data with national security implications. First seen on cyberscoop.com Jump to article: cyberscoop.com/google-unc6508-china-espionage-threat/
-
Labcorp Agrees to Pay $35M to Settle AMCA Data Breach
Diagnostics Lab Reported 10.3M Patients Affected by Collection Agency’s Hack. Medical laboratory testing giant Labcorp has agreed to pay $35 million to settle class action litigation stemming from a 2018 hacking incident on now-defunct American Medical Collections Agency. Labcorp reported the vendor breach in 2019 as affecting nearly 10.3 million patients. First seen on govinfosecurity.com…
-
Why AI Defenses Fail Without Data and Identity Fundamentals
RPC’s Spencer Scott on Why Security Basics Must Come Before Agentic AI Adoption. Organizations are racing toward agentic AI defenses, but without clean data, identity and asset management in place, those defenses will fall short. Security fundamentals must come first, said Spencer Scott, head of information security at RPC. First seen on govinfosecurity.com Jump to…
-
Hackers Demand $2M From Nintendo Over Alleged Data Breach
A threat actor claims to have stolen Nintendo data and is demanding $2 million. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/hackers-demand-2m-from-nintendo-over-alleged-data-breach/
-
Maine closes data breach portal to the public after fake reports
Maine is still allowing companies to report breaches, but won’t make the portal easily available to the public until after it completes an audit of its procedures to stop such incidents, according to a press release from the Maine attorney general’s office. First seen on therecord.media Jump to article: therecord.media/maine-turns-off-breach-portal-fake-reports
-
Council of Europe investigates ShinyHunters data breach claims
The Council of Europe, the continent’s oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/

