Tag: data
-
UN food agency investigates breach exposing data of Gaza aid recipients
In a message sent to aid recipients via Telegram over the weekend, the World Food Programme (WFP) said that “unauthorized parties” had accessed data stored in its self-registration application in Gaza. First seen on therecord.media Jump to article: therecord.media/un-food-agency-investigates-gaza-aid-breach
-
Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages
Cybercriminal tactics are evolving as phishing campaigns increasingly shift away from fake login pages toward infostealer malware designed to quietly harvest sensitive data from infected systems. While traditional credential-harvesting pages remain in use, threat actors are now prioritizing methods that reduce user interaction and increase data collection efficiency. Infostealers are purpose-built malware families that extract…
-
ClawHub, Cisco, and Vercel Skill Detection Tools Evaded by Malicious Uploads
Security researchers have shown that AI skill security scanners from ClawHub, Cisco, and Vercel’s skills.sh can be reliably bypassed using simple techniques, raising serious concerns about agentic AI supply chain defenses. In tests conducted by Trail of Bits, multiple malicious skills designed to exfiltrate data, hijack agents, or execute arbitrary code were successfully uploaded and…
-
Automated Bots Overtake Human Users in Global Internet Traffic for the First Time
Automated bots have officially overtaken human users in global internet traffic for the first time, marking a major shift in how the web is accessed and used. Recent data from Cloudflare Radar shows that bots now generate 57.5% of all HTTP requests to HTML pages. In comparison, human activity has dropped to 42.5%. The trend…
-
ETSI sets security requirements for AI data centers and cloud platforms
ETSI has published TS 104 033, a technical specification that defines security requirements for AI computing platforms. The specification establishes a security framework for … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/04/etsi-securing-ai-computing-platforms-standard/
-
Smashing Security podcast #470: This AI security flaw might be impossible to fix
A website called “UK visa portal” has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren’t. And when a journalist tried to warn the company, it was lawyers who responded. First seen on grahamcluley.com Jump to article: grahamcluley.com/smashing-security-podcast-470/
-
How to Recover Data from iCloud Backup Without Resetting Your iPhone
Restore data from an iCloud backup without the necessity of resetting your iPhone. Discover proven methods to get back your photos, messages, contacts, and many more things in a very easy way. First seen on hackread.com Jump to article: hackread.com/how-to-recover-icloud-backup-data-resetting-iphone/
-
Musk’s X Asks US FTC to Nullify Data Security Order
Social Media Platform Files Petition With Agency Over May 2022 Consent Order. Elon Musk’s social media company wants a do-over with the U.S. Federal Trade Commission in a petition arguing the agency should terminate data security oversight 16 years early. The FTC began Tuesday a public comment period for X’s request to set aside or…
-
Vobis Ventures Buys Optiv Consulting to Expand AI Security
500-Person Team Will Help Vobis Blend AI, Data and Security Architecture Services. Vobis Ventures acquired Optiv’s 500-person consulting business to combine cybersecurity architecture expertise with AI implementation, governance and agentic AI security capabilities as enterprises struggle to manage the risks of rapidly expanding AI deployments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/vobis-ventures-buys-optiv-consulting-to-expand-ai-security-a-31857
-
Ultrahuman says hackers accessed customers’ wellness data via internal tool
The breach at wearable ring maker Ultrahuman stemmed from credentials stolen from a malware-infected employee laptop. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/03/ultrahuman-says-hackers-accessed-customers-wellness-data-via-internal-tool/
-
The worst hacks and breaches of 2026 (so far)
From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/03/the-worst-hacks-and-breaches-of-2026-so-far/
-
Alcasec, >>Robin Hood of Spanish Hackers,<< Jailed for 31 Months Over Data Theft
Alcasec, the “Robin Hood of Spanish Hackers,” is jailed for 31 months after admitting to stealing and selling Spanish citizens’ banking data. First seen on hackread.com Jump to article: hackread.com/alcasec-robin-hood-of-spanish-hackers-jail-data-theft/
-
Only 11% of production agents pass the AI agent security bar
Enterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/03/research-ai-agent-security-capability/
-
Grand Theft Auto V cheat service Atlas Menu hacked, user data exposed
First seen on scworld.com Jump to article: www.scworld.com/brief/grand-theft-auto-v-cheat-service-atlas-menu-hacked-user-data-exposed
-
California sues 23andMe over 2023 data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/california-sues-23andme-over-2023-data-breach
-
Veeam’s new DataAI Command Platform connects data, access, identities, and AI
First seen on scworld.com Jump to article: www.scworld.com/news/veeams-new-dataai-command-platform-connects-data-access-identities-and-ai
-
Auditors Rip NIST Management of NVD Program
Auditors Accuse Agency of Mismanagement and Program Overlap. Management by the National Institute of Standards and Technology of a repository of vulnerability data came under sharp criticism from federal auditors who said the agency approached it with lack of strategic planning and decisive action. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/auditors-rip-nist-management-nvd-program-a-31848
-
Russian hackers exploit WinRAR vulnerability for data theft
First seen on scworld.com Jump to article: www.scworld.com/brief/russian-hackers-exploit-winrar-vulnerability-for-data-theft
-
Spanish police arrest individual in connection with data leak from state organizations
First seen on scworld.com Jump to article: www.scworld.com/brief/spanish-police-arrest-individual-in-connection-with-data-leak-from-state-organizations
-
China Uses Dual-Method Cyberattack on Czech Orgs
China is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/china-uses-dual-method-attack-czech-taiwan-orgs
-
ShinyHunters Alleges 42M Records Stolen from Charter Communications
Charter confirmed a cybersecurity incident after ShinyHunters claimed it stole customer data through a vishing attack. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/shinyhunters-alleges-42m-records-stolen-from-charter-communications/
-
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation.Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used…
-
Data dive: Mapping the UK public sector’s hyperscale dependence
UK government and local authorities have built critical infrastructure amid a web of US hyperscaler cloud and other providers, which brings risks of exposure to a narrow set of non-UK suppliers First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366643799/Data-dive-Mapping-the-UK-public-sectors-hyperscale-dependence
-
Spain arrests suspected hacker for publishing personal data of police, prosecutors and cyber officials
Police described the incident as a large-scale disclosure of sensitive personal information that posed a threat to both the affected individuals and the institutions they serve. The data was allegedly posted on multiple internet platforms. First seen on therecord.media Jump to article: therecord.media/spain-arrests-suspected-hacker-for-publishing-data-on-sensitive-government-workers
-
New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions
GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected. First seen on hackread.com Jump to article: hackread.com/wordpress-malware-steam-profile-comments-instructions/
-
64,000 accounts exposed in breach of GTA V cheat service Atlas Menu
Atlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, has been added to the Have I Been Pwned database following a data breach that exposed tens of … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/02/atlas-menu-cheat-service-data-breach/
-
Mustang Panda Uses LNK, PowerShell Chain to Deploy PlugX RAT
Mustang Panda is using a fake “Browser Updater” and a multi”‘stage LNKPowerShell loader to sideload PlugX through a legitimate G DATA antivirus binary, ultimately beaconing over HTTPS to a hard”‘coded C2 while hiding configuration and strings behind layered encryption and API hashing. Mustang Panda is a China”‘nexus APT group, long associated with PlugX remote access…
-
Sensitive government personnel data posted online, Spanish police arrest suspect
The Spanish National Police arrested a man in Granada for allegedly leaking personal data belonging to members of several sensitive state institutions. According to police, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/02/spain-government-data-leak-arrest/
-
34 Malicious Packages Steal Cloud Keys, Wallets, and SSH Credentials
Tags: ai, attack, cloud, credentials, crypto, cyber, data, hacker, malicious, open-source, pypi, supply-chainHackers are actively abusing open-source ecosystems to steal sensitive developer data through a large-scale supply chain attack dubbed “TrapDoor,”. The campaign spans npm, PyPI, and Crates.io, leveraging 34 malicious packages and 384 versions to target developers working in cryptocurrency, DeFi, AI, and cloud environments. The attackers weaponized legitimate package installation and build mechanisms to silently…

