Tag: data
-
100.000 Dollar gestrichen Update – – Intel ‘pausiert” Bug-Bounty-Prämien
Intel hat sein bisheriges Bug-Bounty-Programm eventuell ausgesetzt. Das neue Meldeprogramm lockt Sicherheitsforscher nicht mehr mit Geld. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/100-000-dollar-gestrichen-intel-stoppt-moeglicherweise-bug-bounty-praemien.99474
-
Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
Security researchers have revealed a vulnerability chain known as “SalesBleed,” associated with Salesforce’s Agentforce. This vulnerability could allow attackers to extract sensitive CRM data through an indirect prompt injection embedded in a public Web-to-Lead form. The attack does not require a Salesforce login or a click from the victim and could leak data via DNS…
-
100.000 Dollar gestrichen Update – – Intel stoppt offenbar Bug-Bounty-Prämien
Intel hat sein bisheriges Bug-Bounty-Programm eventuell ausgesetzt. Das neue Meldeprogramm lockt Sicherheitsforscher nicht mehr mit Geld. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/100-000-dollar-gestrichen-intel-stoppt-moeglicherweise-bug-bounty-praemien.99474
-
Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers’ containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not…
-
Cloudflare Containers Flaw Could Expose Data From Other Customers’ Workloads
Cloudflare has addressed a cross-tenant data exposure vulnerability in its Containers platform that could have allowed one customer’s workload to recover residual data belonging to other customers on the same infrastructure. This flaw also affected Cloudflare Sandboxes and the Browser Run service within Browser Rendering, both of which utilize the same underlying disk implementation. Cloudflare…
-
Half of threat hunters say bad data is their biggest problem
Half of security professionals name data quality or quantity as their biggest barrier to effective threat hunting, according to the SANS 2026 Threat Hunting Survey. Teams with … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/25/sans-threat-hunting-data-quality/
-
AI Is Changing Cybersecurity Jobs, Not Erasing Them
SANS Institute’s Rob Lee on AI Transforming Cyber Jobs. AI is reshaping entry-level cybersecurity, but SANS Institute’s Rob Lee says the data doesn’t show junior jobs disappearing. Instead, he expects the starting point to move higher as AI accelerates technical work, raises skill expectations and creates new security roles. First seen on govinfosecurity.com Jump to…
-
AI Is Changing Cybersecurity Jobs, Not Erasing Them
SANS Institute’s Rob Lee on AI Transforming Cyber Jobs. AI is reshaping entry-level cybersecurity, but SANS Institute’s Rob Lee says the data doesn’t show junior jobs disappearing. Instead, he expects the starting point to move higher as AI accelerates technical work, raises skill expectations and creates new security roles. First seen on govinfosecurity.com Jump to…
-
Island Gets $400M to Take Worker Security Into the Agent Era
Non-Human Identity and Transient Networks Extend Controls Beyond Human Workers. Island raised $400 million at a $6.4 billion valuation to extend its worker-centric security platform to AI agents, applying data, identity, network, endpoint and observability controls to non-human workers while funding growth toward profitability and a potential IPO. First seen on govinfosecurity.com Jump to article:…
-
Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges
Two executives at a data extraction and digital forensics company that sold several U.S. agencies its software were arrested for allegedly lying about the fact that its technology is made in Russia. First seen on therecord.media Jump to article: therecord.media/russia-forensics-technology-doj
-
OpenAI Agent Breached Australian Medicare Statistics Portal
An OpenAI agent bypassed controls on Australia’s Medicare statistics portal, accessed non-public data and was not reported to officials for nearly 3 months. First seen on hackread.com Jump to article: hackread.com/openai-agent-breached-australian-medicare-portal/
-
Breach Roundup: Thousands of AI Relays Hide China Users
Tags: ai, breach, china, cisa, cve, cybercrime, data, data-breach, flaw, google, jobs, north-korea, russia, scam, vpnAlso, CISA Ends Weekly CVE Bulletin After 22 Years, Check Point VPN Flaw Exploited. This week: AI relay servers connect to China, CISA ends weekly CVE bulletin, cybercriminal guilty pleas and sentences, drug dealers hijack Google Maps, Russian Burger King customers’ data leaked, North Korean fake job scams, SectopRAT, a Check Point VPN flaw and…
-
Kyiv internet providers report major outages after Russian attacks damage data centers
At least four internet providers serving Kyiv and other parts of Ukraine suffered partial connectivity losses following Wednesday’s drone attack, according to internet monitoring group NetBlocks. First seen on therecord.media Jump to article: therecord.media/kyiv-internet-providers-report-outages-after-russian-strikes
-
Astrana latest healthcare tech firm to report data breach to SEC
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel. First seen on therecord.media Jump to article: therecord.media/astrana-cyberattack-sec-ransomware
-
Ghost Service Accounts Enable M365 Data Theft in Chile
Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization’s entire M365 environment. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ghost-service-accounts-m365-data-theft-chile
-
Prompt-Injection Bug Hits $4B Agentic AI App ‘Manus’
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/prompt-injection-bug-agentic-ai-app-manus
-
Prompt-Injection Bug Hits $4B Agentic AI App ‘Manus’
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/prompt-injection-bug-agentic-ai-app-manus
-
CISA Charts New Quality Era for Global CVE Program
CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-quality-era-global-cve-program/
-
Meta locks itself out of user data on its AI glasses
Meta is expanding Private Processing to its AI glasses, extending their security protections into cloud data centers. The system runs AI models inside confidential virtual … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/24/meta-private-processing-for-ai-glasses/
-
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/
-
Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds
SANS Institute report claims data rather than skills is now the main hurdle for threat hunters First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/data-top-bottleneck-barrier-threat/
-
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation. This flaw could allow a local user on a shared server to access calendar events and contacts from other hosting accounts. The issue affects cPanel/WHM version 120 and later, highlighting the risks associated with tenant isolation in shared-hosting environments.…
-
Shiny Hunters Claim FBI Breach, Offer Sample of Alleged Stolen Data
The FBI is investigating an apparent breach of its networks after the cybercriminal group Shiny Hunters claimed on Tuesday to have stolen personal data belonging to thousands of federal agents. Two sources familiar with the matter confirmed the probe, which centers on the bureau’s FBIjobs recruitment website. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/shiny-hunters-fbi-breach-fbijobs-agent-data/
-
Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE
A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company originally described it as a spoofing issue with a CVSS score of 6.5. In reality, it is an authenticated RCE flaw rated 8.8. That gap matters, because security teams that trusted the first label may…
-
ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents’ Data
ShinyHunters hacks the FBI Jobs portal and claims sensitive data on nearly all FBI agents and job applicants before the site is taken offline for security work. First seen on hackread.com Jump to article: hackread.com/shinyhunters-hacks-fbi-jobs-portal-fbi-agents-data/
-
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/
-
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release. First seen on therecord.media Jump to article: therecord.media/canadian-regulator-opens-probe-of-idscan-following-data-breach
-
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release. First seen on therecord.media Jump to article: therecord.media/canadian-regulator-opens-probe-of-idscan-following-data-breach
-
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
The theft of agents’ personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/
-
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/

