Tag: data
-
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
-
Shai-Hulud Attack Nips Cyber-Firm CrowdSec’s GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data
-
ShinyHunters Hacked Cl0p. Now What About Cl0p’s Victims?
ShinyHunters defaced Cl0p’s Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims
-
Data dive: Mapping UK police forces’ hyperscale dependence
Computer Weekly used public DNS records to map which outside companies Britain’s 48 police forces connect to and found a service that has quietly standardised on one US hyperscaler First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650799/Data-dive-Mapping-UK-police-forces-hyperscale-dependence
-
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
The use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/retail-ai-agents-visibility-data-breaches-netskope/831002/
-
How to Boost Cryptographic Agility Across the Enterprise
A Risk-Based Approach Can Turn an Overwhelming Migration Into a Workable Plan. Experts advise organizations preparing for post-quantum cryptography to start with a focused inventory of cryptography in use, rank systems and data by business exposure, and build internal capacity to change algorithms and certificates safely. Vendors should also commit to crypto agility. First seen…
-
TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands
A Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell, Scheduled Tasks, and runtime C# compilation to establish resilient persistence and continuously steal business documents. The implant also captures screenshots, extracts saved Wi-Fi passwords, harvests clipboard data, and executes arbitrary commands received from its operators. While the original delivery method is unconfirmed, the location is consistent…
-
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/zyxel-switches-cve-2026-7273-vulnerability-exploited/
-
CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/
-
Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
Master of Malt reported a customer data breach after attackers allegedly compromised an application key linked to Ribon, a third-party BigCommerce app managed by Be A Part Of that identifies itself as a Fastr brand. BigCommerce notified the retailer of the incident on September 18, 2026, prompting Master of Malt to reach out to affected…
-
Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data
A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business targets across 29 countries, stealing at least 18,566 sensitive records from one Western government organization. GreyNoise linked the activity to a malicious cyber actor (MCA) it has tracked through its Global Observation Grid since early June. The…
-
Windows 11 26H1 Security Update Expands Secure Boot Certificate Protection
Microsoft has released the cumulative security update for September 2026 for Windows 11 version 26H1. This update expands the range of systems that can automatically receive new Secure Boot certificates. KB5124012, released on September 8, brings devices to OS Build 28000.2954. It includes enhanced, high-confidence device-targeting data to improve certificate deployment coverage across supported PCs…
-
Google Fined Euro403 Million for GDPR Violations Over Location Data Processing
Ireland’s Data Protection Commission (DPC) has imposed a Euro403 million administrative fine on Google Ireland Limited for breaching the EU General Data Protection Regulation (GDPR) by processing users’ location data. This decision follows an inquiry initiated in February 2020 after complaints from European consumer rights organizations, including BEUC. The investigation examined Google’s practices from May…
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
21st September Threat Intelligence Report
Tags: breach, data, data-breach, exploit, government, intelligence, service, threat, vpn, vulnerabilityJapan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/21st-september-threat-intelligence-report/
-
Building Crypto Agility Across the Enterprise
A Risk-Based Approach Can Turn an Overwhelming Migration Into a Workable Plan. Experts advise organizations preparing for post-quantum cryptography to start with a focused inventory of cryptography in use, rank systems and data by business exposure, and build internal capacity to change algorithms and certificates safely. Vendors should also commit to crypto agility. First seen…
-
Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
Website Defacement Tied to Alleged Theft of Oracle E-Business Suite Exploits Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p’s data-leak site, dropped names of the group’s alleged members, and demanded a large ransom in response to alleged death threats and the theft of its Oracle E-Business…
-
Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
Website Defacement Tied to Alleged Theft of Oracle E-Business Suite Exploits Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p’s data-leak site, dropped names of the group’s alleged members, and demanded a large ransom in response to alleged death threats and the theft of its Oracle E-Business…
-
Google Fined Euro403 Million Over Location Data Practices
Ireland’s DPC fined Google Euro403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google Euro403 million, and the case behind it goes back six years, to a set of complaints that never really went away. The DPC launched the investigation in February 2020 after…
-
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
-
ShinyHunters Hacked Clop. Now What About Clop’s Victims?
ShinyHunters defaced Clop’s Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims
-
EU data regulator fines Google more than $460 million for location data violations
Ireland’s Data Protection Commission will fine Google more than Euro403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020. First seen on therecord.media Jump to article: therecord.media/google-europe-location-data-fine
-
EU data regulator fines Google more than $460 million for location data violations
Ireland’s Data Protection Commission will fine Google more than Euro403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020. First seen on therecord.media Jump to article: therecord.media/google-europe-location-data-fine
-
EU data regulator fines Google more than $460 million for location data violations
Ireland’s Data Protection Commission will fine Google more than Euro403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020. First seen on therecord.media Jump to article: therecord.media/google-europe-location-data-fine
-
Not So Harmonious: EU States Hoard Cyber Incident Data
Cross-Border Cooperation Hasn’t Reached Cybersecurity Incidents, Auditors Find. When hackers triggered cascading disruptions to European air travel in fall 2025, none of the affected countries – including Germany, Belgium and Ireland – activated European Union-level coordination to cope with the incident. The go-it-alone approach is endemic. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/so-harmonious-eu-states-hoard-cyber-incident-data-a-32881
-
Google Fined $463M Over EU Location Data Practices
Irish DPC Says Google Unlawfully Processed and Retained Users’ Location Data. Ireland’s Data Protection Commission fined Google 403 million euros after finding GDPR violations in its processing, retention and disclosure of location data across Web & App Activity, Location History and Android Location Accuracy. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/google-fined-463m-over-eu-location-data-practices-a-32879
-
Google Fined Euro403 Million Over GDPR Violations Tied to Location Data
Google has been fined Euro403 million for breaking the EU’s data protection law, the GDPR, in the way three of its features handled people’s location data from May 2018 to February 2020.Ireland’s Data Protection Commission (DPC), Google’s lead regulator in the EU, also ordered the company to make its processing comply with the law within…
-
Google Fined Euro403 Million Over GDPR Violations Tied to Location Data
Google has been fined Euro403 million for breaking the EU’s data protection law, the GDPR, in the way three of its features handled people’s location data from May 2018 to February 2020.Ireland’s Data Protection Commission (DPC), Google’s lead regulator in the EU, also ordered the company to make its processing comply with the law within…
-
Google Fined Euro403 Million Over GDPR Violations Tied to Location Data
Google has been fined Euro403 million for breaking the EU’s data protection law, the GDPR, in the way three of its features handled people’s location data from May 2018 to February 2020.Ireland’s Data Protection Commission (DPC), Google’s lead regulator in the EU, also ordered the company to make its processing comply with the law within…

