Tag: data
-
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers/
-
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering and product design data. This chaining enables unauthenticated remote code execution, allowing attackers to deploy…
-
The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating
Artificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with their data, revealing a major “AI trust gap.”…
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
-
Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials
A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path…
-
Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access
Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional email phishing volumes tied to major platforms like Tycoon2FA decline. Microsoft’s recent email threat landscape data for Q2 2026 shows a sharp downstream impact from the March disruption of the…
-
How Purpose-Built AI Can Speed Up Clinical Trials
Amber Hill, CEO of Research Grid, on Safely Overcoming Clinical Trial Bottlenecks. Clinical trial teams lose time to patient sourcing, site selection, manual data entry and other tasks. Amber Hill, CEO of Research Grid, discusses how purpose-built AI can safely automate administrative work, improve data quality and help promising treatments reach patients faster. First seen…
-
Breach Roundup: Zelle Must Face NY Lawsuit Over Fraud
Also, Spain Fines 23andMe Over 2023 Data Breach. This week: Zelle can’t transfer out of a New York state lawsuit alleging poor controls over rampant fraud, a hack wiped Romania’s land registry, Spain fined 23andMe, Australia’s Origin Energy data breach and pirate World Cup streaming sites seized. Malware found hiding in Microsoft 365 calendars. First…
-
Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained
Learn how BitLocker, passkeys, Microsoft Defender, and other Windows 11 security features protect your data, accounts, apps, and devices. The post Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-11-security-cheat-sheet/
-
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-laundry-bear-zimbra-exploit/
-
Microsoft Copilot Deployments Delayed Over Security Concerns
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-copilot-delayed-over/
-
Major Australian energy supplier confirms customer data compromised
Tags: dataOrigin Energy said it was working to figure out how many Australians were affected by a recent data breach. First seen on therecord.media Jump to article: therecord.media/australia-origin-energy-data-breach
-
How Synthetic Identity Fraud is Coming for Machine Identities
Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn’t exist. Since no…
-
Months-long breach exposes South Korean diplomats’ personal data
South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/south-korea-diplomatic-academy-data-breach/
-
Agentic AI Challenges Progress in Confidential Computing
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/agentic-ai-challenges-progress-in-confidential-computing
-
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims
A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the theft and triage of high-value corporate targets. Unlike commodity stealers that focus mainly on browser passwords, Dolphin X is positioned as an enterprise-adjacent data vacuum with a built-in AI-powered victim scoring…
-
Swiss train maker Stadler refuses Everest $12 million ransomware demand
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier’s file-sharing platform. First seen on therecord.media Jump to article: therecord.media/stadler-refuses-everest-ransom-demand
-
Hackers Lurked for 10 Months Inside South Korea Diplomatic System
The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy’s online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas. First seen on thecyberexpress.com…
-
Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack
Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/stadler-everest-ransom-demand/
-
Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse, where usernames and passwords exposed in unrelated third-party breaches are automatically tested against consumer platforms.…
-
Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months
Unknown attackers maintained long-term, covert access to South Korea’s diplomatic training infrastructure for nearly ten months, exposing personal data tied to almost the entire diplomatic cadre and highlighting structural weaknesses in the Foreign Ministry’s security governance. South Korea’s Ministry of Foreign Affairs (MoFA) has confirmed a prolonged compromise of the Korea National Diplomatic Academy (KNDA)…
-
Critical Adobe Acrobat Chrome Extension Flaw “HermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users
Guardio Labs has disclosed a critical vulnerability chain in the Adobe Acrobat Chrome extension that could allow a malicious website to hijack and exfiltrate rendered WhatsApp Web data from affected users. This vulnerability is tracked as CVE-2026-48294 and has impacted Adobe Acrobat extension version 26.5.2. The extension is installed across approximately 329 million browsers. Adobe…
-
Building a defense in depth strategy for sensitive data
In this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/defense-in-depth-strategy-video/
-
Adobe Acrobat extension vulnerability allowed WhatsApp data theft
First seen on scworld.com Jump to article: www.scworld.com/brief/adobe-acrobat-extension-vulnerability-allowed-whatsapp-data-theft
-
Carla car rental data exposed in unsecured AWS bucket
First seen on scworld.com Jump to article: www.scworld.com/brief/carla-car-rental-data-exposed-in-unsecured-aws-bucket
-
North Korean IT Worker Scams Fueling Ukrainian Invasion
Leaked Payment Server Data Lets Researchers Trace Money Flows. Salaries paid to North Korean IT workers end up converted to ammunition used against Ukraine, warns new research based on a trove of leaked payment server data. North Korea has for years smuggled remote and contract IT workers onto Western payrolls. First seen on govinfosecurity.com Jump…
-
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-controlled webpage to silently steal a visitor’s WhatsApp chats, contacts, profile name,…
-
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/

