Tag: leak
-
Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
AI agents can misuse legitimate access. Learn why action-level security, trusted policy enforcement and verified approvals are critical to stop data leaks First seen on hackread.com Jump to article: hackread.com/authenticated-safe-ai-agents-action-level-security/
-
Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data
Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website. First seen on therecord.media Jump to article: therecord.media/atb-ukraine-cyberattack-ransomware
-
âš¡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook.There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch…
-
N0n ransomware: what you need to know
N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. First seen on fortra.com Jump to…
-
Spain Arrests Teen Suspected of Running KillSec Ransomware
3 Arrested as Police Seize Leak Site and US Charges Dutch Suspect. Spanish police arrested a 16-year-old suspected of running the KillSec ransomware group as authorities seized its servers and leak site, while U.S. prosecutors charged a Dutch national accused of helping the group extort victims, including a Puerto Rico company. First seen on govinfosecurity.com…
-
Operation KillSwitch: Police Dismantle KillSec Ransomware Group
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more…
-
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid.The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site.Investigators identified…
-
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
-
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
-
GitHub-Leak: 543.699 Zugangsdaten sind noch immer gültig
GitHub-Leak mit 543.699 gültigen Zugangsdaten: Untersuchung zeigt, wie lange geleakte Credentials öffentlich bleiben und weiter funktionieren First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/github-leak-543699-zugangsdaten-334237.html
-
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform’s security measures to prevent accidental leaks of sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/
-
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes.DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when…
-
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes.DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when…
-
OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext
OpenSSL has announced a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation that could allow a remote peer to read unintended plaintext heap memory during handshake data transmission or trigger a denial-of-service condition. This vulnerability, tracked as CVE-2026-84782, stems from an out-of-bounds read when handling DTLS handshake message retransmissions. The issue affects various…
-
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A group of academics from VUSec and Scuola Superiore Sant’Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR).”The key insight is that, while…
-
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
-
“Drunk” AI is terrible at keeping secrets
AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/drunk-ai-models-jailbreak-research/
-
Quantum random numbers can pass the tests and still leak clues to attackers
Tags: leakThe European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random number generators … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/quantum-random-number-generator-qrng-guidance/
-
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/
-
Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
Security researchers have revealed a vulnerability chain known as “SalesBleed,” associated with Salesforce’s Agentforce. This vulnerability could allow attackers to extract sensitive CRM data through an indirect prompt injection embedded in a public Web-to-Lead form. The attack does not require a Salesforce login or a click from the victim and could leak data via DNS…
-
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts…
-
Microsoft Password Reset Portal Can Leak Account Verification Details
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication. First seen on hackread.com Jump to article: hackread.com/microsoft-password-reset-portal-leak-account-details/
-
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
A newly identified ransomware operation tracked as Galago has emerged with apparent operational links to the Panzer ransomware group, raising concerns of an expanding double-extortion ecosystem targeting organizations worldwide. Researchers began directly monitoring Galago’s dark leak site (DLS) on 15 September 2026. At the time of observation, the group’s Tor-based leak portal was inactive and…
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html
-
Hacker hacken Hacker: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html
-
AI Drives Surge in Bot and API Threats
Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-drives-surge-in-bot-and-api/
-
Shinyhunters hackt Clop: Zwei berüchtigte Cybergangs streiten sich im Darknet
Opfer der Hackergruppe Clop könnten erneut unter Druck geraten. Shinyhunters hat die Datenleckseite gekapert und droht mit Leaks über Lösegeldzahlungen. First seen on golem.de Jump to article: www.golem.de/news/shinyhunters-hackt-clop-zwei-beruechtigte-cybergangs-streiten-sich-im-darknet-2609-213312.html
-
Clop Ransomware Responds to ShinyHunters Amid Eight-Figure Demands
Clop responds to ShinyHunters after its leak site takeover as the group demands an eight-figure payment, interest and a public apology in their escalating feud. First seen on hackread.com Jump to article: hackread.com/clop-ransomware-responds-shinyhunters-demands/

