Tag: security-incident
-
How to prioritize AI agent security by business impact
Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/prioritize-ai-agent-security-business-impact/
-
Wo sich wertvolle Metriken für das Security-Operations-Center finden lassen
Wie effizient ein Security-Operations-Center (SOC) arbeitet, ist durchaus messbar. Leider lassen sich Unternehmen oft von nichtssagenden Metriken blenden. Ontinue, Experte für Managed-Extended-Detection and Response (MXDR), erklärt anhand von drei Personas, wie Unternehmen maßgeschneiderte KPIs definieren. Schließt ein Security-Operations-Center täglich hunderte Tickets von Security-Incidents, ist das erst einmal beeindruckend. Diese Zahl kann allerdings trügen, denn in…
-
Von der Planung bis zum Betrieb IT-Systeme richtig aufbauen und verwalten
Die IT-Infrastruktur eines Unternehmens ist wie das Fundament eines Gebäudes: Solange alles funktioniert, denkt kaum jemand darüber nach. Wenn aber etwas schiefgeht ein Server ausfällt, Daten verloren gehen oder ein Sicherheitsvorfall eintritt zeigt sich schlagartig, wie gut oder schlecht das Fundament gelegt wurde. Viele Unternehmen, gerade im Mittelstand, entwickeln ihre IT-Infrastruktur historisch gewachsen: […] First…
-
Top Agentic SOC Vendors Defining Autonomous Security Operations
More than 100 vendors now position themselves as AI SOC platforms, but the category didn’t even exist 18 months ago. The Cloud Security Alliance found that AI-enhanced SOCs investigated cloud security incidents 4561% faster than manual teams, explaining the boom in interest. The vendors truly defining the AI SOC space are the ones The post…
-
London Hydro customer data potentially compromised in security incident
First seen on scworld.com Jump to article: www.scworld.com/brief/london-hydro-customer-data-potentially-compromised-in-security-incident
-
Klue Breach Exposes Salesforce Data at Cybersecurity Firms
A security incident at Klue exposed Salesforce data across multiple cybersecurity firms. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/klue-breach-exposes-salesforce-data-at-cybersecurity-firms/
-
Klue OAuth breach victim list grows as Icarus hackers claim attack
Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
-
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026.To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert published…
-
Azul schließt Sicherheitslücke im Java-Stack, die autonome KI-Angreifer ausnutzen können
Autonome KI-Exploit-Tools unterscheiden nicht zwischen regulierten und unregulierten Zielen. Doch die Konsequenzen eines Sicherheitsvorfalls in regulierten Umgebungen sind gravierend First seen on infopoint-security.de Jump to article: www.infopoint-security.de/azul-schliesst-sicherheitsluecke-im-java-stack-die-autonome-ki-angreifer-ausnutzen-koennen/a45545/
-
FIFA schrammt knapp an schwerem IT-Sicherheitsvorfall vorbei
…wäre da nicht die Hartnäckigkeit eines ethischen Hackers in Japan gewesen. Die FIFA hat sich mit einer schwerwiegenden Sicherheitslücke, über die Bobdahacker gestern berichtete, beinahe ein Eigentor geschossen. Der japanische Hacker fand heraus, dass sich jedermann einfach mit einem Ausweis auf der offiziellen FIFA-Agentenplattform registrieren konnte. Durch eine fehlerhafte clientseitige Rollenprüfung im Backend konnte… First…
-
Ozempic Maker Novo Nordisk Confirms Security Incident After $25M Hacker Demand
Hackers claim they stole 1.3TB of Novo Nordisk data, including clinical trial and AI model information, after issuing a $25 million demand. The post Ozempic Maker Novo Nordisk Confirms Security Incident After $25M Hacker Demand appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-novo-nordisk-1-3tb-theft-25m-demand-emea/
-
Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)
Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/16/cisco-sd-wan-cve-2026-20262-exploited/
-
Maine Shuts Down Breach Reporting Portal Following Fake VRChat and Discord Submissions
The Office of the Maine Attorney General has temporarily taken its public data breach reporting portal offline following the discovery of fraudulent submissions falsely claiming security incidents at VRChat and Discord. The incident, disclosed in an official statement on June 12, 2026, highlights growing concerns over the integrity and potential abuse of publicly accessible breach…
-
Japanese energy firm loses drive with data of 10.9 million clients
Kyushu Electric Power Co., Inc. has disclosed a physical security incident that affects private data of more than 10 million customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/
-
Mehr als die Hälfte der europäischen Unternehmen hat im vergangenen Jahr einen Sicherheitsvorfall durch nicht-menschliche Identitäten erlebt
Keeper Security weist heute auf eine erhebliche Lücke in der Governance hin: Unternehmen weiten den Einsatz von KI-gesteuerten und nicht-menschlichen Identitäten aus, ohne über die erforderlichen Kontrollmechanismen zu verfügen, um deren Sicherheit zu gewährleisten. Erkenntnisse aus einer Umfrage unter Cybersicherheitsexperten auf der Infosecurity Europe 2026 in London zeigen, dass KI-Agenten und nicht-menschliche Identitäten mittlerweile fest…
-
Mackay Sugar Security Incident Forces Mill Shutdowns and Halts Harvesting Operations
Australia’s second-largest sugar producer, Mackay Sugar, is investigating a cyberattack that has disrupted parts of its operations and temporarily halted sugarcane harvesting in Queensland’s Mackay region. The Mackay Sugar security incident has led to the suspension of milling activities at two of the company’s facilities while cybersecurity specialists and authorities work to determine the nature and impact…
-
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of its open-source projects being compromised to inject an information stealer into the code.”Our priority is to protect customers and the broader ecosystem,” a Microsoft spokesperson told The Hacker News via email. “We…
-
Hacked, leaked, and held for ransom: the worst breaches of 2026 so far
From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/07/the-worst-hacks-and-breaches-of-2026-so-far/
-
Cloud Security Alliance Report Highlights Growing Patch Gap Risks
AI is accelerating exploitation timelines while known vulnerabilities remain a leading cause of security incidents, according to a CSA report. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cloud-security-alliance-report-highlights-growing-patch-gap-risks/
-
The worst hacks and breaches of 2026 (so far)
From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/03/the-worst-hacks-and-breaches-of-2026-so-far/
-
Known vulnerabilities behind most application security incidents
Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/03/csa-application-security-incidents/
-
Organisationen vor Supply-Chain-Attacken schützen
Der Sicherheitsvorfall bei Unimed ist nur einer der letzten in einer langen Kette von Supply-Chain-Angriffen, die verheerende Wirkung erzeugen können. Die Auswirkungen sind besonders in Bezug auf IT-Infrastrukturen in Krankenhäusern enorm, denn sie treffen auf durch Reformen verunsicherte Belegschaften, die sich täglichem Stress ausgesetzt sehen und darauf angewiesen sind, dass die Digitalisierung das bringt, was sie…
-
Responding to Breaches With AI? Beware Cross-Contamination
Separate Breach Details Can Bleed Into Each Other, Incident Responders Find. Cybersecurity investigators who use artificial intelligence tools to draft incident response reports, beware: Information tied to one security incident can contaminate a report into a separate incident, if both get drafted using the same AI tool in the same session, researchers warn. First seen…
-
Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning
A zero-click attack targeting iPhones on iOS 16 hijacked WhatsApp accounts without linked devices, warnings, or user interaction. There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for money transfers, and when you check the >>Linked…
-
71 Prozent der Unternehmen waren im vergangenen Jahr von mindestens einem Identitätsdiebstahl betroffen
Der Report ‘State of Identity Security 2026″ von Sophos kommt zu dem Ergebnis, dass menschliches Versagen und mangelhaftes Identitätsmanagement bei nicht-menschlichen Akteuren die Hauptursachen für die meisten Angriffe sind, während autonome KI das Risiko weiter erhöht. Die Umfrage zeigt, dass 71 Prozent der Unternehmen (Deutschland: 62 Prozent) im vergangenen Jahr mindestens einen identitätsbezogenen Sicherheitsvorfall erlitten…
-
Cisco warns of AI inaccuracies in security incident reports
First seen on scworld.com Jump to article: www.scworld.com/brief/cisco-warns-of-ai-inaccuracies-in-security-incident-reports
-
Grafana confirms GitHub token breach cybercrime group claims the attack
Tags: attack, breach, cybercrime, data, data-breach, extortion, github, group, leak, security-incident, theftGrafana confirmed a GitHub token breach that exposed source code, but said no customer data or systems were affected. Grafana Labs confirmed a security incident after the extortion group Coinbase Cartel listed it on a leak site and claimed data theft on May 15. The breach was triggered by a compromised token that gave attackers…

