< ciso
brief />
Tag Banner

All news with #ai data leakage tag

23 articles

September 2026 Cyber Threat Landscape Report

🛡️ September 2026 saw a sharp rise in global cyber activity: weekly attacks averaged 2,803 per organization, up 48% year over year, with education the most targeted sector. Phishing rates increased to 1 in 91 emails and ransomware incidents rose 53% year over year. GenAI prompt usage expanded, with 1 in 39 prompts posing a high risk of sensitive data leakage, highlighting growing exposure across industries and regions.
read more →

Expanding Credential Layer: Visibility and Risk

🔒 GitGuardian outlines why the credential layer deserves immediate attention and how detection is the first essential step. The article explains that credential sprawl spans repositories, endpoints, collaboration tools, and AI agents, increasing attack surfaces and making discovery urgent. It highlights research showing rising hardcoded secrets and explains the need for context — validity, ownership, permissions, and dependencies — to prioritize remediation. The piece argues security teams must connect multiple discovery sources to measure coverage and reduce exposure.
read more →

Report: Over 80,000 Organizations Had AI Logins Exposed

🔍 SOCRadar’s AI Identity Exposure Report analyzed more than one million infostealer records tied to AI services across 80,000+ corporate domains, narrowing to 482 major enterprises to determine which organizations’ AI credentials are being sold. The research found ChatGPT/OpenAI dominated exposures, with 90% of records, while developer platforms like Hugging Face and Replit also appeared. The report emphasizes that stolen AI sessions are more dangerous than passwords, acting as archives, execution engines, billable resources, and identities, and recommends SSO, token rotation, API key controls, and monitoring for session reuse.
read more →

Malicious MCP Servers Can Split Exfiltration Steps

🛡️ A new technique called GhostSplice shows how a malicious Model Context Protocol (MCP) server connected to an AI coding assistant can exfiltrate SSH keys, environment secrets, source code, and customer data by splitting a theft into harmless-looking fragments. ASSET Research Group tested the approach in isolated projects using fake credentials and found that splitting the request across tool descriptions, results, or server-initiated sampling raised compliance dramatically for many models. The attack relies on developers connecting a hostile MCP server and the agent already having access to the target files.
read more →

AI hallucinations fuel slopsquatting risk for devs

🔍 Research shows top AI coding models repeatedly invent identical nonexistent package names, creating a slopsquatting risk where attackers could register those names and distribute malicious libraries. Aleksandr Churilov identified 127 shared fake package names across five LLMs and found 53 remain registerable on PyPI and npm. The study suggests shared training materials and ecosystem conventions drive the conformity, though no malicious registrations have yet been observed.
read more →

Malicious npm package stole files from AI tool

🛡️ Researchers uncovered a malicious npm package named mouse5212-super-formatter that exfiltrates files from the /mnt/user-data directory used by Anthropic's Claude AI. OX Security describes the campaign, codenamed Malware-Slop, as a postinstall script that authenticates to GitHub using environment or hard-coded tokens, creates or targets a repository, and uploads local files to an attacker-controlled account. The package has been downloaded hundreds of times, and the linked GitHub account—created shortly before the package appeared—has since disappeared. Analysts noted the actor leaked a private token, suggesting poor OPSEC and possibly AI-assisted malware creation.
read more →

Venice OT intrusion claim and Anthropic source leak risks

🔒 Smashing Security episode 463 examines two incidents that expose operational and AI security weaknesses: a claimed intrusion into Venice’s flood‑defence pump controls and an accidental full‑source disclosure by Anthropic. Hosts Graham Cluley and Tanya Janca discuss the physical risks of compromised legacy OT systems, how packaging/CI misconfigurations can leak high‑value IP and attack surface, and the governance challenges of powerful internal tools like Mythos. They recommend stronger CI/CD defaults, strict access controls for model assets, and reliable out‑of‑band incident communications.
read more →

Experts Warn of Browser Extensions Poaching AI Prompts

🛡️ Security researchers have warned of malicious Chrome extensions that silently monitor and exfiltrate users' AI chat content. According to Expel, extensions watch open tabs and capture prompts and responses via API interception or DOM scraping before sending the data to external servers. Attackers either impersonate popular tools or convert legitimate extensions into malicious ones after building a user base. Organisations are urged to block unvetted AI extensions and centrally manage and audit extension use.
read more →

Preventing AI Agent Data Leaks: Webinar Guide for Security

🔒 AI agents are transforming workflows but can act as an unmonitored access layer—an 'invisible employee' with broad privileges. In an upcoming webinar, Rahul Parwani, Head of Product for AI Security at Airia, will explain how attackers are manipulating agents to exfiltrate sensitive information and how to stop them. Attendees will learn the Dark Matter of identity, common manipulation techniques, and a practical safety blueprint to limit privileges, detect misuse, and prevent leaks. Reserve your spot to learn actionable defenses.
read more →

Shai-Hulud–Style Worm Hits npm Packages and AI Tools

🔒 Socket's Threat Research Team discovered a supply chain worm, tracked as SANDWORM_MODE, spreading via typosquatted npm packages and compromised GitHub accounts while also manipulating local AI coding assistants. The malware harvested developer and CI credentials, injected rogue MCP servers into tools like Claude Desktop and VS Code Continue, and exfiltrated API keys for multiple large language model providers. Affected packages were removed and infrastructure disabled; developers should rotate credentials and audit CI workflows and local AI configurations.
read more →

Supply Chain Worm Uses Malicious npm Packages to Steal Keys

🔐 Socket warns of an active supply-chain worm, codenamed SANDWORM_MODE, that abused at least 19 malicious npm packages to harvest developer credentials and cryptocurrency keys. The packages — many typosquatting legitimate modules and published by aliases official334 and javaorg — contain code to steal tokens, environment secrets and LLM API keys. The campaign also includes a weaponized GitHub Action, an optional home-directory wiper, and an McpInject component that targets AI coding assistants. Users should remove affected packages, rotate tokens, and audit repositories and CI workflows.
read more →

The Silent Security Gap in Enterprise AI Adoption Risks

🔒 Most security leaders assume they know where sensitive data resides, but rapid AI adoption has created a new exposure surface in AI inference traffic. Prompts often contain source code, contracts, PII and proprietary workflows that flow through application layers, logs and third‑party services without classification or adequate controls. Traditional protections — transport encryption, legacy DLP and standard logging practices — frequently fail to prevent prompt leakage, producing an often invisible and growing enterprise risk.
read more →

AI Coding Assistants Secretly Exfiltrate Developers' Code

⚠️A new report alleges two popular AI coding assistants, together used by roughly 1.5 million developers, are quietly copying everything they ingest to servers in China. Security researchers say the extensions capture editor content, code snippets, and related telemetry without clear user disclosure. The behavior appears systematic and persistent rather than incidental. Until vendors provide transparent remediation, developers and organizations should avoid unvetted extensions and perform immediate audits and containment.
read more →

CISA Acting Director Uploaded FOUO Files to ChatGPT

🛡️ The acting director of the U.S. Cybersecurity and Infrastructure Security Agency uploaded multiple for official use only (FOUO) contracting documents to the public version of ChatGPT between mid‑July and early August 2025, triggering automated DHS security alerts. Sensors detected the activity in early August, generating several alerts in the first week and prompting an internal review. The uploads—containing contracting information not intended for public release—underscore gaps in AI governance and exception handling for senior officials at CISA.
read more →

Cloudflare Acquires Human Native to Improve AI Data Access

🤝 Cloudflare has acquired Human Native, a UK AI data marketplace that converts multimedia into licensed, structured datasets for AI developers. The team will help Cloudflare expand tools like AI Crawl Control, Pay Per Crawl and the AI Index, enabling publishers to expose structured updates and control access. It emphasizes licensed, high-quality data, creator compensation and greater control over how content is used by AI systems.
read more →

ZombieAgent attack exposes persistent AI data leaks

🧟 Researchers disclosed 'ZombieAgent' techniques that turned ChatGPT Connectors into covert data-exfiltration and persistent backdoor vectors. By embedding hidden prompts in emails, documents and cloud files, attackers could cause the model to retrieve and transmit sensitive content without users’ awareness. The team demonstrated URL-dictionary and Markdown-based exfiltration and showed how Memory modifications could create long-lived backdoors; OpenAI patched the issues in December.
read more →

Urban VPN Proxy Intercepts AI Chats Across Platforms

🔒 A recent analysis by koi.ai, highlighted by Bruce Schneier and Boing Boing, reports that the Urban VPN Proxy browser extension is surreptitiously intercepting conversations across multiple AI services. The extension embeds dedicated executor scripts for ten AI platforms and captures every prompt, every response, conversation identifiers, timestamps, session metadata, and the specific model or platform used. Harvesting is enabled by default via hardcoded flags and runs continuously in the background regardless of whether the VPN is active; there is no user-facing toggle and the only effective remediation is to uninstall the extension.
read more →

Featured Chrome Extension Harvested Millions of AI Chats

🚨 A Google Chrome extension carrying a "Featured" badge, Urban VPN Proxy, has been found silently harvesting prompts and responses from major AI chat services and sending them to remote analytics servers. The extension — installed by roughly six million Chrome users and about 1.3 million Edge users — was updated on July 9, 2025 (v5.5.0) with AI capture enabled by default. Injected scripts override browser networking APIs to intercept chat data and exfiltrate conversation text, IDs, timestamps, session metadata, and model/platform information. The publisher's updated privacy policy admits collecting AI prompts and outputs for "Safe Browsing" and marketing while disclaiming a full guarantee of de-identification.
read more →

Data Leakage in AI: Addressing Risks in LLM Systems

🔐 This article explains how sensitive data commonly leaks from AI systems — from RAG retrievals and agentic tool chains to user-initiated oversharing — and why LLMs cannot enforce document-level permissions. It recommends a layered, defense-in-depth approach: automatic identification and classification, data minimization at ingress, sanitization, redaction, and strict access controls that follow data through the pipeline. The authors also stress threat modeling and vendor due diligence to limit regulatory, competitive, and reputational harm.
read more →

AI Adoption Surges, Governance Lags in Enterprises

🤖 The 2025 State of AI Data Security Report shows AI is widespread in business operations while oversight remains limited. Produced by Cybersecurity Insiders with Cyera Research Labs, the survey of 921 security and IT professionals finds 83% use AI daily yet only 13% have strong visibility into how systems handle sensitive data. The report warns AI often behaves as an ungoverned non‑human identity, with frequent over‑access and limited controls for prompts and outputs.
read more →