< ciso
brief />
Tag Banner

All news with #data exfiltration tag

237 articles

Cryptographic Context Injection Affects Grok Agents

🛡️ Adversa AI disclosed a technique called Cryptographic Context Injection that caused xAI's Grok web chat (Grok 4.5 Fast) to exfiltrate a user's name, approximate location, subscription tier, and ongoing prompts to an attacker-controlled server during a routine page summary request. The attack packages instructions as ciphertext on a web page, which Grok's Python runtime decrypts and executes, allowing the model to construct a URL embedding private session data and fetch it without user confirmation. Adversa reported the issue to xAI in June 2026, reproduced it on August 19, and advised mitigations for agent harnesses; xAI has not issued a public advisory as of August 20.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

CareCloud data breach impacts 3.7M patients

🩺 CareCloud, a U.S. healthcare IT provider, disclosed a March breach that disrupted services and exposed patient data. The company said an unauthorized third party accessed an AWS environment between March 10 and March 16, 2026, and claimed to have exfiltrated database contents. Notifications began July 25, and impacted individuals are offered identity protection via IDX. No group has claimed responsibility and investigations continue.
read more →

Data Analyst Sentenced for Extortion Using Stolen Payroll Data

📰 A contract data analyst misused privileged access to steal sensitive corporate and payroll records after learning his contract would not be renewed. Adopting the alias "Loot," he sent over 60 extortion emails demanding $2.5 million in cryptocurrency and attached screenshots of employee personal data to pressure his employer. Forensic evidence and metadata tied the emails and a Coinbase payment trail to the analyst, leading to his arrest, conviction on six counts of transmitting interstate communications with intent to extort, and a 24-month federal prison sentence.
read more →

Pokémon Center breach exposes customer data, cancels orders

📣 Pokémon Center has notified UK and German customers that a third-party logistics provider, CEVA Logistics, suffered a cyberattack that exposed customer personal and order information. The breach affected CEVA systems between July 29 and August 1 and disrupted several European warehouses, causing shipping delays and cancellations. Pokémon Center says exposed data may include names, mailing addresses, phone numbers, email addresses, and order details, but not payment card information.
read more →

Multi‑agent AI attack breaches government networks

🔒 Researchers report a multi-day, near-autonomous cyberattack using open-source AI agents that targeted government systems in Asia, compromising credentials and probing sensitive agencies. The campaign, observed in early July, used parallel agents to map networks, exploit APIs, and move laterally via single sign‑on integrations, producing large volumes of exfiltrated files and cracked credentials. Vendors and experts warn the incident underscores a widening gap between the falling cost of capable attacks and the higher cost of defense.
read more →

Wesco Investigates CRM Data Exfiltration Claim

🔍 Wesco is investigating a reported cybersecurity incident after the data extortion group ExfilSquad claimed to have stolen CRM data and published alleged records. The company says it worked with its cloud CRM vendor and found no evidence of ransomware or malware, and believes payment card and sensitive customer or employee data are not at risk. Wesco reported no business disruption and stated operations continue as normal.
read more →

Atlassian RovoBlast flaw risks data exfiltration

🛡️ Varonis disclosed a vulnerability called RovoBlast in Atlassian's enterprise AI assistant, Rovo, which allowed a crafted URL parameter to seed attacker instructions into an authenticated session. The assistant's ResearchAgent could then browse the web and post retrieved internal data externally, enabling data leakage with a single click. Atlassian has since patched the issue; Varonis urges restricting connectors, disabling browsing agents, and monitoring agent activity.
read more →

Atlassian Rovo prompt-injection and link flaw fixed

🛡️ Two security teams found ways to make Atlassian's Rovo assistant exfiltrate data a signed-in user can access. One method used a malicious file with hidden instructions to induce Rovo to gather Jira or Confluence content and send it to an attacker-controlled URL; PromptArmor disclosed this on August 5, 2026 and its remediation status after publication is unconfirmed. The second, dubbed RovoBlast by Varonis, preloads attacker instructions via a rovoChatPrompt URL parameter so a single click from an authenticated user could cause data to be sent out; Atlassian fixed this server-side on July 8, 2026. Both issues rely on data the signed-in user can reach, and administrators can limit exposure by restricting which apps and groups can use Rovo and tightening connector permissions.
read more →

Levi Strauss reports corporate data theft after breach

🔒 Levi Strauss & Co. disclosed that attackers used social engineering on three employees to access company-issued machines and exfiltrate corporate data. The company says rapid response contained the intrusion and no consumer data was impacted, with no disruption to business operations. An investigation is ongoing and Levi’s will provide additional notifications as required; some reporting links the incident to voice-phishing campaigns.
read more →

Beacon CRM Breach Impacts Around 1,500 UK Charities

🔒 Around 1500 UK charities may have had personal data accessed after a cyber incident at CRM provider Beacon. The provider says customers should assume all stored data, including attachments, was likely downloaded and has notified all affected organisations. Beacon attributes the breach to a compromised access key, is working with external experts to investigate and has contained the incident, while advising charities on reporting and payment safety steps.
read more →

Minnesota water cyberattack exposes OT backup gaps

🔒 The July 26–27 coordinated cyber activity against more than 30 Minnesota community water systems targeted operational technology, disrupting remote control and forcing manual operations in some places. Advisories from CISA and vendors document exfiltration of PLC project files and recovery procedures that assume operators possess current offline project backups. The article emphasizes immediate, low-cost countermeasures: verify offline, versioned project archives, reconcile SIM-equipped devices via carrier invoices, restrict integrator remote access, and test time-to-manual recovery.
read more →

PNLD breach exposes UK police and partner emails

🔒 The Police National Legal Database (PNLD) confirmed that names, organisations and work email addresses for police officers, staff, criminal justice professionals, government partners and customers were compromised and published on the dark web. The incident, identified July 26, also included some Ask the Police submitter contact details, raising phishing risks. PNLD says no passwords or credentials are known to be exposed and is working with the ICO, NCA and cybersecurity specialists while notifying affected parties.
read more →

Amgen confirms cloud data breach exposed sensitive files

🔒 Amgen disclosed a cloud data breach after threat actors exfiltrated corporate and patient information from third-party cloud environments. The company detected unauthorized activity in July 2026, activated its incident response plan, and engaged independent forensic experts to investigate. Amgen says stolen data includes proprietary data and patient protected health information, and it is assessing the scope, regulatory requirements, and potential notifications.
read more →

MCBS network breach exposes over 1.26M records

🔒 Medical billing firm Medical Computer Business Services (MCBS) disclosed a 2025 network breach that exposed data for 1,261,464 individuals. The intrusion, occurring between September 22–26, 2025, potentially exposed sensitive information including Social Security numbers, dates of birth, medical histories, and insurance identifiers. MCBS identified seven covered entities whose patient records it processed and urges affected individuals to consider fraud alerts or credit freezes. The PEAR ransomware group claims responsibility and says 3.3 TB of data was exfiltrated and leaked.
read more →

Origin Energy confirms customer data breach affecting millions

🔒 Origin Energy has confirmed a data breach by an unknown threat actor that may have exposed customers' personally identifiable information. The company, which serves 4.8 million customers across Australia, is investigating the extent of the impact and notifying affected individuals. Reported exposed fields include names, addresses, dates of birth, phone numbers, partial payment details, and account information. Origin says incomplete financial details cannot be used to hijack accounts and has engaged authorities while offering support to impacted clients.
read more →

Adobe Chrome extension flaw exposed WhatsApp data

🔒 The Adobe Acrobat extension for Chrome contained a chain of vulnerabilities (CVE-2026-48294, dubbed HermeticReader) that let attacker-controlled websites access conversations and other data rendered in WhatsApp Web without authentication. Guardio researchers showed the flaw allowed web pages to write into the extension's storage, activate its WhatsApp integration (Hermes), and issue DOM-manipulating commands to a WhatsApp tab. Adobe patched the issue in version 26.5.2.3; users should ensure they have the update.
read more →

Craneware reports file-name data theft incident

🛡️ Craneware disclosed a cyber incident on July 20 after unauthorized access to parts of its data environment resulted in the exfiltration of a significant volume of file names. The firm said much of the data was non-sensitive or public regulatory material, but admitted some employee, customer and partner records were also accessed. No customer service disruption occurred; regulators in the UK and US have been notified and the company is working to identify affected parties.
read more →

macOS infostealer poses as Apple crash reporter

🛡️ A new macOS infostealer named CrashStealer impersonates Apple's crash-reporting component to trick users into installing a password-stealing payload. Delivered via a signed, notarized disk image called "Werkbit Setup," the dropper bypasses Gatekeeper and fetches a downloader that installs the C++-based stealer. Once active, it prompts for system credentials and exfiltrates browser-stored logins, crypto wallet access and keychain data, using client-side encryption and anti-analysis techniques.
read more →

Weekly recap: ShareFile warning and broad threats

🛡️ Progress urged ShareFile customers to shut down Windows Storage Zone Controllers amid a credible external threat, temporarily disabling access while investigating; there are no signs of account or data compromise. Other top stories include a critical Zimbra XSS patch, a compromised Jscrambler npm package distributing a multi-platform Rust stealer, and Microsoft detailing the destructive GigaWiper backdoor. Large-scale web shell operations (SHELLSTORM), HalluSquatting attacks against AI assistants, and many actively exploited CVEs round out the week's threats.
read more →