< ciso
brief />
Tag Banner

All news with #data leak tag

40 articles

Apple fixes Hide My Email unmasking vulnerability

🔒 Apple patched a vulnerability in its Hide My Email service that could reveal users' real email addresses when forwarded messages were rejected as spam. The fix was deployed on July 3, 2026, after the flaw was disclosed to Apple by Tyler Murphy of EasyOptOuts on June 13, 2025. The issue allowed real addresses to appear in mail transfer logs and affected addresses created before July 7, 2026. Apple now says the problem is resolved, even as a class action alleges misleading privacy claims.
read more →

Study Reveals Browser Wallets Enable Cross‑Site Tracking

🔎 Researchers at KU Leuven analyzed 85 popular browser-based crypto wallet extensions and found systemic privacy leaks that can link and de-anonymize users. The wallets reveal addresses in clear text to external servers, announce installed wallets to sites, and often fail to revoke access on logout. These behaviors allow separate addresses to be correlated, stale permissions to persist across sessions, and authorized wallets to expose addresses inside embedded frames, enabling cross-site tracking and potential deanonymization.
read more →

Friday Squid Blogging: Squidbleed Vulnerability

🦑 A decades-old bug in the Squid proxy can leak HTTP request data, a flaw dubbed "Squidbleed." This post mixes a lighthearted squid image with serious security discussion, noting the vulnerability's age and potential impact on privacy. The author also invites readers to discuss other current security news not yet covered.
read more →

Exposed server reveals mass WordPress backdoor campaign

🔍 Researchers found a cybercrime crew's unsecured server containing tools, logs, and target lists that revealed a large-scale webshell access brokerage dubbed WP-SHELLSTORM. The exposed files showed automated scanners exploiting known WordPress and Joomla plugin flaws, notably the Breeze caching and Joomla JCE bugs, and included lists naming over 1.4 million domains. Two security teams analyzed the leaked repository and measured confirmed compromises in the thousands, while also tracing earlier credential-stealing activity against corporate Nacos instances. The leak underscores how public exploits and poor operator hygiene enabled mass compromise at scale.
read more →

Employee uploads to AI tools nearly double enterprise risk

📈 The Zscaler 2026 AI Threat Report warns that sensitive enterprise data uploaded to AI and ML applications nearly doubled year-over-year, driven largely by tools like Grammarly and ChatGPT. The report found a 93% increase in enterprise data transfers and identified over 410 million DLP violations tied to ChatGPT and 242 million for Codium, exposing PII, financials, source code and healthcare data. Zscaler recommends inventorying GenAI apps, disabling risky defaults, enforcing zero trust for model interactions and applying inline inspection to protect sensitive information.
read more →

Critical RCE and Data-Leak Flaws in SEPPMail Gateway

🔒 InfoGuard Labs disclosed multiple critical vulnerabilities in SEPPMail Secure E-Mail Gateway that allow unauthenticated remote code execution, path traversal, deserialization flaws, and exposure of sensitive server data. Researchers demonstrated an exploit chain leveraging the LFT path traversal (CVE-2026-2743) to overwrite syslog configuration and obtain a Perl reverse shell, enabling full appliance takeover and mail interception. SEPPmail has released fixes across versions 15.0.2.1, 15.0.3 and 15.0.4 and urges administrators to apply updates immediately.
read more →

Handala Hackers Leak US Marines' Data, Send Threats

🚨 US Marines stationed near the Persian Gulf reported receiving chilling WhatsApp messages beginning Monday that urged them to call home and make final goodbyes. The messages were signed by the Iran-linked Handala hacking group and allegedly originated from a Bahraini phone number that was likely spoofed or hijacked. A day later, Handala posted that it had published names and phone numbers of 2,379 Marines and boasted of possessing addresses, family details and daily routines. While authorities caution that such claims may rely on scraped or recycled data rather than a fresh breach, the campaign’s intent to intimidate service members is clear.
read more →

Apple issues emergency iOS fix for persistent notifications

🔒 Apple released an emergency update to fix a Notification Services logging flaw that allowed deleted alerts to remain stored on devices, potentially exposing message content. Tracked as CVE-2026-28950, the vulnerability is resolved in iOS 26.4.2 and iPadOS 26.4.2, with backports provided for older supported releases. Apple said the root cause was a logging issue and that improved data redaction prevents notifications marked for deletion from persisting. The company did not confirm whether the flaw was exploited or how long retained data could remain accessible.
read more →

FBI Recovers Deleted Signal Messages from iPhone DB

🔐 The FBI reportedly extracted copies of incoming Signal messages from an iPhone’s internal push notification database after the app was deleted. The extraction occurred during a criminal case where physical access allowed forensic tools to retrieve notification previews stored by iOS. The case underscores the privacy risk when message previews are enabled and the importance of disabling notification previews within Signal or device settings.
read more →

Windows Recall Still Permits Silent Data Extraction

🛡️ A security researcher says Microsoft’s Windows Recall feature remains vulnerable to quiet exfiltration of everything it captures by malware running in the same user context. Alexander Hagenah published a proof-of-concept called TotalRecall Reloaded and disclosed the issue to Microsoft on March 6; Microsoft reviewed and closed the report April 3, calling the behavior "by design." Hagenah says the gap lies not in encryption but in how decrypted screenshots and text are handled and displayed in an unprotected process, allowing same-user code to read Recall data without admin rights or kernel exploits.
read more →

Germany Becomes Primary Target in European Data Leaks

🔒 Google Threat Intelligence reports a sharp rise in data leak site (DLS) activity targeting Germany, with German victim posts growing 92% in 2025—triple the European average. Attackers have shifted focus to the digitized industrial base and the Mittelstand, exploiting mid‑tier DLS groups such as SAFEPAY and Qilin. GTI observed forum recruitment and extortion tactics traced to actors like Sarcoma. Caveats note that DLS counts often reflect failed negotiations and are one signal among many; GTI recommends proactive third‑party risk management, multifactor authentication, and endpoint hardening.
read more →

Anthropic's Claude Code Source Leaked via npm Packaging

🔓Anthropic confirmed that internal source code for its coding assistant Claude Code was inadvertently published after a packaging error when version 2.1.88 was released to npm. The package included a source map exposing nearly 2,000 TypeScript files and over 512,000 lines of code; the release has since been removed. Anthropic says no customer data or credentials were exposed and is implementing measures to prevent recurrence.
read more →

Anthropic Map File Error Exposes Claude Code Source

🔓 An Anthropic employee accidentally published a source map in a public npm package, which allowed the proprietary source for Claude Code to be reconstructed. Anthropic says this was a release packaging error and that no sensitive customer data or credentials were exposed, and that it is rolling out measures to prevent recurrence. Security experts warn that source maps reveal original code, comments, internal constants and prompts, making vulnerabilities and secrets easier to find; the same mistake reportedly occurred previously.
read more →

Anthropic accidentally publishes Claude Code source on NPM

🚨 Anthropic says it accidentally published the closed-source Claude Code source when an NPM release (v2.1.88) included a 60MB cli.js.map file that embedded original sources. The reconstructed tree contains roughly 1,900 files and 500,000 lines of code, and the leak has spread across GitHub and other platforms. Anthropic confirmed no customer data or credentials were exposed, called the incident a packaging error caused by human mistake, and is issuing DMCA takedowns while rolling out measures to prevent recurrence.
read more →

England Hockey Probes Alleged AiLock Ransomware Breach

🔒 England Hockey is investigating claims that the AiLock ransomware gang stole approximately 129GB of data and listed the organization on its leak site, threatening to publish files unless a ransom is paid. The governing body says it has prioritized an inquiry involving internal teams, external specialists, and cooperation with law enforcement. England Hockey cannot yet provide specifics while the investigation continues and urges members to remain vigilant for phishing and suspicious account activity.
read more →

LeakyLooker: Nine Cross-Tenant Flaws in Looker Studio

🔒 Tenable Research disclosed nine cross-tenant vulnerabilities, collectively named LeakyLooker, in Looker Studio that could allow attackers to run arbitrary SQL and access datasets across tenants. The flaws affected connectors including BigQuery, Spanner, PostgreSQL, MySQL, Google Sheets and Cloud Storage and involved SQL injection, data leaks via report elements and a BigQuery denial-of-wallet issue. Google has applied global fixes to its fully managed service and no customer action is required, though organisations should review sharing settings and limit unused connectors.
read more →

Malicious AI Assistant Extensions Harvest LLM Data

🔒 Microsoft Defender investigated malicious Chromium browser extensions that impersonated legitimate AI assistant tools to collect LLM chat histories and browsing telemetry. Distributed via the Chrome Web Store and compatible with both Google Chrome and Microsoft Edge, the extensions captured full URLs and chat snippets from platforms such as ChatGPT and DeepSeek, reaching roughly 900,000 installs and activity in over 20,000 enterprise tenants. Microsoft provides detections, hunting queries, and mitigation guidance to contain exposure and remediate affected devices.
read more →

South Korea NTS Publishes Seed Phrase, Loses $4.8M Crypto

🔑 South Korea's National Tax Service (NTS) accidentally included a photograph in a press release that exposed a handwritten cryptocurrency mnemonic seed phrase next to a seized Ledger device. Within hours the wallet holding roughly 4 million PRTG tokens (about US $4.8M) was emptied. The NTS removed the release and issued an apology; the incident underscores that publishing a wallet's seed phrase instantly nullifies any cold-storage security.
read more →

Star Citizen Developer Discloses Backup Data Breach

🔒 Cloud Imperium Games (CIG), developer of Star Citizen and Squadron 42, disclosed a breach discovered on 21 January 2026 in which attackers accessed certain backup systems. The company says unauthorized access affected limited user personal data — primarily account metadata and contact details such as username, name and date of birth. CIG states no credentials or payment information were stored in the affected systems, access was read-only, and it has found no evidence of data modification or public leakage while it continues to monitor and investigate the incident.
read more →

Ransomware leak sites escalate pressure on victims

🔒 Data leak sites (DLSs) have become the backbone of modern ransomware's double‑extortion strategy, combining data theft with public blackmail to force payment. Attackers publish carefully curated samples, use timers and deadlines, and exploit urgency to magnify reputational, regulatory, and financial harm. Law enforcement agencies and security teams warn that DLS content fuels follow‑on crimes like phishing and identity fraud. Organizations are urged to adopt EDR/XDR, Zero Trust, patched systems, resilient air‑gapped backups, and targeted user training.
read more →