Tag: security

Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online

More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of…

Read More

Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service

Researcher inds ClarityCheck’s exposed 450GB database with 9M+ user images Leak included faces, profiles, and photos, risking identity theft and phishing abuse Company secured access quickly; no evidence of dark web distribution or misuse so far An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting…

Read More

Experts manage to hack Microsoft Copilot by continually asking it questions about itself

Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive data Exploit used malicious URLs and persistent memory poisoning to bypass guardrails Microsoft patched CVE‑2026‑24301 server‑side; technique may affect other AI models Microsoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and…

Read More

‘This technology turns every router into a potential means for surveillance’: Report claims Wi-Fi devices could ‘quietly identify’ people with nearly 100% accuracy

Ordinary Wi-Fi networks can reportedly identify people without cameras or consent KASTEL researchers achieved nearly 100% identification accuracy across 197 volunteers tested Wi-Fi signals can reportedly reveal people from different viewing angles A new study suggests that ordinary Wi-Fi networks could be repurposed to identify individuals without cameras, sensors, or…

Read More

MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves

CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately Less than a week after being publicly disclosed, a macOS vulnerability…

Read More

Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in

Two US senators have proposed a new Water Cyber Shield Act to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure. The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against…

Read More