Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label data security. Show all posts

Study Warns Enterprise AI Rollouts Are Outpacing Data Security Checks

 

Companies are adopting AI tools faster than they are testing whether their underlying data is appropriately secure, a new report from governance firm Syskit suggests. Based on a survey of 327 IT and security decision-makers at U.S. and U.K. organizations with at least 500 workers, Syskit's State of Microsoft 365 Governance Report, published Sept. 10, found that 76% of the companies surveyed had deployed or tested enterprise AI tools such as Copilot in their Microsoft 365 environments, but less than half (43%) had conducted a thorough review of file permissions and potential oversharing risks prior to deployment, and the rest skipped the review process or reviewed only partially.  

There was a similar gap for oversight over AI agents. While 91% of respondents said they were confident about their knowledge of what AI agents were and had access to, in practice, barely one in five companies (22%) had a formal policy outlining permitted agents' access, and roughly one in 10 (9%) had an agent that had inherited all the permissions of the person who had deployed it. "If you look at tools such as Copilot, you can see the value it can bring," said Syskit CEO Toni Frankola, noting that some content could be exposed purely based on permissions that had been set years ago and then simply forgotten about, and that AI had removed the friction that had previously prevented accidental exposure. 

"Permission audits may be the most critical and least desirable step in preparing a safe and secure AI deployment." The report also highlighted areas of weakness in Microsoft 365 environments overall. Roughly 41% of organizations had SharePoint sites that were publicly available with no access restrictions, 35% had visible files for past employees, and a third had files shared publicly with "Everyone." Ownerless content was the biggest concern, with 47% of organizations citing orphaned teams, groups and sites, which had no one accountable for reviewing or securing them, despite being accessible to an AI just as readily as any other content.  

"There seems to be a disconnect between confidence and reality with regard to the management and control of data and information," said Frankola. "While eight in 10 (83%) organizations feel confident that they know exactly who can access specific sensitive information, only 4% could provide a complete access report for an auditor within an hour if asked ... and more than half would need at least a day to prepare one." Perhaps most concerningly, 90% of organizations said they had suffered or suspected a security incident related to incorrectly configured permissions or excessive access in the last two years, and 39% confirmed that a security incident had definitely occurred.

South Korean Startup Suffers Breach Due to Encryption Management Failure


Modu-ui, a South Korean government backed startup support platform, suffered a data breach in July. The breach later disclosed a critical encoding key management compromise, showing how encoded information can still become vulnerable when enterprises can’t protect encoding keys properly. 

About Modu-ui

Modu-ui stores participants’ personal details such as email addresses, names, and startup ideas, and the platform also supports a nationwide startup audition overseen by SMEs and Startups (MSS) of the South Korean Ministry.

Suspicions were already raised a month prior to the reported data breach that applicants’ personal data could be structured and exposed via API responses inside the platform. The government said it had taken prompt action but did not reveal if it had upgraded Modu-ui’s security infrastructure.

Startup details leaked

In June, the Ministry of SMEs and Startups disclosed that summaries of startup ideas and personal details had been exposed. Later, it started a detailed enquiry along with National Police Agency, National Intelligence Service, and the Cyber Security Center.

In July, the agencies confirmed that the leak of encoding keys via an API was the reason for the startup idea and personal data leak.

About the breach

The exposed data had already been encoded but the encoded data needs an encoding key decoding.

In this case, the encoding key was leaked along with the API data, causing in the leak of evaluation comments, startup idea summaries and email addresses related to 5000 successful applicants. 

According to the Ministry, the encoding key had been included inside the API and a third party retrieved API data via methods like web crawling, causing the exposure of the key.

Private email addresses were not shown on the public-facing interface but officials believed they could be retrieved via AI-based web crawling. 

Impact on organizations

The incidents also demonstrate the dangers of hard-coding encoding keys as fixed values inside databases, application code, similar environments, or databases.

When businesses follow this method, the keys can become vulnerable in addition to the data or systems they are meant to protect. The main reason for this incident can be viewed as security infrastructure failure in incorporating  robust encoding key management.

Officials found 39 IP addresses related to the access of the exposed data coming from South Korea. Authorities also said that investigations led to more details such as potential connections to AI solution providers.

Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer's Personal Device

 

Officials in Florida confirmed Thursday that the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer who had stored login information on a personal device. The ShinyHunters cybercriminal organization claimed on Monday that it had obtained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). 

The department did not respond to repeated requests for comment throughout the week but publicly confirmed the breach's legitimacy on Thursday night. Officials said they first learned of the breach on September 4 and initially attributed it to an unnamed "international cybercriminal organization." 

According to the department, an investigation determined that a criminal actor exploited a single Plant City Police Department user's credentials, which had been improperly stored on the employee's personal electronic device. Plant City is a small suburb outside Tampa. FLHSMV has since notified other Florida government offices and is partnering with the Florida Digital Service to investigate the incident. 

As proof of access, ShinyHunters shared alleged photos of a DMV record tied to American financier and convicted child sex offender Jeffrey Epstein. When claims of the breach first surfaced, some cybersecurity experts speculated it might be connected to the recently confirmed breach involving 153 million driver's licenses leaked by identity verification firm IDScan. ShinyHunters had previously attempted to purchase the ID database from the hackers behind the IDScan breach.

The group has recently claimed responsibility for attacks on bank IT provider Jack Henry, as well as pharmaceutical and healthcare technology company McKesson, which told regulators that data from its oncology and surgical business units had been stolen. ShinyHunters also caused widespread disruption across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after targeting the world's largest medical device company in April. 

Other victims linked to the group include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. In a related development, artificial intelligence company Anthropic released a report Thursday stating that suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems, and steal data from victims for extortion purposes. 

The report noted that in one case, an operator escalated from a stolen developer token to full administrative access over a victim's cloud environment in approximately three hours. Incident responders at Google also confirmed last week that members of the group are using Anthropic's AI tools at various stages of their attacks. 

The Florida breach adds to a growing list of incidents tied to ShinyHunters, underscoring the group's persistent targeting of both government systems and major corporations, as well as its evolving use of AI tools to accelerate and scale its intrusions.

Turner Discloses Data Breach Exposing Salary Info, Bank Accounts, and SSNs

 

Turner Construction has notified at least 6,098 people of a data breach that uncovered social security numbers, salaries, dates of birth and bank account information used for direct deposit, a filing with the California Office of Attorney General showed. The New York City-based firm found unauthorized access to its systems occurred between July 2 and July 15, the filing with the California Office of Attorney General said. 

Turner confirmed on July 27 that files that contained personal information had been accessed without authorization, and some of the files that were accessed may have also included individuals' passport numbers. Ransomware group Payouts King claimed responsibility for the attack, alleging that the data that had been breached extended far beyond personal data to include engineering documents, military project files, contracts and non-disclosure agreements, a post on ClaimDEPOT, a class-action lawsuit tracking website, said. 

Turner issued a statement that after discovering that unauthorized access to certain files had occurred, the company engaged third-party cybersecurity and forensic experts and that those experts continue to review the files that were accessed. The company said it would notify impacted individuals and other parties as necessary and provide complimentary identity protection services. Turner added it would not comment on claims made by criminal organizations. 

According to ClaimDEPOT, Payouts King first posted information relating to an unidentified victim on July 24 and publicly naming Turner on August 11. The group posted the claims on a Tor network site, which hides the users' locations and identifies, claiming it had obtained 27.2 terabytes of data. Apart from the file types stated in the California attorney general filing, Payouts King claimed it had also accessed documents that were protected under International Traffic in Arms Regulations, which are US government rules regulating the export and import of military items, technology and services. Turner is offering five years of identity protection services through IDShield and IDX, the notices filed with the California AG's office said. 

One of the two notices set a November 18 deadline for affected individuals to enroll. The incident comes amid a wave of attacks targeting construction-related domains, an August 6 post on Google's Threat Intelligence blog identifying potentially compromised sites said. Turner is the largest contractor in the industry by revenue and focuses on data centers and advanced technology construction. The booming data center sector drove the firm to build a $44.3 billion backlog by the end of 2025.  

Several law firms have since posted notices of investigations into the Turner incident, seeking plaintiffs for potential class-action lawsuits. Turner also reported that at least 38 Vermont residents were affected by the breach, according to the Office of the Vermont Attorney General.

IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers

 

Identity verification company IDScan is being sued in multiple cases after hackers allegedly gained unauthorized access to the service and started selling more than 153 million driver’s licenses via dark web. Markovits, Stock & DeMarco and Hall Attorneys law firms are investigating the class-action claims against the company, which is based in Louisiana. 

Plaintiffs allege that IDScan failed to protect the information of its clients, including car rental company Hertz. Everything started on September 1 when Krebs revealed that a dark-web illegal identity-theft service called Nexus was selling more than 153 million scans of American and Canadian’s driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. 

He confirmed his sources by searching for his own data and the data of other people who gave their consent to do so. His research showed that all the resources were stolen from IDScan. IDScan sells scanners and specialized software for extracting personal data from official documents. Its technology is used in numerous car rental companies, retail stores, gun shops, banks, pot shops, and hotels across the United States. 

The company has not responded to media inquiries about the data breach, leaving the situation unclear. For now, it is unknown how exactly the breach occurred and how many people were affected. According to Krebs, the Federal Bureau of Investigation (FBI) in New Orleans is investigating the issue, confirming the story, Reuters noted. The FBI spokesperson told Bleepingcomputer that the bureau is looking into the reports but declined further comments due to the sensitivity of the case. The illegal website Nexus that was distributing people’s personal data is closed now. 

However, criminals who stole the information from IDScan still have access to the database. According to Krebs, the compromised data includes the documents of the Secretary of Defense Pete Hegseth and an assistant director of the FBI, which could not be confirmed. Markovits, Stock & DeMarco law firm revealed that IDScan started informing some of its business customers around September 1. The company’s representatives stated that if someone’s ID was scanned in their system, they would contact them to discuss the situation and represent their interests in court. 

In addition, the firm is looking for other organizations to file a class-action lawsuit against the company. Because of the potential number of affected people, other class-action lawsuits may arise, which will have to be consolidated in multidistrict litigation. In addition, other states’ attorneys general and federal regulators may also launch separate investigations into this data security breach. Similar situations with 23andMe, Marriott, and Equifax data compromises happened before and ended in multi-state inquiries or even criminal charges.

Origin Energy Data Breach Traced to Manila Call Centre, Ex-Accenture Employee Identified

 

An ex Accenture worker from Manila is suspected to be behind last month's security breach. Accenture has an office in the city, which supports the energy business in Origin with its customer call centres. It was alleged by a Nine report that the worker attempted to extort the energy provider for money, for its return of the stolen information. 

When approached by ABC News, an Accenture representative said it would be inappropriate to comment on Origin's data security incident. It stated that it is under active investigation. Origin Energy also refused to comment, citing that the breach is the subject of an ongoing criminal investigation. It was revealed the extent of the incident was apparent when, last month, an The Australian reported a hacker had supplied a sample of 50 customer records including names, addresses, emails, dates of birth, phone numbers and billing histories.

Origin Energy reported it to the authorities a potential data breach. The company later told the Business it believed the information of up to 900,000 current and former customers had been accessed. Origin customers told the ABC they felt their personal data could have been breached and expressed frustration with not being given enough detail on the nature of the incident. 

It is the latest in a series of major cybersecurity incidents affecting Australian companies. Qantas suffered a significant hack in 2025, while Optus and Medibank both experienced mass data breaches in 2022. Origin confirmed it became aware of a potential security threat in early July, but did not initially take it seriously. It has advised affected customers to be on guard against scams and said specialist identity and cyber support services are available. 

Origin chief executive Frank Calabria addressed the incident in July, saying the company had completed the first of its review into the customer data security breach. It apologised to customers for placing trust in Origin to safeguard its information. The Australian Federal Police (AFP) confirmed it is working closely with Origin Energy and relevant partners after the reported cyber incident.

An AFP spokesperson said the focus of investigators is on gathering evidence, identifying those responsible and disrupting any associated criminal activity. It added Origin Energy has been cooperative and transparent in its engagement with investigators, and continues to assist the ongoing investigation. No information has yet been released about possible charges against the former Accenture employee identified by the investigation.

Trezor Data Breach Rises to 67,000 US Customers


Hardware cryptocurrency wallet organization Trezor has disclosed that additional 67,000 customers in the US have been impacted by a data breach consisting of its shipping provider, ShipMonk. 

The recent news has notably increased the number of consumers potentially exposed in the incident.  “We're deeply saddened to share the news that the recent data breach affects more customers than originally thought,” Trezor said on X. 

As per Trezor, the additional 67000 customers placed orders from November 2019 to August 2021. 

What is leaked?

The leaked data consists of customers' email, phone numbers, names, addresses, order numbers, and shipping addresses. According to Trezor, the data was stored by ShipMonk even though Trezor had earlier received assurance that previous consumer data had been erased. 

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.

According to experts, the breach is not impacting Trezor’s own systems. 

Who are impacted?

Trezor said its hardware wallets are safe and there are no signs that customers’ recovery seed phrases or private keys were breached in the leak. 

As per Trezor, “All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected.”

Potential impact

But Trezor and cybersecurity experts are worried that the stolen data could be exploited for social engineering and targeted phishing attacks. Threat actors could misuse customers’ details regarding their Trezor purchases to create scam phone calls or fraud messages.

This can be a serious problem for cryptocurrency users. A threat actor could mimic a company employee if they know someone owns a Trezor wallet and ask the target to verify their wallet or account. 

User advisory

If successful, the attacker could steal the target’s recovery seed phrase, which can allow access to cryptocurrency funds. “Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security,” the company added. 

The announcement comes after the August incident when 13,689 customers had been impacted by the same shipping-provider. At the time, Trezor estimated around 14,000 customers to have been affected by the breach. The recent disclosure of 67,000 suggests the scope of the incident was larger than expected.

Thomson Reuters Court Records Breach Exposes Sensitive Data Across North America

 

Sensitive court records and personal information were spilled from a data breach in the court system, which impacts at least 12 states in the U.S., including the U.S. Virgin Islands and Canada, Thomson Reuters announced on Wednesday. The breach occurred in C-Track, a court case management software, run by one of Thomson Reuters’ subsidiaries. 

The company remains silent on how the hackers accessed the program, who was responsible and how much data was compromised, as well as the number of individuals impacted. Thomson Reuters stressed that the breach was within their own environment and “not related to security vulnerabilities in the networks, systems or data of the courts.” The company discovered unauthorized access to its system on June 30, and it initiated an investigation alongside outside cyber security experts and law enforcement. 

Their probe established that unauthorized intruders accessed some C-Track files in March. Meanwhile, a separate disclosure by the Montana Supreme Court revealed that Thomson Reuters advised the state court officials that unauthorized access to C-Track persisted up to June, which means that hackers may have remained undetected within the system for several months. The sensitive information spilled includes names, Social Security numbers, driver licenses, medical information, dates of birth, and health insurance. 

Thomson Reuters added that confidential, redacted, or otherwise restricted information from court records may have been accessed in some jurisdictions, but the company confirmed that no abuse of the situation has occurred. The data breach did not impact the operations of C-Track, which continues to function normally. Thomson Reuters implemented additional security measures, following the breach, after they were approved by outside cybersecurity experts, although the company did not disclose who they were. 

The courts in the U.S. whose data is at risk, according to the company, are the appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, and Wyoming. In addition, several Pennsylvania courts, 10 Ohio district courts of appeals, the Supreme Court, and the Superior Court of the U.S. Virgin Islands are also on the list. The breach in Oregon Judicial Department added another state to the list, expanding the reach to at least 12 states. 

Nevada officials reminded their residents that the types of data compromised differs from state to state, and that not all the data in each state is necessarily confidential or protected. They added that, for example, in Montana, most of the data already was publicly available, but the state’s court system acknowledged the breach of the drivers’ licenses and dates of birth. 

In addition, several of the jurisdictions were notified weeks after Thomson Reuters became aware of the security threat. For example, the court administrator of Montana and the Ontario Ministry of the Attorney General were notified of the unauthorized access to the data on July 23. The chief justices of Ontario agreed that it still remains unclear what information was at risk and how many people were impacted. Thomson Reuters notifies affected individuals that they can receive 12 months of free of credit monitoring and identity theft protection.

5 Million WordPress Sites Exposed to SQL Injection Vulnerability


A severe security flaw in a famous WordPress migration plugin and backup could allow threat actors to take command of over millions of sites, experts have warned.

About the security flaw

The security flaw is tracked as CVE-2026-19949, it impacts the Backup plugin and All-in-One WP Migration, which is utilized by over five million active wordpress installations. The plugin lets site owners to migrate, import, export, and backup sites, this consists of media files, themes, plugins, and databases.

As per Bleeping Computer, the flaw is a second-order SQL injection vulnerability that could permit an unauthorized threat actor to run malicious code on a compromised site. The flaw impacts variants 7.109 and earlier and has been given high severity, with a 8.8 CVSS score.

Reporting of the flaw

The vulnerability was found by security expert Jack Taylor, who reported the incident to cybersecurity company Wordfence, which investigated and disclosed the flaw. On August 15, 2026, Wordfence informed the plugin’s developer, Servmask, which released variant 7.220 on August 20 to patch the flaw. 

“On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations,” Wordfence reported.

Attack tactic

Contrary to flaws that can be abused immediately, this vulnerability consists of an extra step. Threat actors first place specially tailored data on a compromised website. 

The malicious information remains latent until a website admin does a backup restoration of the archive. “This vulnerability makes it possible for unauthenticated attackers to inject SQL that is later executed when a site administrator performs an archive restore, which can be used to leak the plugin’s secret key and ultimately achieve remote code execution, leading to complete site takeover,” Wordfence said.

Misuse of malicious data

In the restoration stage, the stored malicious data can be used as SQL commands which allows threat actors to take out sensitive data from the website’s database.

An important target is the plugin’s secret ai1wm_secret_key.. If a threat actor accesses this key, it can possibly be used to move from database access to remote code execution (RCE), allowing the threat actor more control over the compromised website.

Through RCE, threat actors could install malicious code, change website files, and create backdoors.

Addressing the flaw

ServMask addressed the CVE-2026-19949 in variant 7.110 of the plugin. Users are advised to update their websites to the latest patched versions of Backup and All-in-One WP Migration.

On August 20, ServMask addressed the CVE-2026-19949 vulnerability in version 7.110 of the plugin.

Face ID and Fingerprint Unlocks May Put Your Privacy at Risk

 

Face ID and fingerprint unlock features allow for more convenient smartphone and account access but offer less privacy in the case of forced disclosure. According to PCMag , the police can compel an individual to unlock a phone using biometrics but not with a pin or password. The debate over the convenience versus safety of biometric verification became a heated topic this year after the FBI stormed the home of Washington Post reporter Hannah Natanson. 

The court records obtained by the 404 Media revealed that the bureau was unable to open Natanson’s iPhone due to it being protected by Lockdown mode. However, a federal judge later issued a warrant compelling Natanson to unlock her computer using fingerprint. Facial recognition and fingerprint scans are termed biometrics. They can be used to authorize access to computers, phones, and other technology. With passkeys, one can also digitally unlock online accounts and services. 

A passkey can be generated using biometrics or a passcode on a device with lock options. PCmag points out that there is nothing wrong with wanting convenience over security. On the contrary, those at higher risk of government and corporate surveillance and thus prone to coercion should consider using a passcode or passphrase instead of biometric verification. iPhone users can also consider using Lockdown mode. This setting is useful in preventing unauthorized access to the device by eliminating the option of attaching files through messages, installing device management configuration profiles, calls, and FaceTime. 

The option is available in Settings under Privacy and Security. Android also has a lockdown setting that can be used to disable biometric options to secure the smartphone in cases where the owner is fearful that their fingerprint or facial scan might be compromised. Android 13 and later versions offer Advanced Protection mode which requires hardware security keys or passkeys to access Google accounts. It also prevents the downloading of malicious apps and files and stops unauthorized access to Google services by third-party apps. Those wishing to turn off biometric verification can delete their prints or scans from their devices. 

According to PCmag , fingerprints and facial scans are saved on the phone or computer and not on the cloud. Android users can delete their biometric data by heading to Security and Privacy and tapping Device unlock/Biometrics and setting a passcode. iPhone users can go to Face ID/Touch ID & Passcode and reset Face ID or delete their fingerprint. 

PCMag contends that phone security is only a small component of personal security. One should also read the terms and conditions of technology companies, close online accounts that are not necessary, reduce digital footprints, and utilize different strong passwords to gain more control of personal data.

Berlin Confirms Extortion Attempt After Network Compromise as Manchester Airports Group Reports Customer Data Theft

 

The state of Berlin confirms that it is the victim of an extortion attempt after allegedly having its network hacked back in August. Authorities say they will not give in to the hackers’ demands. 

Forensic analyses of the network of the Senate Department of Mobility, Transport, Climate Protection and the Environment have revealed additional data thefts outside the network in the period between August 7 and 12. The department had first noticed data loss on August 7 and had been cut off on August 14. Berlin is currently still investigating the extent and scope of the data loss, saying that it is possible that personal data or other confidential information had been accessed. 

The amount of data stolen in the cyber-attack on Berlin has not been disclosed officially; however, one entry on the dark web by the hackers’ group Rhysida, published on August 28, claims that 5,79 TB of data containing personal information of 12,076 people were stolen. The entry also stated that approximately 1,44 million files had been scanned. 

According to the post, the target of the attack was Berlin, Germany, without specifying any ransom value. Der Spiegel revealed that the ransom note was published by the hacker collective Rhysida, citing the group’s dark web blog and security sources. According to the report, a monitoring service confirmed on Friday that a post titled “Berlin, Germany” appeared on the leak site of Rhysida on August 28. Berlin has not officially attributed the attack to any hacker group. 

A joint security advisory released by the U.S. Cybersecurity and Infrastructure Security Agency, the FBI and the Multi-State Information Sharing and Analysis Center highlights that Rhysida has been abusing compromised legitimate usernames and passwords from remote access services and has been using phishing and the Zerologon vulnerability (CVE-2020-1472). The advisory recommends prioritizing the response to known exploited vulnerabilities, implementing multi-factor authentication and network segmentation. 

Berlin’s data protection commissioner and the Federal Office for Information Security have been informed of the attack. Interior Minister Iris Spranger stated that, according to preliminary information, no data from the election-relevant IT systems were removed from the network. Thus far, no election functions have been interrupted. Meanwhile, Manchester Airports Group (MAG) has announced that a cyber-security incident involving the unauthorized collection of customer data occurred at its UK airports. 

The personal data of passengers who booked car parking, lounges, or Fast Track services or who subscribed to in-airport WiFi were affected. The data compromised in the breach include customers’ email addresses, phone numbers, vehicle registration numbers, and postcode details. According to MAG, the data do not include customers’ payment or bank details, and no impact has been made on passengers’ safety or aviation safety or airport operations.

As of August 29, the online booking system, called Manage My Booking, has been temporarily offline for security reasons. It has been reported that affected customers have been contacted directly and have been warned to be vigilant of further communication attempts from unauthorized third parties.

39 Child Tracking Brands Linked to One Chinese Server, Exposing 45 Security Vulnerabilities

 

GPS trackers for children may put the tracked individuals and the people tracking them in danger, according to an investigation presented at the Black Hat security conference. Vangelis Stykas, CTO of Kumio, and Felipe Solferini, principal AI security engineer, discovered that 39 different consumer brands of parental monitoring devices share the same server in China where the data stored on them are processed. 

The researchers named the producers of the technologies, which the mentioned companies used in their devices, SeTracker, SinoTrack and TKStar. They found 45 different vulnerabilities that could allow unauthorized access to children’s smart devices enabling eavesdropping, video surveillance, and total remote control of the system where valuable information is stored. The researchers stated that to perform all these actions, a hacker would need only a free account on any of these platforms. 

The scientists also found that parental monitoring devices of different brands did not have the necessary authorization restrictions, which allowed accessing their systems freely. These devices could collect and store much more personal information than monitoring their location. Some of them have the functionality to record the screen, as well as control the camera and microphone. Thus, the location of the tracked device, photographs and video, the child’s screen, the applications and websites he visits, and his personal information can be known to unauthorized people. 

At the beginning of the demonstration, the researchers showed how they managed to run a script on a children’s smartwatch, which, among other things, dialed a phone number and transmitted an audio signal without any notification on the displayed screen that the call had begun. The scientists emphasized that the experiment was carried out ethically, and they used devices provided to them for the investigation. Stykas and Solferini also discovered that attacks on the system could have been made two years before the investigation began. 

This indicates that, in principle, someone could have been able to track the child’s location and personal data without his knowledge. The researchers contacted the companies more than 30 times, but received no response. One unknown dealer, however, responded to the scientists, noting that he was helping them investigate and would forward the information to the manufacturer. Researchers have concluded that parental monitoring devices pose a serious danger to privacy and safety by possessing many vulnerabilities. 

The investigation demonstrated that the same server is used for different brands, and the lack of protection allows hackers to gain full control of the system and track all the child’s activities. The report also suggests giving up these devices, and for those parents who want to control their children’s devices, the scientists recommended using the built-in tools of the giants: Apple Screen Time, Google Family Link, and Microsoft Family Safety.

Roblox Privacy System Tracks Data Across Hundreds of Systems as Platform Faces Child Safety Concerns

 

Roblox announces new federated central data coordination, but the system also acts as a reminder of the amount of data the company stores about its users and their activity on the platform As the platform boasts more than 132 million daily users, half of which are under the age of 18, Roblox has a large-scale privacy and safety issue. 

At the Black Hat security conference, Roblox engineering manager Hao Zhang and principal privacy software engineer Yiwen Luo spoke about the company’s approach to operational privacy and data deletion. One user request to delete data could trigger over 600 subtasks that need to be tackled by different teams and systems. According to Zhang, the entire system is complex and requires close collaboration between hundreds of systems; one of the biggest challenges was figuring out where exactly the data about the user is stored. 

Luo added that per the privacy policy, Roblox collects and stores most information about the user for as long as the account is active on the platform. The topics range from chat content, audio and video data, device information, and demography, to email and phone number, government ID and selfie for voice chat and other restricted content, payment information, and username, date of birth, and password. Roblox has experienced a 3.5X growth in year-over-year privacy-related user data requests. 

The new federated management system aims to handle such requests in a more efficient system-wide manner across the company’s systems and data platforms, as well as the third-party ones storing user data. Roblox is using artificial intelligence and other technologies to improve moderation, safety, and privacy on its platform. The company’s system, called Sentinel, is designed to detect harmful content and messages using machine learning algorithms. 

Roblox also relies on a combination of human moderation and automated tools to review and filter game catalogs, chat content, and other materials. It implements preventive algorithms and age-estimation solutions as a part of its safety measures. However, the growing use of tracking systems, tools, and the controversy around the age-verification laws in over half of the U.S. states have sparked debates regarding data privacy and potential risks to users’ safety and data privacy. 

The expansion of Roblox’s operations has also led to increased scrutiny from regulators. After the games containing violent and extremist content were leaked, and the lawsuits regarding the company’s alleged role in facilitating predation and grooming were filed, Roblox’s moderation capabilities and safety tools have come under the magnifying glass. The Roblox Sentinel documentation reveals that roughly 1,200 potential child-endangerment reports had been reviewed.

Still, there was no information about how many of those had been confirmed as actual cases. While the new federated security system allows Roblox to have more visibility and control over where the data about its users is stored and how does the company handles data deletion requests, its transparency around the matter is limited by the amount of data the company stores about its users and the extent to which it monitors its platforms.

North Korean Hackers Target 1,640 Companies Across 57 Countries, Researcher Finds

 

North Korean hackers have been targeting the infrastructure and cryptocurrency wallets worldwide. Greek security expert Vangelis Stykas identified 1,640 organizations across 57 countries hit by the attack. His investigation, which gained unauthorized access to the networks run by North Korean hackers, took about 22 months. 

At the Black Hat conference in Las Vegas, Stykas spoke about the attacks, mentioning that around 700 to 800 companies out of 1,640 had fallen victim to “truly malicious” intrusion. In some cases, the servers and AWS accounts were compromised at the root level by state-sponsored groups. Stykas did not disclose how he managed to infiltrate the North Korean hacking groups. He noted that his computer might have been infected with the group’s malware since their computers were infected. 

The security analyst had access to Slack and Discord accounts controlled by the hackers and gathered five terabytes of data. Lazarus Group complex, one of the North Korean state-sponsored hacking groups, has been using encrypted messaging services like Telegram and Signal to coordinate crypto heists and money laundering schemes. According to the report by Chainalysis, which monitors illicit crypto transactions, North Korean hackers have generated more than $2.02 billion in 2025, a 51 percent increase from the previous year. 

Their cumulative cryptocurrency theft since 2017 reached about $6.75 billion in value through crypto heists. Moreover, 76% of crypto heists worldwide occurred in the first four months of 2026, with North Korean-sponsored groups being the masterminds behind these crimes. The groups are also changing their tactics, shifting from compromised encryption keys to social engineering to infiltrate new crypto exchanges. Stykas added that toward the end of 2024, attackers primarily used social engineering to convince victims to install malicious software on their computers by posing as recruiters offering high-paying IT jobs. 

The software would allow hackers to access the victims’ computers under the guise of testing their skills. The list of companies targeted by North Korean hackers includes Chinese smartphone manufacturer Oppo, Boston’s Children Hospital, tech firms in Japan, Italy’s judicial organizations, and Belgium’s Flemish government. Several of the organizations, including Flemish government agencies and Boston’s Children Hospital, noted that the breach originated from third-party contractors, and the damage was minimal. 

Moreover, Stykas added that many of his warnings went unheeded by the organizations that had fallen victim to the attacks. His research revealed that many organizations are using third-party contractors and service providers that operate as subcontractors for different firms. A single compromised third-party organization can lead to a security breach of multiple organizations. 

North Korean hackers not only target crypto wallets but also use their IT expertise to infiltrate organizations and exfiltrate data. Experts believe that North Korea continues to fund its nuclear program from the proceeds of these crimes.  Moreover, hackers pose as legitimate IT professionals offering their services on job boards, eventually getting hired and transferring the earnings to North Korean banks. Authorities believe North Korean hackers’ activities are designed to circumvent sanctions imposed on the country. 

According to experts, the infiltration of crypto exchanges, technology companies, and financial organizations will enable North Korea to bypass sanctions while funding its military expansion and nuclear program. Andariel hacker group, which targets defense and nuclear-related organizations, was dismantled by security agencies in 2024.

Clop-Linked Web Shell Targets PTC Windchill Servers in Data Theft Attacks

 

A custom Java web shell, associated with the Clop ransomware group, was created to target the PTC Windchill and FlexPLM servers by decrypting their credentials, enumerating file repositories, and stealing data. Researchers at cybersecurity firm ReliaQuest discovered the web shell after analyzing the recent data-theft campaign that abused the critical remote code execution vulnerability, CVE-2026-12569, affecting PTC Windchill. 

According to the researchers, the attackers did not use a traditional web shell to gain persistent access to the targeted servers. Instead, they used a custom component that demonstrated an in-depth understanding of the target application’s internal API, database schema, keystore, and file-vault structure. ReliaQuest notes that the discovered resource is an application-specific variation of the Clop ransomware group’s known mass exploitation framework. The web shell was linked to the Clop ransomware group because of extortion e-mails sent by the threat actors using the e-mail addresses associated with the data-leakage web site operated by Clop. 

In addition, the researchers identified X-windchill-req headers used by the web shell, which were also used by the Clop ransomware group in the past, as well as similar tactics, techniques, and procedures (TTPs). Earlier this year, Clop ransomware group’s infrastructure was found to target enterprise business software solutions such as Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. This campaign, which affected the MOVEit Transfer application, compromised more than 2,770 organizations worldwide. 

The web shell is implemented as JavaServer Pages (JSP), which directly imports the PTC Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, giving the threat actors’ access to PTC Windchill’s native functions, including the database, encrypted credentials decryption, and locating files stored in the application’s vaults. The web shell’s command execution capability was established using the custom protocol that utilizes the HTTP X-windchill-req header. 

Overall, the custom component allowed the attackers to achieve multiple malicious objectives, including Windchill secrets and configuration data theft, file vault discovery and enumeration, directory listing, file retrieval and deletion, executing additional Java classes, and identifying the server’s operating system. Besides that, ReliaQuest reports that the web shell’s implementation contains the Windchill vault enumeration code that queries multiple Windchill database tables, namely ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem. 

The PTC released a set of security updates to address CVE-2026-12569 on June 17. Additionally, the vulnerability was included in the CISA’s Known Exploited Vulnerabilities catalog earlier this week after the PTC reported active exploitation attempts in the wild. Ransom-ISAC confirmed that ransomware group Clop was behind the attacks by sending extortion emails to the employees of the targeted organizations. ReliaQuest recommends that all the JSP files found in the PTC Windchill directories should be investigated for any suspicious content and that the researchers should look for the X-windchill-req string. 

Moreover, the organizations that determined that their Windchill servers were compromised by the ransomware group should change the LDAP manager’s password and other user credentials because they are considered insecure and may have been leaked.

Tanaka Emerges as Leading Data Leak Broker as Stolen Information Fuels Cybercrime

 

Ransomware attacks are undoubtedly one of the most notorious security threats today. Yet it seems that information itself has become a very popular target among cybercriminals. Particularly, the threat actor called Tanaka has appeared to be the most successful data dealer during the first half of 2026, according to the research conducted by Cyble. Overall, 367 confirmed cases of corporate data leaks or breaches happened worldwide during the first half of 2026, the experts from Cyble have found. 

While the activity of Tanaka appeared to be less prominent than that of many well-known ransomware groups, he has been the most active data dealer according to Cyble research. His activity has resulted in 25 leak posts, which is more than double than the number of posts of other famous data-leak organizations. The threat actor has been targeting organizations in various fields, pursuing different goals. While the Banking, Financial Services and Insurance sector remained the most attractive for criminals with 38 data breach incidents recorded, governments and technology companies have also been frequently targeted by Tanaka. 

It implies that data theft is no more limited by regional or economic factors and can happen to organizations of any size or any industry. In particular, Tanaka has been very active in North America, where 7 leak posts related to the criminal have been discovered this year. Meanwhile, Europe and the UK have witnessed 6 leak posts related to Tanaka, as well. In these regions, financial services, telecom, and retail companies have experienced the most significant challenges, as customer and financial data of these organizations are highly attractive to data prospectors. 

In general, data prospecting has become a significant threat to organizations worldwide, as there are now more opportunities to benefit from the data belonging to other organizations. It is a part of the ransomware attack chain, as ransomware criminals can use the data belonging to the victim as leverage to demand more significant ransoms. However, data extortion is not the only way to monetize data theft, as leaked databases can be further sold on dark web forums and marketplaces. 

In addition, the stolen data can be used for extortion, reconnaissance, and other nefarious purposes. It is necessary for companies to realize that the detection of one’s data being sold or showcased on underground forums should be treated as a serious security incident. It can be a sign of the potential ransomware attack, which should be responded to accordingly. Monitoring the dark web for signs of reconnaissance activities is one of the essential aspects of cybersecurity, which is why professionals may want to consider detecting their organization’s potential exposure to ransomware attackers.

ICE Can Now Buy Your Credit Card Information

Every time you apply for a credit card or update your account details, you may be sharing your data with ICE.

A research by 404 Media said that personal information stored by credit card firms can sail through a network of data brokers and can become accessible to US Immigration and Customs Enforcement (ICE). ICE can then search and investigate your personal data without any warrant. 

“No one signing up for a credit card thinks they’re giving data brokers a thumbs-up to sell their personal information to ICE. Not only is it an outrageous violation of our privacy, [but] it’s impossible for Americans to opt out,” Senator Ron Wyden said to 404 Media in a statement. 

What private information is compromised?

According to 404 media, when someone opens a credit card or updates their personal data, credit card firms share that data with credit bureaus. 

The personal information consists of Social Security numbers, addresses and email addresses, names, and phone numbers. Contrary to credit reports, this data does not have robust legal security. 

Personal information is then sent to credit bureaus, who give the data to Thompson Reuters. From there, the data is incorporated into CLEAR, the firm’s investigative data product. Thomson Reuters sells access to CLEAR to law enforcement authorities, including ICE.

After gaining access to CLEAR, ICE can search through personal information without a warrant. "404 Media has mapped out this supply of data by reviewing U.S. government procurement records and internal documents from companies providing the information." The platform is also combined with a tool that suggests ICE to decide which neighbourhoods to raid. 

"Anytime we update our home addresses on these accounts, credit bureaus get the updates within 24 hours and share it broadly with other data brokers, thanks to legal loopholes that leave our personal information open to misuse and abuse," Just Futures attorney Laura Rivera said to 404 Media.

Thomson Reuters providing personal data to US government

Another report enquired Thompson Reuter’s increasing role in providing personal data to the US Government.

The Department of Homeland Security (DHS) is planning to pay Thomson Reuters $125 million to give access to its databases as part of enquiries into suspected immigration fraud and voter fraud. The agreement will be worth $25 million annually for five years respectively.

GrapheneOS Duress Feature Puts Digital Privacy and Evidence Laws to the Test

 

A federal case concerning a local Atlanta activist is fueling controversy over privacy issues relating to cell phone searches and whether simply wiping data from a device qualifies as destroying evidence. The case involves GrapheneOS, an open-source privacy-focused customized Android OS that utilizes the so-called duress PIN/password to permanently delete data from a phone if the correct code is entered by investigators. 

GrapheneOS developers describe their creation’s features on the project’s website, noting that it includes a “duress PIN/password” that causes the phone to immediately wipe all user data and any eSIMs from the device when the “wrong” passcode is entered at the time of credential prompt. According to court records, and reports by the press, in January 2025, Samuel Tunick, an Atlanta-based activist, was taken into custody by the US Customs and Border Protection (CBP) agents at the airport in Atlanta upon his return from the Dominican Republic. 

It seems Tunick was questioned by the customs officials several times and eventually gave them a password to his phone. His phone was wiped immediately after he entered the code. Samuel now faces charges brought by federal prosecutors who alleged that he “conspired to destroy property of the United States.” The defense is arguing that the search was not lawful; the activist was not informed of his constitutional rights and was not allowed to contact a lawyer. 

Additionally, Samuel’s attorney points out that Tunick was accused of possessing child sexual abuse material, and the only reason why he was searched was because of his activism surrounding the Stop Cop City movement. It is worth noting that privacy and security specialists have raised concerns regarding the matter and regard it as an important precedent. The GrapheneOS Foundation, an entity that maintains the software, has stated that it believed that its customized Android OS features “security capabilities that are appropriate and legitimate.” 

Some experts suggest that even if Tunick did wipe his phone, there is no way investigators could prove that he did not do so because of his decision to employ GrapheneOS. The case creates grounds for debate about the potential for cell phone software to create challenges for law enforcement. In particular, the case’s outcome will set a legal precedent about whether a device owner’s intentional interference with a search (by wiping data) constitutes evidence tampering. 

GrapheneOS itself is a valid privacy-centric OS, but the case concerning the Atlanta activist will shape the jurisprudence surrounding the wiping of cell phone data by users and the extent to which such action may be regarded as obstructing law enforcement.

Canadian Hacker Pleads Guilty for Stealing Data and Extortion


A Canadian man recently pleaded guilty in a U.S. federal court in planning one of the largest data theft campaigns in recent times, to his involvement in retrieving organization accounts at cloud storage provider company Snowflake. He stole data from 165 companies in an attempt to extort millions of dollars from the targets. 

Connor Riley Moucka is 26-yr old, and also worked under aliases Waifu and Alexander Moucka, was arrested on October 30, 2024, for stealing information from millions of people from organizations that used Snowlake’s storage features. Moucka admitted to four charges: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count, out of an original 11-count indictment.

How did the attacks happen?

Between February and October 2024, Moucka and his partner John Erin Binns, also arrested for these attacks, accessed Snowflake accounts. Rather than exploiting a flaw in Snowflake's platform itself, the pair relied on credentials harvested through infostealer malware to log into customer accounts. They stole accounts that were not secured by multi-factor authentication (MFA) via login credentials through an infostealer malware.

Without MFA protection, the hackers only needed the right usernames and passwords to sign into customer accounts. After gaining access, the hackers only needed custom-built software to sail through cloud storage incidents for important information.

The illegal access was used for identifying important information such as user roles, IP addresses, and organization name in cloud storage incidents that used Snowflake services.

The accused tried to blackmail various firms after stealing TBs of data from their Snowflake user accounts and got around $2.5 million in bitcoin from three targets.

Scale of the campaign

According to the prosecutors, the campaign exploited data linked to over 100 million individuals and resulted in $9.5 million losses for organizations. The list of impacted companies include: Ticketmaster, Santander, AT&T, Advance Auto Parts, Los Angeles Unified School District, Pure Storage, QuoteWizard/LendingTree, and Neiman Marcus.

Moucka allegedly stole around $495,000 from ransom payments. AT&T paid around $370,000 to avoid future leaks of text records and customer calls. 

“In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data,” the US Department of Justice said in a press release. 

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.” 

Greatness PhaaS Uses Phishing Code to Escape 2FA and Attacks Microsoft 365 Users


The commercial phishing-as-a-service (PhaaS) toolkit called Greatness, distributed via Telegram that uses token theft with device code and adversary-in-the-middle (AiTM) credential phishing in single operator products, has become a latest crimeware tool for the threat actors. 

About the campaign

Experts found a live campaign that abused spoofed customer-side safe sender exclusions and RingCentral emails to escape email gateway checks and send phishing traps attacking Microsoft 365 accounts. 

"Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure," ZeroBec, who discovered the campaign, said in a report. 

"The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace. This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems."

The phishing platform was first found by Cisco Talos in May 2023, showing how hackers are including it in their campaigns to attack Microsoft 365 business users since May 2022.

About the subscription

Built to ease cybercrime, access to Greatness is given through a subscription available on Telegram channel called @GreatnessPage having over 3,250 subscribers and works as a central hub for feature updates and announcements. Hackers can get a subscription at $289 per month, rising from $120 per month from January 2024. The subscription offers access to an operator that consists of a dashboard with CAPTCHA selection, domain configuration, campaign statistics, and more than 11 downloadable trap templates including QR codes, voicemail, and document sharing. 

How is Telegram used?

The operators of Telegram channel in November 2025 said that Greatness keeps stolen cookies secure through one-way hash protection and the information can be taken out only by the customers via their Telegram account two factor authentication code.

Threat actors that buy a subscription by giving their bot API token and Telegram chat ID can use the panel via an “O365 Panel” login page that needs a 9-character license key and a user ID. Once registered, customers are shown a dashboard and an operator-particular domain.

The dashboard is a standard place that provides campaign statistics such as heat map of victims and captured cookies. "Observed templates include: AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer, and additional variants. "Each template contains pre-built HTML, PDF redirectors, SVGs, and letter templates, lowering the barrier to entry so operators do not need to build lures from scratch."