Advertisement
Cryptographic Context Injection Exposes Grok Chat Data
Adversa AI reveals Cryptographic Context Injection, allowing web pages to steal Grok user data and chat prompts without user consent.
CVE-2026-24301: CoSnitch Exploits Microsoft Copilot Personal
Varonis disclosed CoSnitch (CVE-2026-24301), affecting Microsoft Copilot Personal, enabling one-click data exfiltration and persistent memory poisoning.
Beacon CRM Data Breach Exposes Over 1,000 Charity Databases
Beacon CRM data breach exposed personal details of supporters across 1,000+ charities due to a compromised AWS access key.
Webmail CSS Injection: Hidden Data Exfiltration Threats
Security researchers warn that Cascading Style Sheets can exfiltrate sensitive data from webmail inboxes if vendors fail to sanitize styles.
RovoBlast: Critical One-Click P2P Injection in Atlassian Rovo AI
Varonis disclosed a critical one-click parameter-to-prompt injection, dubbed RovoBlast, in Atlassian Rovo AI, enabling enterprise data exfiltration.
Atlassian Rovo Indirect Prompt Injection Exfiltrates Jira Data
Atlassian Rovo is vulnerable to indirect prompt injection and URL parameter manipulation, leaking Jira and Confluence data to external servers.
Advertisement
Levi Strauss & Co. Corporate Data Stolen via Social Engineering
Levi Strauss & Co. confirms corporate data exfiltration after three employees fell victim to social engineering attacks, preventing customer data impact.
AI Security Strategy: Managing the Network as a Control Plane
Analyze the transition of network firewalls into the primary control plane for securing AI workloads and preventing data exfiltration in enterprise environments.
ShinyHunters Targeting Healthcare: Data Theft Surges, Health-ISAC Warns
Health-ISAC warns of increasing ShinyHunters data theft attacks on healthcare and med-tech organizations. Learn about TTPs and critical mitigations.
ShinyHunters Claims Ernst & Young Hack: Analysis of Third-Party Risks
Ernst & Young faces data theft claims from ShinyHunters following a breach of a third-party platform. Learn about the impact and vendor security mitigation.
Coca-Cola Subsidiary Fairlife Impacted by Ransomware Data Theft
The Coca-Cola Company confirms a data breach at subsidiary Fairlife following a ransomware attack. Learn about the impact and mitigation strategies.
MCBS Data Breach: PEAR Ransomware Group Impacts 1.2 Million Patients
Medical Business Management Services (MCBS) confirms a massive data breach affecting 1.2 million people after a 3 TB data theft by the PEAR ransomware group.
OnTrac Data Breach: Corporate Network Hack Compromises Customer Info
OnTrac discloses a corporate network breach impacting customer personal data. Learn about the incident timeline and how to mitigate logistics sector risks.
Anubis Ransomware Targets Fairlife, Threatens Data Leak
The Anubis ransomware gang claims responsibility for a cyberattack on Coca-Cola's Fairlife, threatening a data leak. Learn about their TTPs and mitigation.
HollowGraph Malware Uses Microsoft Graph for Stealthy C2
HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.
OkoBot Framework: Multi-Payload Data & Crypto Theft Attacks
The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.
Spirals Ransomware: Rapid Network Encryption in Under 24 Hours
Analysis of Spirals ransomware, a high-velocity threat actor capable of completing corporate intrusions and data encryption in less than one day.
xAI Grok Build Repository Upload Risks: Analyzing CLI Data Exposure
xAI's Grok Build CLI version 0.2.93 discovered uploading entire Git repositories, including history and secrets, to remote storage without user consent.
Lidl Data Breach: Service Provider Hack Exposes Customer Info
Lidl notifies customers in Germany, Belgium, and Netherlands after a third-party service provider breach exposed personal data and order histories.
Healthcare Service Provider Cyberattacks Surge — Supply Chain Risk
Cyberattacks on healthcare service providers more than doubled in H1 2026, signaling a shift in targeting toward the medical supply chain and data aggregators.
Progress ShareFile Storage Zone Controller Security Threat - Shut Down Now
Progress Software urges customers to shut down ShareFile Storage Zone Controllers immediately following reports of a credible external security threat.
Dialogflow CX 'Rogue Agent' Bug Enabled AI Conversation Hijacking
A 'Rogue Agent' vulnerability in Google Dialogflow CX could have allowed attackers to silently manipulate AI conversations, exfiltrate data, and compromise multiple…
CitrixBleed: NetScaler Memory Disclosure Exploited Post-Disclosure
CitrixBleed, a new vulnerability in NetScaler appliances, is being actively exploited using public PoC code to retrieve arbitrary memory content. Patch immediately.