<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Data Exfiltration</title><description>Cybersecurity articles tagged #Data Exfiltration on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Cryptographic Context Injection Exposes Grok Chat Data</title><link>https://runtimerebel.com/blog/cryptographic-context-injection-exposes-grok-chat-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/cryptographic-context-injection-exposes-grok-chat-data</guid><description>Adversa AI reveals Cryptographic Context Injection, allowing web pages to steal Grok user data and chat prompts without user consent.</description><pubDate>Thu, 20 Aug 2026 16:23:24 GMT</pubDate><category>Xai</category><category>Adversa AI</category><category>Prompt Injection</category><category>Data Exfiltration</category><category>Grok</category></item><item><title>CVE-2026-24301: CoSnitch Exploits Microsoft Copilot Personal</title><link>https://runtimerebel.com/blog/cve-2026-24301-cosnitch-exploits-microsoft-copilot-personal</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-24301-cosnitch-exploits-microsoft-copilot-personal</guid><description>Varonis disclosed CoSnitch (CVE-2026-24301), affecting Microsoft Copilot Personal, enabling one-click data exfiltration and persistent memory poisoning.</description><pubDate>Wed, 19 Aug 2026 00:39:19 GMT</pubDate><category>Data Exfiltration</category><category>Prompt Injection</category><category>CVE-2026-24301</category><category>Microsoft Copilot Personal</category><category>Memory Poisoning</category></item><item><title>Beacon CRM Data Breach Exposes Over 1,000 Charity Databases</title><link>https://runtimerebel.com/blog/beacon-crm-data-breach-exposes-over-1000-charity-databases</link><guid isPermaLink="true">https://runtimerebel.com/blog/beacon-crm-data-breach-exposes-over-1000-charity-databases</guid><description>Beacon CRM data breach exposed personal details of supporters across 1,000+ charities due to a compromised AWS access key.</description><pubDate>Sun, 16 Aug 2026 00:43:21 GMT</pubDate><category>Data Breach</category><category>Cloud Security</category><category>Data Exfiltration</category><category>Beacon CRM</category><category>Charities</category></item><item><title>Webmail CSS Injection: Hidden Data Exfiltration Threats</title><link>https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/webmail-css-injection-hidden-data-exfiltration-threats</guid><description>Security researchers warn that Cascading Style Sheets can exfiltrate sensitive data from webmail inboxes if vendors fail to sanitize styles.</description><pubDate>Mon, 10 Aug 2026 01:01:51 GMT</pubDate><category>Web Security</category><category>Data Exfiltration</category><category>Phishing</category><category>Vulnerabilities</category></item><item><title>RovoBlast: Critical One-Click P2P Injection in Atlassian Rovo AI</title><link>https://runtimerebel.com/blog/rovoblast-critical-one-click-p2p-injection-in-atlassian-rovo-ai</link><guid isPermaLink="true">https://runtimerebel.com/blog/rovoblast-critical-one-click-p2p-injection-in-atlassian-rovo-ai</guid><description>Varonis disclosed a critical one-click parameter-to-prompt injection, dubbed RovoBlast, in Atlassian Rovo AI, enabling enterprise data exfiltration.</description><pubDate>Sat, 08 Aug 2026 16:23:23 GMT</pubDate><category>Data Exfiltration</category><category>Enterprise Security</category><category>AI Security</category><category>Atlassian Rovo AI</category><category>RovoBlast</category></item><item><title>Atlassian Rovo Indirect Prompt Injection Exfiltrates Jira Data</title><link>https://runtimerebel.com/blog/atlassian-rovo-indirect-prompt-injection-exfiltrates-jira-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/atlassian-rovo-indirect-prompt-injection-exfiltrates-jira-data</guid><description>Atlassian Rovo is vulnerable to indirect prompt injection and URL parameter manipulation, leaking Jira and Confluence data to external servers.</description><pubDate>Sat, 08 Aug 2026 16:21:55 GMT</pubDate><category>Zero-Day</category><category>Data Exfiltration</category><category>Cloud Security</category><category>Atlassian</category><category>Jira</category></item><item><title>Levi Strauss &amp; Co. Corporate Data Stolen via Social Engineering</title><link>https://runtimerebel.com/blog/levi-strauss-co-corporate-data-stolen-via-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/levi-strauss-co-corporate-data-stolen-via-social-engineering</guid><description>Levi Strauss &amp; Co. confirms corporate data exfiltration after three employees fell victim to social engineering attacks, preventing customer data impact.</description><pubDate>Fri, 07 Aug 2026 16:42:59 GMT</pubDate><category>Levi Strauss</category><category>Social Engineering</category><category>Data Exfiltration</category><category>Corporate Data</category><category>UNC6671</category></item><item><title>AI Security Strategy: Managing the Network as a Control Plane</title><link>https://runtimerebel.com/blog/ai-security-strategy-managing-the-network-as-a-control-plane</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-security-strategy-managing-the-network-as-a-control-plane</guid><description>Analyze the transition of network firewalls into the primary control plane for securing AI workloads and preventing data exfiltration in enterprise environments.</description><pubDate>Thu, 30 Jul 2026 14:06:15 GMT</pubDate><category>AI Security</category><category>Network Firewall</category><category>LLM Security</category><category>Data Exfiltration</category><category>Zero Trust</category></item><item><title>ShinyHunters Targeting Healthcare: Data Theft Surges, Health-ISAC Warns</title><link>https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</guid><description>Health-ISAC warns of increasing ShinyHunters data theft attacks on healthcare and med-tech organizations. Learn about TTPs and critical mitigations.</description><pubDate>Wed, 29 Jul 2026 20:57:58 GMT</pubDate><category>ShinyHunters</category><category>Healthcare</category><category>Data Theft</category><category>Health ISAC</category><category>Phishing</category><category>Data Exfiltration</category></item><item><title>ShinyHunters Claims Ernst &amp; Young Hack: Analysis of Third-Party Risks</title><link>https://runtimerebel.com/blog/shinyhunters-claims-ernst-young-hack-analysis-of-third-party-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-claims-ernst-young-hack-analysis-of-third-party-risks</guid><description>Ernst &amp; Young faces data theft claims from ShinyHunters following a breach of a third-party platform. Learn about the impact and vendor security mitigation.</description><pubDate>Wed, 29 Jul 2026 06:32:39 GMT</pubDate><category>ShinyHunters</category><category>Ernst Young</category><category>Third Party Risk</category><category>Data Exfiltration</category><category>Financial Services</category></item><item><title>Coca-Cola Subsidiary Fairlife Impacted by Ransomware Data Theft</title><link>https://runtimerebel.com/blog/coca-cola-subsidiary-fairlife-impacted-by-ransomware-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/coca-cola-subsidiary-fairlife-impacted-by-ransomware-data-theft</guid><description>The Coca-Cola Company confirms a data breach at subsidiary Fairlife following a ransomware attack. Learn about the impact and mitigation strategies.</description><pubDate>Mon, 27 Jul 2026 17:43:54 GMT</pubDate><category>Fairlife</category><category>Coca Cola</category><category>Ransomware</category><category>Data Exfiltration</category><category>Third Party Risk</category></item><item><title>MCBS Data Breach: PEAR Ransomware Group Impacts 1.2 Million Patients</title><link>https://runtimerebel.com/blog/mcbs-data-breach-pear-ransomware-group-impacts-1-2-million-patients</link><guid isPermaLink="true">https://runtimerebel.com/blog/mcbs-data-breach-pear-ransomware-group-impacts-1-2-million-patients</guid><description>Medical Business Management Services (MCBS) confirms a massive data breach affecting 1.2 million people after a 3 TB data theft by the PEAR ransomware group.</description><pubDate>Mon, 27 Jul 2026 07:34:29 GMT</pubDate><category>MCBS</category><category>PEAR Ransomware</category><category>Healthcare Security</category><category>Data Exfiltration</category></item><item><title>OnTrac Data Breach: Corporate Network Hack Compromises Customer Info</title><link>https://runtimerebel.com/blog/ontrac-data-breach-corporate-network-hack-compromises-customer-info</link><guid isPermaLink="true">https://runtimerebel.com/blog/ontrac-data-breach-corporate-network-hack-compromises-customer-info</guid><description>OnTrac discloses a corporate network breach impacting customer personal data. Learn about the incident timeline and how to mitigate logistics sector risks.</description><pubDate>Fri, 24 Jul 2026 21:05:16 GMT</pubDate><category>Ontrac</category><category>Data Exfiltration</category><category>Logistics Security</category><category>Pii Breach</category></item><item><title>Anubis Ransomware Targets Fairlife, Threatens Data Leak</title><link>https://runtimerebel.com/blog/anubis-ransomware-targets-fairlife-threatens-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/anubis-ransomware-targets-fairlife-threatens-data-leak</guid><description>The Anubis ransomware gang claims responsibility for a cyberattack on Coca-Cola&apos;s Fairlife, threatening a data leak. Learn about their TTPs and mitigation.</description><pubDate>Tue, 21 Jul 2026 21:12:30 GMT</pubDate><category>Anubis Ransomware</category><category>Fairlife</category><category>Coca Cola</category><category>Data Exfiltration</category><category>Ransomware Group</category></item><item><title>HollowGraph Malware Uses Microsoft Graph for Stealthy C2</title><link>https://runtimerebel.com/blog/hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2</guid><description>HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.</description><pubDate>Mon, 20 Jul 2026 18:05:43 GMT</pubDate><category>HollowGraph</category><category>Microsoft Graph</category><category>Microsoft 365</category><category>C2</category><category>Data Exfiltration</category><category>API Abuse</category></item><item><title>HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2</title><link>https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</guid><description>HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.</description><pubDate>Mon, 20 Jul 2026 18:05:24 GMT</pubDate><category>HollowGraph</category><category>Microsoft 365</category><category>Microsoft Graph API</category><category>Espionage</category><category>C2</category><category>Data Exfiltration</category><category>Group IB</category></item><item><title>OkoBot Framework: Multi-Payload Data &amp; Crypto Theft Attacks</title><link>https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</guid><description>The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.</description><pubDate>Thu, 16 Jul 2026 21:02:27 GMT</pubDate><category>OkoBot</category><category>Malware</category><category>Infostealer</category><category>Cryptocurrency Theft</category><category>Credential Theft</category><category>Data Exfiltration</category></item><item><title>Spirals Ransomware: Rapid Network Encryption in Under 24 Hours</title><link>https://runtimerebel.com/blog/spirals-ransomware-rapid-network-encryption-in-under-24-hours</link><guid isPermaLink="true">https://runtimerebel.com/blog/spirals-ransomware-rapid-network-encryption-in-under-24-hours</guid><description>Analysis of Spirals ransomware, a high-velocity threat actor capable of completing corporate intrusions and data encryption in less than one day.</description><pubDate>Thu, 16 Jul 2026 10:12:46 GMT</pubDate><category>Spirals Ransomware</category><category>Screenconnect</category><category>Rclone</category><category>Data Exfiltration</category></item><item><title>xAI Grok Build Repository Upload Risks: Analyzing CLI Data Exposure</title><link>https://runtimerebel.com/blog/xai-grok-build-repository-upload-risks-analyzing-cli-data-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/xai-grok-build-repository-upload-risks-analyzing-cli-data-exposure</guid><description>xAI&apos;s Grok Build CLI version 0.2.93 discovered uploading entire Git repositories, including history and secrets, to remote storage without user consent.</description><pubDate>Tue, 14 Jul 2026 09:59:54 GMT</pubDate><category>Xai</category><category>Grok Build</category><category>Git Security</category><category>Data Exfiltration</category><category>AI Security</category></item><item><title>Lidl Data Breach: Service Provider Hack Exposes Customer Info</title><link>https://runtimerebel.com/blog/lidl-data-breach-service-provider-hack-exposes-customer-info</link><guid isPermaLink="true">https://runtimerebel.com/blog/lidl-data-breach-service-provider-hack-exposes-customer-info</guid><description>Lidl notifies customers in Germany, Belgium, and Netherlands after a third-party service provider breach exposed personal data and order histories.</description><pubDate>Mon, 13 Jul 2026 14:40:17 GMT</pubDate><category>Lidl Breach</category><category>Third Party Risk</category><category>Supply Chain Attack</category><category>Retail Security</category><category>Data Exfiltration</category></item><item><title>Healthcare Service Provider Cyberattacks Surge — Supply Chain Risk</title><link>https://runtimerebel.com/blog/healthcare-service-provider-cyberattacks-surge-supply-chain-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/healthcare-service-provider-cyberattacks-surge-supply-chain-risk</guid><description>Cyberattacks on healthcare service providers more than doubled in H1 2026, signaling a shift in targeting toward the medical supply chain and data aggregators.</description><pubDate>Sat, 11 Jul 2026 06:14:50 GMT</pubDate><category>Healthcare Security</category><category>Supply Chain Attack</category><category>H1 2026 Trends</category><category>Data Exfiltration</category></item><item><title>Progress ShareFile Storage Zone Controller Security Threat - Shut Down Now</title><link>https://runtimerebel.com/blog/progress-sharefile-storage-zone-controller-security-threat-shut-down-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/progress-sharefile-storage-zone-controller-security-threat-shut-down-now</guid><description>Progress Software urges customers to shut down ShareFile Storage Zone Controllers immediately following reports of a credible external security threat.</description><pubDate>Fri, 10 Jul 2026 21:06:52 GMT</pubDate><category>Progress Software</category><category>ShareFile</category><category>Storage Zone Controller</category><category>Data Exfiltration</category><category>Windows Server</category></item><item><title>Dialogflow CX &apos;Rogue Agent&apos; Bug Enabled AI Conversation Hijacking</title><link>https://runtimerebel.com/blog/dialogflow-cx-rogue-agent-bug-enabled-ai-conversation-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/dialogflow-cx-rogue-agent-bug-enabled-ai-conversation-hijacking</guid><description>A &apos;Rogue Agent&apos; vulnerability in Google Dialogflow CX could have allowed attackers to silently manipulate AI conversations, exfiltrate data, and compromise multiple…</description><pubDate>Wed, 08 Jul 2026 14:16:28 GMT</pubDate><category>Google Dialogflow CX</category><category>Rogue Agent</category><category>AI</category><category>Conversation Hijacking</category><category>Data Exfiltration</category><category>Cloud Security</category></item><item><title>CitrixBleed: NetScaler Memory Disclosure Exploited Post-Disclosure</title><link>https://runtimerebel.com/blog/citrixbleed-netscaler-memory-disclosure-exploited-post-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/citrixbleed-netscaler-memory-disclosure-exploited-post-disclosure</guid><description>CitrixBleed, a new vulnerability in NetScaler appliances, is being actively exploited using public PoC code to retrieve arbitrary memory content. Patch immediately.</description><pubDate>Fri, 03 Jul 2026 07:27:45 GMT</pubDate><category>Citrix Bleed</category><category>NetScaler</category><category>Arbitrary Memory Content</category><category>PoC Exploitation</category><category>Data Exfiltration</category></item><item><title>AI Agents Vulnerable to Data Leak via Poisoned MCP Tools</title><link>https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</guid><description>Microsoft warns that malicious tool descriptions for AI agents can lead to stealthy data exfiltration, bypassing security controls by mimicking routine actions.</description><pubDate>Wed, 01 Jul 2026 01:02:51 GMT</pubDate><category>AI Agents</category><category>Data Exfiltration</category><category>Supply Chain Attack</category><category>Microsoft</category><category>Prompt Injection</category></item><item><title>Agentic AI Identity Problem: New Attack Surface for Enterprises</title><link>https://runtimerebel.com/blog/agentic-ai-identity-problem-new-attack-surface-for-enterprises</link><guid isPermaLink="true">https://runtimerebel.com/blog/agentic-ai-identity-problem-new-attack-surface-for-enterprises</guid><description>Agentic AI systems pose novel identity and access management challenges, creating new attack vectors for data exfiltration and privilege escalation.</description><pubDate>Mon, 29 Jun 2026 17:07:07 GMT</pubDate><category>Agentic AI</category><category>AI Security</category><category>Identity Management</category><category>LLM Security</category><category>Privilege Escalation</category><category>Data Exfiltration</category><category>Zero Trust</category></item><item><title>Klue Supply Chain Attack Hits Salesforce Instances of Security Firms</title><link>https://runtimerebel.com/blog/klue-supply-chain-attack-hits-salesforce-instances-of-security-firms</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-supply-chain-attack-hits-salesforce-instances-of-security-firms</guid><description>Attackers breached competitive intelligence platform Klue, exfiltrating data from Salesforce instances of customers including Huntress and Recorded Future.</description><pubDate>Fri, 19 Jun 2026 09:44:49 GMT</pubDate><category>Klue</category><category>Salesforce</category><category>Huntress</category><category>Recorded Future</category><category>SaaS Security</category><category>Data Exfiltration</category></item><item><title>Chinese Espionage: Google Workspace Rule Abuse in Research Sectors</title><link>https://runtimerebel.com/blog/chinese-espionage-google-workspace-rule-abuse-in-research-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-espionage-google-workspace-rule-abuse-in-research-sectors</guid><description>China-linked threat actors exploited REDCap server backdoors and manipulated Google Workspace mail rules to exfiltrate North American research data.</description><pubDate>Tue, 16 Jun 2026 01:12:06 GMT</pubDate><category>REDCap</category><category>Google Workspace</category><category>Cyber Espionage</category><category>China</category><category>Data Exfiltration</category></item><item><title>China-Nexus Actor: Year-Long Espionage Against US Researchers</title><link>https://runtimerebel.com/blog/china-nexus-actor-year-long-espionage-against-us-researchers</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-nexus-actor-year-long-espionage-against-us-researchers</guid><description>A China-nexus actor spied on US researchers for a year, stealing RedCAP credentials and exfiltrating sensitive data from numerous institutions, discovered by Google.</description><pubDate>Mon, 15 Jun 2026 17:49:38 GMT</pubDate><category>China Nexus Actor</category><category>Espionage</category><category>US Researchers</category><category>RedCAP Credentials</category><category>Data Exfiltration</category><category>Nation State Threat</category></item><item><title>Microsoft 365 Copilot SearchLeak: One-Click Data Exfiltration</title><link>https://runtimerebel.com/blog/microsoft-365-copilot-searchleak-one-click-data-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-365-copilot-searchleak-one-click-data-exfiltration</guid><description>Varonis Threat Labs uncovered &apos;SearchLeak&apos;, a one-click flaw in Microsoft 365 Copilot Enterprise Search allowing exfiltration of emails, files, and MFA codes.</description><pubDate>Mon, 15 Jun 2026 17:44:57 GMT</pubDate><category>Microsoft 365 Copilot</category><category>SearchLeak</category><category>Data Exfiltration</category><category>One Click Exploit</category><category>Varonis Threat Labs</category></item><item><title>University of Nottingham Confirms Breach After ShinyHunters Data Leak</title><link>https://runtimerebel.com/blog/university-of-nottingham-confirms-breach-after-shinyhunters-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/university-of-nottingham-confirms-breach-after-shinyhunters-data-leak</guid><description>The University of Nottingham confirms a data breach after the ShinyHunters group leaked over 450,000 records, highlighting risks to academic data security.</description><pubDate>Thu, 11 Jun 2026 09:39:20 GMT</pubDate><category>ShinyHunters</category><category>University of Nottingham</category><category>Higher Education</category><category>Data Exfiltration</category><category>PII Leak</category></item><item><title>OpenAI ChatGPT Lockdown Mode: Mitigating Prompt Injection Exfiltration</title><link>https://runtimerebel.com/blog/openai-chatgpt-lockdown-mode-mitigating-prompt-injection-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-chatgpt-lockdown-mode-mitigating-prompt-injection-exfiltration</guid><description>OpenAI introduces ChatGPT Lockdown Mode for personal accounts to prevent prompt injection attacks from exfiltrating sensitive data via external tools.</description><pubDate>Sat, 06 Jun 2026 16:29:48 GMT</pubDate><category>OpenAI</category><category>ChatGPT</category><category>Prompt Injection</category><category>Data Exfiltration</category><category>AI Security</category><category>Lockdown Mode</category></item><item><title>Dashlane Brute-Force Attack: Safeguarding Encrypted Password Vaults</title><link>https://runtimerebel.com/blog/dashlane-brute-force-attack-safeguarding-encrypted-password-vaults</link><guid isPermaLink="true">https://runtimerebel.com/blog/dashlane-brute-force-attack-safeguarding-encrypted-password-vaults</guid><description>Dashlane reports a brute-force attack resulting in the download of encrypted user vaults. Learn about the impact and remediation steps for this identity threat.</description><pubDate>Tue, 02 Jun 2026 09:34:12 GMT</pubDate><category>Dashlane</category><category>Brute Force</category><category>Credential Stuffing</category><category>Password Manager</category><category>Data Exfiltration</category></item><item><title>Enterprise AI Risk Concentrated Among Power Users in 2026 Report</title><link>https://runtimerebel.com/blog/enterprise-ai-risk-concentrated-among-power-users-in-2026-report</link><guid isPermaLink="true">https://runtimerebel.com/blog/enterprise-ai-risk-concentrated-among-power-users-in-2026-report</guid><description>LayerX Security’s 2026 report reveals that enterprise AI risk is concentrated among power users, highlighting a significant visibility gap for security teams.</description><pubDate>Thu, 28 May 2026 13:24:16 GMT</pubDate><category>LayerX Security</category><category>AI Security</category><category>Data Exfiltration</category><category>Shadow AI</category><category>Insider Risk</category></item><item><title>Malicious npm Package Targets Claude AI User Data — Technical Analysis</title><link>https://runtimerebel.com/blog/malicious-npm-package-targets-claude-ai-user-data-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-package-targets-claude-ai-user-data-technical-analysis</guid><description>Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.</description><pubDate>Wed, 27 May 2026 17:12:05 GMT</pubDate><category>NPM</category><category>Claude AI</category><category>Supply Chain Attack</category><category>Data Exfiltration</category><category>Anthropic</category></item><item><title>GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft</title><link>https://runtimerebel.com/blog/github-data-breach-analysis-of-teampcp-internal-repository-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-data-breach-analysis-of-teampcp-internal-repository-theft</guid><description>GitHub confirms the theft of 4,000 internal repositories by threat actor TeamPCP. Learn the technical implications and defense strategies for security teams.</description><pubDate>Thu, 21 May 2026 09:16:24 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Source Code Theft</category><category>Internal Repositories</category><category>Data Exfiltration</category></item><item><title>BlackFile: Analyzing UNC6671 Vishing &amp; Cloud Data Extortion</title><link>https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</guid><description>Examines UNC6671&apos;s BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 &amp; Okta. Actionable mitigations included.</description><pubDate>Fri, 15 May 2026 20:32:33 GMT</pubDate><category>UNC6671</category><category>BlackFile</category><category>Vishing</category><category>AitM</category><category>Microsoft 365</category><category>Okta</category><category>SharePoint</category><category>OneDrive</category><category>Data Exfiltration</category><category>Extortion</category><category>Social Engineering</category></item><item><title>West Pharmaceutical Breach: Analysis of System Encryption</title><link>https://runtimerebel.com/blog/west-pharmaceutical-breach-analysis-of-system-encryption</link><guid isPermaLink="true">https://runtimerebel.com/blog/west-pharmaceutical-breach-analysis-of-system-encryption</guid><description>West Pharmaceutical Services confirms data exfiltration and system encryption in a major cyberattack. Learn about the impact and defense strategies.</description><pubDate>Thu, 14 May 2026 00:55:20 GMT</pubDate><category>West Pharmaceutical</category><category>Ransomware</category><category>Data Exfiltration</category><category>Pharmaceutical Sector</category><category>Manufacturing</category></item><item><title>Anatomy of E-Commerce Fraud: Detecting and Mitigating Phishing Sites</title><link>https://runtimerebel.com/blog/anatomy-of-e-commerce-fraud-detecting-and-mitigating-phishing-sites</link><guid isPermaLink="true">https://runtimerebel.com/blog/anatomy-of-e-commerce-fraud-detecting-and-mitigating-phishing-sites</guid><description>A technical analysis of fraudulent retail infrastructure, exploring domain spoofing, CDN obfuscation, and credit card exfiltration techniques.</description><pubDate>Wed, 13 May 2026 09:10:20 GMT</pubDate><category>Phishing</category><category>E Commerce Fraud</category><category>Social Engineering</category><category>Domain Spoofing</category><category>Data Exfiltration</category></item><item><title>Hugging Face Model Supply Chain Vulnerability: Tokenizer Hijacking</title><link>https://runtimerebel.com/blog/hugging-face-model-supply-chain-vulnerability-tokenizer-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-model-supply-chain-vulnerability-tokenizer-hijacking</guid><description>Attackers can weaponize Hugging Face AI models by manipulating tokenizer files, leading to model output hijacking and sensitive data exfiltration.</description><pubDate>Tue, 12 May 2026 20:40:02 GMT</pubDate><category>Hugging Face</category><category>AI Security</category><category>ML Security</category><category>Supply Chain Attack</category><category>Data Exfiltration</category><category>Tokenizer Manipulation</category></item><item><title>LLM Text-in-Text Steganography: Emerging Covert Channel Risks</title><link>https://runtimerebel.com/blog/llm-text-in-text-steganography-emerging-covert-channel-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/llm-text-in-text-steganography-emerging-covert-channel-risks</guid><description>Analysis of how Large Language Models enable sophisticated text-in-text steganography for covert communication, data exfiltration, and C2 operations.</description><pubDate>Mon, 11 May 2026 13:11:36 GMT</pubDate><category>LLM</category><category>Steganography</category><category>Data Exfiltration</category><category>AI Security</category><category>Covert Channels</category></item><item><title>Bypassing Enterprise DLP via Browser-Based Data Exfiltration</title><link>https://runtimerebel.com/blog/bypassing-enterprise-dlp-via-browser-based-data-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-enterprise-dlp-via-browser-based-data-exfiltration</guid><description>Examine how modern SaaS workflows and generative AI prompts bypass traditional DLP, creating significant visibility gaps in enterprise security posture.</description><pubDate>Thu, 07 May 2026 16:41:43 GMT</pubDate><category>DLP</category><category>Data Exfiltration</category><category>SaaS Security</category><category>GenAI Risk</category><category>Browser Security</category></item><item><title>Google Chrome ABE Bypass: Heightened Infostealer Threat</title><link>https://runtimerebel.com/blog/google-chrome-abe-bypass-heightened-infostealer-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-abe-bypass-heightened-infostealer-threat</guid><description>VoidStealer Trojan authors bypass Google Chrome&apos;s App-Bound Encryption (ABE), enabling infostealers to exfiltrate cookies and credentials from users.</description><pubDate>Thu, 07 May 2026 00:51:02 GMT</pubDate><category>Google Chrome</category><category>App Bound Encryption</category><category>ABE Bypass</category><category>VoidStealer</category><category>Infostealer</category><category>Data Exfiltration</category></item><item><title>Sandhills Medical Ransomware Breach Affects 170,000 Patients</title><link>https://runtimerebel.com/blog/sandhills-medical-ransomware-breach-affects-170000-patients</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandhills-medical-ransomware-breach-affects-170000-patients</guid><description>Sandhills Medical Foundation discloses a data breach affecting 170,000 individuals after an Inc Ransom attack involving sensitive medical and personal data.</description><pubDate>Thu, 30 Apr 2026 08:53:00 GMT</pubDate><category>Inc Ransom</category><category>Sandhills Medical Foundation</category><category>Healthcare Security</category><category>PHI</category><category>Data Exfiltration</category></item><item><title>NSA Insider Threat Lessons: Chris Inglis on Post-Snowden Security</title><link>https://runtimerebel.com/blog/nsa-insider-threat-lessons-chris-inglis-on-post-snowden-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/nsa-insider-threat-lessons-chris-inglis-on-post-snowden-security</guid><description>Former NSA Deputy Director Chris Inglis reflects on the Snowden leaks, offering critical insights for CISOs on insider threat detection and enculturation.</description><pubDate>Wed, 29 Apr 2026 08:54:19 GMT</pubDate><category>Insider Threat</category><category>NSA</category><category>Chris Inglis</category><category>Edward Snowden</category><category>Data Exfiltration</category><category>Cyber Culture</category></item><item><title>Trigona Ransomware: Custom Tool for Faster Data Exfiltration</title><link>https://runtimerebel.com/blog/trigona-ransomware-custom-tool-for-faster-data-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/trigona-ransomware-custom-tool-for-faster-data-exfiltration</guid><description>Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.</description><pubDate>Thu, 23 Apr 2026 20:26:10 GMT</pubDate><category>Trigona</category><category>Ransomware</category><category>Data Exfiltration</category><category>Custom Tool</category><category>Cybercrime</category></item><item><title>Microsoft and Salesforce Patch Prompt Injection Flaws in AI Agents</title><link>https://runtimerebel.com/blog/microsoft-and-salesforce-patch-prompt-injection-flaws-in-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-and-salesforce-patch-prompt-injection-flaws-in-ai-agents</guid><description>Researchers identified prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce that could allow attackers to exfiltrate sensitive data.</description><pubDate>Wed, 15 Apr 2026 12:32:01 GMT</pubDate><category>Microsoft Copilot</category><category>Salesforce Agentforce</category><category>Prompt Injection</category><category>Data Exfiltration</category><category>AI Security</category></item><item><title>McGraw-Hill Data Breach: Salesforce Misconfiguration Exploited</title><link>https://runtimerebel.com/blog/mcgraw-hill-data-breach-salesforce-misconfiguration-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/mcgraw-hill-data-breach-salesforce-misconfiguration-exploited</guid><description>McGraw-Hill confirms a data breach after threat actors exploited a Salesforce misconfiguration, exposing internal records and student information.</description><pubDate>Tue, 14 Apr 2026 20:25:19 GMT</pubDate><category>McGraw Hill</category><category>Salesforce</category><category>Mogilevich</category><category>Misconfiguration</category><category>Data Exfiltration</category></item><item><title>Hims Data Breach Exposes Patient PHI — Technical Impact Analysis</title><link>https://runtimerebel.com/blog/hims-data-breach-exposes-patient-phi-technical-impact-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/hims-data-breach-exposes-patient-phi-technical-impact-analysis</guid><description>Analysis of the Hims &amp; Hers Health data breach exposing sensitive PHI. Learn how threat actors use health data for targeted extortion and phishing campaigns.</description><pubDate>Sat, 11 Apr 2026 00:38:27 GMT</pubDate><category>Hims Hers Health</category><category>Phi Exposure</category><category>Telehealth Security</category><category>Data Exfiltration</category><category>Extortion</category></item><item><title>Securing Enterprise Browser Environments Against AI Extension Risks</title><link>https://runtimerebel.com/blog/securing-enterprise-browser-environments-against-ai-extension-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-enterprise-browser-environments-against-ai-extension-risks</guid><description>Discover the security blind spots of AI browser extensions and how to mitigate data exfiltration risks in corporate environments via managed policies.</description><pubDate>Fri, 10 Apr 2026 12:25:18 GMT</pubDate><category>Browser Security</category><category>AI Threats</category><category>Shadow AI</category><category>Data Exfiltration</category><category>LayerX</category></item></channel></rss>