<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Data Theft</title><description>Cybersecurity articles tagged #Data Theft on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>UAT-10147: Agentic AI Enhances Post-Compromise Operations</title><link>https://runtimerebel.com/blog/uat-10147-agentic-ai-enhances-post-compromise-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-10147-agentic-ai-enhances-post-compromise-operations</guid><description>Chinese-speaking adversary UAT-10147 leverages agentic AI for scaled exploitation, reconnaissance, and persistence on Windows and Linux web servers.</description><pubDate>Thu, 20 Aug 2026 16:28:14 GMT</pubDate><category>Agentic AI</category><category>Quasar RAT</category><category>Data Theft</category><category>UAT 10147</category><category>Metasploit</category></item><item><title>CVE-2026-12569: Clop Exploits Windchill with Custom Web Shell</title><link>https://runtimerebel.com/blog/cve-2026-12569-clop-exploits-windchill-with-custom-web-shell</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-12569-clop-exploits-windchill-with-custom-web-shell</guid><description>Clop ransomware group exploited CVE-2026-12569 in PTC Windchill and FlexPLM servers, deploying a custom web shell for deep data theft. Patch immediately.</description><pubDate>Wed, 19 Aug 2026 00:40:12 GMT</pubDate><category>Clop</category><category>PTC Windchill</category><category>CVE-2026-12569</category><category>Webshell</category><category>Data Theft</category></item><item><title>Clop Ransomware Exploits CVE-2026-12569 in PTC Products</title><link>https://runtimerebel.com/blog/clop-ransomware-exploits-cve-2026-12569-in-ptc-products</link><guid isPermaLink="true">https://runtimerebel.com/blog/clop-ransomware-exploits-cve-2026-12569-in-ptc-products</guid><description>Shell investigates potential data theft by Clop gang after exploitation of critical CVE-2026-12569 in PTC Windchill and FlexPLM instances.</description><pubDate>Sun, 16 Aug 2026 08:18:07 GMT</pubDate><category>Ransomware</category><category>Data Theft</category><category>PTC Windchill</category><category>Clop</category><category>CVE-2026-12569</category></item><item><title>UNC6671 Targets Financial Sector via Vishing and AiTM Phishing</title><link>https://runtimerebel.com/blog/unc6671-targets-financial-sector-via-vishing-and-aitm-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6671-targets-financial-sector-via-vishing-and-aitm-phishing</guid><description>UNC6671, linked to BlackFile, exploits vishing and AiTM phishing against financial firms for cloud data theft and extortion.</description><pubDate>Sun, 09 Aug 2026 16:23:40 GMT</pubDate><category>Vishing</category><category>Financial Sector</category><category>Data Theft</category><category>UNC6671</category><category>BlackFile</category></item><item><title>ShinyHunters Targeting Healthcare: Data Theft Surges, Health-ISAC Warns</title><link>https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-targeting-healthcare-data-theft-surges-health-isac-warns</guid><description>Health-ISAC warns of increasing ShinyHunters data theft attacks on healthcare and med-tech organizations. Learn about TTPs and critical mitigations.</description><pubDate>Wed, 29 Jul 2026 20:57:58 GMT</pubDate><category>ShinyHunters</category><category>Healthcare</category><category>Data Theft</category><category>Health ISAC</category><category>Phishing</category><category>Data Exfiltration</category></item><item><title>Mount Royal University Data Breach: Network Intrusion, Data Theft, and Deletion</title><link>https://runtimerebel.com/blog/mount-royal-university-data-breach-network-intrusion-data-theft-and-deletion</link><guid isPermaLink="true">https://runtimerebel.com/blog/mount-royal-university-data-breach-network-intrusion-data-theft-and-deletion</guid><description>Mount Royal University confirms a significant data breach involving network intrusion, data theft, and subsequent deletion of files from storage systems.</description><pubDate>Thu, 09 Jul 2026 03:27:03 GMT</pubDate><category>Mount Royal University</category><category>Data Breach</category><category>Network Intrusion</category><category>Data Theft</category><category>Higher Education</category></item><item><title>Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software</title><link>https://runtimerebel.com/blog/vidar-infostealer-malvertising-campaign-smbs-targeted-by-fake-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/vidar-infostealer-malvertising-campaign-smbs-targeted-by-fake-software</guid><description>A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…</description><pubDate>Wed, 08 Jul 2026 17:40:40 GMT</pubDate><category>Vidar Infostealer</category><category>Malvertising</category><category>SMBs</category><category>Cryptomining</category><category>Data Theft</category><category>Pirated Software</category></item><item><title>Kairos Group Extorts $1M from US Government in Data-Theft Campaign</title><link>https://runtimerebel.com/blog/kairos-group-extorts-1m-from-us-government-in-data-theft-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/kairos-group-extorts-1m-from-us-government-in-data-theft-campaign</guid><description>A US government entity paid $1M to the Kairos group to prevent a data leak, signaling a shift from traditional ransomware to pure data-theft extortion.</description><pubDate>Sat, 04 Jul 2026 17:08:22 GMT</pubDate><category>Kairos</category><category>Data Theft</category><category>Extortion</category><category>US Government</category><category>Ransom ISAC</category></item><item><title>FBI Warns: Russian APTs Target Signal Backup Keys via Phishing</title><link>https://runtimerebel.com/blog/fbi-warns-russian-apts-target-signal-backup-keys-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warns-russian-apts-target-signal-backup-keys-via-phishing</guid><description>FBI and CISA warn of Russian intelligence targeting Signal users. Attackers phish for backup recovery keys, enabling full account takeover and message history access.</description><pubDate>Fri, 26 Jun 2026 20:38:49 GMT</pubDate><category>Russian Intelligence</category><category>Signal</category><category>Phishing</category><category>Account Takeover</category><category>Data Theft</category></item><item><title>CryptoBandits Malware: Tor-Abusing Backdoor &amp; Data Theft</title><link>https://runtimerebel.com/blog/cryptobandits-malware-tor-abusing-backdoor-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/cryptobandits-malware-tor-abusing-backdoor-data-theft</guid><description>CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.</description><pubDate>Fri, 19 Jun 2026 16:55:32 GMT</pubDate><category>CryptoBandits</category><category>Backdoor</category><category>Tor</category><category>SOCKS5 Proxy</category><category>Data Theft</category><category>Remote Code Execution</category></item><item><title>Microsoft Copilot &apos;SearchLeak&apos; Attack: AI Prompt Injection Data Theft</title><link>https://runtimerebel.com/blog/microsoft-copilot-searchleak-attack-ai-prompt-injection-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-copilot-searchleak-attack-ai-prompt-injection-data-theft</guid><description>Analysis of the critical Microsoft Copilot &apos;SearchLeak&apos; attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.</description><pubDate>Tue, 16 Jun 2026 13:59:42 GMT</pubDate><category>Microsoft Copilot</category><category>AI Security</category><category>Prompt Injection</category><category>SearchLeak</category><category>Data Theft</category><category>LLM Security</category></item><item><title>ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed</title><link>https://runtimerebel.com/blog/shinyhunters-exploits-oracle-erp-zero-day-to-breach-higher-ed</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-exploits-oracle-erp-zero-day-to-breach-higher-ed</guid><description>ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.</description><pubDate>Sat, 13 Jun 2026 05:36:54 GMT</pubDate><category>ShinyHunters</category><category>Oracle ERP</category><category>Zero-Day</category><category>Higher Education</category><category>Data Theft</category></item><item><title>UNC3753 Targets US Law Firms with Vishing &amp; Physical Intrusions</title><link>https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</guid><description>UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.</description><pubDate>Fri, 05 Jun 2026 16:59:08 GMT</pubDate><category>UNC3753</category><category>Luna Moth</category><category>Silent Ransom Group</category><category>Vishing</category><category>Social Engineering</category><category>Data Theft</category><category>Extortion</category><category>Law Firms</category><category>Physical Intrusion</category><category>RMM</category><category>WinSCP</category><category>Rclone</category></item><item><title>China&apos;s Dual-Method Cyberattack Targets Czech, Taiwan Orgs with Azureveil</title><link>https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</guid><description>Nation-state actors linked to China employ dual-method spear-phishing with Azureveil malware to target Czech and Taiwan organizations for data theft.</description><pubDate>Tue, 02 Jun 2026 21:12:29 GMT</pubDate><category>China</category><category>Azureveil</category><category>Spear Phishing</category><category>Data Theft</category><category>Czech Republic</category><category>Taiwan</category><category>Nation State</category></item><item><title>Radiology Associates of Richmond Breach Affects 266,000 Patients</title><link>https://runtimerebel.com/blog/radiology-associates-of-richmond-breach-affects-266000-patients</link><guid isPermaLink="true">https://runtimerebel.com/blog/radiology-associates-of-richmond-breach-affects-266000-patients</guid><description>A data breach at Radiology Associates of Richmond has exposed the sensitive health and personal information of over 266,000 individuals.</description><pubDate>Mon, 25 May 2026 13:19:30 GMT</pubDate><category>Radiology Associates of Richmond</category><category>PHI</category><category>Healthcare</category><category>Data Theft</category></item><item><title>Ukraine Identifies Odesa-Based Infostealer Operator</title><link>https://runtimerebel.com/blog/ukraine-identifies-odesa-based-infostealer-operator</link><guid isPermaLink="true">https://runtimerebel.com/blog/ukraine-identifies-odesa-based-infostealer-operator</guid><description>Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.</description><pubDate>Thu, 21 May 2026 00:58:31 GMT</pubDate><category>Infostealer</category><category>Ukraine Cyberpolice</category><category>Data Theft</category><category>Credential Stuffing</category><category>Odesa</category></item><item><title>MacSync Stealer Distributed via Malicious Homebrew Ad Campaign</title><link>https://runtimerebel.com/blog/macsync-stealer-distributed-via-malicious-homebrew-ad-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/macsync-stealer-distributed-via-malicious-homebrew-ad-campaign</guid><description>Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.</description><pubDate>Fri, 01 May 2026 20:25:24 GMT</pubDate><category>MacSync Stealer</category><category>Homebrew</category><category>macOS</category><category>Malvertising</category><category>Data Theft</category></item><item><title>OpenEMR Flaws: Database Compromise, RCE, and Patient Data Theft Risks</title><link>https://runtimerebel.com/blog/openemr-flaws-database-compromise-rce-and-patient-data-theft-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/openemr-flaws-database-compromise-rce-and-patient-data-theft-risks</guid><description>Analysis of 38 security flaws in OpenEMR, an EHR platform used by over 100,000 healthcare providers, enabling database compromise, RCE, and data theft.</description><pubDate>Wed, 29 Apr 2026 20:32:29 GMT</pubDate><category>Openemr</category><category>EHR</category><category>Healthcare Security</category><category>AI Driven Security</category><category>Data Theft</category><category>RCE</category><category>Database Compromise</category></item><item><title>Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments</title><link>https://runtimerebel.com/blog/compromised-checkmarx-kics-supply-chain-attack-on-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-checkmarx-kics-supply-chain-attack-on-developer-environments</guid><description>A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.</description><pubDate>Thu, 23 Apr 2026 16:40:50 GMT</pubDate><category>Checkmarx</category><category>KICS</category><category>Supply Chain Attack</category><category>Developer Tools</category><category>VS Code</category><category>Docker</category><category>Data Theft</category></item><item><title>Sapphire Sleet&apos;s ClickFix: North Korea Targets macOS Users</title><link>https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</guid><description>North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.</description><pubDate>Thu, 16 Apr 2026 20:22:49 GMT</pubDate><category>Sapphire Sleet</category><category>ClickFix</category><category>macOS</category><category>North Korea</category><category>Phishing</category><category>Data Theft</category><category>APT</category></item><item><title>UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware</title><link>https://runtimerebel.com/blog/uac-0247-targets-ukrainian-healthcare-via-data-theft-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0247-targets-ukrainian-healthcare-via-data-theft-malware</guid><description>UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.</description><pubDate>Thu, 16 Apr 2026 08:40:22 GMT</pubDate><category>UAC 0247</category><category>Ukraine</category><category>Healthcare Security</category><category>Information Stealer</category><category>Data Theft</category></item><item><title>Mercor Hit by LiteLLM Supply Chain Attack – Lapsus$ Claims 4TB Data Theft</title><link>https://runtimerebel.com/blog/mercor-hit-by-litellm-supply-chain-attack-lapsus-claims-4tb-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/mercor-hit-by-litellm-supply-chain-attack-lapsus-claims-4tb-data-theft</guid><description>AI recruiting firm Mercor is investigating a LiteLLM supply chain attack, with Lapsus$ claiming to have stolen 4TB of sensitive data.</description><pubDate>Thu, 02 Apr 2026 12:29:10 GMT</pubDate><category>Mercor</category><category>LiteLLM</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Data Theft</category><category>AI Security</category></item><item><title>ShinyHunters Breach: European Commission Cloud Data Theft</title><link>https://runtimerebel.com/blog/shinyhunters-breach-european-commission-cloud-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breach-european-commission-cloud-data-theft</guid><description>ShinyHunters claimed responsibility for a cyber intrusion and 350GB data theft from European Commission cloud systems. Understand the TTPs and mitigation.</description><pubDate>Mon, 30 Mar 2026 12:35:44 GMT</pubDate><category>ShinyHunters</category><category>European Commission</category><category>Data Theft</category><category>Cloud Security</category><category>Cyber Intrusion</category><category>Exfiltration</category></item><item><title>Apple Warns of Coruna and DarkSword Exploit Kits Targeting iOS</title><link>https://runtimerebel.com/blog/apple-warns-of-coruna-and-darksword-exploit-kits-targeting-ios</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-warns-of-coruna-and-darksword-exploit-kits-targeting-ios</guid><description>Apple warns of Coruna and DarkSword exploit kits targeting older iOS versions via malicious web content to steal sensitive data. Update your devices now.</description><pubDate>Fri, 20 Mar 2026 08:17:32 GMT</pubDate><category>Apple</category><category>iOS</category><category>Coruna</category><category>DarkSword</category><category>Exploit Kit</category><category>Data Theft</category></item><item><title>SnappyClient C2 Implant Targets Crypto Wallets for Data Theft</title><link>https://runtimerebel.com/blog/snappyclient-c2-implant-targets-crypto-wallets-for-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/snappyclient-c2-implant-targets-crypto-wallets-for-data-theft</guid><description>A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.</description><pubDate>Thu, 19 Mar 2026 00:37:20 GMT</pubDate><category>SnappyClient</category><category>C2</category><category>Crypto Wallets</category><category>Data Theft</category><category>Remote Access</category><category>Malware</category></item><item><title>Claudy Day: Prompt Injection and XSS Flaws Target Claude AI Users</title><link>https://runtimerebel.com/blog/claudy-day-prompt-injection-and-xss-flaws-target-claude-ai-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/claudy-day-prompt-injection-and-xss-flaws-target-claude-ai-users</guid><description>Researchers uncover &apos;Claudy Day&apos;, a trio of vulnerabilities in Anthropic&apos;s Claude AI that allow data theft through malicious Google search results.</description><pubDate>Wed, 18 Mar 2026 16:30:53 GMT</pubDate><category>Anthropic</category><category>Claude</category><category>Prompt Injection</category><category>Data Theft</category><category>LLM Security</category></item><item><title>Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges</title><link>https://runtimerebel.com/blog/ransomware-ttps-shift-from-cobalt-strike-to-native-tools-data-theft-surges</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-ttps-shift-from-cobalt-strike-to-native-tools-data-theft-surges</guid><description>Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.</description><pubDate>Wed, 18 Mar 2026 00:37:35 GMT</pubDate><category>Ransomware</category><category>TTPs</category><category>Cobalt Strike</category><category>Data Theft</category><category>Native Windows Tools</category><category>Post Exploitation</category></item><item><title>Elementor Ally Plugin SQLi: Unauthenticated Data Theft Risk</title><link>https://runtimerebel.com/blog/elementor-ally-plugin-sqli-unauthenticated-data-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/elementor-ally-plugin-sqli-unauthenticated-data-theft-risk</guid><description>An unauthenticated SQL injection vulnerability in the Elementor Ally WordPress plugin affects over 400,000 sites, risking sensitive data exposure.</description><pubDate>Wed, 11 Mar 2026 20:13:50 GMT</pubDate><category>SQL Injection</category><category>WordPress</category><category>Elementor Ally</category><category>Web Accessibility</category><category>Data Theft</category></item><item><title>Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer</title><link>https://runtimerebel.com/blog/chrome-extensions-quicklens-and-buildmelon-hijacked-via-ownership-transfer</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-extensions-quicklens-and-buildmelon-hijacked-via-ownership-transfer</guid><description>Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.</description><pubDate>Mon, 09 Mar 2026 12:18:29 GMT</pubDate><category>Chrome Extension</category><category>Browser Security</category><category>Supply Chain Attack</category><category>QuickLens</category><category>BuildMelon</category><category>Data Theft</category></item><item><title>Spanish Authorities Dismantle Anonymous Fénix Hacktivist Node</title><link>https://runtimerebel.com/blog/spanish-authorities-dismantle-anonymous-fenix-hacktivist-node</link><guid isPermaLink="true">https://runtimerebel.com/blog/spanish-authorities-dismantle-anonymous-fenix-hacktivist-node</guid><description>Spain&apos;s National Police arrested four members of Anonymous Fénix, a hacktivist group targeting government infrastructure with DDoS and data exfiltration.</description><pubDate>Tue, 24 Feb 2026 12:24:21 GMT</pubDate><category>Anonymous F U00e9nix</category><category>Spain</category><category>Hacktivism</category><category>DDoS</category><category>Law Enforcement</category><category>Data Theft</category></item></channel></rss>