Topic: sensitive data

  • Can Your Vibrator Be Hacked?

    Can Your Vibrator Be Hacked?

    App-connected smart devices, including intimate items like sex toys, collect sensitive usage data and location information through their companion apps, raising significant privacy concerns. Manufacturers may sell this collected customer data to third-party brokers, who can combine it with other ...

    Read More »
  • Secure Your Copilot: Sentra's Zero-Trust Data Protection

    Secure Your Copilot: Sentra's Zero-Trust Data Protection

    Sentra has introduced a specialized security solution to protect sensitive enterprise data within Microsoft 365 Copilot environments, ensuring compliance and safeguarding confidential information. The platform offers capabilities such as discovery and classification of sensitive data, data access...

    Read More »
  • French Teen Detained for Massive Government Data Breach

    French Teen Detained for Massive Government Data Breach

    A 15-year-old suspect has been arrested in France for allegedly orchestrating a massive data breach at France Titres, the government agency managing passports and ID cards. Between 12 and 18 million data records, including ID numbers, names, emails, and dates of birth, were put up for sale on cyb...

    Read More »
  • ChatGPT's Lockdown Mode blocks data theft and more

    ChatGPT's Lockdown Mode blocks data theft and more

    OpenAI's Lockdown Mode, now available to all ChatGPT users, protects against prompt injection attacks by limiting outbound network requests to prevent data theft. The feature disables live web browsing, deep research, agent mode, and file downloads, restricting ChatGPT to cached content and user-...

    Read More »
  • Brave Exposes Critical AI Browser Security Flaws

    Brave Exposes Critical AI Browser Security Flaws

    Brave uncovered critical security flaws in AI browsers like Perplexity Comet and Fellou, where malicious websites can hijack AI assistants to access sensitive user accounts and data through indirect prompt injection attacks. These vulnerabilities allow attackers to embed hidden commands in webpag...

    Read More »
  • Google's VaultGemma: Secure, Private AI for Sensitive Data

    Google's VaultGemma: Secure, Private AI for Sensitive Data

    Google has launched VaultGemma, a new large language model that uses differential privacy to protect sensitive information during training, making it suitable for industries like healthcare and finance. The model is open-sourced for researchers and developers to experiment with privacy-preserving...

    Read More »
  • India's Income Tax Portal Security Flaw Exposed Taxpayer Data

    India's Income Tax Portal Security Flaw Exposed Taxpayer Data

    A security flaw on India's official income tax e-Filing portal allowed logged-in users to access other taxpayers' confidential data, including bank details and government ID numbers, by manipulating web requests. The vulnerability, identified as an insecure direct object reference (IDOR), was rep...

    Read More »
  • Concentric AI Launches Private Scan Manager for AWS GovCloud

    Concentric AI Launches Private Scan Manager for AWS GovCloud

    Concentric AI has expanded its platform to support **AWS GovCloud (US)**, enabling U.S. government agencies and contractors to deploy its AI-driven data security within isolated cloud environments to meet stringent federal compliance standards. The new Private Scan Manager allows these organizati...

    Read More »
  • Google Admits Fake Law Enforcement Account in Portal

    Google Admits Fake Law Enforcement Account in Portal

    Google confirmed that cybercriminals created a fake law enforcement account in its Law Enforcement Request System but deactivated it before any data was accessed or requests processed. The breach was claimed by a hacking group linked to known cybercrime organizations, which used social engineerin...

    Read More »
  • PhantomRaven NPM Attack Steals Dev Data in 88 Packages

    PhantomRaven NPM Attack Steals Dev Data in 88 Packages

    The PhantomRaven campaign targets the npm registry using malicious packages that employ tactics like 'slopsquatting' and Remote Dynamic Dependencies to evade detection and steal developer data. Once installed, the malware harvests sensitive information, including developer credentials, CI/CD plat...

    Read More »
  • Adobe Analytics Bug Exposed Customer Data to Other Users

    Adobe Analytics Bug Exposed Customer Data to Other Users

    A software bug during a system upgrade on September 17, 2025, caused Adobe Analytics to inadvertently share customer data across different organizational accounts, affecting 3-5% of collected data. The incident impacted multiple Adobe services, including Data Collection and Customer Journey Analy...

    Read More »
  • Veeam Agent Commander: Unified AI Risk Detection & Recovery

    Veeam Agent Commander: Unified AI Risk Detection & Recovery

    Veeam has launched **Agent Commander**, a unified platform to proactively detect AI threats, protect systems, and precisely reverse AI-driven mistakes, enabling secure enterprise AI scaling. The platform merges data resilience and security by integrating Veeam's expertise with Securiti AI, offeri...

    Read More »
  • OpenAI Models to Power US Military Operations

    OpenAI Models to Power US Military Operations

    OpenAI's release of open-weight models has attracted US military and defense contractors, enabling secure, offline AI deployment in sensitive environments without cloud reliance. These models allow for deep customization using their weights, supporting mission-specific tasks like translation and ...

    Read More »
  • Rapid7 Boosts Exposure Command with Runtime Validation & DSPM

    Rapid7 Boosts Exposure Command with Runtime Validation & DSPM

    Rapid7 has enhanced its Exposure Command platform with new cloud security features, integrating "runtime validation" and "Data Security Posture Management (DSPM)" to help organizations identify and prioritize exploitable risks based on actual attack paths and business impact. The platform shi...

    Read More »
  • Major Indian Pharmacy Chain Exposes Customer Data and Systems

    Major Indian Pharmacy Chain Exposes Customer Data and Systems

    A major security flaw at DavaIndia Pharmacy allowed unauthorized creation of "super admin" accounts, compromising sensitive customer data like health purchases and delivery details. The vulnerability also enabled manipulation of critical systems, including altering prescription requirements for m...

    Read More »
  • Secure Agentic Workflows with Skyflow's Runtime AI Data Protection

    Secure Agentic Workflows with Skyflow's Runtime AI Data Protection

    Moving from AI demos to production-ready agentic applications is hindered by the challenge of securely granting autonomous agents access to sensitive data without creating security or compliance risks. Skyflow's new Runtime AI Data Security platform integrates with AWS's agentic AI services to pr...

    Read More »
  • Rubrik Launches Security Cloud Sovereign for Data Compliance

    Rubrik Launches Security Cloud Sovereign for Data Compliance

    Rubrik has launched a new solution, Security Cloud Sovereign, to help global organizations meet strict data compliance and security challenges, particularly around data residency and access control. The platform gives customers definitive control over where their data is stored and who can access...

    Read More »
  • U.S. State Privacy Laws: Your Essential Guide

    U.S. State Privacy Laws: Your Essential Guide

    The U.S. lacks a unified federal privacy law, creating a complex patchwork of state regulations that businesses must navigate, with common consumer rights but differing scopes and obligations. Key state privacy laws, such as those in California, Virginia, and Colorado, set specific thresholds for...

    Read More »
  • AI Security Map: How Vulnerabilities Cause Real-World Harm

    AI Security Map: How Vulnerabilities Cause Real-World Harm

    A single prompt injection vulnerability in an AI chatbot can rapidly expose sensitive data, erode user trust, and trigger regulatory scrutiny, demonstrating how technical flaws can quickly escalate into broader operational and societal consequences. The AI Security Map introduces two interconnect...

    Read More »
  • Shadow AI Leaks: The Hidden Risk of Personal LLM Accounts

    Shadow AI Leaks: The Hidden Risk of Personal LLM Accounts

    The unmonitored use of personal AI accounts for work, known as Shadow AI, strips organizations of visibility and control over nearly half of all workplace generative AI activity. This lack of governance leads to heightened data security risks, including a surge in policy violations and the potent...

    Read More »