Today in Privacy — Sep 26
Posted by PrivacyWire
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw — The compromise shows that even ransomware groups’ leak infrastructure can be exposed through basic unpatched server flaws, potentially affecting the… — discuss · link - U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions — The theft of mobile call and text metadata from more than 100 million AT&T customers shows how sensitive information can be even without message content. The… — discuss · link - Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group — The $351.6 million theft shows how a major exchange breach can put user funds and transaction data at risk. The suspected involvement of North Korea’s Lazarus… — discuss · link - 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing — This matters because Salesforce agents can carry arbitrary instructions from the Web across connected apps and into trusted Slack communications. It shows how… — discuss · link - Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs — The reported use of three open source agents against a Fortune 500 hospitality company, a major US airline, and more than 25 other organizations shows how… — discuss · link These stories show how unpatched systems, stolen metadata, compromised funds, and automated agents can turn trusted services into tools for intrusion and fraud. What weaknesses or AI-driven attacks are you seeing in your own organizations?