dataexfiltration (3)

31198463869?profile=RESIZE_400xA hacker recently claimed to have exfiltrated tens of gigabytes of internal development data allegedly belonging to global professional services firm Accenture.  The incident became public when a threat actor on the PwnForums forum boasted of compromising the company and stealing 35 gigabytes of data.  According to the hacker, the stolen information includes Azure access keys, tokens, configuration files, RSA and SSH keys, and internal source code.  As proof of possession, the actor posted a scr

13733277071?profile=RESIZE_400xCybersecurity firm Tenable discovered three critical flaws that allowed for prompt injection and data exfiltration from Google’s Gemini AI.  Learn why AI assistants are the new weak link.  Researchers have recently discovered three critical security flaws within Google’s Gemini AI assistant suite,[1] which they’ve dubbed the “Gemini Trifecta.”  These vulnerabilities, publicly disclosed around October 1, 2025, made Gemini vulnerable to prompt injection and data exfiltration, putting users at risk

13658112496?profile=RESIZE_400xResearchers from FortiGuard Labs recently uncovered an active delivery site that hosts a weaponized HTA script and silently drops the infostealer “NordDragonScan” into victims’ environments.  Once installed, NordDragonScan examines the host and copies documents, harvests entire Chrome and Firefox profiles, and takes screenshots.  The package is then sent over TLS to its command-and-control server, “kpuszkiev.com,” which also serves as a heartbeat server to confirm the victim is still online and