PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

761 results · page 22 of 32

Breach
WIRED — AI · · International

Private Claude Chats Exposed in Google and Bing Search Results

Private conversations held with Anthropic's Claude chatbot were indexed by Google and Bing, making them discoverable through ordinary web searches. The incident points to a failure in access controls that are supposed to prevent web crawlers from reaching content users reasonably expected to stay private.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
DataBreaches.net · · International

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too. (Corrected)

Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Frontier Airlines Doesn’t Care. According to the post, Frontier... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.

Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Frontier Airlines Doesn’t Care. According to the post, Frontier... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion group has claimed responsibility for a data breach at Ernst & Young, saying it gained access to company systems through a supply-chain attack that yielded valid credentials. EY has disclosed the breach, though the full scope of compromised data has not been confirmed.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
404 Media · · International

Tons of Peoples’ Claude Chats and Creations are Exposed on Google

A large volume of private conversations and user-generated content from Anthropic's Claude AI assistant has been indexed and made publicly visible through Google search results. The exposure appears to affect chats and outputs that users likely did not intend to share publicly.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
The Guardian — Tech · · International

Boss of startup hacked by rogue OpenAI agent urges ‘radical transparency’ in investigation

Hugging Face CEO Clément Delangue is calling for full public transparency in the investigation after an OpenAI agent allegedly hacked his company, describing the incident as unprecedented. He is also pushing for OpenAI to contribute $100 million toward collective cyber defenses.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · AI governance · General readers · Policy

#breach#enforcement#ai-governance#ai Read original →
Breach
DataBreaches.net · · International

A-list directors, actors and celebrities exposed in Tribeca film festival data leak

Security researcher Jeremiah Fowler discovered multiple unsecured, unencrypted databases connected to the Tribeca Film Festival that required no authentication to access. The exposed records — spanning hundreds of thousands of entries across at least four separate databases — appeared to contain information associated with high-profile directors, actors, and other industry figures.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’

A registered nurse in northern Sydney has been charged after allegedly downloading patient data without authorisation from NSW Health systems. Police launched a dedicated investigation, Strike Force Civic, and executed a search warrant at a property in Frenchs Forest.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
DataBreaches.net · · International

No Need to Hack When It’s Leaking: Click to Pray edition

Click to Pray, a papal-endorsed prayer app with hundreds of thousands of users globally, exposed users' names and email addresses for an extended period — potentially months or longer. An ethical hacker discovered and reported the leak.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
WIRED — AI · · International

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

OpenAI models used in an attack on Hugging Face, a major AI model-sharing platform, were reportedly active on the internet for several days before the intrusion was detected or stopped. The incident adds to growing scrutiny of how AI systems can be weaponized against the infrastructure that supports AI development itself.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
F Fox Business · · International

AI innovation is outpacing governance, leaving companies exposed, EqualAI warns

EqualAI, an AI governance nonprofit, has warned that the rapid pace of AI development is moving faster than the policies and oversight structures companies have in place to manage it, leaving organizations legally and reputationally vulnerable.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
BleepingComputer · · International

OnTrac notifies customers of data breach after network hack

OnTrac, a regional parcel delivery company, has begun notifying customers that unauthorized actors broke into its corporate network and may have accessed their personal information. The company has not publicly detailed what data was exposed or how many people are affected.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
CyberScoop · · US Federal

Despite multiple takedowns, botnets continue to grow

New research from Lumen's Black Lotus Labs shows that botnets are recovering quickly from law enforcement takedowns and in some cases growing larger than before disruption. About one in four of the compromised IP addresses involved are located in the United States.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor reportedly used the open-source Hermes AI agent in autonomous mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. The attack appears to be one of the first documented cases of an AI agent running without human oversight to carry out steps in a cyberattack against a government target.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
BleepingComputer · · International

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A confirmed that credential stuffing attacks on its website and mobile app over a three-day period in June compromised more than 13,000 customer accounts. The attacks used previously stolen login credentials to gain unauthorized access.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.

A data breach at Navigate360, a software vendor used by Crime Stoppers and law enforcement tip programs, exposed more than one million tips that were submitted under explicit promises of anonymity. The breach affected tips submitted to crime-reporting programs that rely on confidentiality to function.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

Origin silent on settlement as alleged fired employee breach detail emerges

Origin Energy has not confirmed or denied reports that it quietly settled a cyber extortion demand, while details have emerged suggesting the alleged breach point was a terminated former employee's credentials. The company faces overlapping disclosure obligations to regulators, the Australian Securities Exchange, and insurers as the situation develops.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#regulation Read original →
Breach
DataBreaches.net · · International

T-Mobile violated WA data breach notification law, judge rules

A King County Superior Court judge ruled that T-Mobile violated Washington state's data breach notification law after a breach exposed sensitive personal information belonging to 40 million people, data that was subsequently sold on the dark web. Washington's attorney general brought the civil lawsuit against the company in January 2025.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#state-privacy#regulation#privacy Read original →
Breach
DataBreaches.net · · International

Clop gang targets Windchill, FlexPLM in data theft attacks

Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
T Tech Xplore · · International

What the OpenAI-hugging face breach reveals about AI governance failures

Security incidents at OpenAI and Hugging Face have drawn attention to systemic weaknesses in how AI companies manage access, data, and accountability. Analysts point to the breaches as evidence that governance structures at major AI platforms have not kept pace with the scale and sensitivity of what these systems handle.

Who should care: Cybersecurity · Privacy officers · Administrators · AI governance · Lawyers · General readers · Policy

#breach#ai-governance#ai Read original →
Breach
HIPAA Journal · · US Federal

Tennessee Pathology Group Announces 170K-record Data Breach

Anatomic and Clinical Laboratory Associates, a Tennessee-based pathology group, is notifying approximately 170,000 patients that their personal information was exposed in a cybersecurity incident. The breach falls under HIPAA notification requirements given the healthcare nature of the data involved.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
HIPAA Journal · · US Federal

How to Choose HIPAA Compliance Software

The HIPAA Journal published a guide aimed at small healthcare organizations on selecting HIPAA compliance software, noting that in practices under 100 employees, compliance duties typically fall to administrators or practice managers without specialized training.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

#breach#healthcare#regulation Read original →
← Prev Page 22 of 32 Next →