Tag

Data Leak

All articles tagged with #data leak

Calendar invites expose private data through Google Gemini prompt injection
technology1 month ago

Calendar invites expose private data through Google Gemini prompt injection

Researchers demonstrated a prompt-injection attack against Google Gemini by embedding a malicious payload in a Google Calendar invite description. When the recipient asks Gemini about their schedule, the assistant executes the embedded instructions, creates a new event, and copies private meeting details into the event description, leaking sensitive data to the attacker. Google added mitigations after the disclosure, underscoring the need for context-aware defenses as AI assistants access calendar data.

Active Exploitation of Critical MongoDB Vulnerability CVE-2025-14847
database-security2 months ago

Active Exploitation of Critical MongoDB Vulnerability CVE-2025-14847

A critical vulnerability in MongoDB, CVE-2025-14847, allows unauthenticated attackers to remotely leak sensitive data by exploiting a flaw in zlib compression, with over 87,000 instances potentially affected worldwide. Users are advised to update their MongoDB versions and implement mitigations such as disabling zlib compression and restricting server exposure.

MongoBleed Vulnerability in MongoDB Now Actively Exploited in the Wild
technology2 months ago

MongoBleed Vulnerability in MongoDB Now Actively Exploited in the Wild

A critical security flaw called MongoBleed (CVE-2025-14847) in MongoDB servers is actively exploited in the wild, allowing attackers to leak sensitive data through malformed network packets before authentication, affecting many versions and exposing approximately 87,000 vulnerable instances worldwide. Immediate patching and monitoring are recommended.

Discord breach may have exposed 70,000 government IDs and data of 5.5 million users
technology4 months ago

Discord breach may have exposed 70,000 government IDs and data of 5.5 million users

Hackers claim to have stolen data of 5.5 million Discord users from the company's Zendesk support system, including government IDs and partial payment info, but Discord denies a breach and suggests the attack involved a compromised third-party support account. The hackers demand ransom and threaten to leak the data if not paid, while Discord states they will not reward illegal actions.

ShinyHunters Claims Massive Salesforce Data Breach and Extortion
cybersecurity4 months ago

ShinyHunters Claims Massive Salesforce Data Breach and Extortion

An extortion group called ShinyHunters, along with associated groups, has launched a website leaking data from 39 companies affected by Salesforce breaches, threatening to release personal data unless ransom demands are met. The attacks involved voice phishing and OAuth token theft, impacting major corporations like Google, Disney, and IKEA, with the group warning of further extortion campaigns.

Lovense Faces Privacy Breach with User Email Leak and Account Risks
technology7 months ago

Lovense Faces Privacy Breach with User Email Leak and Account Risks

Lovense, a major maker of internet-connected sex toys, failed to fully fix security flaws that exposed users' email addresses and allowed account takeovers, risking privacy and safety, especially for vulnerable users like cam models. The bugs were disclosed by security researcher BobDaHacker, who received a bug bounty but went public after Lovense delayed fixing the issues for 14 months.

UK secretly relocated thousands of Afghans and kept the public in the dark
world7 months ago

UK secretly relocated thousands of Afghans and kept the public in the dark

Thousands of Afghans who worked with British forces were secretly relocated to the UK, but their personal data was leaked, causing fear for their safety as they face potential threats from the Taliban. The UK government apologized for the data breach, which is considered one of the largest and most costly in British history, raising concerns about the safety of these refugees.