Normal view
-
Security – Cisco Blog
- Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
DHS Official Resigns, Citing ‘War on Immigrants’
Private Claude Chats Exposed in Google and Bing Search Results
-
/r/netsec - Information Security News & Discussion
- Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
-
ZDNet | security RSS
- Framework's new Pro modular laptop is everything I wanted (minus the cost of memory)
Framework's new Pro modular laptop is everything I wanted (minus the cost of memory)
New vBulletin Vulnerability!
CVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- From Google Ads to Terminal: Dissecting an Apple Support Impersonation Campaign Abusing Claude Share.
Weekly Update 514: This Week in Data Breaches
The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn't respond when I tried to report it", and now news that the two parties have "come to an agreement". Maybe money was paid, or maybe Origin made some promises to restrain the hounds if commitments about data deletion were made. But both outcomes, of course, provide no guarantee that data has been nuked, so now they get to spend perpetuity waiting for the data that maybe - just maybe - it leaks. And we all should be working on precisely that assumption, just like we did with Optus and Medibank and Latitude and Ticketek and Qantas...
References
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Chick-fil-A Data Breach Explained: What Customers Need to Know
This week in scams and cybersecurity news,
Chick-fil-A disclosed that hackers may have accessed customer loyalty accounts using stolen usernames and passwords leaked in previous breaches.
It’s a reminder that reusing passwords across websites can be dangerous and allow one breach to snowball into many others.
Here’s what happened and what customers need to know:
So How Did Hackers Breach Chick-fil-A?
Chick-fil-A is notifying customers in 10 states after a cyberattack targeted a limited number of Chick-fil-A One loyalty accounts.
According to multiple reports, attackers used a technique known as credential stuffing, in which criminals take usernames and passwords stolen in previous data breaches and automatically test them across other websites and apps.
If someone has reused the same password, attackers may be able to access additional accounts without ever hacking the company directly.
Chick-fil-A said the attackers may have accessed customer information including:
- Names and email addresses
- Chick-fil-A One membership numbers
- Mobile Pay numbers and QR codes
- The last four digits of stored payment cards
- Gift card balances
- Birth dates, phone numbers, and addresses (if customers stored them)
The company says it has logged affected users out of their accounts, removed stored payment methods, restored impacted rewards balances, and is notifying customers who may have been affected.
| Credential stuffing: |
| A cyberattack where criminals use usernames and passwords stolen in previous data breaches to automatically sign in to other websites and apps. If you’ve reused the same password across multiple accounts, one breach can give attackers access to many of them. |
| How to Protect Yourself: Use a unique password for every account, enable multi-factor authentication, and use a password manager to securely create and store strong passwords. |
How McAfee Helps Before, During, and After a Data Breach
Before a breach
Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.
Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.
Password Manager helps you create and securely store strong, unique passwords for every account, reducing the risk that one stolen password can unlock multiple accounts.
During a breach
Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.
Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.
After a breach
Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information.
Other Scam News This Week
Student loan scams are on the rise. Experts warn that changing federal student loan repayment rules are creating confusion that scammers are exploiting with fake debt relief offers, phishing emails, and identity theft schemes targeting borrowers. (PBS News)
AI agent reportedly carried out a cyberattack. AI platform Hugging Face says an autonomous AI agent executed a sophisticated attack against its internal systems from start to finish; an early example of AI taking on an active role in cyberattacks rather than simply assisting human hackers. (Axios)
Paidwork breach reportedly exposes 23 million users. Security researchers say data from the microtask platform may include names, addresses, phone numbers, bank account details, and password hashes, highlighting how even smaller online accounts can become valuable targets for cybercriminals. (Malwarebytes)
And we’ll be back next week with more news.
The post Chick-fil-A Data Breach Explained: What Customers Need to Know appeared first on McAfee Blog.
DEF CON Middle East Postponed
The Journey towards Logically Air-Gapped Deployment
-
/r/netsec - Information Security News & Discussion
- The way AI voice phishing gets demonstrated is making people worse at spotting it
The way AI voice phishing gets demonstrated is making people worse at spotting it
AI voice phishing isn't a cloned voice with a bot doing the talking. It's a human operator running a real time voice changer. Which matters, because every "how to spot a voice phishing / deepfake" tell is a text to speech artifact and none of them survive voice conversion.
Disclosure .. I build voice phishing simulation for a living, so I have a horse in this race. But to show exactly how a real time voice changer works, I built a free demo so people can hear one for themselves ..
Speak into it and you come back as someone else, live. No signup, capped at 60 seconds, and there's 8 cloud GPUs behind it doing the conversion so expect a queue. Five fixed identities to pick from .. deliberately not your own voice cloned back at you, because that's not the threat. You're hearing what an operator sounds like wearing someone else's voice. We've also seeded artifacts into the output audio so it cant be lifted and used for anything real.
[link] [comments]
Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere
-
/r/netsec - Information Security News & Discussion
- Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
-
/r/netsec - Information Security News & Discussion
- XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search
XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search
-
/r/netsec - Information Security News & Discussion
- Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
Caught this in three open directories on a Hong Kong server, exposed July 9 to 13. The agent is Hermes, open source, and the recovered logs show it running LinPEAS and walking a ministry web root without a human in the loop. Target was Thailand's Ministry of Finance.
[link] [comments]
For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark
-
Security – Cisco Blog
- Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall