Data exfiltration stories
Shadow AI is prompting new controls for smaller businesses, as Acronis’s tool lets MSPs monitor unsanctioned AI use and block data leaks.
AI-driven attacks are pushing firms to hide systems from the public internet rather than rely on patching flaws after discovery.
New guidance aims to help firms curb data leakage and rogue actions as AI agents and models are embedded in daily operations.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Enterprises face a new security gap as AI agents spread without oversight, with one preview model finding attack paths in hours rather than days.
AI tools are creating hidden east-west traffic that security teams struggle to monitor, raising the risk of data leakage and compromise.
Malicious rules are helping hackers hide in Microsoft 365 inboxes, with Proofpoint saying it saw the tactic in 10% of taken-over accounts.
Attackers hid malware in familiar package workflows, prompting Sonatype to log 21,764 malicious open-source packages in the quarter.
Most firms are not ready for AI-driven API attacks, with Salt saying 92% have yet to reach advanced security maturity.
Visibility alone will not stop sensitive data leaking into AI tools, so security teams must turn DSPM findings into live controls and data lineage.
A Monday-morning Microsoft 365 login from Germany was flagged, letting a partner reset a compromised account before attackers could act.
It could cut migration cycles from days to minutes for firms modernising virtual estates, while keeping data in place for some VM moves.
Security researchers say long automated jobs can make Claude Code’s deny rules fall back to user prompts, weakening protections in CI/CD pipelines.
Victims in healthcare, education and finance have faced Medusa ransomware within 24 hours of flaws emerging, Microsoft says.
Malicious downloads can now be caught at runtime, as the new tool records hidden network calls and file writes before deployment.
Sensitive chats and uploaded files could have been quietly leaked from ChatGPT via DNS tunnelling before OpenAI fixed the flaw.
ThreatLabz says the latest Xloader strain uses layered encryption and decoy servers to frustrate analysts while stealing browser credentials.
Native checks will now flag prompt injection and data leakage across more of the AI agent stack as enterprises push systems into production.
Hospitals are paying up to avoid costly downtime, as criminals exploit known flaws and buy access for as little as USD $2,000.
Singapore’s digital economy faces rising pressure as attacks climbed 22% in March, far outpacing a 5% global decline.