##DataExfiltration
September 23, 2026 at 5:49 AM
The hunters just became the hunted.

ShinyHunters claims to have taken down Clop’s darknet site. BlackFog CEO Dr. Darren Williams explains why it matters for stolen corporate data.

cybermagazine.com/news/why-did...

#Cybersecurity #Ransomware #DataExfiltration
Why did ShinyHunters Take Down Clop's Darknet site?
BlackFog CEO Darren Williams warns of new risks as ShinyHunters hacks rival Clop, whose site displayed: “Domain Seized By ShinyHunters”
cybermagazine.com
September 22, 2026 at 3:15 PM
📰 CISA Perintahkan Pemerintah AS Patch Celah Zyxel GS1900 yang Aktif Dieksploitasi

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/22/cisa-zyxel-gs1900-cve-2026-7273-dieksploitasi/

#activeExploitation #cisa #cve-2026-7273 #cybersecurity #dataExfiltration #dataTheft #exploit #fi
September 22, 2026 at 1:27 PM
TASK#STOMP backdoor steals files, Wi-Fi, clipboard via stealthy PowerShell & scheduler misuse. #Malware #PowerShell #Security #EndpointSecurity #DataExfiltration #ThreatIntel thedailytechfeed.com/powershell-b...
September 21, 2026 at 2:43 PM
Is your team's shadow AI a productivity boost or a security time bomb? 💣

We all know the benefits of AI; but when employees use unapproved tools, your data is at risk.

#ShadowAI #AISecurity #DataExfiltration #CyberSecurity #DataProtection #KootekConsulting
September 2, 2026 at 1:00 PM
Cyber Alert in Automotive
JLR crippled by cyberattack, Stellantis hit via Salesforce breach. Dr. Darren Williams, CEO @BlackFog: “Data is the real prize. Unless we stop the flow, ransomware is just the tip of the iceberg.”

Read more: www.ien.com/operations/a...

#CyberSecurity #DataExfiltration
As Jaguar Land Rover Struggles to Restart Production, Stellantis Faces Breach Linked to Salesforce
Jaguar Land Rover faces extended production shutdown due to cyber attack, with potential losses of $67.6 million weekly and far-reaching supply chain impacts.
www.ien.com
September 24, 2025 at 1:54 PM
GhostSplice attack uses malicious MCP servers to exploit BO coding agents, leading to covert data exfiltration. #AI #PotatoSecurity #MCP #DataExfiltration #GhostSplice #AIAgents https://thedailytechfeed.com/malicious-mcp-servers-exploit-ai-coding-agents-to-exfiltrate-sensitive-data/
August 11, 2026 at 10:59 AM
📰 DeadLock Ransomware Memanfaatkan Blockchain untuk Menahan Upaya Takedown Infrastruktur

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/12/deadlock-ransomware-blockchain/

#bit
co#bitcoink#blockchaine#curve25519r#cyberAttackr#cybersecurityB#dataBreachE#dataExfiltrationl#deadlock#doub
August 12, 2026 at 8:31 AM
Microsoft probing if DeepSeek-linked group improperly obtained OpenAI data
• Microsoft notified OpenAI of activity that may violate terms
• Individuals were observed exfiltrating data using OpenAI
archive.ph/76oCX #communism #DataExfiltration #AI #DeepSeek
January 30, 2025 at 10:45 AM
Indirect prompt injection hides covert commands in normal web pages, manipulating LLM agents for payment fraud, data theft, and DoS attacks. Research reveals hidden payloads in text, comments, and metadata. #IndirectPrompt #DataExfiltration #USA
Indirect prompt injection is taking hold in the wild - Help Net Security
The open web is filling with hidden “traps” called indirect prompt injection (IPI) that embed covert instructions in ordinary pages to manipulate LLM-powered agents. Google and Forcepoint research documents real-world IPI examples—from benign prompts to payment fraud, data exfiltration, DoS and destructive commands—and shows attackers hide payloads in invisible text, comments and metadata. #IndirectPromptInjection #Forcepoint
www.hendryadrian.com
April 25, 2026 at 5:00 AM
GhostSplice attack uses malicious MCP servers to exploit AI coding agents, leading to covert data exfiltration. #AI #CyberSecurity #MCP #DataExfiltration #GhostSplice #AIAgents https://thedailytechfeed.com/malicious-mcp-servers-exploit-ai-coding-agents-to-exfiltrate-sensitive-data/
August 11, 2026 at 10:59 AM
TrojPix enables rapid data exfiltration from air-gapped computers via video cable emissions, posing new security challenges. #TrojPix #AirGap #CyberSecurity #DataExfiltration thedailytechfeed.com/trojpix-atta...
July 6, 2026 at 11:47 AM
Critical RCE vulnerability found in Cl0p ransomware's data exfiltration tool. Even cybercriminals aren't immune to security flaws. #CyberSecurity #Ransomware #Cl0p #DataExfiltration Link: thedailytechfeed.com/critical-vul...
July 3, 2025 at 3:40 PM
Scattered Spider has been making headlines.
New ransomware tactics, rising enterprise targets, and growing impact.

📊 Get the full breakdown + how to stay ahead:
👉 www.blackfog.com/scattered-sp...

#CyberSecurity #Ransomware #ThreatIntel #BlackFog #DataExfiltration #CISO
Scattered Spider’s Expanding Web of Ransomware Attacks | BlackFog
Scattered Spider led 2024–2025 attacks on retailers, insurers & airlines using social engineering, identity theft and ransomware.
www.blackfog.com
July 22, 2025 at 12:43 PM
February 27, 2025 at 6:32 PM
New research from Proofpoint ‼️

Threat actors are using #phishing tactics to trick users into giving access to #M365 accounts.

⚠️ Successful compromise leads to #accounttakeover, #dataexfiltration, and more.

Blog: brnw.ch/21wYtcM

Here’s what you need to know. 🧵⤵️
December 18, 2025 at 4:56 PM
A single click mounted a covert, multistage attack against Copilot https://arstechni.ca... #dataexfiltration #promptinjections #Security #copilot #Biz&IT #LLMs #AI
January 15, 2026 at 12:01 AM
Security Researchers Warn of ‘Reprompt’ Flaw That Turns AI Assistants Into Silent Data Leaks #ArtificialIntelligence #CyberSecurity #DataExfiltration
Security Researchers Warn of ‘Reprompt’ Flaw That Turns AI Assistants Into Silent Data Leaks
  Cybersecurity researchers have revealed a newly identified attack technique that shows how artificial intelligence chatbots can be manipulated to leak sensitive information with minimal user involvement. The method, known as Reprompt, demonstrates how attackers could extract data from AI assistants such as Microsoft Copilot through a single click on a legitimate-looking link, while bypassing standard enterprise security protections. According to researchers, the attack requires no malicious software, plugins, or continued interaction. Once a user clicks the link, the attacker can retain control of the chatbot session even if the chat window is closed, allowing information to be quietly transmitted without the user’s awareness. The issue was disclosed responsibly, and Microsoft has since addressed the vulnerability. The company confirmed that enterprise users of Microsoft 365 Copilot are not affected. At a technical level, Reprompt relies on a chain of design weaknesses. Attackers first embed instructions into a Copilot web link using a standard query parameter. These instructions are crafted to bypass safeguards that are designed to prevent direct data exposure by exploiting the fact that certain protections apply only to the initial request. From there, the attacker can trigger a continuous exchange between Copilot and an external server, enabling hidden and ongoing data extraction. In a realistic scenario, a target might receive an email containing what appears to be a legitimate Copilot link. Clicking it would cause Copilot to execute instructions embedded in the URL. The attacker could then repeatedly issue follow-up commands remotely, prompting the chatbot to summarize recently accessed files, infer personal details, or reveal contextual information. Because these later instructions are delivered dynamically, it becomes difficult to determine what data is being accessed by examining the original prompt alone. Researchers note that this effectively turns Copilot into an invisible channel for data exfiltration, without requiring user-entered prompts, extensions, or system connectors. The underlying issue reflects a broader limitation in large language models: their inability to reliably distinguish between trusted user instructions and commands embedded in untrusted data, enabling indirect prompt injection attacks. The Reprompt disclosure coincides with the identification of multiple other techniques targeting AI-powered tools. Some attacks exploit chatbot connections to third-party applications, enabling zero-interaction data leaks or long-term persistence by injecting instructions into AI memory. Others abuse confirmation prompts, turning human oversight mechanisms into attack vectors, particularly in development environments. Researchers have also shown how hidden instructions can be planted in shared documents, calendar invites, or emails to extract corporate data, and how AI browsers can be manipulated to bypass built-in prompt injection defenses. Beyond software, hardware-level risks have been identified, where attackers with server access may infer sensitive information by observing timing patterns in machine learning accelerators. Additional findings include abuses of trusted AI communication protocols to drain computing resources, trigger hidden tool actions, or inject persistent behavior, as well as spreadsheet-based attacks that generate unsafe formulas capable of exporting user data. In some cases, attackers could manipulate AI development platforms to alter spending controls or leak access credentials, enabling stealthy financial abuse. Taken together, the research underlines that prompt injection remains a persistent and evolving risk. Experts recommend layered security defenses, limiting AI privileges, and restricting access to sensitive systems. Users are also advised to avoid clicking unsolicited AI-related links and to be cautious about sharing personal or confidential information in chatbot conversations. As AI systems gain broader access to corporate data and greater autonomy, researchers warn that the potential impact of a single vulnerability increases substantially, underscoring the need for careful deployment, continuous monitoring, and ongoing security research.
dlvr.it
January 16, 2026 at 5:24 PM
Security Experts Warn of Audio Leakage Through Gaming Mice #CyberSecurity #Cyberthreats #DataExfiltration
Security Experts Warn of Audio Leakage Through Gaming Mice
  A startling discovery has been made in a study by researchers at UCI, which pertains to a rare side-channel risk associated with high-performance optical mice. The study found that the sensors and polling rates that enable precision can also be used as clandestine acoustic detectors. Known as Mic-E-Mouse, the technique involves reconstructing nearby speech from the minute vibrations that are recorded by sensors in mice with a DPI rating over 20,000; by applying advanced signal-processing pipelines and machine-learning enhancements, the research team proved that recognizable speech and intelligible audio could be recovered from raw data collected by mice packets.  A critical aspect of the attack is that it requires only a vulnerability on the host computer that can be accessed through the use of high-frequency mouse readings-a capability readily found in many creative applications, games, and even seemingly benign web interfaces-before the harvested packets can be exfiltrated and processed off-site using the exploitation of high-frequency mouse readings.  Considering that top-tier gaming mice have become increasingly affordable, the findings highlight a widening attack surface in everyday consumer hardware and underscore how manufacturers and security teams must consider reevaluating their assumptions about peripheral trust and data exposure for everyday consumer hardware.  According to a recent study published by a team of researchers at the University of California, Irvine, the modern high DPI optical sensors - designed for flawless precision in gaming and creative applications - can actually act as sophisticated listening devices inadvertently.   As a result of the “Mic-E-Mouse” experiment, it was discovered that these sensors, particularly those with a resolution exceeding 20,000 DPI, have been found to be capable of detecting imperceptible desk vibrations induced by nearby speech and to reconstruct audio under controlled conditions with a rate of 42 to 61 percent accuracy by combining advanced signal processing and neural network models.  There is no need to install malicious software or acquire administrative privileges for this exploitation, unlike traditional surveillance methods. Almost any legitimate application that can access mouse data in high frequency – such as games, design tools, or even routine productivity tools – can be used to harvest raw sensor readings by using high-frequency mouse data.  It is possible to transmit these data streams off-site for audio reconstruction without alerting the user, so that they can appear indistinguishable from regular input traffic. What makes this discovery particularly troubling is that it is easily accessible to anyone: gaming mice are now available for a price of under thirty dollars, resulting in a technology that is able to sit innocuously on millions of desks around the world.  In many cases, these devices, once trusted to enhance precision and performance, may now, unknowingly, be used as channels of covert eavesdropping - changing the very devices designed to maximize digital efficiency into instruments of eavesdropping. It is the responsibility of Habib Fakih, Rahul Dharmaji, Youssef Mahmoud, Halima Bouzidi, and Mohammad Abdullah Al Faruque, a team from the Department of Electrical Engineering and Computer Science at the University of California, Irvine, to a detailed study published on arXiv on September 16, 2025, that outlines the technical framework that underpins this unconventional method of eavesdropping.  It was developed by the researchers that they could convert shifting, seemingly random data associated with mouse movements into discernible audio signals by using a sophisticated, multi-phase pipeline. A significant improvement in signal clarity of +19 dB was achieved by systematically filtering noise and reconstructed speech patterns through advanced signal processing and machine learning algorithms. Speech recognition accuracy ranged between 42% and 61% across standard speech datasets, with the system performing systematically filtering noise, reconstructing speech patterns, and regenerating speech patterns.  In particular, what makes this attack especially insidious is that it is straightforward: you do not have to install malware, escalate privileges, or use complex intrusion techniques. This method requires merely access to high-frequency mouse data, which is usually obtained through legitimate applications such as creative software or gaming platforms that require real-time input from the user.  It is almost impossible to differentiate the entire data collection process from normal mouse activity in the background, which is completely undetectable, while the audio reconstruction can take place remotely on an attacker's server, which is completely invisible in the background. It is crucial that hardware manufacturers introduce safeguards against this novel form of exploitation to prevent this form of exploitation from taking place in the future, as demonstrated by a video proof-of-concept released by the research team.   According to the researchers, the implications of this study go beyond the lab as well—widely available high-DPI mouse products at affordable prices mean millions of devices in homes and offices could inadvertently become surveillance tools. It is clear from these findings that technological advancements often come with unforeseen vulnerabilities, which highlights how technological advancement can often lead to unexpected failures.  It is a multi-stage system which uses subtle desk vibrations to translate normal mouse sensor data into audible speech through a multi-stage process. It was designed by the researchers to collect non-uniform motion data from high-definition (DPI) sensors, then to apply advanced signal processing techniques like Wiener filtering to suppress noise and isolate meaningful vibration patterns based on this data.  An artificial neural network that is trained on existing speech datasets reconstructs intelligible audio from these filtered signals, thereby increasing the signal-to-noise ratio by as much as 19 decibels in controlled test environments. The researchers also discovered that the effectiveness of the attack was heavily influenced by the environment.  Softer material surfaces, such as paper or plastic, proved to transmit vibrations more effectively than denser materials, such as thick cardboard or rigid desks, while the most accurate results were achieved with normal conversational speech levels from 60 to 80 decibels. In the paper’s appendix, 26 models of mouse – which cost between $35 and $350 – have been identified as vulnerable to this type of exploitation as they continue to push for higher sensor precision at lower costs.  While the potential exposure to these sensors does extend beyond individuals, there are increasing risks that can be posed to corporations, government, and military organizations. According to the researchers, Mic-E-Mouse is a vector within a larger threat model of data exfiltration. In order to protect against this threat, defenders need to consider a combination of technical and procedural countermeasures.  These measures include limiting high-frequency polling rates in enterprise software, monitoring applications that transmit raw HID telemetry, implementing tight policies regarding endpoints and USB drives, and installing vibration-damping surfaces at sensitive areas. As part of their advocacy, they suggest collaborating with hardware vendors in order to introduce firmware-level randomization, as well as better API documentation, to prevent unauthorized high-frequency sampling from happening. The study reinforces the conclusion of a critical security study: the physical environment becomes a potential data channel as consumer sensors become more sensitive, which modern security architectures need to be able to counter. Researchers at UC Irvine created an experiment where they captured raw, noisy motion data from a high-DPI optical mouse sensor while simultaneously replaying speech in order to test the sensor's ability to detect vibration-based acoustic signals.  A number of factors contributed to the low quality of the initial data traces, including non-uniform sampling, quantization errors, and frequency limitations inherent in consumer hardware systems. Using machine-learning methods in combination with filters that remove background noise, correct any inconsistencies in the sampling process, and utilize sampling inconsistencies to reconstruct distinct audio signals, the researchers were able to overcome these challenges.  There has been a significant improvement in signal quality, with gains of up to +19 decibels, as well as speech recognition performances that are capable of extracting meaningful phrases and context-a significant advantage for the intelligence community as well as privacy officials.   An interesting aspect of this exploit is that it does not require the access to privileged permissions or operating system audio interfaces; it just requires the ability to read and transmit HID packet data, a feature that a lot of legitimate applications already do. Because of this vulnerability, a wide range of environments are potentially vulnerable, from corporate offices to government workstations to home computers, and it can affect a wide range of environments.  A high-fidelity mouse on a desk could allow you to reconstruct conversations taking place at a desk where there was a high-fidelity mouse, for example, confidential meetings, strategic discussions, or private calls, without having to activate the microphone at all. A number of security experts argue that Mic-E-Mouse is essentially an extension of data exfiltration risk, which necessitates layered defenses.  As mitigations, risks should be reduced by limiting high-frequency pointer polling in enterprise software, monitoring raw HID traffic coming out of endpoints, tightening endpoint protection controls, and enforcing strict controls on USB device usage. A physical precaution is the use of vibration-damping mouse pads, and the use of peripherals with a lower DPI in sensitive areas to reduce the risk of exposure.  It is also recommended that manufacturers implement firmware-level randomization and greater API transparency, which allows operating systems to mediate high-frequency data requests by implementing firmware-level randomization. Having said that, the study emphasizes that this is an important part of a wider concern regarding cybersecurity: as everyday sensors become more powerful and affordable, they also open up unanticipated doors to data leaks, transforming even the most trusted peripheral devices into surveillance-related tools.  In light of the recent revelations regarding Mic-E-Mouse, it becomes increasingly evident that the advancement of consumer technology must be accompanied by a rigorous evolution in security awareness. As devices become smarter, faster, and more precise, they also become more susceptible to being misused in a way that is often undetected by conventional defense mechanisms.  It is evident from the UC Irvine team's findings that it is essential for hardware designers, software developers, and cybersecurity experts to collaborate in order to establish new standards for sensor privacy and data governance. In addition to immediate measures, organizations should foster a culture of “peripheral hygiene,” whereby every connected device is treated as a potential data source that must be validated and controlled.  By encouraging vendors to be transparent, integrating firmware-based safeguards, and educating users on emerging side-channel risks, it is possible to close the gap between innovation and exploitation. It is important to note that Mic-E-Mouse isn't just an isolated exploit—it is a warning shot signaling the very surface and sensors surrounding us have become a target of cybercrime. There is a thin line between performance and privacy, and vigilance rather than convenience should define the next phase of digital trust, since performance needs to be balanced against privacy.
dlvr.it
October 9, 2025 at 1:09 PM
Team Cymru uncovered an open directory on 5.78.84[.]144 exposing the full Beast ransomware toolkit, including Windows/Linux binaries, scripts to disable backups, and data exfiltration methods linked to BEAST LEAKS. #BeastRansomware #DataExfiltration
The Beast Returns: Analysis of a Beast Ransomware Server
Team Cymru discovered an open directory on 5.78.84[.]144 that contained a full Beast ransomware operator toolkit, revealing tools and binaries used across reconnaissance, credential theft, lateral movement, exfiltration, and cleanup. The collection included Windows and Linux Beast binaries, scripts to disable backups and wipe traces, and evidence of data exfiltration workflows...
www.hendryadrian.com
April 6, 2026 at 6:00 AM
Data Exfiltration - I have just completed this room! Check it out: tryhackme.com/room/dataxex... #tryhackme #DNSexfiltration #ICMPexfiltration #DNSTunneling #HTTPTunneling #DataExfiltration #dataxexfilt via
@realtryhackme
TryHackMe | Cyber Security Training
An online platform for learning and teaching cyber security, all through your browser.
tryhackme.com
December 20, 2023 at 3:40 PM
Microsoft patched the Copilot Studio prompt‑injection bug, but data still slipped out. How bad is the leak and what does it mean for AI security? Dive into the details from Capsule Security’s Naor Paz. #CopilotStudio #PromptInjection #DataExfiltration

🔗 aidailypost.com/news/microso...
April 15, 2026 at 9:20 PM
FBI warns of North Korean IT workers using stolen identities to infiltrate companies, posing serious security threats. #CyberSecurity #NorthKorea #ITSecurity #InsiderThreats #DataExfiltration #FBI thedailytechfeed.com/fbi-warns-of...
July 31, 2026 at 2:03 PM
El lado del mal - OpenAI "Lockdown Mode" para luchar contra (la exfiltración de datos en ataques de) Prompt Injection www.elladodelmal.com/2026/06/open... #OpenAI #ChatGPT #AI #IA #PromptInjection #DataExfiltration #InteligenciaArtificial
OpenAI "Lockdown Mode" para luchar contra (la exfiltración de datos en ataques de) Prompt Injection
Blog personal de Chema Alonso ( https://MyPublicInbox.com/ChemaAlonso ): Ciberseguridad, IA, Innovación, Tecnología, Cómics & Cosas Personasles.
www.elladodelmal.com
June 8, 2026 at 5:05 AM