ISC2 domain 2
Asset Security
The information itself: classification, retention and deletion, and incidents where it is the data that goes astray.
News
21 articles in this subject area
Records are being pulled from Salesforce and ServiceNow portals that need no login
Reco is tracking an ongoing campaign it calls City-Forum, in which a single tool written in Go pulls records from customer portals in Salesforce Experience Cloud and ServiceNow. All the traffic comes from one server that has been standing since March 2025, and the targets include telecoms, banks, software vendors and public sector portals.
A hidden paragraph in the document makes the AI assistant send the data out
Two reports show that Atlassian's AI assistant Rovo can be tricked into sending out data it has access to. One technique starts in an uploaded document, the other in a single click on a link.
Hidden instructions in Word make Copilot alter and spread documents
Researcher Håkon Måløy published an attack chain against Copilot for Word on 28 July 2026. Hidden instructions in an ordinary document make Copilot alter content and copy the payload into new documents. Microsoft has deployed several mitigations across 144 days of coordinated disclosure, without closing the vulnerability class.
DentaQuest discloses data breach affecting more than 23 million people
The ShinyHunters extortion group claims it stole 234 GB from dental benefits administrator DentaQuest and has published the data after failed negotiations. The company's notice states more than 23 million people are affected.
EY notifies clients after third-party platform breach
Attackers downloaded client documents containing identity and card details from a third-party platform EY used for tax work.
Extortion without encryption: Unit 42 on the new extortion economy
Palo Alto Unit 42 describes how data theft and extortion increasingly happen without any ransomware at all.
GitHub confirms theft of around 3,800 internal repositories
A GitHub employee was compromised by a malicious VSCode extension, and data from around 3,800 internal repositories was stolen.
Cloud keys and system details leaked in a public GitHub repository
A CISA contractor exposed AWS GovCloud credentials and internal system details in a public repository.
Microsoft issues mitigation advice for the YellowKey BitLocker bypass
YellowKey lets an attacker with physical access bypass BitLocker. Microsoft points to TPM with PIN and a WinRE registry change.
Trellix confirms unauthorised access to its source code repository
Trellix says attackers accessed part of its internal source code, with no evidence so far that the code was altered or leaked.
Anthropic exposed Claude source code through a packaging error
Hundreds of thousands of lines of code, internal APIs and design details were exposed through human error in an internal release process.
New payment skimming in web shops hides behind WebRTC
Sansec describes a technique where stolen payment data leaves through the browser's own real-time features, outside normal controls.
Telus Digital confirms breach after claim of a stolen petabyte
Outsourcing provider Telus Digital confirms a data breach in which ShinyHunters claims to have taken nearly one petabyte of data.
Researchers show LLM agents can identify who is behind anonymous posts
From a handful of comments, the language models inferred a poster's location, occupation and interests across different platforms.
Thirty fake AI extensions in Chrome harvested user data
LayerX has found 30 Chrome extensions posing as AI assistants that proxied user questions and data through their own infrastructure.
Code error let Copilot Chat summarise email that DLP should have blocked
A bug in Microsoft 365 Copilot Chat meant confidential email in Sent Items and Drafts could be summarised despite active DLP rules.
Former Google engineer convicted of stealing AI trade secrets
Linwei Ding has been convicted in the US of economic espionage after taking more than 2,000 confidential AI documents to a China-based startup.
Malicious VS Code extensions with 1.5 million installs stole source code
Koi Security found two extensions marketed as AI coding assistants that covertly profiled users and harvested files at scale.
Malicious Chrome extensions stole ChatGPT and Deepseek conversations
Ox Security found two Chrome extensions exfiltrating ChatGPT and Deepseek conversations every 30 minutes, along with all open tab URLs.
Ransomware is shifting from encryption to pure data theft
Morphisec describes how ransomware crews increasingly skip encryption and instead extract data quietly over weeks or months.
Free VPN extensions read AI conversations and run hidden code
Koi has found that popular browser extensions marketed as free VPNs collect AI conversations, and in one case hide executable code inside an icon file.