Data exfiltration stories
Supply chain attacks are pushing cyber risk upstream, putting managed service providers under pressure from customers and regulators over shared access.
Stolen credentials and AI-generated phishing are accelerating attacks, as Flashpoint tracked 22 million illicit discussions and 7.4 million infected hosts.
More groups are now driving attacks, leaving victim numbers flat even as ransomware operations reached a record 93 active crews in the quarter.
Ransomware victims jumped 49% in July, while organisations worldwide also faced 16% more cyber attacks year on year.
Organisations still miss most stealthy intrusions after logins, as Picus found only 14% of simulated attacks triggered alerts and exfiltration defence was 7%.
By blocking stolen-logins abuse at file level, the new feature aims to curb both data theft and ransomware even after an account is compromised.
Fragmented defences are leaving most security teams unable to trace sensitive data after incidents, according to Netskope research.
Prompt-injection attacks and data leaks are the main risks as businesses connect Copilot and Gemini to email, files and internal tools.
Businesses using AI agents face new risks of data leakage and malicious actions as ESET folds detection into its PROTECT platform.
Security teams face a wider visibility gap as Tenable adds Google Gemini, MCP and AI coding tools to its exposure management platform.
Boards are under pressure to curb staff use of ChatGPT and similar tools, as pasted data could expose customer records and source code.
Security teams face a sharper risk from hidden AI agents as Cyera says non-human identities in Fortune 500 companies jumped 480% in six months.
Misconfigured test setups let three Claude models touch live systems, exposing production data and credentials during security exercises.
Defenders now face a 48-hour window after proof-of-concept code appears, as attackers use AI to speed exploits and hit software chains.
Undisclosed attacks now dominate ransomware activity, with 2,027 incidents logged in the quarter and data theft reported in 97% of disclosed cases.
Faster digital payments are leaving fintech firms exposed as regulators and attackers pressure weak controls and resilience across the sector.
Many AI agents can already reach far more sensitive corporate data than staff, prompting Bedrock Data to add real-time access controls.
Up to 85 government accounts were compromised in a four-day campaign that also reached nuclear and energy organisations, researchers said.
Security teams can now stop rogue enterprise AI agents in seconds as Straiker adds runtime controls to its wider testing platform.
Security teams face new exposure as AI agents inherit permissions and move data across business systems, Reco says.