1 link tagged with all of: data-breach + supply-chain + ai-attacks + email-spoofing + security-tools
Links
This daily roundup covers a 40 GB data breach at the University of Nottingham, a lost-drive incident exposing 10.9 million Japanese utility customers, and a proof-of-concept Exchange spoofing flaw. It also highlights automated AI-driven attack research, supply-chain toolkits on GitHub, and new product launches for dependency patching and taint analysis.
- ShinyHunters exploited a zero-day gadget chain in University of Nottingham's PeopleSoft to steal 40GB of data on 454,600 students, including passport numbers and disability details.
- Kyushu Electric Power lost a physical backup drive exposing personal and usage data for 10.9 million customers.
- InfoGuard's "Ghost-Sender" exploit spoofs any Exchange Online address (even CEO/noreply) via a one-line PowerShell script, bypassing SPF, DKIM, and DMARC.
- A researcher earned over $500,000 in bug bounties using an AI-driven fuzzer to scrape thousands of Google API keys and find leaky internal-only endpoints.
data-breach
ai-attacks
supply-chain
email-spoofing
security-tools