Highly sensitive personal information compiled via spyware targeting a European celebrity was publicly accessible until a security researcher discovered and reported the exposure.
The incident demonstrates the severe risks posed by stalkerware—surveillance software designed to monitor targets without consent. The exposed dataset included intimate details that could enable harassment, blackmail, or physical harm.
A researcher identified the publicly accessible data and notified relevant parties, prompting its removal. The exposure highlights a critical vulnerability: even when spyware successfully infiltrates a device, poor data security practices by attackers or third parties can compound the damage.
Stalkerware remains a persistent threat, often deployed by intimate partners or individuals with physical access to targets' devices. Unlike traditional malware, it operates with the victim's initial access credentials, making detection difficult.
The case underscores the need for stronger device security practices, including regular password changes, two-factor authentication, and monitoring for unauthorized app installations. Privacy advocates continue pushing for stricter regulations on stalkerware distribution and sales.
Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.
Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.
Security research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.
More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.