Engadget: Microsoft AI researchers mistakenly leaked 38TB of company data

Engadget: Microsoft AI researchers mistakenly leaked 38TB of company data. “A Microsoft AI research team that uploaded training data on GitHub in an effort to offer other researchers open-source code and AI models for image recognition inadvertently exposed 38TB of personal data. Wiz, a cybersecurity firm, discovered a link included in the files that contained backups of Microsoft employees’ computers. Those backups contained passwords to Microsoft services, secret keys and over 30,000 internal Teams messages from hundreds of the tech giant’s employees, Wiz says.”

American Songwriter: Kanye West Files Lawsuit Against Social Media Account Leaking His Music

American Songwriter: Kanye West Files Lawsuit Against Social Media Account Leaking His Music. “In the past year alone, Kanye West has been hit with about six lawsuits by paparazzo photographers, Boogie Down Productions, former brand partners at Adidas and Gap, and former employees at his Donda Academy. However, this week, he filed a suit of his own, alleging that a well-known hip-hop blog has been illegally leaking his music.”

Ars Technica: Hacker gains admin control of Sourcegraph and gives free access to the masses

Ars Technica: Hacker gains admin control of Sourcegraph and gives free access to the masses. “An unknown hacker gained administrative control of Sourcegraph, an AI-driven service used by developers at Uber, Reddit, Dropbox, and other companies, and used it to provide free access to resources that normally would have required payment.”

Bleeping Computer: BreachForums database and private chats for sale in hacker data breach

Bleeping Computer: BreachForums database and private chats for sale in hacker data breach. “While consumers are usually the ones worried about their information being exposed in data breaches, it’s now the hacker’s turn, as the notorious Breached cybercrime forum’s database is up for sale and member data shared with Have I Been Pwned.”

TechRadar: Thousands of Docker container images could be leaking security secrets

TechRadar: Thousands of Docker container images could be leaking security secrets. “A report from RWTH Aachen University in Germany analyzed more than 330,000 Docker Hub images, as well as thousands of private registries. The results showed 8.5% of the material hosting sensitive data, which could include private keys, or API secrets. As a result, online platforms and its users could be targeted by cybercriminals. In total, more than 52,000 private keys, and more than 3,100 unique API secrets were found exposed.”

The Register: Data leak at major law firm sets Australia’s government and elites scrambling

The Register: Data leak at major law firm sets Australia’s government and elites scrambling . “HWL Ebsworth is the kind of big-end-of-town law firm that attracts governments and large corporates as clients. Those clients are now scrambling to understand if their data has leaked. Australia’s federal government has reportedly established a task force to determine the extent of its exposure – which is thought to include some sensitive military material.”

How-To Geek: Toyota’s New Data Breach Affects 260,000 Car Owners

How-To Geek: Toyota’s New Data Breach Affects 260,000 Car Owners. “It’s been a wild few weeks for Toyota owners. If you happen to own a Toyota, you might want to keep reading, as the company has identified a data breach that affects hundreds of thousands of owners.”

Infosecurity Magazine: Retailer Database Error Leaks Over One Million Customer Records

Infosecurity Magazine: Retailer Database Error Leaks Over One Million Customer Records. “A database configuration error at a popular automotive retailer led to the exposure of 1TB of records, including customers’ personal information, according to WebsitePlanet. Security researcher Jeremiah Fowler reported the incident to the web-builder site, having traced the records to Philadelphia-based business SimpleTire.”

PC Magazine: Twitter Says ‘Security Incident’ Caused Circles Tweets Leak

PC Magazine: Twitter Says ‘Security Incident’ Caused Circles Tweets Leak. “Twitter has admitted that an incident where private tweets intended for posters’ close friends that ended up on strangers’ feeds happened because of a security breach, The Guardian reports(Opens in a new window). Twitter Circles permits users to set a list of close friends and post tweets that only they can read. The incident last month saw Circle tweets popping up in the For You timeline of users who followed the Circle tweet poster but aren’t in their Circle.”

Krebs on Security: Many Public Salesforce Sites are Leaking Private Data

Krebs on Security: Many Public Salesforce Sites are Leaking Private Data. “A shocking number of organizations — including banks and healthcare providers — are leaking private and sensitive information from their public Salesforce Community websites, KrebsOnSecurity has learned. The data exposures all stem from a misconfiguration in Salesforce Community that allows an unauthenticated user to access records that should only be available after logging in.”

Washington Post: Chinese hackers will ‘probably’ breach protected government networks within 5 years, leaked document says

Washington Post: Chinese hackers will ‘probably’ breach protected government networks within 5 years, leaked document says. “China’s government is testing capabilities to get around a cybersecurity model that the federal government has embraced — and that testing, combined with ‘advanced infiltration techniques,’ will ‘probably’ allow Chinese access to some government networks protected by the model within the next five years, according to a leaked classified document that hasn’t previously been reported.”

Inquirer: For weeks, PNP staff database was exposed – cyber expert

Inquirer (Philippines): For weeks, PNP staff database was exposed – cyber expert. “An unprotected database containing more than a million identity documents and private records of Philippine National Police personnel and applicants was exposed online for at least six weeks before access to the data was restricted in March, according to a report by a cybersecurity tracker.”

New York Times: New Leaked Documents Show Broad Infighting Among Russian Officials

New York Times: New Leaked Documents Show Broad Infighting Among Russian Officials. “The new batch, which contains 27 pages, reinforces how deeply American spy agencies have penetrated nearly every aspect of the Russian intelligence apparatus and military command structure. It also shows that the breach of American intelligence agencies could contain far more material than previously understood.”

Washington Post: Leaker of U.S. secret documents worked on military base, friend says

Washington Post: Leaker of U.S. secret documents worked on military base, friend says. “The man behind a massive leak of U.S. government secrets that has exposed spying on allies, revealed the grim prospects for Ukraine’s war with Russia and ignited diplomatic fires for the White House is a young, charismatic gun enthusiast who shared highly classified documents with a group of far-flung acquaintances searching for companionship amid the isolation of the pandemic.”

Bleeping Computer: Kodi discloses data breach after forum database for sale online

Bleeping Computer: Kodi discloses data breach after forum database for sale online. “The Kodi Foundation has disclosed a data breach after hackers stole the organization’s MyBB forum database containing user data and private messages and attempted to sell it online. Kodi is a cross-platform open-source media player, organizer, and streaming suite, that supports a vast array of third-party add-ons enabling the users to access content from various sources or customize their experience.”